Legal

Data Processing Addendum

Last updated October 8, 2026

This Data Processing Addendum (the "DPA") sets out the terms on which SzafranSoft (Łukasz Szafrański), which operates Veridical, processes personal data on behalf of business customers that use the Veridical code-review Service. It contains the terms Article 28 of the EU General Data Protection Regulation (GDPR) requires, and it forms part of the Terms of Service at /terms. Effective date and Last updated: October 8, 2026.

011. Parties, scope and how this DPA applies

In this DPA, "Veridical," "we," "us" and "our" mean SzafranSoft (Łukasz Szafrański), a sole trader registered in the Polish Central Registration and Information on Business (CEIDG), ul. Myśliwska 24/34, 80-126 Gdańsk, Poland, NIP 5833526510, REGON 540460539. "Customer" means the company, organization or professional that has accepted the Terms of Service and uses the Service for its business. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the GDPR.

"Customer Personal Data" means personal data that Veridical processes on Customer's behalf to provide the Service: personal data in Your Content (as defined in the Terms of Service), in other data Customer or its users submit to the Service, or in data the Service receives from a repository Customer connects. Examples are names, usernames and email addresses in commit metadata, the text of pull-request descriptions and comments, and personal data inside code, configuration, test data or files.

This DPA applies automatically when Customer accepts the Terms of Service, and no separate signature is needed. If Customer needs a signed copy for its records, it can ask at contact@veridical.dev.

This DPA does not cover personal data for which Veridical is the controller, such as account and workspace identity, billing records, security and abuse-prevention records, website data, product analytics and correspondence. The Privacy Policy at /privacy describes that processing. This DPA also does not apply where an individual uses the Service for purely personal purposes; the Privacy Policy applies instead.

If this DPA conflicts with the Terms of Service, this DPA controls for Customer Personal Data. If Standard Contractual Clauses apply under Section 9 and conflict with this DPA, the Standard Contractual Clauses control.

022. Roles of the parties

Customer is the controller of Customer Personal Data, or a processor acting for another controller. Veridical is Customer's processor. Where Customer acts as a processor, Customer confirms that its controller has authorized the processing and the sub-processors described in this DPA, and Veridical acts as Customer's sub-processor.

Customer is responsible for having a lawful basis for the processing, for giving its data subjects any notices the law requires, and for having the right to submit Your Content to the Service. As the Privacy Policy also asks, Customer should not submit special-category personal data, data about criminal convictions, passwords, access tokens or private keys.

033. Details of the processing

The processing is described below. Where Standard Contractual Clauses apply, their Annex I uses the same description.

  • Subject matter: providing the Service, which reviews pull requests in repositories Customer authorizes and returns findings, evidence and checks, together with support and security of the Service.
  • Duration: for as long as Customer uses the Service, and then until deletion under Section 11.
  • Nature and purpose: receiving, storing, analyzing and transmitting repository and pull-request data to produce review findings, evidence receipts, checks and, where Customer requests them, fixes; sending the relevant parts of the code and pull-request context to a model provider for analysis; running builds and tests in isolated execution environments; publishing results to the repository Customer connected; and support, security and abuse prevention for the Service.
  • Categories of data subjects: Customer's personnel and contractors; contributors to Customer's repositories, such as commit authors, reviewers and commenters; and any other individuals whose personal data Customer includes in its repositories.
  • Types of personal data: names, usernames and forge account identifiers; email addresses in commit metadata; the text of pull-request descriptions, review comments and commit messages; and any personal data in code, configuration, test data or files Customer submits.
  • Special categories of personal data: none intended (see Section 2).
  • Frequency: continuous, each time a review runs on a repository Customer has connected or Customer requests one.

044. Processing on Customer's instructions

Veridical processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers to a third country, unless EU or member-state law to which Veridical is subject requires otherwise. In that case Veridical will tell Customer of that legal requirement before processing, unless that law prohibits it.

