Draft, not yet in force. Some details on this page have not been filled in yet, shown in double braces.

Data Processing Agreement

Between the customer who accepts the Terms of Service ("Controller") and Xinru Tang, Möwenweg 5, 91056 Erlangen, Germany ("Processor"). Effective from {{EFFECTIVE_DATE}}. It forms part of the Terms of Service.

1. Subject matter, duration, nature and purpose

2. Instructions

The Processor processes personal data only on the Controller's documented instructions, including with regard to transfers of personal data to a third country or an international organisation. These are the Terms of Service, this agreement, and the Controller's use of the app's settings (for example, turning weekly monitoring on or off). The exception is where Union or Member State law requires otherwise, in which case the Processor informs the Controller first unless the law forbids that. If the Processor believes an instruction infringes data protection law, it tells the Controller.

3. Confidentiality

Everyone authorised by the Processor to process the personal data is bound by confidentiality.

4. Security

The Processor applies the technical and organisational measures in Annex 2 (Art. 32 GDPR). It may improve them, but must not lower the level of protection.

5. Sub-processors

The Controller gives general authorisation for the sub-processors in Annex 3. The Processor will announce any addition or replacement {{NOTICE_DAYS}} days in advance {{HOW — e.g. on the Annex 3 page and in the app}}. The Controller may object on reasonable data protection grounds. If the objection can't be resolved, the Controller may terminate. The Processor imposes the same data protection obligations on each sub-processor, and remains liable for them.

6. Assistance

The Processor helps the Controller, taking the nature of the processing into account:

7. Personal data breaches

The Processor notifies the Controller without undue delay, and at the latest within {{BREACH_NOTICE_HOURS, e.g. 48}} hours, after becoming aware of a personal data breach. The notice includes the information required by Art. 33(3) GDPR as far as it is available. The notice goes to {{HOW — the connecting administrator's email is the only contact the Processor holds}}.

8. Deletion or return at the end

At the end of the processing, the Processor deletes or returns the personal data, at the Controller's choice:

No copies are retained except where Union or Member State law requires, and except in the Processor's encrypted database backups, which expire and are overwritten within 7 days. If the Processor's database itself is ever deleted or replaced, an encrypted final snapshot of it is taken automatically, and the Processor deletes that snapshot within 7 days. Technical logs, which are not designed to contain personal data, expire within 30 days.

9. Audits

The Processor makes available the information needed to demonstrate compliance with Art. 28 GDPR, and allows audits by the Controller or an auditor it mandates. Audits need reasonable notice ({{AUDIT_NOTICE_DAYS}} days), take place during business hours, and happen no more than once a year unless there is a breach. {{COST_ALLOCATION}}

10. International transfers

Personal data is processed and stored in the EU, in Ireland (AWS region eu-west-1). The Processor does not itself transfer it outside the EEA.

Amazon Web Services ({{AWS_CONTRACTING_ENTITY}}), the sub-processor in Annex 3, belongs to a group whose parent company is in the United States, so access from outside the EEA cannot be ruled out entirely (for example, for support, or under a legal order to the parent). Any such transfer is covered by the Standard Contractual Clauses in the AWS Data Processing Addendum, and by Amazon.com, Inc.'s certification under the EU-US Data Privacy Framework (Art. 45 and 46 GDPR). Any other transfer outside the EEA takes place only on the Controller's documented instructions and with a transfer mechanism under Chapter V GDPR.


Annex 1: Data subjects, data, retention

Data subjects: the Controller's Google Workspace users. The Controller's administrators are among them: their directory details and usage are processed like any other user's, and the app keeps, for the Controller, which administrator declared a price and which one receives change emails.

Not covered by this agreement: the administrator's sign-in identity (the email address the administrator signs in with, held in the sign-in session and as the connecting administrator of the domain). The Processor uses it as its own controller to sign the administrator in and to know who connected the domain, as described in the Privacy Policy, section 2.

Data Retention
Users: Google user id, email address, organisational unit, suspended/archived status, account creation time, last sign-in time 12 months per scan; the two most recent completed scans are always kept. A person's details are deleted once no kept scan refers to them and no scan has seen them for 12 months
Users: licence (SKU) held; per-app last-activity timestamps and activity counts (Gmail, Drive, Chat, sign-in); the resulting activity verdict and licence cost same
Users: 2-step verification status, number of admin roles, number of third-party apps, Google's password strength and length labels, less secure app access status same
Users holding a Gemini add-on: number of Gemini uses and latest use time same
Raw Google API responses, restricted by the Processor's requests to the fields above: Google user id, email address, organisational unit, suspended/archived status, creation and last sign-in time, licence held, the usage and security values above, and, for Gemini add-on holders, when they used Gemini. No IP addresses, names, other profile details or content 30 days
The Controller's encrypted Google access token; email of an administrator who declared a price Until disconnect, or automatically after 12 months in which no administrator opened the app. A declared price, with its administrator's email, is also deleted when the Controller changes the billing currency
{{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} Administrators: email address of one who switched on change emails Until they switch them off or unsubscribe, or another administrator reconnects the domain; each queued email 30 days
Database backups containing any of the above 7 days after the data left the live database
A final snapshot of the database, taken automatically only if the database itself is deleted or replaced Deleted by the Processor within 7 days
Technical logs (record ids, error codes, error types, and for some errors an error message and code location; no personal data by design. A failed scan is logged with its error type and location only, and the database is set not to put data values in its error messages) 30 days

No special categories of data (Art. 9 GDPR) are processed. The Processor does not process the content of email, files, calendars, chats or AI prompts.

Annex 2: Technical and organisational measures

Annex 3: Sub-processors

Sub-processor Service Location
Amazon Web Services ({{AWS_CONTRACTING_ENTITY}}) Hosting, database, backups and logs EU, Ireland (eu-west-1)
Amazon Web Services (Amazon Bedrock) {{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} Writing the AI summary on the dashboard, from aggregate figures only EU, Ireland (eu-west-1)
Amazon Web Services (Amazon SES) {{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} Sending change emails to an administrator who switched them on: their address, and counts and amounts only EU, Ireland (eu-west-1)
{{OTHERS or none}}

Google is not a sub-processor. It is the source of the data, and the Controller's own provider. GitHub hosts the Processor's source code and build pipeline and receives no personal data of the Controller, so it is not a sub-processor either.