Data processing agreement (GDPR article 28)
1. Parties
Controller: Your company, Squadlog customer.
Processor: Kadiaak OÜ, Tallinn, Estonia, publisher of Squadlog (squadlog.app).
2. Subject and duration
The processor processes, on behalf of the controller, the data needed for the Squadlog service: showing the GitHub activity of internal teams. This agreement lasts as long as the subscription, then until the data is deleted.
3. Description of the processing
| Purpose | Following development activity per team (commits, pull requests, reviews, issues), alerts and summaries for team leads. No computed performance score, no automated decision. |
|---|---|
| Data subjects | Tracked developers (members); users of the service (owner, admins, managers). |
| Data | Display name, work email, GitHub logins, activity metadata (dates, repositories, pull request titles and sizes, reviews). No source code is stored. |
| Retention | By plan: 30 days, 90 days or 12 months of history, then rolling deletion. Raw payloads: 90 days. Audit log: 12 months. |
| Location | European Union: Laravel Cloud, Frankfurt region (AWS eu-central-1). |
4. Processor obligations
- Process data only on documented instructions of the controller, including this agreement and the service settings.
- Ensure the confidentiality of people authorized to process the data.
- Apply the security measures of the annex (encryption, access control, logging, encrypted backups).
- Help the controller answer data subject requests (member JSON export and deletion are available in the service).
- Notify any personal data breach within 48 hours of becoming aware of it.
- Delete the data no later than 30 days after the workspace is deleted.
- Make available the information needed to demonstrate compliance and allow reasonable audits.
5. Sub-processors
| Laravel Cloud (Laravel Holdings Inc.) | Hosting, Frankfurt region. Standard contractual clauses and the Laravel Cloud DPA are annexed. |
|---|---|
| Amazon Web Services EMEA | Underlying infrastructure, eu-central-1. |
| Stripe Payments Europe | Billing (buyer data only). |
| Postmark or Resend | Transactional email. |
The controller is informed 30 days before any new sub-processor and may object by terminating.
6. Annex: security measures
TLS in transit; keys and secrets encrypted at rest; GitHub tokens never persisted beyond one hour; read-only access to organizations; HMAC verification of webhooks; strict isolation between workspaces tested on every release; 2FA available; append-only audit log; encrypted daily backups kept 30 days, restore tested every quarter.
Signature
For the controller: Title:
For Kadiaak OÜ: accepted electronically by providing the service.