Data Processing Agreement
This Data Processing Agreement (“DPA”) applies where you use rickub to process personal data for which you are the controller — for example personal data contained in the repositories, issues or CI configuration you push. For that data, ARUKU acts as your processor under Article 28 GDPR. It forms part of, and is subject to, our Terms of Service.
1. Roles
You are the controller and ARUKU is the processor of the personal data you submit to rickub in the course of using the service (“Customer Personal Data”). For your own account data, ARUKU is the controller — see the Privacy Policy.
2. Subject matter, duration, nature and purpose
We process Customer Personal Data only to provide the hosting, collaboration and CI features of rickub, for the duration of your use of the service. The nature of processing is storage, transmission, backup, and computation strictly necessary to deliver those features.
3. Instructions
We process Customer Personal Data only on your documented instructions, which include your configuration and use of the service, unless required to act otherwise by EU or Member State law (in which case we inform you unless the law prohibits it).
4. Confidentiality
Personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it strictly on a need-to-know basis under deny-by-default access control.
5. Security (Art. 32)
We implement appropriate technical and organisational measures, including encryption in transit and at rest, access control, audit logging, tested backups, and CI job isolation. These are described on our Security & trust page.
6. Subprocessors
You give general authorisation for us to engage the subprocessors listed on the Subprocessors page. We impose data-protection obligations on each subprocessor equivalent to those in this DPA, and we remain responsible for their performance. We will give notice of intended additions or replacements so you can object on reasonable data-protection grounds.
7. International transfers
Customer Personal Data is processed within the EU/EEA. We will not transfer it outside the EEA without an appropriate transfer mechanism under Chapter V GDPR.
8. Assistance
Taking into account the nature of processing, we assist you with data-subject requests, with security, breach notification, and data protection impact assessments, insofar as the information is available to us.
9. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information you need to meet your own notification obligations.
10. Deletion and return
On termination, or on your request, we delete or return Customer Personal Data and delete existing copies, save where storage is required by law. You can export your data at any time from within the service.
11. Audits
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and security safeguards.
12. Requesting a signed DPA
To execute a countersigned copy of this DPA, contact legal@rickub.com.