This Data Processing Agreement ("DPA") forms part of the ReviewPilot Terms of Service and sets out the terms required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") for the processing of personal data that ReviewPilot carries out on behalf of its customers.
1. Parties and scope
This DPA is entered into between the customer that has accepted the Terms of Service (the "Controller") and [Company legal name, Unipessoal Lda], NIPC [NIPC], with registered office at [Registered address, Portugal] (the "Processor"). It applies automatically when the Controller accepts the Terms of Service.
This DPA applies to personal data contained in, or associated with, the repositories and pull requests the Controller connects to ReviewPilot ("Customer Personal Data"). It does not cover data that the Processor handles as a controller, such as account and billing data, which is described in the Privacy Policy.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Sub-processor" means any processor engaged by the Processor to process Customer Personal Data. "Standard Contractual Clauses" means the clauses adopted by Commission Implementing Decision (EU) 2021/914.
3. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the ReviewPilot service: retrieving pull-request and branch changes from the source control platforms the Controller authorises, sending them for analysis to the AI provider configured by the Controller, storing and presenting the resulting findings and, where enabled, publishing reviews back to the pull request.
The processing lasts for the term of the Terms of Service and until deletion of Customer Personal Data under section 11. Its nature includes collection, retrieval, storage, structuring, transmission, consultation and erasure. Its sole purpose is to provide, secure and support the service for the Controller. Further details are set out in Annex I.
4. Instructions from the Controller
The Processor processes Customer Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by Union or Member State law, in which case it will inform the Controller before processing unless that law prohibits it.
The Terms of Service, this DPA and the Controller's configuration of the service, such as the repositories connected, the AI provider selected, the retention period chosen, review guidance and whether reviews are published, constitute the Controller's complete instructions. The Processor will inform the Controller immediately if, in its opinion, an instruction infringes data protection law.
The Controller is responsible for the lawfulness of the processing it instructs, including having a legal basis and informing data subjects such as its developers.
5. Confidentiality and security
The Processor ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access it only as needed to provide the service.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, the Processor implements the technical and organisational measures described in Annex II. The Processor may update these measures provided the overall level of protection is not reduced.
6. Sub-processors
The Controller gives the Processor general authorisation to engage sub-processors. The sub-processors in use on the date of this DPA are listed in Annex III.
The Processor will notify the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or in the service. The Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, the Controller may terminate the affected service and receive a refund of prepaid fees for the period after termination.
The Processor imposes on each sub-processor, by contract, data protection obligations that are no less protective than those in this DPA, and remains liable to the Controller for the performance of the sub-processor's obligations.
7. AI providers engaged by the Controller
ReviewPilot operates on a bring-your-own-key basis. The AI provider that analyses pull-request content (for example OpenAI, Anthropic or Google) is selected by the Controller, which enters into its own agreement with that provider and supplies its own API key.
The AI provider is therefore engaged directly by the Controller and is not a sub-processor of the Processor. When the Processor transmits pull-request content to that provider, it does so on the Controller's instruction and on the Controller's behalf. The provider's processing, including any retention or international transfer, is governed by the Controller's agreement with it, and the Controller is responsible for ensuring that agreement meets the requirements of data protection law.
8. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights. If the Processor receives such a request directly, it will forward it to the Controller without undue delay and will not respond itself unless instructed.
The Processor also provides reasonable assistance to the Controller in ensuring compliance with its obligations on security, breach notification, data protection impact assessments and prior consultation with supervisory authorities, taking into account the information available to the Processor.
9. Personal data breaches
The Processor will notify the Controller of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 72 hours after becoming aware of it.
The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Where information is not yet available, it will be provided in phases. The Processor will take reasonable steps to contain and remediate the breach and will cooperate with the Controller.
