Last updated: September 2026 · This agreement applies to all DevLyTicks customers automatically, on account creation. On request, a countersigned version can be issued at [email protected].
When our customer (the organization that owns the DevLyTicks workspace) processes personal data made available through the service — including the personal data of its employees and of repository contributors — our customer is the controller (or an intermediary processor) and DevLyTicks acts as its processor within the meaning of Article 28 GDPR. For our own prospecting, platform administration and lawful-interest purposes described in the Privacy Policy, DevLyTicks acts as an independent controller.
DevLyTicks may engage the following sub-processors to operate the service, subject to contractual data protection obligations at least as protective as this agreement:
We maintain a current list of sub-processors on this page. Where we add a new sub-processor, we notify the customer with 30 days' prior notice, during which the customer may reasonably object (documented refusal on legitimate data-protection grounds). Removal/suspension of primary data outside the EU does not occur without appropriate safeguards (including the EU Standard Contractual Clauses).
DevLyTicks ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
DevLyTicks assists the controller in responding to data subject requests (access, rectification, deletion, portability, restriction, objection). Data subjects may also exercise certain rights directly in-product (Account → Danger Zone: data export and account deletion), which DevLyTicks will confirm to the controller. Requests received by DevLyTicks from data subjects related to customer content are redirected to the controller unless legally prohibited.
DevLyTicks notifies the controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach, providing the information available to enable the controller to meet its own notification obligations, and further information as it becomes available.
DevLyTicks provides reasonable assistance with data protection impact assessments and with enquiries from supervisory authorities, insofar as legally permissible. Nothing prevents the controller from cooperating with supervisory authorities.
At the end of the provision of services, at the customer's choice, DevLyTicks deletes or returns all personal data relating to the customer within 30 days, and the same applies to existing sub-processors, unless EU or national law requires retention (e.g. accounting records).
The customer may, upon reasonable prior written notice and no more than once per year (except following a data breach), audit DevLyTicks' compliance with this agreement by means of (i) reviewing the public documentation available on the Security page, (ii) written questionnaires, or (iii) third-party, confidentiality-bound on-site audits where volatility of the data makes remote review insufficient. Formal certification reports (e.g. SOC 2 Type II once certification is complete) will be provided when available.
This agreement is incorporated into and forms part of our Terms of Service; it takes effect when a workspace is created or a repository is connected. We may update this document to reflect changes in services or law; changes that materially reduce the customer's protection are notified by email 30 days in advance.
Contact: [email protected] (DevLyTicks, TODO (e.g. SAS, SASU, EURL, sole trader)).
See also: Privacy Policy · Security