Data processing addendum
This addendum sets out the terms on which we would process personal data on someone's behalf. It is short, because on the tools there is nothing to process.
Scope
This addendum applies where a customer, acting as controller, instructs us to process personal data as processor. As of the review date at the top of this page, the published tools do not create that relationship: they run entirely in the visitor's browser and transmit nothing to us. The addendum exists so that the terms are already settled if that ever changes, and so that the change is visible as a diff rather than a surprise.
Roles
Where personal data is processed on a customer's behalf, the customer is the controller and we are the processor. Where we process data for our own purposes, such as the pageview telemetry on the portfolio site (V-4), we are the controller for that processing and it is covered by the privacy policy rather than by this addendum.
Instructions
We process personal data only on documented instructions from the controller, including transfers, unless required otherwise by law. If we believe an instruction breaches applicable data protection law, we will say so.
Confidentiality
Access is limited to the people who need it to deliver the service. As of the review date there is one such person, the owner of this toolchain. Anyone else granted access would be bound by a duty of confidentiality before receiving it.
Security
Our technical measures are published as a list, with how each one is checked and when it was last checked. See controls. We would rather be held to a list someone can verify than to an adjective.
Subprocessors
The current list is on the subprocessors page. The controller authorises those subprocessors. We will give notice of an addition before it processes data, and the notice is the commit that changes that page.
Two entries on that list are recorded as open (V-1, DNS and registrar, and V-6, company email). We do not treat an unconfirmed vendor as an authorised one.
Data subject requests
Because the tools hold nothing, a request about them has nothing to return. For any processing this addendum does cover, we will assist the controller in responding to a request within the time the law allows.
Personal data breach
We would notify the controller without undue delay after becoming aware of a breach affecting their personal data, with what we know at the time rather than waiting for a complete picture.
Deletion and return
On termination, personal data processed on the controller's behalf is deleted or returned at the controller's choice. Data held in a visitor's own browser is theirs to clear and was never ours to return.
International transfers
The subprocessors listed operate internationally. Where a transfer requires a lawful mechanism, the relevant standard contractual clauses or equivalent apply.
Audit
The published controls list, the public repositories and the commit history are the audit trail. We will answer reasonable questions in writing.
Changes
This document is versioned with the repository. The version and the review date are at the top of this page.