Draft, not yet in force. Some details on this page have not been filled in yet, shown in double braces.
Data Processing Agreement
Between the customer who accepts the Terms of Service ("Controller") and Xinru Tang, Möwenweg 5, 91056 Erlangen, Germany ("Processor"). Effective from {{EFFECTIVE_DATE}}. It forms part of the Terms of Service.
1. Subject matter, duration, nature and purpose
- Subject matter and purpose. The Processor analyses the Controller's Google Workspace domain to identify licences that appear unused, estimate their cost, and show account security facts and change over time.
- Nature. Automated reading of Google APIs, storage and computation. The Processor makes no changes in the Controller's domain.
- Duration. Until the Controller disconnects the domain, or the Terms end.
- Data and data subjects. Categories of personal data and data subjects: Annex 1.
2. Instructions
The Processor processes personal data only on the Controller's documented instructions, including with regard to transfers of personal data to a third country or an international organisation. These are the Terms of Service, this agreement, and the Controller's use of the app's settings (for example, turning weekly monitoring on or off). The exception is where Union or Member State law requires otherwise, in which case the Processor informs the Controller first unless the law forbids that. If the Processor believes an instruction infringes data protection law, it tells the Controller.
3. Confidentiality
Everyone authorised by the Processor to process the personal data is bound by confidentiality.
4. Security
The Processor applies the technical and organisational measures in Annex 2 (Art. 32 GDPR). It may improve them, but must not lower the level of protection.
5. Sub-processors
The Controller gives general authorisation for the sub-processors in Annex 3. The Processor will announce any addition or replacement {{NOTICE_DAYS}} days in advance {{HOW — e.g. on the Annex 3 page and in the app}}. The Controller may object on reasonable data protection grounds. If the objection can't be resolved, the Controller may terminate. The Processor imposes the same data protection obligations on each sub-processor, and remains liable for them.
6. Assistance
The Processor helps the Controller, taking the nature of the processing into account:
- Data subject requests. The app lets the Controller export scan results and delete all data itself. For anything else, the Processor responds within {{DAYS}} days of a request to {{PRIVACY_CONTACT_EMAIL}}.
- Security, breach notification, DPIAs and consultation with authorities (Art. 32–36 GDPR). The Processor provides the information it holds.
7. Personal data breaches
The Processor notifies the Controller without undue delay, and at the latest within {{BREACH_NOTICE_HOURS, e.g. 48}} hours, after becoming aware of a personal data breach. The notice includes the information required by Art. 33(3) GDPR as far as it is available. The notice goes to {{HOW — the connecting administrator's email is the only contact the Processor holds}}.
8. Deletion or return at the end
At the end of the processing, the Processor deletes or returns the personal data, at the Controller's choice:
- Return. Before disconnecting, the Controller can download the scan results itself, as CSV files, from the app at any time. That download is how personal data is returned.
- Deletion. When the Controller disconnects the domain (Settings → Disconnect this domain), the Processor deletes all personal data of the Controller at once, and withdraws its Google access. Earlier deletion applies as set out in Annex 1.
No copies are retained except where Union or Member State law requires, and except in the Processor's encrypted database backups, which expire and are overwritten within 7 days. If the Processor's database itself is ever deleted or replaced, an encrypted final snapshot of it is taken automatically, and the Processor deletes that snapshot within 7 days. Technical logs, which are not designed to contain personal data, expire within 30 days.
9. Audits
The Processor makes available the information needed to demonstrate compliance with Art. 28 GDPR, and allows audits by the Controller or an auditor it mandates. Audits need reasonable notice ({{AUDIT_NOTICE_DAYS}} days), take place during business hours, and happen no more than once a year unless there is a breach. {{COST_ALLOCATION}}
10. International transfers
Personal data is processed and stored in the EU, in Ireland (AWS region eu-west-1). The
Processor does not itself transfer it outside the EEA.
Amazon Web Services ({{AWS_CONTRACTING_ENTITY}}), the sub-processor in Annex 3, belongs to a group whose parent company is in the United States, so access from outside the EEA cannot be ruled out entirely (for example, for support, or under a legal order to the parent). Any such transfer is covered by the Standard Contractual Clauses in the AWS Data Processing Addendum, and by Amazon.com, Inc.'s certification under the EU-US Data Privacy Framework (Art. 45 and 46 GDPR). Any other transfer outside the EEA takes place only on the Controller's documented instructions and with a transfer mechanism under Chapter V GDPR.