Customer's documented instructions are the Terms of Service and this DPA, together with Customer's configuration and use of the Service, such as the repositories it connects, the reviews and fixes it requests, and its workspace settings. Additional instructions need Veridical's written agreement.

Veridical will tell Customer immediately if, in its opinion, an instruction infringes the GDPR or other EU or member-state data-protection law.

055. Confidentiality

Veridical ensures that every person it authorizes to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and processes Customer Personal Data only as needed to provide, support and secure the Service.

066. Security

Veridical implements the technical and organizational measures Article 32 GDPR requires, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to individuals. The current measures are listed in Section 14. Veridical may update them, but will not reduce the overall level of protection while Customer uses the Service.

077. Sub-processors

Customer gives Veridical general written authorization to engage sub-processors. The current sub-processors are listed in Section 15.

Veridical will tell Customer about any intended addition or replacement of a sub-processor at least 30 days before the change, by updating Section 15 and emailing the workspace owner's account email address. Customer may object on reasonable data-protection grounds by writing to contact@veridical.dev within that period. The parties will discuss the objection in good faith. If it is not resolved, Customer may stop using the affected part of the Service before the change takes effect, and Veridical will refund any prepaid fees for the period after that date.

Veridical imposes on each sub-processor, by written contract, data-protection obligations that give at least the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organizational measures. Veridical remains fully liable to Customer for the performance of each sub-processor's obligations.

088. Assistance to Customer

Data-subject requests. If Veridical receives a request from a data subject about Customer Personal Data, it will pass the request to Customer without undue delay and will not answer it, other than to refer the data subject to Customer, unless Customer instructs otherwise. Taking into account the nature of the processing, Veridical will help Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise data-subject rights.

Other obligations. Taking into account the nature of the processing and the information available to it, Veridical will reasonably help Customer meet its obligations under Articles 32 to 36 GDPR, which cover security, personal data breach notification, data-protection impact assessments and prior consultation with a supervisory authority.

099. International transfers

Veridical stores Customer Personal Data primarily in Google Cloud's Warsaw region (europe-central2), in Poland. Some sub-processors in Section 15 may process it outside the European Economic Area (EEA). In particular, the model provider's deployments use Microsoft's Global Standard deployment type, under which Microsoft may process a review request in any Azure region where the model is available.

Veridical transfers Customer Personal Data outside the EEA only to a country covered by an adequacy decision of the European Commission, or with an appropriate safeguard under Article 46 GDPR, principally the European Commission's Standard Contractual Clauses, or, where the recipient is certified, under the EU-US Data Privacy Framework. Customer authorizes the transfers needed for the sub-processors in Section 15 on that basis.

1010. Personal data breaches

Veridical will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, by email to the workspace owner's account email address. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Veridical will give further information as it becomes available and will take reasonable steps to contain the breach and reduce its effects.

A notification under this Section is not an admission of fault or liability.

1111. Deletion and return

Customer can stop new processing at any time by uninstalling the Veridical GitHub App or removing a repository from it. Comments and checks already published to a repository stay there, under that repository's own controls.

When Customer stops using the Service, or earlier on Customer's written request to contact@veridical.dev, Veridical will delete Customer Personal Data within 30 days, unless EU or member-state law requires Veridical to keep it. Before deletion, Customer may ask for a copy of the review findings Veridical holds for its workspace, and Veridical will provide it in a commonly used electronic format.

Some copies expire on their own schedule rather than on request: review artifacts in object storage are deleted automatically 30 days after they are created, after which deleted objects remain recoverable for 7 days; database backups and recovery logs are kept for 7 days; and operational logs expire under the periods in the Privacy Policy. Until they expire, these copies stay protected under this DPA and are not used for any other purpose.

1212. Information and audits

Veridical will make available to Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Security page at /security, and written answers to reasonable security questionnaires, which Customer may send once in any 12 months.

