Skip to content

Data Processing Addendum

This DPA forms part of the Terms of Service or other written agreement between the customer and Fahid Digital Ventures LLC. It applies where we process personal data on your behalf in connection with GitAegis. It is incorporated automatically into the Agreement for all Team and Enterprise plans and requires no signature; if your procurement process requires a signed copy, request one at privacy@gitaegis.com.

Last updated
10 August 2026

1.Definitions

1.1 “Data Protection Law” means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK GDPR and Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection, and US state privacy laws including the CCPA as amended.

1.2 “Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach”, and “supervisory authority” have the meanings given in the EU GDPR, and equivalent terms under other Data Protection Law are read accordingly.

1.3 “Customer Personal Data” means personal data contained in Customer Data that we process on your behalf under the Agreement.

1.4 “Services” means GitAegis as described in the Agreement: the desktop application, the account service at app.gitaegis.com, and the cloud capabilities enabled on your plan.

1.5 “Subprocessor” means a third party engaged by us to process Customer Personal Data.

1.6 “SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.

1.7 “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

1.8 “Business”, “service provider”, and “sell” have the meanings given in the CCPA.

2.Roles of the parties

2.1 For Customer Personal Data processed under the Agreement, you are the controller and Fahid Digital Ventures LLC is the processor. Under the CCPA, you are the business and we are a service provider.

2.2 Where you are yourself a processor for another controller, you warrant that you have the authority of that controller to appoint us as a subprocessor on these terms, and references to your instructions include that controller’s instructions passed through you.

2.3 We are an independent controller for a limited set of data we need for our own purposes, and this DPA does not apply to it: billing and tax records, account administration for the individual who contracts with us, security and abuse-prevention logs, and website analytics. Our processing as controller is described in the Privacy Policy.

2.4 We do not sell or share Customer Personal Data, and we do not retain, use, or disclose it for any purpose other than performing the Services, except as permitted by Data Protection Law. We certify that we understand this restriction and will comply with it.

3.Scope and duration

3.1 This DPA applies from the effective date of the Agreement and for as long as we process Customer Personal Data.

3.2 It survives termination of the Agreement until all Customer Personal Data has been deleted or returned under section 14.

3.3 It applies to all environments in which the Services are provided, including production, staging where Customer Personal Data is present, and backups.

3.4 It does not apply to purely local use of the desktop application, which transmits nothing and creates no processing relationship. See Privacy Policy §2.

3.5 Operational status. The paid cloud editions described in this document are not in operation. GitAegis ships today for macOS with no cloud service running, so nothing described here is processing anyone's data yet. Two requests the application does make are outside that scope and are described where they belong: the update check, which carries no identifier, and the AI commit report, which runs on a signed-in account when the user asks for one. This document is published for review, not as a live notice.

4.Nature and purpose of processing

4.1 We process Customer Personal Data to provide, secure, maintain, and support the Services, as described in Annex I.

4.2 The processing operations include collection, storage, retrieval, transmission, structuring, restriction, erasure, and destruction.

4.3 We do not use Customer Personal Data to train models.

4.4 A material technical fact that shapes this DPA: capsule objects are encrypted on the Customer’s device before upload, and we do not hold the key material. With respect to capsule contents we process ciphertext and associated metadata only. We cannot read, search, extract, amend, or produce capsule contents, for you, for a data subject, or for a third party. Where an instruction requires access to capsule plaintext, we cannot carry it out, and section 6.4 applies.

5.Categories of data subjects and personal data

5.1 Categories of data subjects and of personal data are set out in Annex I, sections A.3 and A.4.

5.2 No special category data as defined in Article 9 of the GDPR is required by the Services, and you must not submit any. If you do so, it is processed under this DPA without our having agreed to any additional measures specific to it.

5.3 You are responsible for the lawfulness of the personal data you submit, for having a lawful basis for it, and for providing any notice or obtaining any consent required from data subjects.

6.Customer instructions

6.1 We process Customer Personal Data only on your documented instructions, including for international transfers, unless required otherwise by law to which we are subject.

