Data Processing Addendum
How coderband LLC processes personal data for BuiltBrief customers under GDPR Article 28, with transfer terms and sub-processors.
Last updated: 9 October 2026
This Data Processing Addendum ("DPA") forms part of the BuiltBrief Terms of Service between coderband LLC, the company that operates BuiltBrief ("we", the processor), and the customer ("you", the controller). It applies automatically when you use BuiltBrief and we process personal data for you. You don't need to sign anything separately. If you need a countersigned copy, email hello@builtbrief.com.
Words like "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR. "Data protection law" means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and other laws that apply to the processing.
1. The processing
| Subject matter | Providing BuiltBrief: reading connected GitHub repositories and producing digests and briefs |
| Duration | The term of the agreement, plus up to 30 days for deletion |
| Nature | Collection through the GitHub API, transient analysis by an AI model, storage of metadata and generated text, email delivery |
| Purpose | Reporting on work, repositories and teams for the controller. Not the evaluation, monitoring, discipline, pay or termination of individuals |
| Data subjects | Contributors to connected repositories (employees, contractors, outside contributors), people named in repository content, and brief recipients |
| Personal data | the account owner's GitHub username and ID; names, emails or other personal data that appear in PR and issue titles, descriptions, comments or diffs; timestamps and status of the controller's PRs, issues, checks and deployments; recipient email addresses |
| Special categories | None intended. You must not use BuiltBrief to process special-category data on purpose |
Stored versus transient. We store metadata, digests and briefs. Diffs, PR and issue text are processed in memory and sent to our AI sub-processor, but not stored by us.
2. Our obligations as processor
We will:
- Follow your instructions. We process personal data only on your documented instructions. The Terms, this DPA and your settings in BuiltBrief are your instructions. If the law requires other processing, we'll tell you first unless the law forbids it. We'll tell you if we think an instruction breaks data protection law.
- Respect the purpose limit. We won't build per-person scores, rankings, leaderboards or activity profiles, even if asked.
- Keep it confidential. Everyone we authorize to process the data is bound by confidentiality.
- Keep it secure. We apply the measures in Annex 2 (Art. 32 GDPR) and may improve them over time, as long as we don't lower overall protection.
- Use sub-processors only on these terms. See section 4.
- Help with data subject requests. Using appropriate measures, we'll help you answer requests to exercise data subject rights. If we receive a request about your data, we'll pass it to you without undue delay and won't answer it ourselves unless you ask us to or the law requires it.
- Help with your compliance. We'll give reasonable help with security, breach notification, data protection impact assessments and prior consultation (Arts. 32 to 36 GDPR), taking into account the information available to us.
- Report breaches. We'll tell you without undue delay, and aim to do so within 48 hours, after becoming aware of a personal data breach affecting your data. We'll give you the information we have and update you as we learn more.
- Delete at the end. After uninstall, account deletion or the end of the agreement, we delete your personal data within 30 days, unless the law requires us to keep it. You can export your briefs before then.
- Show compliance. We'll make available the information needed to show we meet Art. 28 GDPR and allow reasonable audits (section 6).
3. Your obligations as controller
You will:
- have a lawful basis for the processing, and connect only repositories you're authorized to connect;
- notify contributors whose work BuiltBrief reads, using our notice templates or your own;
- meet any consultation or co-determination duties, such as with a works council, before you connect repositories;
- carry out a data protection impact assessment where the law requires one;
- not use BuiltBrief, or its output, to evaluate, discipline, compensate or terminate individual workers.
4. Sub-processors
You give us general authorization to use sub-processors. Our current sub-processors are listed in Annex 1.
- Each sub-processor is bound by a written contract with data protection obligations at least as protective as this DPA.
- We'll give you at least 30 days' notice by email before adding or replacing a sub-processor that processes your personal data.
- You may object on reasonable data protection grounds within that period. We'll then try in good faith to resolve it. If we can't, you may terminate the affected service and get a refund of prepaid fees for the unused period.
