Data Processing Addendum
Last updated: 2026-10-01
This Data Processing Addendum ("DPA") forms part of the Terms of Service between DevKit Srl, Via Teodoro Valfrè 11, 00165 Roma, Italy, VAT IT15026561009 ("DevKit", "we") and the customer named in the account ("you"). It applies where we process personal data on your behalf inside Customer Data, as Article 28 of Regulation (EU) 2016/679 (GDPR) requires. Terms with a capital letter have the meaning given in the Terms of Service; "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "supervisory authority" and "personal data breach" have the meaning given in the GDPR.
- Roles. For personal data inside Customer Data you are the controller and we are the processor. For account data, billing status, service logs and support messages we are an independent controller, as the Privacy Policy describes; this DPA does not cover them.
- Details of the processing. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
- Instructions. We process personal data inside Customer Data only on your documented instructions: this DPA, the Terms of Service, and your use of the features of the Service (uploading, matching, timelines, exports), including with regard to transfers (clause 9). We do not process it for our own purposes. Where the law of the European Union or a Member State to which we are subject requires other processing, we tell you of that legal requirement before the processing, unless that law prohibits it on important grounds of public interest. We tell you immediately if, in our opinion, an instruction infringes the GDPR or other data protection law of the European Union or a Member State, and may pause the instruction until it is confirmed or withdrawn.
- Confidentiality. Only persons who need access to operate the Service or to support you at your request have access to Customer Data, and each is bound by a confidentiality obligation. We do not read Customer Data except to operate the Service, to support you at your request, or where the law requires it.
- Security. We apply the technical and organisational measures in Annex II, taking into account the state of the art, the costs of implementation and the risks of the processing, as Article 32 GDPR requires. We may update them as long as the level of protection does not fall.
- Sub-processors. You give general authorisation to the sub-processors listed in Annex III. We tell you by email to your account's users at least 30 days before adding or replacing a sub-processor. You may object within that period on reasonable, documented grounds relating to data protection; if we cannot resolve the objection, you may end the affected subscription before the change takes effect, and we refund fees already paid for the period after it ends. We impose on every sub-processor, by contract, data protection obligations equivalent to this DPA, and we remain responsible to you for its performance.
- Assistance. Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in answering requests from data subjects who exercise their rights under Chapter III GDPR: the export features of the Service serve access and portability requests, we delete individual records as clause 10 says, and we forward to your account's users, without undue delay, any request that reaches us and concerns Customer Data. We also assist you, on request, in meeting your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation) with the information available to us.
- Personal data breach. We tell you of a personal data breach affecting Customer Data without undue delay after becoming aware of it, and no later than 48 hours after, by email to your account's users, with the information Article 33(3) GDPR requires as far as it is available, and provide the rest as it becomes known. Telling you of a breach is not an admission of fault.
- Transfers. Customer Data is stored in Frankfurt, Germany. We do not transfer personal data inside Customer Data outside the European Union or the European Economic Area, except through the sub-processors in Annex III and the safeguards named there: an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for certified companies, or the standard contractual clauses adopted by the Commission.
- Deletion and return. You can export all Customer Data at any time while your subscription is active and for 30 days after it ends, as the Terms of Service describe. We delete Customer Data within 90 days after the end of your subscription, and backup copies expire within 30 days after that; backups are used only to restore the Service as a whole, and after a restore we delete again what had been deleted since the backup was taken. Where the law of the European Union or a Member State requires us to keep data, we keep it only as long as required and process it for no other purpose. We delete individual records (a product, a version or an uploaded SBOM with everything recorded for it, or an Article 14 case) within 14 days of your request to support@devkit.dev.
- Information and audits. We make available to you the information needed to demonstrate compliance with Article 28 GDPR, on request, through this DPA, our documentation and the reports and certifications our sub-processors publish. Once in any 12-month period, and in addition where a supervisory authority requires it or after a personal data breach affecting Customer Data, on 30 days' written notice, you or an auditor you appoint and we accept on reasonable grounds may audit our compliance with this DPA, during business hours, under a confidentiality obligation, remotely where that suffices, and at your cost. We may charge for time spent beyond one working day per audit.
