DevLyTicks - Engineering Intelligence Platform Logo
DevLyTicks
Features
PricingDocumentation
Sign InStart Free
Start

Data Processing Agreement (DPA)

Last updated: September 2026 · This agreement applies to all DevLyTicks customers automatically, on account creation. On request, a countersigned version can be issued at [email protected].

1. Roles of the parties

When our customer (the organization that owns the DevLyTicks workspace) processes personal data made available through the service — including the personal data of its employees and of repository contributors — our customer is the controller (or an intermediary processor) and DevLyTicks acts as its processor within the meaning of Article 28 GDPR. For our own prospecting, platform administration and lawful-interest purposes described in the Privacy Policy, DevLyTicks acts as an independent controller.

2. Scope and instructions

  • Subject matter: synchronization, storage and analysis of repository and delivery data, and associated contributor identifiers, for the sole purpose of providing the Service to the organization.
  • Duration: for the term of the customer's subscription.
  • Data subjects: the customer's users, organization members, and contributors identified in connected repositories.
  • Categories of data: account identity data, repository metadata (commits, pull requests, issues, builds, deployments), contributor identifiers (name, commit email, avatar), billing contacts.
  • DevLyTicks processes personal data only on documented instructions from the customer, except where required by EU or member state law (in which case we inform the customer before processing, unless the law prohibits it).
  • The customer guarantees it holds the necessary rights over the connected repositories and informs the data subjects in its capacity as controller.

3. Sub-processors

DevLyTicks may engage the following sub-processors to operate the service, subject to contractual data protection obligations at least as protective as this agreement:

  • Hetzner Online GmbH (Germany) — infrastructure hosting (ISO 27001 certified).
  • Stripe (EU entities) — payment processing and invoicing.
  • PostHog Inc. (PostHog Cloud EU) — product analytics, consent-gated.
  • Email service provider — transactional emails, reports and newsletters.
  • Large language model providers — solely for the AI chat feature, when used by the customer.
  • Source providers (GitHub, GitLab, Bitbucket, Azure DevOps) — acting under the tokens the customer connects.

We maintain a current list of sub-processors on this page. Where we add a new sub-processor, we notify the customer with 30 days' prior notice, during which the customer may reasonably object (documented refusal on legitimate data-protection grounds). Removal/suspension of primary data outside the EU does not occur without appropriate safeguards (including the EU Standard Contractual Clauses).

4. Confidentiality and personnel

DevLyTicks ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security measures

  • TLS 1.2+ encryption in transit and encryption of personal data at rest.
  • Strong authentication, including support for two-factor authentication and session revocation.
  • Network isolation, automatic patching and dependency updates.
  • Internal production access restricted to need-to-know; support access to accounts is time-bound and announced in-product.
  • Logging and continuous monitoring of production environments.
  • Regular backups; restores are tested.

6. Data subject rights assistance

DevLyTicks assists the controller in responding to data subject requests (access, rectification, deletion, portability, restriction, objection). Data subjects may also exercise certain rights directly in-product (Account → Danger Zone: data export and account deletion), which DevLyTicks will confirm to the controller. Requests received by DevLyTicks from data subjects related to customer content are redirected to the controller unless legally prohibited.

7. Personal data breach notification

DevLyTicks notifies the controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach, providing the information available to enable the controller to meet its own notification obligations, and further information as it becomes available.

8. Dpia, enquiries and supervision

DevLyTicks provides reasonable assistance with data protection impact assessments and with enquiries from supervisory authorities, insofar as legally permissible. Nothing prevents the controller from cooperating with supervisory authorities.

9. Return and deletion

At the end of the provision of services, at the customer's choice, DevLyTicks deletes or returns all personal data relating to the customer within 30 days, and the same applies to existing sub-processors, unless EU or national law requires retention (e.g. accounting records).

10. Audit

The customer may, upon reasonable prior written notice and no more than once per year (except following a data breach), audit DevLyTicks' compliance with this agreement by means of (i) reviewing the public documentation available on the Security page, (ii) written questionnaires, or (iii) third-party, confidentiality-bound on-site audits where volatility of the data makes remote review insufficient. Formal certification reports (e.g. SOC 2 Type II once certification is complete) will be provided when available.

11. Effectiveness, changes and contact

This agreement is incorporated into and forms part of our Terms of Service; it takes effect when a workspace is created or a repository is connected. We may update this document to reflect changes in services or law; changes that materially reduce the customer's protection are notified by email 30 days in advance.
Contact: [email protected] (DevLyTicks, TODO (e.g. SAS, SASU, EURL, sole trader)).

See also: Privacy Policy · Security

DevLyTicks Logo
DevLyTicks

Making engineering analytics clear, actionable, and useful for development teams worldwide.

GitHubTwitterLinkedInYouTubeDiscord

Product

  • Features
  • Pricing
  • Documentation
  • Dashboard

Docs

  • Quick Start
  • OAuth Setup
  • Contributor Insights
  • Quality Metrics
  • Team Setup

Company

  • About Us
  • Blog
  • Careers
  • Contact

Support

  • Help Center
  • FAQ
  • Support
  • Privacy Policy
  • Terms of Service
  • Mentions légales
  • Terms of Use
  • Refund Policy
  • DPA
  • Security
© DevLyTicks. All rights reserved. Built with ❤️ for developers.