This Data Processing Agreement ("DPA") is between the customer that accepted the Docdrift Terms of Service ("Customer") and Un martes a las 10 am, S.A. de C.V., Calle Perseo 1304, Col. Concepción La Cruz, C.P. 72836, San Andrés Cholula, Puebla, Mexico ("Docdrift"). It is part of the Terms and applies automatically, without a signature, whenever Docdrift processes Customer Personal Data. If you need a countersigned copy, email [email protected].
If this DPA and the Terms conflict on data protection, this DPA controls. If this DPA and the Standard Contractual Clauses conflict, the Standard Contractual Clauses control.
1. Definitions
- Data Protection Laws: the laws on personal data that apply to the processing under this DPA, including the GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and Mexico's Federal Law on the Protection of Personal Data Held by Private Parties ("LFPDPPP").
- GDPR: Regulation (EU) 2016/679.
- Customer Data: what Customer and its users put into the Service or connect to it, and what the Service derives from it for Customer, as defined in the Terms.
- Customer Personal Data: personal data within Customer Data.
- Subprocessor: a third party that Docdrift engages to process Customer Personal Data.
- Security Incident: a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- SCCs: the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
- UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner.
- "Controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR.
2. Roles
- For Customer Personal Data, Customer is the controller, or a processor acting for its own controller, and Docdrift is Customer's processor. Under the LFPDPPP, Docdrift is Customer's encargado; under the CCPA, Docdrift is Customer's service provider.
- Docdrift is a controller of the account, billing, security and website data it needs to run its business, as explained in its Privacy Policy. This DPA doesn't cover that data.
- Customer is responsible for having a lawful basis to connect Customer Data to the Service and for the instructions it gives.
3. Instructions
- Docdrift processes Customer Personal Data only on Customer's documented instructions. The Terms, this DPA and Customer's use and configuration of the Service (for example, connecting a repository, approving a change or asking a question) are Customer's complete instructions. Other instructions need a written agreement.
- Docdrift tells Customer if, in its opinion, an instruction infringes Data Protection Laws.
- Docdrift may process Customer Personal Data otherwise only when the law that applies to it requires it; then it tells Customer first, unless that law forbids it.
4. Details of the processing
Annex I describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.
5. Confidentiality
Docdrift gives access to Customer Personal Data only to personnel who need it to provide, support or secure the Service and who are bound by confidentiality.
6. Security
Docdrift implements the technical and organizational measures in Annex II. It may update them as long as the overall level of protection doesn't decrease.
7. Subprocessors
- Customer gives Docdrift general authorization to engage Subprocessors. The current list is at docdrift.io/subprocessors.
- Docdrift updates that list at least 30 days before a new Subprocessor starts processing Customer Personal Data, and emails the Owner of Customer's workspaces.
- Customer may object on reasonable data protection grounds by emailing [email protected] within those 30 days. The parties will discuss the objection in good faith. If Docdrift can't address it, Customer may stop using the affected Service and delete its workspace before the change takes effect, without any penalty.
- In an emergency, such as a security incident or a Subprocessor ending its service, Docdrift may replace a Subprocessor sooner and will notify Customer as soon as it can.
- Docdrift imposes on each Subprocessor data protection obligations that are at least as protective as this DPA, and remains responsible to Customer for its Subprocessors' performance.
8. Data subject requests
- The Service lets Customer access, export, correct and delete Customer Personal Data. Docdrift helps further, taking into account the nature of the processing, when Customer can't do it on its own.
- If a data subject contacts Docdrift about Customer Personal Data, Docdrift directs them to Customer and doesn't answer on Customer's behalf unless Customer asks.
9. Assistance
Taking into account the nature of the processing and the information available to it, Docdrift gives Customer reasonable help with data protection impact assessments, prior consultations with supervisory authorities and Customer's security obligations.
10. Security Incidents
- Docdrift notifies Customer without undue delay, and where feasible within 48 hours, after becoming aware of a Security Incident.
- The notice describes, as far as known, the nature of the incident, the categories and approximate number of data subjects and records concerned, its likely consequences, the measures taken or proposed and a contact point. Docdrift sends more information as it learns it.
