Subprocessors
Fahid Digital Ventures LLC uses third parties to provide GitAegis. Each one is a subprocessor under the Data Processing Addendum, each is bound by a written contract with data protection terms no less protective than that DPA, and we remain liable to you for what they do. This page is the authoritative list, and it is updated before a new subprocessor starts processing customer data.
- Last updated
- 29 September 2026
1.What counts as a subprocessor here
1.1 A subprocessor is a third party we engage that processes personal data on our behalf in the course of providing GitAegis.
1.2 The desktop AI commit report is processed by Cloudflare Workers AI, on a signed-in account, when you press its button; it receives commit metadata and changed file paths and never file contents or commit message bodies. Nothing else in the desktop application involves a third party: the update check transmits no personal data, and no other request is made. See Privacy Policy §2.
1.3 Everything in section 2 applies to the paid cloud editions and to the marketing website.
1.4 Where a subprocessor is engaged for a capability that only some plans include, this page says so.
2.Current subprocessors
2.1 Google Analytics 4 and Google Tag Manager are provided by Google for optional marketing-site measurement after visitor consent. Google may process page URLs, referral, interaction, approximate location, device and browser data, and analytics identifiers. See Google Ads Data Processing Terms. The paid cloud edition categories below are planned separately.
2.2 The categories below are the processing the cloud editions require. Each one gets a named vendor, its legal entity, its processing region, and a link to its own data protection terms, on this page, before that vendor receives any customer data.
| Purpose | Data processed |
|---|---|
| Cloud and edge hosting: application servers, databases, network edge, TLS | Account identifiers, device identifiers, Git metadata, audit records, session data, IP addresses |
| Object storage for encrypted capsule objects and exports | Ciphertext only, plus object metadata: size, count, creation time, repository identifier, originating account and device |
| Transactional email: sign-in, verification, renewal reminders, breach notices | Name, email address, and the content of the transactional email |
| Payment processing, invoicing, tax calculation, fraud prevention | Name, email address, billing address, country, tax status, payment token, partial card details, transaction history |
| Error monitoring and crash reporting | Stack traces truncated to our own module names, application version, operating system, error type, account identifier |
| Product and website analytics | Page path, referrer, coarse country, coarse device type; and, with consent, feature usage counters, operation outcomes, error types, timings |
| Customer support desk: ticketing and correspondence | Name, email address, message content, attachments and support bundles you choose to send |
| Status page and incident notifications | Email address of subscribers, incident subscription preferences |
2.3 Naming a vendor before it is engaged would make this page wrong on the day it was published, which is the one thing a subprocessor list must never be.
2.4 Transfer safeguards for processing outside the EEA, UK, or Switzerland are set out in DPA §12.
3.What none of them ever receives
3.1 No subprocessor receives:
- the plaintext of your source code;
- diffs or patch content;
- the plaintext of your commits or your capsule objects. The object storage provider holds ciphertext, and neither it nor we hold the key material to decrypt it;
- your SSH private keys or your keychain contents;
- repository content, file paths, branch names, or repository names in telemetry or error reports.
3.2 The one exception is a support bundle you choose to send, which may reach the support desk provider. Bundles are generated locally, scanned for secrets, and path-redactable before you send them, and nothing is sent until you send it. See Privacy Policy §4.4.
3.3 We do not share data with advertising networks or data brokers, and we do not sell personal data.
4.Not subprocessors
4.1 The following are not subprocessors, because they process data under their own relationship with you rather than on our behalf:
- GitHub. You connect it, you authorise the scopes, and you can revoke access at any time. It is a third-party service under Terms §8.
- Your Git host, your CI system, and your remotes: GitAegis talks to them as you instruct.
- Your operating system’s keychain: a local component, not a service.
- Git itself: required at version 2.38.0 or newer and already installed on your machine. GitAegis never bundles or downloads it.
4.2 Professional advisers and auditors bound by confidentiality are not listed as subprocessors, and they do not receive customer personal data in the ordinary course.
5.How we choose and review them
5.1 Before engaging a subprocessor we review its security posture, its data protection terms, its processing locations, its transfer safeguards, and its own subprocessor list.
5.2 We engage it only under a written contract imposing obligations no less protective than the DPA.
5.3 We review each subprocessor periodically, and immediately after any security incident affecting it that we become aware of. The review cadence is not set in this draft.
5.4 We minimise the data each one receives to what its purpose requires. That is why the object storage provider holds ciphertext, and why error reports carry no repository paths.
5.5 We describe these practices. We do not claim any certification we do not hold, for ourselves or on a vendor’s behalf; where a vendor holds one, that is a matter for the vendor’s own documentation.
6.Notice before a change
6.1 We give advance notice before adding or replacing a subprocessor. How many days is not set in this draft, and it is the same period as DPA §9.5.
6.2 Notice is given in two ways at once:
- by email to every address subscribed to subprocessor notifications; and
- by updating this page, with the change recorded in a change log.
6.3 During the notice period, the new subprocessor does not process customer data.
6.4 Where a change is needed urgently to protect the security or availability of the service (for example replacing a provider that has suffered a serious incident) we may act with shorter notice and will tell you as soon as practicable, with the reason. Your right to object under section 8 still applies.
6.5 Change log. There is nothing to log. The first entry is written when the first subprocessor is engaged, and no entry is ever rewritten afterwards. The log is the evidence that notice was given.
7.Subscribe to change notifications
7.1 Anyone can subscribe, customer or not. There is no subscription page yet, and no transactional email is bound in any environment, so there is nothing that could send a notification today. Until there is, write to privacy@gitaegis.com and we will add you to the list by hand.
7.2 Subscription emails contain the change, the new subprocessor, its purpose and location, the date it takes effect, and a link to object.
7.3 Unsubscribe from any notification email. Unsubscribing removes you from the alerts; it does not remove your right to object under section 8.
8.Your right to object
8.1 If you are a customer, you may object to a new subprocessor on reasonable data protection grounds by writing to privacy@gitaegis.com within the notice period.
8.2 We will work with you in good faith to offer a configuration change or an alternative that avoids the objected-to processing.
8.3 If we cannot offer a reasonable alternative within a reasonable period, you may terminate the affected services and we will refund prepaid fees for the terminated portion of the term. That is your exclusive remedy for an unresolved objection.
8.4 The full terms are at DPA §9.
8.5 Customers with vendor requirements should raise them with sales@gitaegis.com before purchase, so they can be handled in the order form rather than after the fact. There is no regional residency mechanism to offer.
9.Contact
9.1 Subprocessor questions and objections: privacy@gitaegis.com
9.2 A named data protection contact and a postal address for Fahid Digital Ventures LLC are not published in this draft.
9.3 Related: Data Processing Addendum · Privacy Policy · Cookie Policy · Security