trust

The policies, the subprocessor list, and the controls we actually check.

Version 0.0.1 · last reviewed 2026-09-21

Data processing addendum

This addendum sets out the terms on which we would process personal data on someone's behalf. It is short, because on the tools there is nothing to process.

Scope

This addendum applies where a customer, acting as controller, instructs us to process personal data as processor. As of the review date at the top of this page, the published tools do not create that relationship: they run entirely in the visitor's browser and transmit nothing to us. The addendum exists so that the terms are already settled if that ever changes, and so that the change is visible as a diff rather than a surprise.

Roles

Where personal data is processed on a customer's behalf, the customer is the controller and we are the processor. Where we process data for our own purposes, such as the pageview telemetry on the portfolio site (V-4), we are the controller for that processing and it is covered by the privacy policy rather than by this addendum.

Instructions

We process personal data only on documented instructions from the controller, including transfers, unless required otherwise by law. If we believe an instruction breaches applicable data protection law, we will say so.

Confidentiality

Access is limited to the people who need it to deliver the service. As of the review date there is one such person, the owner of this toolchain. Anyone else granted access would be bound by a duty of confidentiality before receiving it.

Security

Our technical measures are published as a list, with how each one is checked and when it was last checked. See controls. We would rather be held to a list someone can verify than to an adjective.

Subprocessors

The current list is on the subprocessors page. The controller authorises those subprocessors. We will give notice of an addition before it processes data, and the notice is the commit that changes that page.

Two entries on that list are recorded as open (V-1, DNS and registrar, and V-6, company email). We do not treat an unconfirmed vendor as an authorised one.

Data subject requests

Because the tools hold nothing, a request about them has nothing to return. For any processing this addendum does cover, we will assist the controller in responding to a request within the time the law allows.

Personal data breach

We would notify the controller without undue delay after becoming aware of a breach affecting their personal data, with what we know at the time rather than waiting for a complete picture.

Deletion and return

On termination, personal data processed on the controller's behalf is deleted or returned at the controller's choice. Data held in a visitor's own browser is theirs to clear and was never ours to return.

International transfers

The subprocessors listed operate internationally. Where a transfer requires a lawful mechanism, the relevant standard contractual clauses or equivalent apply.

Audit

The published controls list, the public repositories and the commit history are the audit trail. We will answer reasonable questions in writing.

Changes

This document is versioned with the repository. The version and the review date are at the top of this page.