- Notifying a Security Incident isn't an admission of fault.
11. Return and deletion
- While Customer uses the Service, it can export its data and disconnect repositories, remove doc sources and delete workspaces or its account. Deletion follows the timelines in section 11 of the Terms and on the Security page: data derived from code, and text written by the Service's AI about it, is deleted within 1 hour; what Customer's team wrote or imported stays in a trash for 30 days, where the Owner can restore it, export it or empty it sooner; deleted data leaves backups within 84 days.
- When the Terms end, Docdrift deletes Customer Personal Data on the same timelines, unless the law requires it to keep some of it. Customer can export its data before and while it's in the trash.
12. Audits
- Docdrift makes available the information needed to show compliance with this DPA: this DPA, the Security page and written answers to Customer's reasonable security questionnaires, once a year.
- If that isn't enough to meet a requirement of Data Protection Laws or of a supervisory authority, or after a Security Incident, Customer may audit Docdrift's processing of Customer Personal Data, itself or through an independent auditor bound by confidentiality. Customer gives at least 30 days' notice, the audit takes place during business hours without disrupting the Service or exposing other customers' data, it happens at most once a year unless a supervisory authority requires more, and Customer bears its costs.
- The audit rights under the SCCs are met in the same way.
13. International transfers
- Docdrift is established in Mexico. Its servers and database are in Germany and its AI analysis runs in European Union regions; Subprocessors are listed with their locations on the Subprocessors page.
- European Economic Area. Where Customer Personal Data subject to the GDPR is transferred to Docdrift, the SCCs are incorporated into this DPA: Module Two where Customer is a controller and Module Three where Customer is a processor. For both modules:
- Clause 7 (docking clause) applies;
- under Clause 9(a), Option 2 (general written authorization) applies, with the notice period in section 7 of this DPA;
- the optional wording in Clause 11(a) doesn't apply;
- under Clause 13, the competent supervisory authority is the one of the Member State where Customer is established or, if Customer isn't established in the EU, where its representative is established;
- under Clauses 17 and 18, the SCCs are governed by the law of Ireland and disputes go to the courts of Ireland;
- Annexes I, II and III of the SCCs are Annexes I, II and III of this DPA.
- Docdrift's own GDPR obligations. Docdrift is subject to the GDPR under its Article 3(2) for some processing. The European Commission hasn't yet adopted standard contractual clauses for importers in that situation. Until it does, the parties use the SCCs above as the safeguard for these transfers, and Docdrift will offer the new clauses when they're available.
- United Kingdom. Where Customer Personal Data subject to the UK GDPR is transferred, the UK Addendum applies to the SCCs above. Table 1 is completed with the details in Annex I; Table 2 with the modules and options above; Table 3 with Annexes I to III; and for Table 4, both the importer and the exporter may end the UK Addendum as its Section 19 allows.
- Switzerland. Where the FADP applies, the SCCs above apply with these changes: the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to the GDPR include the FADP; and "Member State" includes Switzerland, so data subjects there can enforce their rights where they live.
- Onward transfers. Docdrift transfers Customer Personal Data to a Subprocessor outside the European Economic Area, the United Kingdom or Switzerland only with a safeguard recognized by Data Protection Laws, such as the SCCs.
- Requests from public authorities. If a public authority asks Docdrift for Customer Personal Data, Docdrift tells Customer, unless the law forbids it, reviews the legality of the request and challenges it where there are reasonable grounds, and discloses only the minimum required. Docdrift hasn't received any such request.
14. CCPA
As a service provider, Docdrift:
- processes Customer Personal Data only for the business purposes in Annex I and doesn't sell or share it, as the CCPA defines those terms;
- doesn't retain, use or disclose it outside the direct business relationship with Customer, or for any purpose other than those business purposes;
- doesn't combine it with personal information it receives from others or collects on its own, except as the CCPA allows;
- complies with the CCPA, gives Customer the same level of privacy protection the CCPA requires, and tells Customer if it can no longer meet its obligations;
- lets Customer take reasonable steps to stop and fix unauthorized use.