6.2 The Agreement, this DPA, and your use of the Services’ configuration and controls constitute your complete documented instructions. Additional instructions require agreement, and may attract a reasonable charge where they require work outside the Services.

6.3 If we are required by law to process beyond your instructions, we will tell you before processing unless that law forbids it on important grounds of public interest.

6.4 We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law, or if we cannot carry it out for the technical reason in section 4.4. We may suspend the affected processing until the instruction is amended or withdrawn.

7.Confidentiality

7.1 We treat Customer Personal Data as confidential and do not disclose it except as this DPA permits.

7.2 Personnel authorised to process Customer Personal Data are bound by written confidentiality obligations that survive the end of their engagement, and are subject to those obligations before access is granted.

7.3 Access is limited to personnel who need it to provide or support the Services, is granted on a least-privilege basis, and is revoked promptly on role change or departure. The cadence at which access is reviewed is not set in this draft.

7.4 If we receive a law enforcement or government request for Customer Personal Data, we will redirect the requester to you where possible, and will notify you before disclosing unless legally prohibited. Where prohibited, we will use reasonable efforts to challenge the prohibition and to disclose the minimum required. We publish the frequency of such requests where we are permitted to.

8.Security measures

8.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

8.2 Those measures are set out in Annex II and are incorporated into this DPA as a contractual commitment, not a description of intentions. A measure that would depend on a period nobody has set is absent from Annex II rather than stated vaguely.

8.3 We may update the measures over time. We will not reduce the overall level of security provided during the term.

8.4 We describe our practices and controls. We do not claim any certification we do not hold. Where a certification or third-party attestation is obtained, it will be published on the Security page and named there, and only then.

8.5 You are responsible for your own side of the shared control model: managing your users and seats, deciding which repositories have cloud backup enabled, and safeguarding the key material described in section 4.4.

9.Subprocessors

9.1 You give general written authorisation for us to engage subprocessors, subject to this section.

9.2 The list of subprocessors, with purpose, data processed, location, and a link to each one’s own data protection terms, is at Subprocessors. No vendor is named on it yet.

9.3 Before a subprocessor starts processing Customer Personal Data, we impose data protection obligations on it by written contract that are no less protective than those in this DPA, and appropriate to the processing it performs.

9.4 We remain fully liable to you for the performance of each subprocessor’s obligations.

9.5 Notice of change. We will give advance notice before adding or replacing a subprocessor, by email to the addresses subscribed to subprocessor notifications and by updating the subprocessors page. The length of that notice period is not set in this draft.

9.6 Right to object. You may object to a new subprocessor on reasonable data protection grounds by writing to privacy@gitaegis.com within the notice period. We will work with you in good faith to offer a change in configuration or an alternative that avoids the objected-to processing.

9.7 If we cannot offer a reasonable alternative within a reasonable period, you may terminate the affected Services by written notice, and we will refund prepaid fees for the terminated portion of the term. That is your exclusive remedy for an unresolved objection.

9.8 Where a change is needed urgently to protect the security or availability of the Services, we may appoint a subprocessor with shorter notice and will tell you as soon as practicable, with the reason. Your right to object under 9.6 still applies.

10.Data subject requests

10.1 Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to data subject requests.

10.2 The self-service tooling the pack describes (access, correction, export, restriction and deletion from within the account) is not built. Until it is, requests are handled by a person at privacy@gitaegis.com.

10.3 If a data subject contacts us directly about Customer Personal Data, we will not respond substantively. We will acknowledge, tell them to contact you, and forward the request to you promptly, unless you have instructed us otherwise.

10.4 We may charge for assistance that is disproportionate or repeated, after telling you the cost first.

10.5 The technical limit in section 4.4 applies to requests as well: we can delete encrypted capsule objects whole, and we cannot extract, amend, or produce their contents.

10.6 We also assist you, taking account of the information available to us, with data protection impact assessments and prior consultations under Articles 35 and 36 of the GDPR.

