Data processing agreement (summary)
Last updated 27 August 2026
[FILL IN] need real values before publication.This page summarises the data processing agreement between [FILL IN — registered company name, e.g. BlueGrid d.o.o.] and its business customers, as required by Article 28(3) GDPR. It is written to be readable. The signed agreement, with the Standard Contractual Clauses annexed, is the binding document; where the two differ, the signed agreement wins. Ask [FILL IN — contact@bluegrid.io] for a copy to sign.
Read the roles carefully. GitSearch involves two distinct sets of personal data with two different arrangements, and confusing them is the most common mistake:
- For your users — your employees who sign in — you are the controller and we are your processor. This agreement governs that.
- For GitHub profile data, we and you are independent controllers. We decide to collect and store it; you decide what to do with it once you see or export it. Neither of us processes it on the other's instructions, so Article 28 does not apply to it. Section 8 explains this.
1. Subject matter and duration
We process your users' personal data in order to provide GitSearch, for as long as your subscription lasts, plus the deletion window in the terms of service.
2. Nature and purpose of the processing
Hosting, storage, authentication, access control, audit logging, backup and support. The purpose is to give your named users access to the service and to give you an accountable record of what they did in it.
3. Categories of data and data subjects
Data subjects: your employees and contractors who hold a GitSearch user.
Personal data: name, business email address, password hash, role, status, sign-in timestamps, IP address and user agent recorded in audit entries, searches run and their parameters.
Special categories: none. Do not enter special category data into the service.
4. Our obligations
- We process your users' data only on your documented instructions, which are given by your use of the service and by the settings your administrators choose. If we believe an instruction breaches the GDPR or the ZZPL, we will tell you.
- Everyone with access is bound by confidentiality obligations.
- We implement the technical and organisational measures in section 6.
- We assist you, taking into account the nature of the processing, with data subject requests, with data protection impact assessments, and with breach notification.
- We notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data.
- At the end of the contract we delete or return your users' data at your choice, except where retention is legally required.
- We make available the information needed to demonstrate compliance and allow audits under section 7.
5. Sub-processors
You give general authorisation for the sub-processors listed below. We will give you [FILL IN — proposed 30] days' notice before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve your objection you may terminate the affected service without penalty.
- [FILL IN — hosting provider name], Germany — hosting of the application, database and job queue.
- [FILL IN — transactional email provider, once chosen. No email provider is in use at the date of this draft; invitation links are surfaced in the admin interface.]
- [FILL IN — error monitoring provider, if introduced. None today.]
We impose the same data protection obligations on each sub-processor and remain fully liable for their performance.
6. Technical and organisational measures (Article 32)
- TLS for all data in transit; encryption at rest for the database volume and for stored API credentials.
- Passwords stored only as salted bcrypt hashes; no plaintext, ever.
- Session cookies marked HttpOnly, SameSite=Lax and Secure in production; sessions revalidated against the database on every request so that revoking access takes effect immediately.
- Role-based access control enforced in the service layer rather than only in the interface, with authorisation checks covered by automated tests.
- Audit logging of administrative actions, including both identities where a super user is impersonating.
- Least-privilege access to production for our staff; [FILL IN — describe access review cadence and MFA requirements].
- Backups: [FILL IN — frequency, retention and restore testing].
- [FILL IN — vulnerability management, patching cadence, penetration testing schedule.]
7. Audits
Once per year, and after a breach, you may ask for information demonstrating our compliance. Where that is not sufficient you may conduct an audit, or appoint an independent auditor who is not our competitor, on 30 days' notice, during business hours, without unreasonable disruption, at your cost, and subject to confidentiality.
8. GitHub profile data: independent controllers
We are not your processor for GitHub profile data, and you are not ours. Each of us determines our own purposes:
- We decide which profiles to collect, what to store, and how long to keep them. Our legal basis and our balancing test are in the privacy policy.
- You decide who to contact, what to say, what to record in your own systems, and how long to keep it. You need your own legal basis, your own Article 14 notice to the people you approach, and your own retention rule.
Each of us is responsible for its own compliance and answers to supervisory authorities for it. We will pass on any objection or erasure request that identifies you, and you must act on it.
[FILL IN — counsel should confirm this characterisation. An argument exists that the arrangement is joint controllership under Article 26 for the collection stage, in which case an Article 26 arrangement and a public summary of it would be required instead.]
9. International transfers
Data is stored in Germany. Our staff access it from Serbia, which is outside the EEA and not covered by an adequacy decision, so those transfers rely on the Standard Contractual Clauses annexed to the signed agreement, together with the supplementary measures and the transfer impact assessment described in the privacy policy.
10. Contact
Data protection matters: [FILL IN — privacy@bluegrid.io]. Contractual matters: [FILL IN — contact@bluegrid.io].