10. International transfers
The Processor will not transfer Customer Personal Data to a country outside the European Economic Area that is not covered by an adequacy decision unless appropriate safeguards are in place, in particular the Standard Contractual Clauses, together with supplementary measures where required. Where the Standard Contractual Clauses apply between the parties, they are incorporated by reference and prevail over this DPA in case of conflict.
11. Deletion and return
Pull-request diffs are deleted immediately after analysis by default. If the Controller selects a retention period of 7 or 30 days, diffs are purged automatically when that period ends. The Controller can change the retention period at any time in the service.
At the end of the provision of the service, the Processor will, at the Controller's choice, delete or return all Customer Personal Data, and delete existing copies within [deletion period], unless Union or Member State law requires further storage.
12. Information and audits
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an independent auditor mandated by it.
Audits require at least 30 days' written notice, take place during normal business hours, are limited to once in any 12-month period unless required by a supervisory authority or following a personal data breach, must not compromise the security or confidentiality of other customers, and are carried out at the Controller's expense. The Processor may first answer by providing written information or relevant certifications.
13. Term, liability and precedence
This DPA remains in force for as long as the Processor processes Customer Personal Data on behalf of the Controller. Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where such limitations are not permitted by law. In case of conflict between this DPA and the Terms of Service, this DPA prevails with regard to the processing of Customer Personal Data.
This DPA is governed by the laws of Portugal, and the courts identified in the Terms of Service have jurisdiction.
Annex I: Details of processing
- Controller: the customer identified in its ReviewPilot account.
- Processor: [Company legal name, Unipessoal Lda], [Registered address, Portugal], contact [privacy email].
- Categories of data subjects: the Controller's developers, committers, pull-request authors and reviewers, and other people whose details appear in the connected repositories.
- Categories of personal data: code diffs and the personal data they may contain (such as names, email addresses or other identifiers present in code or comments), pull-request titles and metadata, repository and branch names, commit identifiers, source control usernames of authors, and triage decisions made by team members.
- Special categories of data: none intended. The Controller should not submit such data.
- Frequency: continuous, whenever a review is requested manually or triggered by a webhook.
- Nature of processing: retrieval from source control, transmission to the Controller's AI provider, storage, display, publication of reviews where enabled, and deletion.
- Purpose: providing AI-assisted code review to the Controller.
- Retention: diffs are deleted after analysis by default, or after 7 or 30 days if the Controller so chooses; findings and metadata are kept until deleted by the Controller or the end of the service.
Annex II: Technical and organisational measures
- Encryption of credentials: AI provider API keys and source control access tokens are encrypted at rest with AES-256-GCM and are never displayed back to users after being saved.
- Encryption in transit: traffic between users, the service, source control platforms and AI providers is encrypted with TLS.
- Webhook integrity: incoming webhooks are verified with HMAC signatures using per-connection secrets, and unsigned or invalid requests are rejected.
- Least-privilege source access: the service requests read access to repositories and pull requests, and write access to post reviews only when the Controller enables publishing.
- Access control: every record is scoped to a team, with strict isolation between teams and role-based permissions for owners and engineers. Passwords are hashed, and invitation links are single-use and expire after seven days.
- Data minimisation and retention: diffs are discarded after analysis by default, and any retention window chosen by the Controller (7 or 30 days) is enforced by an automatic purge job that runs every hour.
- Accountability: triage decisions on findings are recorded with the user and time, and access to the service is logged for security and troubleshooting purposes.
- Personnel: access to production systems is restricted to authorised personnel bound by confidentiality.
- Resilience: the service is hosted with [hosting provider], which provides physical security, redundancy and backups for the underlying infrastructure.
Annex III: Sub-processors
- [hosting provider]: application and database hosting; location [hosting region].
- [email provider]: delivery of transactional emails, such as notifications and invitations; location [email provider region].
[Merchant of Record, e.g. Paddle] processes billing data as an independent controller and reseller, and does not process Customer Personal Data. The AI provider selected by the Controller is engaged directly by the Controller and is not a sub-processor (see section 7).