11.Personal data breach notification

11.1 We will notify you of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it. A fixed outer limit in hours is a contractual commitment this draft does not state.

11.2 The notification will be sent to the security contact you have registered on the account, and to the account owner if none is registered. Keep that contact current. It is where breach notice goes.

11.3 The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information.

11.4 Where we cannot provide all of that at once, we will provide it in phases without further undue delay, and will keep you updated as the investigation proceeds.

11.5 We will take reasonable steps to contain and remediate the breach, and will preserve evidence for investigation.

11.6 Notification is not an admission of fault or liability by either party.

11.7 We will not make a public statement identifying you in connection with a breach without your prior consent, unless legally required.

11.8 Notifying supervisory authorities and affected data subjects is your responsibility as controller. We will provide the information you reasonably need to do it on time.

12.International transfers

12.1 No hosting provider and no processing region have been chosen, so Annex I section A.7 lists none and this section cannot yet be made concrete for a particular destination.

12.2 Where we process personal data subject to the EU GDPR outside the EEA without an adequacy decision, the SCCs apply and are incorporated by reference, with:

  • Module Two (controller to processor) where you are a controller;
  • Module Three (processor to processor) where you are a processor acting for another controller;
  • Clause 7 (docking clause) included;
  • Clause 9, option 2 (general written authorisation) with the notice period in section 9.5;
  • Clause 11, the optional independent dispute resolution language, not included;
  • Annex I and Annex II of the SCCs populated by Annex I and Annex II of this DPA.

12.3 The governing law under Clause 17 and the forum under Clause 18(b) are not stated in this draft. Both are settled with EEA and UK data protection counsel.

12.4 Where personal data subject to the UK GDPR is transferred, the UK Addendum applies to the SCCs, with Tables 1 to 4 completed by reference to this DPA and the ending selected as “Importer”.

12.5 Where personal data subject to Swiss law is transferred, the SCCs apply with references read as references to the Swiss FADP, the competent authority read as the Federal Data Protection and Information Commissioner, and the term “member state” read so as not to prevent data subjects in Switzerland from enforcing their rights in their place of habitual residence.

12.6 We will notify you if we become subject to a legal requirement that would prevent us from complying with the SCCs, and you may suspend transfers or terminate the affected Services.

12.7 We conduct a transfer impact assessment for each destination and provider, and will make its conclusions available on request under section 13.

12.8 There is no data residency mechanism. We cannot bind an account, a workspace or an object to a region, and this DPA does not offer to.

12.9 The SCCs and the UK Addendum are attached in full as executed annexes to a signed customer agreement. Incorporation by reference on a web page is not sufficient for a signature copy.

13.Audits

13.1 We will make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

13.2 In the first instance, you may satisfy 13.1 by reviewing:

  • this DPA and Annex II;
  • the Security page;
  • the Subprocessors page;
  • our written responses to a reasonable security questionnaire;
  • any third-party assessment or penetration test summary we make available.

13.3 If that is not sufficient for a documented regulatory reason, you may request an audit on written notice, no more than once in any twelve-month period, unless required more often by a supervisory authority or following a personal data breach affecting your data. The length of notice required is not set in this draft.

13.4 Audits are conducted during business hours, subject to confidentiality obligations, in a manner that does not disrupt the Services or compromise the data of other customers, and are limited to systems and records relevant to your Customer Personal Data.

13.5 An auditor you mandate must not be a competitor of ours and must sign a confidentiality undertaking.

13.6 Each party bears its own audit costs. We may charge our reasonable costs for on-site audits and for assistance beyond an included allowance, quoted in advance. That allowance is not set in this draft.

13.7 Findings are confidential and may be used only to assess compliance with this DPA.

14.Deletion and return on termination

14.1 On termination or expiry of the Agreement, you may export Customer Personal Data yourself, through the Services, for a stated window. The length of that window is not set in this draft.

14.2 On your written request within that window, we will return Customer Personal Data in a structured, commonly used, machine-readable format. We may charge our reasonable costs for an export that goes beyond the Services’ own export tooling.