Veridical will allow for and contribute to audits, including inspections, by Customer or an independent auditor Customer mandates, where that information is not enough to demonstrate compliance, or where a supervisory authority or a personal data breach requires it. Customer will give at least 30 days' written notice, except after a personal data breach or at a supervisory authority's request. Audits take place during normal business hours, avoid unreasonable disruption, are subject to appropriate confidentiality, and are at Customer's cost. Audits of a sub-processor's facilities are carried out through that sub-processor's own audit reports and certifications.

1313. Liability, duration, changes and governing law

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where mandatory law does not allow them. Nothing in this DPA limits a data subject's rights under the GDPR.

This DPA lasts for as long as Veridical processes Customer Personal Data. Veridical may update it by posting a new version at /dpa and changing the effective date. A change that materially reduces the protection of Customer Personal Data will not apply to Customer until at least 30 days after notice by email to the workspace owner, unless the law requires it sooner.

This DPA is governed by Polish law, the law that governs the Terms of Service, and disputes about it are resolved as the Terms of Service describe.

1414. Security measures

These are the technical and organizational measures Veridical applies to Customer Personal Data. They are design controls, not a certification or a guarantee, and they restate what the Security page and the Privacy Policy describe.

  • Encryption in transit: connections to the website, the application and the API use TLS.
  • Encryption at rest: Customer Personal Data is stored in Google Cloud services, which encrypt stored data by default.
  • Region: the control plane, database, object storage and review workers run in Google Cloud's Warsaw region.
  • Tenant isolation: authorization is scoped to the workspace (tenant), and customer views omit provider credentials.
  • Repository access: GitHub webhook signatures are verified before any work is accepted, and GitHub installation tokens are short-lived and scoped to the repository being reviewed.
  • Execution isolation: reviews run in isolated execution environments. Review workers do not receive the GitHub App private key or standing cloud credentials, and secrets and secret-bearing environment variables are redacted from receipts.
  • Secrets: provider credentials are held in a managed secret store, separate from review workloads.
  • Retention: source-derived artifacts in object storage expire automatically (Section 11), and other data is kept under the retention periods in the Privacy Policy.
  • Records: audit records of privileged activity are kept, as the Privacy Policy describes.
  • Personnel: access to production systems is limited to the people who operate the Service, who are bound by confidentiality (Section 5).
  • Incidents: suspected personal data breaches are handled under Section 10.

1515. Sub-processors

Veridical uses the following sub-processors for Customer Personal Data. Each processes it only to provide its part of the Service.

  • Google Cloud Platform (Google) - hosting of the Service: application, database, object storage, queues, logs, key management and isolated review execution. Location: Warsaw, Poland (europe-central2).
  • Microsoft Azure OpenAI (Microsoft) - model processing of code and pull-request context for reviews. Location: the Azure resource is in Germany West Central; with the Global Standard deployment type, Microsoft may process a request in any Azure region where the model is available (Section 9).
  • WorkOS - sign-in, single sign-on and directory sync for Customer's users, where Customer's organization connects its identity provider. Location: may process data in the United States.
  • Resend - delivery of service emails to Customer's users, which may include workspace and repository names. Location: may process data in the United States.

1616. Providers that are not sub-processors

These providers receive only data for which Veridical is the controller, or act for Customer under Customer's own agreement, so they are not sub-processors of Customer Personal Data. The Privacy Policy describes them.

  • Stripe - checkout, subscriptions and payments for paid plans. Stripe handles payment credentials directly and may act as an independent controller for regulated payment activities.
  • PostHog (EU cloud), Google Analytics 4 and Microsoft Clarity - measurement that runs only with consent. PostHog event properties exclude code, finding text, email addresses and authentication tokens.
  • GitHub and other forges - Customer's own provider, used under Customer's own agreement with it. Veridical reads from and publishes to the repositories Customer connects.

1717. Contact

Questions about this DPA, objections to a sub-processor, data-subject requests that reach Customer about the Service, and breach contacts go to contact@veridical.dev. Postal address: SzafranSoft (Łukasz Szafrański), ul. Myśliwska 24/34, 80-126 Gdańsk, Poland.

Questions about this data processing addendum? Email contact@veridical.dev.