15. LFPDPPP (Mexico)
As encargado, Docdrift processes Customer Personal Data only as Customer instructs and not for its own purposes; keeps it confidential and secure; doesn't transfer it except to Subprocessors under section 7 or as Customer instructs; and deletes it when the relationship ends, as section 11 describes.
16. Liability
Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Laws or the SCCs don't allow those limits.
17. Term
This DPA lasts as long as Docdrift processes Customer Personal Data.
Annex I · Description of the processing
A. Parties
- Data exporter: Customer, as identified in its Docdrift account. Contact: the Owner of Customer's workspace, at the email of their account. Role: controller or processor. Activities: using the Service.
- Data importer: Un martes a las 10 am, S.A. de C.V., Calle Perseo 1304, Col. Concepción La Cruz, C.P. 72836, San Andrés Cholula, Puebla, Mexico. Contact: [email protected]. Role: processor. Activities: providing the Service.
B. Transfer and processing
- Categories of data subjects: Customer's users (the Owner, members and invited people); people who appear in connected repositories, pull requests, issues and documents, such as authors and contributors; repository admins who approve publishing a Verified page; and other people named in content Customer's team writes.
- Categories of personal data: names, email addresses, GitHub usernames and IDs; authorship and activity records in the workspace; pull request titles and description excerpts; imported issues; statements from connected documents; decisions, requests, notes, questions and Docdrift Docs pages; AI-written texts about Customer's product; and any personal data that happens to appear in names of files, symbols or configuration keys derived from code.
- Special categories: none intended. Customer agrees not to connect them (see the Acceptable Use Policy).
- Frequency: continuous, while Customer uses the Service.
- Nature of the processing: reading code in memory and storing only derived data; reading documents and storing their statements and structure; storing what Customer's team writes; analysis with AI models on Google Cloud Vertex AI with zero data retention; showing results in the app, GitHub checks and comments, emails, the MCP server and connected assistants; exporting and deleting.
- Purpose: providing the Service under the Terms, including support and security.
- Retention: while Customer's workspace is active, then as section 11 describes.
- Transfers to Subprocessors: for the purposes, data and locations on the Subprocessors page, for as long as each provides its service.
C. Competent supervisory authority
As set out in section 13.
Annex II · Technical and organizational measures
- Source code never stored. Code is cloned into temporary memory for each job, never swapped to disk, and deleted when the job ends. Only derived data is kept.
- Isolated parsing. Customer code is parsed in sandboxed processes with no network access, an empty environment and per-file memory and CPU limits.
- Secret detection. Every text field is scanned before it's saved, and detected secrets are removed.
- Workspace isolation. Every record belongs to one workspace; access is checked in the application and again in the database with row-level security; cross-workspace access is tested on every change.
- Encryption. TLS for all traffic. Credentials for Notion and Google are encrypted with AES-256-GCM using a key per workspace. Tokens Docdrift issues are stored only as hashes. Database backups are encrypted.
- AI provider. Google Cloud Vertex AI in the European Union only, with zero data retention: data caching off and its locations checked at each deployment, request and response logging off, and no use of data for training.
- Least privilege. Separate GitHub Apps for reading and for writing; an allowlist blocks any GitHub call the app isn't meant to make. Cloud identities have only the permissions they need.
- Access control. Roles and per-project access; passwordless sign-in with single-use codes stored as hashes; rotating sessions; rate limits; an audit log of sensitive actions, visible to the Owner on the Team plan.
- Logging. Logs contain IDs and counts, never file paths or file contents, and are kept for 30 days.
- Untrusted content. Content from code and documents is treated as data, never as instructions; Docdrift's AI can't take actions; every change to Customer's repositories or documents needs a person's approval.
- Deletion. Deletions are logged in a purge journal that is applied again if a backup is ever restored.
- Resilience. Daily backups with regular restore tests; monitoring of the servers and the Service.
- Incident response and disclosure. A process to assess and notify Security Incidents, and a public Responsible Disclosure Policy.
Annex III · Subprocessors
The Subprocessors authorized on the date of this DPA are those on the Subprocessors page, which is incorporated by reference.