14.3 After the export window, we will delete Customer Personal Data from live systems, and it will age out of backups, after which backup media is overwritten in the ordinary course. Both periods are numbers this draft does not state.

14.4 Encrypted capsule objects are deleted whole. We cannot decrypt them for you first (section 4.4). Export before the window closes.

14.5 We may retain Customer Personal Data where required by law, and where we do, we will keep it confidential, protect it under this DPA, and process it only for the purpose requiring retention. Billing and tax records are the usual case: see Privacy Policy §7.

14.6 On request, we will certify in writing that deletion has been carried out.

15.Liability and order of precedence

15.1 Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, to the extent permitted by law.

15.2 Nothing in this DPA limits any right a data subject has under Data Protection Law, or any liability that cannot lawfully be limited.

15.3 Order of precedence, where terms conflict: (1) the SCCs and UK Addendum, (2) this DPA, (3) the Agreement, (4) any other document.

15.4 If a provision of this DPA is invalid, the rest stands and the parties will replace it with a valid provision achieving the same purpose.

15.5 This DPA is governed by the law stated in the Agreement, except where Data Protection Law requires otherwise, and except as stated in section 12 for the SCCs.

16.Contact

16.1 Data protection: privacy@gitaegis.com

16.2 Security and breach reports: security@gitaegis.com: see the Vulnerability Disclosure Policy.

16.3 A named data protection contact, Article 27 representatives for the EU and the UK, and a postal address for Fahid Digital Ventures LLC are not published in this draft.

17.Annex I: Processing details

A.1 Parties. The data exporter and controller is the Customer identified in the Agreement, at the address in its account record, with the account owner and any registered security or privacy contact as its contacts. The data importer and processor is Fahid Digital Ventures LLC, contactable at privacy@gitaegis.com. Its registered address and registration number are not stated in this draft.

A.2 Duration. For the term of the Agreement, plus the retention and deletion periods in section 14.

A.3 Categories of data subjects.

  • Customer's employees, contractors, and other authorised users of the Services
  • Customer's administrators and billing contacts
  • Individuals identified in Git metadata that the Customer transmits: commit authors and committers, including those who are not users of the Services
  • Individuals identified through connected provider accounts: GitHub account holders whose activity appears in linked pull requests, reviews, and comments
  • Individuals who contact Customer's support or whose details appear in support correspondence

A.4 Categories of personal data.

Categories of personal data processed on the customer's behalf under this DPA.
CategoryDetail
Account identifiersName, email address, password hash, organisation, role, language
Device identifiersPer-installation identifier, OS and version, application version, CPU architecture, device name
Authentication dataSession identifiers
Subscription and billing recordsPlan, seats, renewal date, billing country, tax status, invoice history
Git metadataCommit author and committer names, email addresses, timestamps, and repository and branch identifiers, where transmitted for cloud capability
Encrypted capsule objectsCiphertext only, plus object metadata: size, count, creation time, repository identifier, originating account and device
Provider OAuth tokensAccess and refresh tokens and the provider account and host they belong to
Audit recordsActor, action, timestamp, tenant, workspace, repository, outcome, and override evidence
Notification statePer-device read state, quiet hours settings
Support correspondenceEmails, attachments, and support bundles the Customer chooses to send
Opt-in telemetryFeature usage counters, operation outcomes, error types, performance timings: where the user has consented

Not processed: source code content, diffs, or commit contents in plaintext; source code content in telemetry or error reports; SSH private keys; keychain contents.

A.5 Sensitive data. None is required or expected. See section 5.2.

A.6 Frequency of processing. Continuous, for the duration of the Agreement.

A.7 Processing locations. None can be listed. No hosting provider and no region have been chosen, and there is no mechanism that would bind a record to one.

A.8 Retention. As set out in Privacy Policy §7 and section 14 of this DPA.

A.9 Subprocessors. As listed at Subprocessors, each with its purpose and processing location, for a duration matching the term of the Agreement.