- Liability. Each party is liable for its own compliance with the GDPR. Our liability under this DPA is subject to the limits of the Terms of Service, to the extent the law permits.
- Term and precedence. This DPA applies as long as we process personal data inside Customer Data on your behalf, and survives the end of the Terms of Service until that processing ends. If this DPA and the Terms of Service conflict on data protection, this DPA prevails. Italian law governs, and the courts of Rome, Italy, have jurisdiction, as in the Terms of Service.
- Contact. Questions about this DPA and data protection: support@devkit.dev.
Annex I: details of the processing.
- Subject matter: the records you keep in the Service, that is software bills of materials (SBOMs), vulnerability findings matched to them, license inventories, the timeline of your handling decisions, Article 14 case records, and the exports made from them.
- Duration: the term of your subscription and the export and deletion periods after it (clause 10).
- Nature and purpose: storage, matching against public vulnerability data, display to the users of your account, and production of exports; all to provide the Service to you.
- Types of personal data: names, email addresses and account names of software authors, maintainers and your personnel where they appear in SBOM metadata, uploaded files, timeline entries and case records. The Service is not designed for special categories of personal data (Article 9 GDPR) or data of children; you agree not to upload them.
- Categories of data subjects: your employees and contractors, and the authors, maintainers and contacts of the software your records name.
Annex II: technical and organisational measures.
- Hosting in a datacenter in Frankfurt, Germany; backups kept in the same datacenter.
- Encrypted transport (TLS) for every connection to the Service and between the Service and its providers.
- Sign-in by email link and API keys; no passwords stored; API keys stored as hashes; each user can end all of their sessions and any user of the account can revoke its API keys; we remove a user from your account without undue delay on your request to support@devkit.dev.
- Access to Customer Data limited to each account's own users; the org boundary is enforced in every query and covered by automated tests.
- Access to production systems limited to named administrators with individual keys and to the deployment pipeline with a key of its own; secrets kept in a secrets manager, never in code.
- Access logs kept for 30 days and error reports for up to 90 days, configured to exclude request contents, user identities and IP addresses from error reports.
- Security updates to the server's operating system applied automatically every day; container images refreshed from their publishers at every release; dependencies checked every week against public vulnerability data.
- Availability monitoring with alerts to the administrators.
- Deletion of Customer Data at the end of the subscription, and of individual records on your request, within the periods in clause 10.
Annex III: sub-processors.
These providers process personal data inside Customer Data on our behalf:
| Provider | Purpose | Personal data | Location | Transfers outside the EU/EEA |
|---|---|---|---|---|
| DigitalOcean, LLC (USA) | Hosting of the Service, its database and backups | All Customer Data | Frankfurt, Germany; backups in the same datacenter | Data is stored in the EU. Access by DigitalOcean or its sub-processors from outside the EU relies on the EU-US Data Privacy Framework, with standard contractual clauses as fallback |
| AC PM LLC (Postmark, an ActiveCampaign company, USA) | Delivery of the emails the Service sends to your users: sign-in links, alerts and account notices | Alert emails name your products and versions and give finding counts and severities; they carry no component data. Recipient addresses are account data under the Privacy Policy | United States | EU-US Data Privacy Framework; standard contractual clauses as alternative |
| Functional Software, Inc. (Sentry, USA) | Error monitoring | Technical error reports, configured to exclude request contents, user identities and IP addresses | Frankfurt, Germany (Sentry EU data region); account metadata in the United States | EU-US Data Privacy Framework, with standard contractual clauses as fallback |
Paddle processes checkout and billing data as an independent controller under its own privacy notice, not as our sub-processor. Doppler (secrets management), GitHub (source code) and UptimeRobot (availability checks of our public pages) do not receive Customer Data.
DevKit Dossier