- We remain responsible for our sub-processors' performance.
5. International transfers
We are in the United States. When personal data is transferred from the EEA to us, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply and are incorporated by reference:
- Module 2 (controller to processor) applies where you are a controller. Module 3 (processor to processor) applies where you act as a processor for someone else.
- Clause 7 (docking clause) applies.
- Clause 9(a): Option 2, general written authorization, with 30 days' notice as in section 4.
- Clause 11(a): the optional language does not apply.
- Clause 13: the supervisory authority is the one competent for you, as data exporter.
- Clauses 17 and 18: the law and courts of Ireland.
- Annex I is section 1 of this DPA, with you as exporter and coderband LLC as importer. Annex II is Annex 2 below. Annex III is Annex 1 below.
UK. For transfers from the UK, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) applies, with the tables filled in from this DPA. Either party may end it as allowed by its Section 19.
Switzerland. For transfers from Switzerland, the SCCs apply with these changes: the Swiss FDPIC is the competent authority, references to the GDPR include the Swiss FADP, and data subjects in Switzerland may enforce their rights there.
Where a sub-processor is certified under the EU-US Data Privacy Framework, we may also rely on that certification for onward transfers.
If the SCCs conflict with this DPA, the SCCs win.
6. Audits
We'll answer reasonable written security and privacy questionnaires once a year, or more often after a breach or if a regulator requires it. If that isn't enough to show compliance, you may audit us, at your own cost, with 30 days' notice, during business hours, under confidentiality and in a way that doesn't disrupt the service or reveal other customers' data. We don't currently hold any third-party security certification.
7. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms, except where data protection law doesn't allow that. If this DPA and the Terms conflict on personal data, this DPA wins.
Annex 1: Sub-processors
| Sub-processor | Purpose | Data | Location | Transfer basis |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting (Workers), database (D1), email delivery (Cloudflare Email Service) | All stored data; brief emails and recipient addresses | USA, global network | DPF and SCCs |
| Anthropic PBC | AI model (Claude API) that writes digests and briefs | Text, diff excerpts and metadata sent for each run, and generated output | USA | SCCs (Anthropic DPA) |
Related services that are not sub-processors under this DPA:
| Service | Role |
|---|---|
| GitHub, Inc. | The source of your repository data, which you hold under your own agreement with GitHub. Also our sign-in provider |
| Stripe, including Sold through Link, LLC | Payment processing as merchant of record. Handles billing data, which we control (with Link acting under its own terms), not your repository data |
Anthropic data use. Anthropic's commercial terms prohibit it from training models on the content we send. By default, it deletes API inputs and outputs within 30 days, or keeps them longer only for usage-policy enforcement or where the law requires.
Annex 2: Security measures
- Least privilege at the source. Read-only GitHub App permissions, without the Contents permission. Customers choose which repositories it can see.
- Data minimization. No storage of source code, diffs, or full PR and issue text. Diffs are size-limited before processing.
- Encryption. TLS for all data in transit. Database encryption at rest (Cloudflare D1, AES-256). GitHub access tokens are not stored: installation tokens are held in memory for at most one hour.
- Short-lived credentials. GitHub installation tokens expire after one hour and are requested per run.
- Authenticated inputs. GitHub and Stripe webhooks are verified with HMAC signatures before they're processed.
- Access control. Sign-in through GitHub OAuth. Reader links are signed and time-limited. Production access is limited to the people who operate the service.
- Tenant isolation. Every record belongs to one workspace and every query is scoped to it.
- AI safety. Repository content is treated as data, not as instructions to the model. The model's output links each claim to its evidence.
- Logging. Operational logs exclude repository content, and are kept for a short period.
- Deletion. Automatic expiry of digests and briefs after 13 months. Full deletion within 30 days after uninstall or account deletion.
- Incident response. A documented process for investigating and notifying breaches.
- Vulnerability disclosure. Reports go to security@builtbrief.com.