Data Processing Addendum
Last updated: 3 August 2026. This DPA forms part of the vasdra Terms of Service when we process personal data on your behalf.
1. Parties and incorporation
This Data Processing Addendum ("DPA") is between you ("Customer", "Controller") and the operator of vasdra at vasdra.dev("vasdra", "Processor"). It supplements the Terms of Service and Privacy Policy. If there is a conflict on data protection, this DPA controls for that subject.
2. Scope
This DPA applies only where and to the extent vasdra processes Personal Data on behalf of Customer in providing the Service, and that data is subject to the GDPR, UK GDPR, or Swiss FADP ("Data Protection Laws"). Account and billing data that vasdra determines the purposes for is described in the Privacy Policy (controller role) and is outside this processor schedule unless otherwise agreed in writing.
3. Definitions
"Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings in the GDPR. "Customer Content" means scan results, findings, evidence references, repository metadata, and similar content Customer submits or instructs vasdra to process via the Service. "Subprocessor" means a third party engaged by vasdra to Process Personal Data on Customer's behalf.
4. Processing details (Article 28 perimeter)
- Subject matter: provision of API change impact monitoring, reporting, alerts, and related features
- Duration: for the term of the Agreement and any post-termination retention required by the Agreement or law
- Nature and purpose: host, store, transmit, and display Customer Content to deliver the Service Customer enables
- Types of Personal Data: may include account identifiers embedded in Customer Content, file paths, commit metadata, evidence snippets, and contact details Customer configures for alerts
- Categories of Data Subjects:Customer's employees, contractors, and other users of Customer's systems, as reflected in Customer Content
5. Customer instructions
vasdra will Process Personal Data in Customer Content only on documented instructions from Customer, including via the Service configuration (connected repos, monitoring toggles, remediation settings), the Terms, this DPA, and written instructions. Customer warrants that its instructions are lawful and that it has a valid legal basis to Process and to instruct vasdra.
6. Processor obligations
vasdra will:
- Process Personal Data only on Customer's documented instructions, unless required by applicable law (in which case vasdra will inform Customer before Processing, unless prohibited)
- Ensure persons authorized to Process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational security measures under Article 32 GDPR; see also Security
- Engage Subprocessors only under Section 7
- Taking into account the nature of Processing, assist Customer by appropriate technical and organizational measures, insofar as possible, for Data Subject rights requests
- Assist Customer with security, breach notification, DPIAs, and prior consultation obligations under Articles 32 to 36, taking into account the nature of Processing and information available to vasdra
- At Customer's choice, delete or return Personal Data in Customer Content after the end of the provision of Processing services, and delete existing copies unless law requires storage
- Make available information necessary to demonstrate compliance with Article 28 and allow for audits as described in Section 9
7. Subprocessors
Customer authorizes vasdra to engage Subprocessors to Process Personal Data as needed to provide the Service. The current list is at vasdra.dev/subprocessors. vasdra will impose data-protection obligations on Subprocessors no less protective than those in this DPA. vasdra remains responsible for Subprocessor performance insofar as required by Data Protection Laws.
vasdra will update the Subprocessors page when engaging a new Subprocessor for Customer Content. Continued use of the Service after the stated effective date constitutes authorization where permitted. If Customer objects on reasonable data-protection grounds, contact help@vasdra.dev before the effective date to discuss alternatives or termination rights under the Terms.
8. International transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland to a third country without an adequacy decision, vasdra will ensure appropriate safeguards (such as EU Standard Contractual Clauses or UK equivalent) with the relevant Subprocessor or affiliate, plus supplementary measures where required.
9. Audits
Upon reasonable written request, and no more than once per twelve-month period unless a competent authority or confirmed Personal Data Breach requires more, vasdra will provide written information and attestations reasonably necessary for Customer to verify compliance. On-site audits require at least thirty days' notice, are limited to facilities relevant to Customer Content, and must not unreasonably disrupt operations. Customer bears its own audit costs unless a material breach of this DPA is confirmed.
10. Breach notification
vasdra will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Content, and will provide information reasonably available to help Customer meet its notification obligations.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms, except where Data Protection Laws prohibit such limitation.
12. Contact
Privacy and DPA requests: help@vasdra.dev.