Data Processing Agreement (DPA)

Version: 1.0
Last updated: April 2, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and FOX Digital ("Processor") for the provision of FoxShield AI code review services ("Services").


1. Definitions

2. Scope and Purpose

The Processor processes Personal Data solely for the purpose of providing AI-powered code review services to the Controller, including:

3. Data Processed

Category Examples Retention
Developer identifiers GitHub username, email, user ID Duration of subscription
Repository metadata Repo name, organization, PR numbers Duration of subscription
PR diff content Changed lines of code, file paths Processed in memory, discarded after review
Review findings Severity, category, line numbers, descriptions Duration of subscription
Aggregated insights Pattern summaries, no raw code Duration of subscription

4. Obligations of the Processor

The Processor shall:

  1. Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
  2. Ensure that persons authorized to process Personal Data are subject to confidentiality obligations.
  3. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
    • Encryption of data in transit (TLS 1.3)
    • Encryption of data at rest (AES-256)
    • Role-based access controls
    • Regular security assessments
    • Isolated container-based infrastructure
  4. Not engage another processor (sub-processor) without prior written authorization from the Controller. See Section 6 for current sub-processors.
  5. Assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection).
  6. Assist the Controller in ensuring compliance with obligations related to security, breach notification, impact assessments, and prior consultation.
  7. At the Controller's choice, delete or return all Personal Data upon termination of the Services, and delete existing copies unless applicable law requires storage.
  8. Make available to the Controller all information necessary to demonstrate compliance with this DPA.

5. Obligations of the Controller

The Controller shall:

  1. Ensure that it has a lawful basis for providing Personal Data to the Processor.
  2. Ensure that Data Subjects have been informed about the processing.
  3. Provide documented instructions for processing.

6. Sub-processors

The Processor currently engages the following sub-processors:

Sub-processor Purpose Location Data Accessed
OpenRouter LLM inference for code analysis US / EU Anonymized code snippets (ephemeral)
Stripe Payment and subscription management US / EU Billing email, subscription tier
GitHub Source code platform, webhook delivery US OAuth tokens, PR metadata
Contabo GmbH Infrastructure hosting Germany (EU) All processed data (encrypted)

The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object to a new sub-processor within 14 days of notification.

7. Data Location

Primary data processing occurs on servers located in Germany (EU), hosted by Contabo GmbH.

For self-hosted Enterprise deployments, all data processing occurs exclusively on the Controller's own infrastructure.

8. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach.

The notification shall include:

9. Data Deletion

Upon termination of the Services or upon the Controller's request:

10. Audit Rights

The Controller may request an audit of the Processor's data processing activities once per calendar year, with at least 30 days' prior written notice.

The audit may be conducted by the Controller or a qualified third-party auditor bound by confidentiality obligations.

The Processor will provide reasonable cooperation and access to relevant documentation, systems, and personnel.

11. Liability

Each party's liability under this DPA is subject to the limitations set out in the main agreement between the parties.

12. Duration and Termination

This DPA shall remain in effect for the duration of the Controller's subscription to FoxShield Services. Obligations regarding data deletion and confidentiality survive termination.

13. Governing Law

This DPA shall be governed by the laws of the jurisdiction specified in the main agreement. In the absence of such specification, the laws of Portugal shall apply.


Signatures

Controller (Customer)

Name:  

Title:  

Date:  

Signature:  

Processor (FOX Digital)

Name: Paulo Fox

Title: Founder

Date:  

Signature:  


To execute this DPA, please contact dpa@foxshield.centralfox.online with a signed copy.