Data Processing Agreement (DPA)
Version: 1.0
Last updated: April 2, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and FOX Digital ("Processor") for the provision of FoxShield AI code review services ("Services").
Table of Contents
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, as defined under GDPR Article 4(1).
- Processing: Any operation performed on Personal Data, including collection, storage, use, and deletion.
- Sub-processor: A third party engaged by the Processor to process Personal Data on behalf of the Controller.
- Data Subject: The identified or identifiable natural person to whom Personal Data relates.
2. Scope and Purpose
The Processor processes Personal Data solely for the purpose of providing AI-powered code review services to the Controller, including:
- Receiving and analyzing pull request diffs via GitHub webhook
- Running security, quality, and performance analysis on code changes
- Posting review findings as comments on pull requests
- Calculating and reporting quality scores
- Aggregating anonymized patterns for the learning engine
3. Data Processed
| Category | Examples | Retention |
|---|---|---|
| Developer identifiers | GitHub username, email, user ID | Duration of subscription |
| Repository metadata | Repo name, organization, PR numbers | Duration of subscription |
| PR diff content | Changed lines of code, file paths | Processed in memory, discarded after review |
| Review findings | Severity, category, line numbers, descriptions | Duration of subscription |
| Aggregated insights | Pattern summaries, no raw code | Duration of subscription |
4. Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
- Ensure that persons authorized to process Personal Data are subject to confidentiality obligations.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS 1.3)
- Encryption of data at rest (AES-256)
- Role-based access controls
- Regular security assessments
- Isolated container-based infrastructure
- Not engage another processor (sub-processor) without prior written authorization from the Controller. See Section 6 for current sub-processors.
- Assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection).
- Assist the Controller in ensuring compliance with obligations related to security, breach notification, impact assessments, and prior consultation.
- At the Controller's choice, delete or return all Personal Data upon termination of the Services, and delete existing copies unless applicable law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA.
5. Obligations of the Controller
The Controller shall:
- Ensure that it has a lawful basis for providing Personal Data to the Processor.
- Ensure that Data Subjects have been informed about the processing.
- Provide documented instructions for processing.
6. Sub-processors
The Processor currently engages the following sub-processors:
| Sub-processor | Purpose | Location | Data Accessed |
|---|---|---|---|
| OpenRouter | LLM inference for code analysis | US / EU | Anonymized code snippets (ephemeral) |
| Stripe | Payment and subscription management | US / EU | Billing email, subscription tier |
| GitHub | Source code platform, webhook delivery | US | OAuth tokens, PR metadata |
| Contabo GmbH | Infrastructure hosting | Germany (EU) | All processed data (encrypted) |
The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object to a new sub-processor within 14 days of notification.
7. Data Location
Primary data processing occurs on servers located in Germany (EU), hosted by Contabo GmbH.
For self-hosted Enterprise deployments, all data processing occurs exclusively on the Controller's own infrastructure.
8. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach.
The notification shall include:
- Nature of the breach, including categories and approximate number of Data Subjects affected
- Name and contact details of the Processor's point of contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach
9. Data Deletion
Upon termination of the Services or upon the Controller's request:
- The Processor will delete all Personal Data within 30 days
- The Processor will provide written confirmation of deletion upon request
- Aggregated, anonymized insights that cannot be linked to any individual or specific code will be retained
10. Audit Rights
The Controller may request an audit of the Processor's data processing activities once per calendar year, with at least 30 days' prior written notice.
The audit may be conducted by the Controller or a qualified third-party auditor bound by confidentiality obligations.
The Processor will provide reasonable cooperation and access to relevant documentation, systems, and personnel.
11. Liability
Each party's liability under this DPA is subject to the limitations set out in the main agreement between the parties.
12. Duration and Termination
This DPA shall remain in effect for the duration of the Controller's subscription to FoxShield Services. Obligations regarding data deletion and confidentiality survive termination.
13. Governing Law
This DPA shall be governed by the laws of the jurisdiction specified in the main agreement. In the absence of such specification, the laws of Portugal shall apply.
Signatures
Controller (Customer)
Name:
Title:
Date:
Signature:
Processor (FOX Digital)
Name: Paulo Fox
Title: Founder
Date:
Signature:
To execute this DPA, please contact dpa@foxshield.centralfox.online with a signed copy.