Legal
Data Processing Addendum
Draft — pending legal review. These terms are published early so you can read what we intend to agree to before you install anything. They have not been reviewed by outside counsel and are not yet in force. Nothing here creates a contract until it is executed or you accept it at sign-up, and we will not apply a materially worse version to an existing customer without 30 days notice.
1. Scope and roles
This addendum forms part of the Terms of Service between SuperDiffs, Inc. (“Processor”) and the customer (“Controller”), and applies to the extent we process personal data on the Controller’s behalf under the UK GDPR, the EU GDPR, and equivalent laws.
| Data | Controller | Processor |
|---|---|---|
| Repository content and everything derived from it | You | Us |
| Your end users’ data that happens to appear in code or fixtures | You | Us |
| Account and billing data about your staff | Us | — |
| Marketing site analytics | Us | — |
We are a controller for the account relationship — see the Privacy Policy — and a processor for the content you point us at. Both are true at once, and the distinction decides which rules apply to which data.
2. What is processed
| Particular | Detail |
|---|---|
| Subject matter | Automated review of pull requests in repositories the Controller connects. |
| Duration | For the term of the agreement, plus the deletion window in section 11. |
| Nature and purpose | Retrieval, sandboxed analysis, transmission of relevant excerpts to model providers, generation and storage of findings, posting review comments back to the Controller’s repositories. |
| Categories of data subjects | The Controller’s developers and contributors; incidentally, any individual whose personal data appears inside repository content — for example in test fixtures, seed data, or commit metadata. |
| Categories of personal data | Identifiers (GitHub logins, names, email addresses in commit metadata) and any personal data the Controller places in its repositories. |
| Special category data | Not intentionally processed. The Controller should not place special category data in repositories connected to the service. |
3. Our obligations as processor
- Process personal data only on documented instructions from you. Your use of the service — which repositories you connect, and your configuration — is the primary instruction.
- Tell you if an instruction appears to breach data protection law, and pause rather than proceed.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement the security measures in section 6 and keep them at least as strong.
- Engage subprocessors only on the terms in section 5.
- Assist you with data subject requests, impact assessments and prior consultations.
- Notify you of personal data breaches under section 9.
- Delete or return personal data under section 11.
- Make available the information needed to demonstrate compliance, under section 10.
4. Your obligations as controller
- Have a lawful basis for the processing you instruct, and give the notices your own users are owed.
- Do not put special category data, payment card data, or health records into repositories connected to the service. Nothing in the product is designed for them.
- Configure path filters so that files you do not want processed are excluded. Filters are your control, and we cannot know that a directory is sensitive unless you say so.
- Manage who in your organisation has repository access, since that is what determines who can see our output.
5. Subprocessors
You give general authorisation for us to engage the subprocessors listed on the subprocessor page, which is incorporated here. We impose data protection obligations on each that are no less protective than this addendum, and we remain liable to you for their performance.
- We give 30 days notice before adding or replacing a subprocessor, by email to your billing contact and in the changelog.
- You may object on reasonable data protection grounds within that window. We will work with you to find an alternative; if there is none, you may terminate the affected part of the service and receive a pro-rata refund.
- 9 subprocessors are listed today, of which 2 are in use and the rest are planned and marked as such.
6. Security measures
The technical and organisational measures required by Article 32. These are the measures in force; where something is planned rather than in place, the trust centre says so rather than this page implying otherwise.
| Area | Measure |
|---|---|
| Encryption | TLS 1.2+ in transit. Encryption at rest for all stores; git bundles encrypted per installation. |
| Isolation | Analysis runs in a per-review disposable instance with default-deny egress. No customer code executes on hosts holding platform credentials. |
| Access control | Least privilege, SSO with mandatory multi-factor for staff, no shared accounts, production access logged and reviewed. |
| Credential handling | The GitHub App signing key is held in a hardware-backed key store and never enters an application process. Repository tokens are single-repository, read-only, one hour. |
| Secret redaction | Detected secrets are redacted before any prompt is constructed. |
| Segregation | Tenant scoping enforced at the data layer; every query is installation-scoped. |
| Resilience | Automated backups with tested restores; point-in-time recovery on the primary database. |
| Secure development | Mandatory review on our own changes, dependency and secret scanning in CI, and an external penetration test scheduled before general availability. |
| Personnel | Background checks where lawful, confidentiality agreements, security training at onboarding. |
7. International transfers
Primary processing is in the European Union. Where personal data is transferred to a country without an adequacy decision, the transfer relies on the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, with the UK International Data Transfer Addendum where the UK GDPR applies. Executing this addendum incorporates those clauses by reference.
For the purposes of the clauses: Annex I is section 2 of this addendum, Annex II is section 6, and Annex III is the subprocessor page. The docking clause applies, and the supervisory authority is that of the Controller’s main establishment.
8. Data subject requests
If a data subject contacts us about content we process for you, we will not respond substantively. We will pass the request to you within five working days and help you answer it — including by locating, exporting, correcting or deleting the data — at no additional charge for a reasonable volume of requests.
9. Personal data breaches
- We notify you without undue delay, and in any case within 72 hours of confirming a personal data breach affecting your data.
- The notification describes the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken or proposed.
- Where we cannot provide all of it at once, we send what we have and follow up in phases rather than waiting for a complete picture.
- We do not notify your regulators or your data subjects on your behalf unless you ask us to in writing.
10. Audit and information rights
- On request, no more than once a year, we provide the information reasonably needed to demonstrate compliance with this addendum — including our security documentation and, once it exists, our SOC 2 report.
- Where that is not sufficient for your regulator, you may audit us, or appoint an independent auditor who is not our competitor, on 30 days notice, during business hours, under confidentiality, and without unreasonable disruption. You bear the cost unless the audit finds material non-compliance.
- We will not grant access to other customers’ data, or to systems where such access could not be prevented, in the course of an audit.
Today there is no SOC 2 report. It is targeted before general availability, Type I first — stated the same way in the trust centre and here so the two cannot tell different stories.
11. Deletion and return
On uninstall or termination
All personal data processed on your behalf is deleted within 30 days through a single audited erasure pipeline covering the database, object storage, caches and search indexes. Backups age out on their own schedule, no longer than 35 days, and are not restored selectively to recover deleted tenant data.
Export first
Findings and review history can be exported from the dashboard while the account is active. We do not hold data hostage; equally, we will not keep it for you after you have asked us to stop.
12. Liability and precedence
Liability under this addendum is subject to the limitations in the Terms of Service, except where those limitations are prohibited by data protection law. If this addendum conflicts with the Terms, this addendum wins for matters of data protection. If it conflicts with the Standard Contractual Clauses, the clauses win.
13. How to execute this
Accepting the Terms of Service accepts this addendum. If your procurement process needs a countersigned copy, or your own paper instead, write to legal@superdiffs.com with the version you need and we will turn it around rather than insisting on ours.