Data Processing Addendum
Version 1.0 · Effective: 13 July 2026 · Operator: Rexstart Labs Pvt Ltd · Questions: open a support ticket
1. Parties and how this DPA applies
This Data Processing Addendum ("DPA") is between the customer that installs the audytx GitHub App, holds an audytx account, or uses the audytx MCP server (the "Controller") and Rexstart Labs Pvt Ltd, the operator of audytx (the "Processor").
This is a click-through addendum: it forms part of the audytx Terms of Service and takes effect automatically when you install the GitHub App, create an account, or call the MCP server. No signature is required.
2. Subject matter, duration, nature and purpose
The processing is the automated static analysis of the Controller's Terraform
configurations: audytx fetches .tf and .tfvars files (or receives
them in an MCP request or an optional plan upload), analyzes them in memory, and
returns findings. No source file content is written to any database or log.
Processing lasts for as long as the GitHub App remains installed or the account remains active, plus the retention period in section 9.
3. Categories of personal data and data subjects
Processed transiently, never persisted: the contents of the Terraform files audytx scans, which may incidentally contain personal data.
Persisted: scan metadata and installation records only — GitHub identifiers such as the account login, repository name, pull-request number and commit SHA, plus scan timings and outcome counts. The complete column list, straight from the database migrations, is published at /trust#storage.
Data subjects: the Controller's personnel, contractors and repository contributors whose GitHub identifiers appear in the processed data.
Account registration data (email, name, password hash), contact-form submissions and cost-sampler reports are processed by Rexstart Labs Pvt Ltd as an independent controller under the Privacy Policy, not under this DPA. audytx neither requests nor is designed to process special categories of personal data.
4. Documented instructions
The Processor processes personal data only on documented instructions
from the Controller. The documented instructions are: installing the GitHub App on chosen
repositories (scan pull requests there), each MCP tool call (scan the submitted content),
each optional plan upload, and any .audytx-baseline.yaml suppression file the
Controller commits. If applicable law requires processing contrary to those instructions,
the Processor will inform the Controller before processing, unless that law prohibits it.
5. Confidentiality
Access to production data is limited to the two founders of Rexstart Labs Pvt Ltd, who are committed to confidentiality. There are no other personnel with access.
6. Security measures
The technical and organisational measures are documented, claim by claim with source references, on the trust & data handling page. In summary:
- Source files are scanned in memory and never stored — there is no copy of your repository at rest anywhere in the service.
- Persisted data is scan metadata only; the complete column list is published at /trust#storage.
- Repository access is a read-only fine-grained GitHub
contentspermission — the write capability is never granted. - Every HTTP response carries centrally-stamped security headers (HSTS, CSP, X-Frame-Options, nosniff), and API credentials are stored as SHA-256 hashes.
- No third-party analytics, advertising, or data-broker services.
7. Subprocessors
The Controller grants general written authorisation for the subprocessors listed at /subprocessors — currently Cloudflare (hosting, storage, queues, transactional email) and GitHub (source of scanned files and destination of results).
The Processor will give at least 30 days' advance notice of any intended addition or replacement by publishing a dated entry on that page. If the Controller objects, its remedy is to stop using the service before the change takes effect — removing the GitHub App immediately and permanently revokes audytx's access.
Each subprocessor is bound by its own data-processing terms, linked from the subprocessor list.
8. Assistance with data subject rights and incidents
Taking into account the nature of the processing (metadata-only storage), the Processor assists the Controller in responding to requests to exercise the rights of a data subject — access, rectification, erasure — for the scan metadata and installation records described in section 3, via a support ticket.
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably needed for the Controller's own notification obligations.
9. Deletion and return
- Removing the GitHub App from your repository or organization immediately and permanently revokes audytx's access.
- Scan metadata records are retained for 90 days, then automatically deleted.
- Earlier deletion of scan metadata for your installation can be requested via a support ticket and is completed within 7 days, with confirmation by reply.
- Account holders can delete their account and its Client IDs from the dashboard.
10. Information and audit
The Processor makes available the information necessary to demonstrate compliance with this DPA: the trust page publishes the storage schema straight from the database migrations, and every factual claim on this page carries an in-repo source reference in the page markup. The Processor will additionally respond to reasonable written audit enquiries submitted via a support ticket.
11. International transfers — Standard Contractual Clauses
Processing runs on Cloudflare's global edge network; scan metadata is stored in an edge SQLite database in the US region, and the Processor is established in India.
Where personal data originating in the EEA, the United Kingdom, or Switzerland is transferred to the Processor, the transfer is governed by the EU Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), which are incorporated into this DPA by reference, with the Controller as data exporter and Rexstart Labs Pvt Ltd as data importer. Where the Controller acts as a processor for its own customers, Module Three (processor to processor) applies instead. For UK transfers the clauses are read with the ICO's International Data Transfer Addendum; for Swiss transfers, with the adaptations required by the FADP.
Annex I to the clauses is completed by sections 2 and 3 of this DPA; Annex II by section 6; the list of subprocessors by /subprocessors. Onward transfers to subprocessors are covered by each subprocessor's own transfer terms, linked from that page.
12. Term and precedence
This DPA applies for as long as the Processor processes personal data on behalf of the Controller and ends automatically when that processing ends (section 9). If this DPA conflicts with the Terms of Service, this DPA prevails with regard to the processing of personal data. Material changes to this DPA are announced the same way as Privacy Policy changes, at least 14 days before taking effect.
Start free during the open beta
Install the GitHub App or point your coding agent at the MCP server — this DPA takes effect automatically, no signature required.