Legal · Updated 2026-10-09

Data Processing Addendum

How coderband LLC processes personal data for BuiltBrief customers under GDPR Article 28, with transfer terms and sub-processors.

Last updated: 9 October 2026

This Data Processing Addendum ("DPA") forms part of the BuiltBrief Terms of Service between coderband LLC, the company that operates BuiltBrief ("we", the processor), and the customer ("you", the controller). It applies automatically when you use BuiltBrief and we process personal data for you. You don't need to sign anything separately. If you need a countersigned copy, email hello@builtbrief.com.

Words like "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR. "Data protection law" means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and other laws that apply to the processing.

1. The processing

Subject matter Providing BuiltBrief: reading connected GitHub repositories and producing digests and briefs
Duration The term of the agreement, plus up to 30 days for deletion
Nature Collection through the GitHub API, transient analysis by an AI model, storage of metadata and generated text, email delivery
Purpose Reporting on work, repositories and teams for the controller. Not the evaluation, monitoring, discipline, pay or termination of individuals
Data subjects Contributors to connected repositories (employees, contractors, outside contributors), people named in repository content, and brief recipients
Personal data the account owner's GitHub username and ID; names, emails or other personal data that appear in PR and issue titles, descriptions, comments or diffs; timestamps and status of the controller's PRs, issues, checks and deployments; recipient email addresses
Special categories None intended. You must not use BuiltBrief to process special-category data on purpose

Stored versus transient. We store metadata, digests and briefs. Diffs, PR and issue text are processed in memory and sent to our AI sub-processor, but not stored by us.

2. Our obligations as processor

We will:

  1. Follow your instructions. We process personal data only on your documented instructions. The Terms, this DPA and your settings in BuiltBrief are your instructions. If the law requires other processing, we'll tell you first unless the law forbids it. We'll tell you if we think an instruction breaks data protection law.
  2. Respect the purpose limit. We won't build per-person scores, rankings, leaderboards or activity profiles, even if asked.
  3. Keep it confidential. Everyone we authorize to process the data is bound by confidentiality.
  4. Keep it secure. We apply the measures in Annex 2 (Art. 32 GDPR) and may improve them over time, as long as we don't lower overall protection.
  5. Use sub-processors only on these terms. See section 4.
  6. Help with data subject requests. Using appropriate measures, we'll help you answer requests to exercise data subject rights. If we receive a request about your data, we'll pass it to you without undue delay and won't answer it ourselves unless you ask us to or the law requires it.
  7. Help with your compliance. We'll give reasonable help with security, breach notification, data protection impact assessments and prior consultation (Arts. 32 to 36 GDPR), taking into account the information available to us.
  8. Report breaches. We'll tell you without undue delay, and aim to do so within 48 hours, after becoming aware of a personal data breach affecting your data. We'll give you the information we have and update you as we learn more.
  9. Delete at the end. After uninstall, account deletion or the end of the agreement, we delete your personal data within 30 days, unless the law requires us to keep it. You can export your briefs before then.
  10. Show compliance. We'll make available the information needed to show we meet Art. 28 GDPR and allow reasonable audits (section 6).

3. Your obligations as controller

You will:

4. Sub-processors

You give us general authorization to use sub-processors. Our current sub-processors are listed in Annex 1.

5. International transfers

We are in the United States. When personal data is transferred from the EEA to us, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply and are incorporated by reference:

UK. For transfers from the UK, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) applies, with the tables filled in from this DPA. Either party may end it as allowed by its Section 19.

Switzerland. For transfers from Switzerland, the SCCs apply with these changes: the Swiss FDPIC is the competent authority, references to the GDPR include the Swiss FADP, and data subjects in Switzerland may enforce their rights there.

Where a sub-processor is certified under the EU-US Data Privacy Framework, we may also rely on that certification for onward transfers.

If the SCCs conflict with this DPA, the SCCs win.

6. Audits

We'll answer reasonable written security and privacy questionnaires once a year, or more often after a breach or if a regulator requires it. If that isn't enough to show compliance, you may audit us, at your own cost, with 30 days' notice, during business hours, under confidentiality and in a way that doesn't disrupt the service or reveal other customers' data. We don't currently hold any third-party security certification.

7. Liability and order of precedence

Each party's liability under this DPA is subject to the limits in the Terms, except where data protection law doesn't allow that. If this DPA and the Terms conflict on personal data, this DPA wins.

Annex 1: Sub-processors

Sub-processor Purpose Data Location Transfer basis
Cloudflare, Inc. Hosting (Workers), database (D1), email delivery (Cloudflare Email Service) All stored data; brief emails and recipient addresses USA, global network DPF and SCCs
Anthropic PBC AI model (Claude API) that writes digests and briefs Text, diff excerpts and metadata sent for each run, and generated output USA SCCs (Anthropic DPA)

Related services that are not sub-processors under this DPA:

Service Role
GitHub, Inc. The source of your repository data, which you hold under your own agreement with GitHub. Also our sign-in provider
Stripe, including Sold through Link, LLC Payment processing as merchant of record. Handles billing data, which we control (with Link acting under its own terms), not your repository data

Anthropic data use. Anthropic's commercial terms prohibit it from training models on the content we send. By default, it deletes API inputs and outputs within 30 days, or keeps them longer only for usage-policy enforcement or where the law requires.

Annex 2: Security measures