ConformOps
How it worksWhat you getPricingCompareReporting deadlinesSecurityCRA resources
Sign inStart free
How it worksWhat you getPricingCompareReporting deadlinesSecurityCRA resourcesSign in
Legal

Data processing agreement

Last updated 30 August 2026

This Data Processing Agreement (DPA) forms part of the ConformOps Terms of Service when a business customer uses ConformOps to process personal data on its behalf. The customer is the Customer and normally the controller; Simone Laudani, operating ConformOps from Italy, is the Processor for Customer Personal Data. ConformOps remains a separate controller for account administration, security, billing, and its own lawful service-operation purposes described in the Privacy notice.

1. Scope, subject, and duration

Processing covers the hosting, sanitization, analysis, evidence mapping, vulnerability correlation, controlled document generation, retrieval, support, and deletion needed to provide the features the Customer selects. It lasts for the service relationship and any limited retention period required by law or the documented purposes below.

2. Documented instructions

The Terms, this DPA, product settings, authorised API and interface actions, and written support instructions are the Customer's documented instructions. ConformOps processes Customer Personal Data only on those instructions unless EU or Member State law requires otherwise. If an instruction appears to infringe applicable data-protection law, ConformOps will inform the Customer and may pause the affected processing while the issue is resolved.

3. Data and people

Data may include names, business contact details, account identifiers, repository and source-path metadata, customer-authored product facts, source content selected by the Customer, assessment and evidence records, reviewer details, reporting-case records, and other personal data present in submitted material. Data subjects may include the Customer's users, staff, contractors, developers, reviewers, suppliers, contacts, and people mentioned in the submitted evidence. Customers must minimise personal data and must not intentionally submit secrets or special-category data that is not needed for the service.

4. Confidentiality and access

The Processor will limit access to people and service providers who need it to provide, secure, support, or lawfully administer the service and who are subject to confidentiality obligations. ConformOps has no customer-source browsing feature, but this DPA does not make the false claim that infrastructure operators can never access data. Any necessary support or incident access must be limited to the purpose and handled confidentially.

5. Technical and organisational measures

  • Current organization membership and product scope are checked on protected server requests; a record identifier alone is not authority.
  • Repository imports use read-only, repository-scoped GitHub access and short-lived installation tokens. Stored user tokens are AES-GCM encrypted.
  • Repository code is never executed. Input type, count, path, and byte limits are enforced before acceptance.
  • Detected confidential secrets are redacted before durable storage, indexing, or optional AI processing. Fingerprints are keyed and non-reversible.
  • Raw ZIP archives are streamed rather than retained. Temporary sanitized ingestion objects are purged after snapshot creation, cancellation, or expiry.
  • D1 is the authorization and control plane, R2 holds sanitized versioned objects, and Vectorize receives only deterministic vectors of redacted evidence.
  • Logs and server-side analytics use allowlisted identifiers and bounded operational fields, not source content, emails, repository names, evidence text, SBOM or vulnerability data, documents, secrets, or tokens.
  • Deletion requests are journaled, resumable, lease-protected, and complete only after every planned durable-store operation verifies.

6. Subprocessors and recipients

The Customer gives general authorisation for subprocessors needed for the selected service path. Cloudflare provides core Worker, D1, R2, Vectorize, Workflow, logging, and network infrastructure. Resend provides transactional email. OpenAI is the only AI provider and receives the limited request described on the AI processing page only when an Owner or Admin enables both the workspace and product settings. PostHog may receive the allowlisted pseudonymous server-side measurement described in the Privacy notice when all deployment gates are enabled. GitHub, Google, Microsoft, Stripe, and OSV receive data only for the integration, sign-in, billing, or vulnerability path the Customer uses.

Before a new subprocessor begins handling Customer Personal Data, ConformOps will update the public provider disclosure and provide advance notice through the registered account contact. The Customer may object on reasonable data-protection grounds before the change. If no reasonable alternative is available, the Customer may stop using the affected optional feature or terminate the affected service.

ConformOps will impose data-protection obligations on each subprocessor that are no less protective for the relevant processing than this DPA requires and remains responsible to the Customer for the subprocessor's performance of those obligations.

7. International transfers and residency

The current service is not represented as EU-only. Processing outside the EEA must use the applicable adequacy decision or Article 46 safeguard for the provider and service. The current placement and missing jurisdiction controls are stated on the Data residency page and are part of this DPA disclosure.

8. Data-subject requests and compliance assistance

Taking account of the nature of the processing, ConformOps will provide reasonable assistance for access, correction, restriction, portability, objection, and deletion requests that concern Customer Personal Data. ConformOps will also provide information reasonably needed for the Customer's data-protection impact assessments and prior consultations, subject to confidentiality, security, proportionality, and applicable charges for exceptional work agreed in advance.

9. Personal-data breaches

ConformOps will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide available information and material updates as described in the Breach notification commitment. The Customer remains responsible for its own regulator and data-subject notification decisions.

10. Return, deletion, and retention

The Customer can download available evidence before deletion. At the Customer's choice through the documented product or account controls, ConformOps will delete Customer Personal Data after the service ends unless law requires retention. Product and account deletion use the verified procedure described on the Deletion page. Statutory billing records, replay-protection keys, and minimal erasure proof remain only for their stated purposes.

11. Information and audits

ConformOps will make information reasonably necessary to demonstrate compliance with this DPA available on request, including the public architecture, security, provider, residency, and deletion disclosures. Reasonable audits may be arranged where those materials are insufficient, subject to advance notice, confidentiality, scope limits that protect other customers, and avoidance of unnecessary disruption. A regulator's lawful authority is not limited by this paragraph.

12. Contact and precedence

DPA requests can be sent to privacy@conformops.eu. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls for that issue. The remainder of the Terms, including applicable law and service boundaries, continues to apply.

ConformOps
How it worksPricingReporting deadlinesSecurityCRA resourcesAI infoTrust centerDPALegal noticePrivacyTerms
Readiness assistance, not legal certification.