A.10 Competent supervisory authority. For SCC purposes, the supervisory authority of the EEA member state in which the data exporter is established, or where the exporter is not established in the EEA, the authority of the member state in which its Article 27 representative is established.

18.Annex II: Technical and organisational measures

These are contractual commitments under section 8.2. They describe controls we operate; they do not claim any certification. They apply to the cloud service, which is not in operation.

Encryption

  • Customer capsule objects are encrypted on the Customer's device before upload. We store ciphertext and do not hold the key material required to decrypt it.
  • Data in transit is encrypted with TLS 1.2 or higher, with modern cipher suites and HSTS on all web endpoints.
  • Data at rest is encrypted using AES-256 or equivalent.
  • Secrets and credentials are held in a managed secrets store, not in source code, configuration files, or environment variables committed to a repository.
  • Passwords are stored only as salted hashes using a memory-hard algorithm.

Access control

  • Access to production requires named individual accounts, multi-factor authentication, and least-privilege role assignment. Shared accounts are not used.
  • Production access is granted through a documented request and is time-bounded where practical.
  • Administrative actions in production are logged with actor, action, and timestamp, and are protected against modification by the person who generated them.

Tenant isolation

  • Customer data is logically separated by tenant identifier, and every data access path carries tenant scope.
  • Audit records carry tenant and repository attribution.
  • Object storage keys are namespaced per tenant, and cross-tenant access is denied by policy, not only by application logic.

Network and infrastructure security

  • Production runs in a private network with restricted ingress and no direct public access to data stores.
  • Administrative interfaces are not exposed to the public internet.
  • Infrastructure is defined as code and changed through reviewed pull requests.

Application security

  • All code changes require review by a second engineer before merge.
  • Automated dependency scanning, static analysis, and secret scanning run in CI, and a failing security check blocks merge.
  • Desktop releases are code-signed.
  • Git subprocesses are launched with a pinned configuration environment and terminal prompting disabled. External diff and merge tools are never executed.
  • Support bundles are generated locally, scanned for secrets, and path-redactable before the Customer chooses to send them.

Logging and monitoring

  • Application, infrastructure, and access logs are centralised and time-synchronised.
  • Logs are scrubbed of source code content, diffs, and repository paths.

Incident response

  • A documented incident response plan assigns roles, severity levels, and communication paths.
  • Breach notification to the Customer without undue delay, per section 11.
  • A post-incident review is carried out with corrective actions tracked to completion.

Personnel

  • Background checks where lawful and proportionate for roles with production access.
  • Written confidentiality obligations before access is granted.
  • Security awareness training at onboarding.
  • Documented offboarding that revokes access and returns equipment.

Supplier management

  • Security and data protection review before a subprocessor is engaged.
  • Written data protection terms no less protective than this DPA.
  • The current list is published at /legal/subprocessors.

Data minimisation and deletion

  • We collect the categories in Annex I section A.4 and no more. Telemetry is opt-in and carries no repository content.
  • Deletion propagates from live systems immediately and through backups within the backup retention window.

Physical security

  • We do not operate our own data centres. Physical access, environmental protection, and media destruction are controlled by the hosting provider.
  • Company devices with any production access use full-disk encryption, screen lock, and remote wipe.

Business continuity. No measure is stated. A backup schedule, a restore-test cadence, and recovery objectives are commitments this draft cannot make: encrypted backups with tested restores are among the things that must exist before the cloud service is offered for sale, and a recovery objective nothing measures is not a commitment.

30-day trial · No card required

A recovery capsule before every risky Git operation.

You see the exact commands before they run, and the operation is refused if the capsule cannot be written.

Requires Git 2.38.0 or newer, already installed.

Every risky operation, in this order

  1. Previewthe exact commands, shown before anything runs
  2. Capsulerefs, index, staged and working changes, untracked files, operation state: written to disk first
  3. Executethe commands as shown, or not at all
  4. Journalplan, commands, capsule id, outcome
No capsule, no operation. Restore plans, previews, and takes its own capsule.