Last updated: 6 October 2026
Data Processing Agreement
Between the customer and DataRBL AB, 559385-4754, Agavägen 64, 181 55 Lidingö, Sweden. Applies when the customer's repositories contain personal data, such as commit author names and email addresses.
1. Roles
The customer is the controller. DataRBL AB is the processor and processes personal data only on the customer's documented instructions, which are given by installing the GitHub App and running reviews.
2. Nature and purpose
Transient processing of repository contents and commit metadata to produce aggregated metrics about the codebase and the team.
3. Data subjects and data
- Data subjects: the customer's developers and other contributors to the repositories.
- Data: commit author names, email addresses and timestamps, processed in memory during a review and not stored.
- Stored: no personal data from repositories. Only aggregated metrics that describe the team as a whole.
4. Duration
For the duration of each review (typically under a few minutes). This agreement lasts as long as the customer uses the service.
5. Processor obligations
- Confidentiality: only authorised personnel bound by confidentiality have access.
- Security: the measures in section 7.
- Sub-processors: listed in the Subprocessors section below. We notify customers at least 30 days before adding or replacing one, and customers may object.
- Assistance: we help the customer respond to data subject requests and with impact assessments, to the extent the processing allows.
- Breaches: we notify the customer without undue delay and no later than 48 hours after becoming aware of a personal data breach.
- Deletion: at the end of the service, no repository personal data remains, as it is never stored.
- Audits: we make available the information needed to demonstrate compliance, and allow reasonable audits on request.
6. International transfers
Analysis runs on GitHub's hosted runners, which may be located outside the EU/EEA. Transfers are based on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses.
7. Technical and organisational measures
- Least privilege: the GitHub App has read-only access to contents and metadata of the repositories the customer selects.
- Ephemeral processing: each review runs on a fresh runner that is destroyed after the job; code is held in memory and never written to our storage.
- No code in logs: analysis logs never contain source code.
- Installation verification: an installation is only linked to an account after the signed-in GitHub user is verified to have access to it.
- Data isolation: row-level security ensures each account only sees its own data.
- Secrets: stored in an encrypted vault; never shared in plain text.
- Encryption: all traffic is encrypted in transit; data at rest is encrypted by our hosting provider.
- Access control: multi-factor authentication on administrative accounts.
Subprocessors
| Subprocessor | Purpose |
|---|---|
| Supabase | database and functions, EU - Frankfurt |
| GitHub | code analysis in GitHub Actions runners |
Stripe acts as merchant of record and is an independent controller for payment data; it is not a subprocessor.