Annex 1: Data subjects, data, retention
Data subjects: the Controller's Google Workspace users. The Controller's administrators are among them: their directory details and usage are processed like any other user's, and the app keeps, for the Controller, which administrator declared a price and which one receives change emails.
Not covered by this agreement: the administrator's sign-in identity (the email address the administrator signs in with, held in the sign-in session and as the connecting administrator of the domain). The Processor uses it as its own controller to sign the administrator in and to know who connected the domain, as described in the Privacy Policy, section 2.
| Data | Retention |
|---|---|
| Users: Google user id, email address, organisational unit, suspended/archived status, account creation time, last sign-in time | 12 months per scan; the two most recent completed scans are always kept. A person's details are deleted once no kept scan refers to them and no scan has seen them for 12 months |
| Users: licence (SKU) held; per-app last-activity timestamps and activity counts (Gmail, Drive, Chat, sign-in); the resulting activity verdict and licence cost | same |
| Users: 2-step verification status, number of admin roles, number of third-party apps, Google's password strength and length labels, less secure app access status | same |
| Users holding a Gemini add-on: number of Gemini uses and latest use time | same |
| Raw Google API responses, restricted by the Processor's requests to the fields above: Google user id, email address, organisational unit, suspended/archived status, creation and last sign-in time, licence held, the usage and security values above, and, for Gemini add-on holders, when they used Gemini. No IP addresses, names, other profile details or content | 30 days |
| The Controller's encrypted Google access token; email of an administrator who declared a price | Until disconnect, or automatically after 12 months in which no administrator opened the app. A declared price, with its administrator's email, is also deleted when the Controller changes the billing currency |
| {{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} Administrators: email address of one who switched on change emails | Until they switch them off or unsubscribe, or another administrator reconnects the domain; each queued email 30 days |
| Database backups containing any of the above | 7 days after the data left the live database |
| A final snapshot of the database, taken automatically only if the database itself is deleted or replaced | Deleted by the Processor within 7 days |
| Technical logs (record ids, error codes, error types, and for some errors an error message and code location; no personal data by design. A failed scan is logged with its error type and location only, and the database is set not to put data values in its error messages) | 30 days |
No special categories of data (Art. 9 GDPR) are processed. The Processor does not process the content of email, files, calendars, chats or AI prompts.
Annex 2: Technical and organisational measures
- Encryption.
- In transit: HTTPS for all traffic.
- At rest: Google access tokens are encrypted with AES-GCM, bound to the tenant as associated data, with a key id for rotation. The database, its backups and snapshots are encrypted at rest by the hosting provider (Amazon RDS storage encryption, AWS-managed key).
- Access control and separation.
- Every query on customer data is scoped to the tenant, and the database enforces tenant-scoped foreign keys.
- The database has no public address (not publicly accessible) and its firewall (security group) accepts connections only from the application. Application credentials are held in AWS Secrets Manager, not in code or images.
- Sessions use
HttpOnly,Secure,SameSite=Laxcookies. - Administrator sign-in is through Google.
- Data minimisation.
- Read-only Google permissions for the directory and reports.
- No content scopes.
- Only counts and timestamps are kept from activity logs.
- An automated build check fails if the code makes a changing request to Google.
- {{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} The AI summary receives aggregate figures only.
- Deletion.
- Raw responses are deleted automatically after 30 days.
- Full deletion on disconnect, verified by an automated test that checks every tenant table.
- Database backups are kept 7 days; a final snapshot, if the database is ever deleted or replaced, is deleted within 7 days; technical logs are kept 30 days.
- No third-party scripts. There are no analytics, trackers, or externally loaded fonts.
- Availability. Automated daily database backups with point-in-time recovery, kept 7 days.
- Organisational measures. {{ACCESS_TO_PRODUCTION, STAFF_CONFIDENTIALITY, INCIDENT_PROCESS, WHO_CAN_READ_LOGS_AND_RESTORE_BACKUPS}}
Annex 3: Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services ({{AWS_CONTRACTING_ENTITY}}) | Hosting, database, backups and logs | EU, Ireland (eu-west-1) |
| Amazon Web Services (Amazon Bedrock) {{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} | Writing the AI summary on the dashboard, from aggregate figures only | EU, Ireland (eu-west-1) |
| Amazon Web Services (Amazon SES) {{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} | Sending change emails to an administrator who switched them on: their address, and counts and amounts only | EU, Ireland (eu-west-1) |
| {{OTHERS or none}} |
Google is not a sub-processor. It is the source of the data, and the Controller's own provider. GitHub hosts the Processor's source code and build pipeline and receives no personal data of the Controller, so it is not a sub-processor either.