Your Code. Your Rules.

Data Processing Agreement

The Article 28 GDPR data processing agreement describing how Git.eu processes Customer Personal Data on the Customer's behalf.

Data Processing Agreement

Article 28 of Regulation (EU) 2016/679 · Version 1.3 · In force from 8 September 2026

0. Scope of this agreement

0.1 This Data Processing Agreement (the "DPA") forms an integral part of the git.eu open beta terms of service (the "Agreement"), entered into between the Customer and Atyk, a société par actions simplifiée currently being registered with the Trade and Companies Register of Strasbourg, trading as Git.eu France, whose registered office is in Strasbourg, France ("Git.eu"). [SIREN number to follow on registration.] It applies automatically from the moment the Customer opens an account. No signature is required for it to take effect.

0.2 It is published at docs.git.eu/legal/dpa.html and can be read in full before any subscription. This English version is the sole contractual version; a French translation is also made available for convenience and, in the event of a discrepancy between the two, this English version prevails. It is provided free of charge, including in PDF format. A copy countersigned by Atyk is sent on simple request to hello@git.eu, free of charge; that copy reproduces this text without amendment.

0.3 The Customer accepts this DPA on its own behalf and, where it opens an account for an organisation, on behalf of that organisation.

1. Definitions

1.1 "GDPR" means Regulation (EU) 2016/679. The terms "controller", "processor", "sub-processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them by the GDPR.

1.2 "Customer Personal Data" means personal data processed by Git.eu on behalf of the Customer in the course of providing the Service, as described in Annex I.

1.3 "Service" means the hosted software forge operated by Git.eu, including the instance selected by the Customer, together with the account, billing and support functions attached to it.

1.4 Terms defined in the Agreement have the same meaning here. Where this DPA and the Agreement conflict on a data protection matter, this DPA prevails.

1.5 Where the Customer is established in Switzerland, or the Service processes personal data of natural persons located in Switzerland on the Customer's behalf, this DPA also applies with respect to the Swiss Federal Act on Data Protection of 25 September 2020 and its implementing ordinance (together, the "FADP"), in force since 1 September 2023. To that extent, references in this DPA to the GDPR, to its articles, and to the "supervisory authority" are read, mutatis mutandis, as references to the corresponding provisions of the FADP and to the Federal Data Protection and Information Commissioner (FDPIC). Where the two regimes diverge on the same point, the provision more protective of the data subject applies.

2. Roles of the parties

2.1 For Customer Personal Data, the Customer is the controller and Git.eu is the processor. The Customer determines what it places in the Service, who may access it, and for how long that data remains there.

2.2 Git.eu acts as controller in its own right for a limited and separate set of processing activities: the identity and billing data required to open, invoice and administer an account; the technical logs required for the security and availability of the Service; and correspondence addressed to it. This processing is described in Git.eu's privacy notice and is not governed by this DPA.

2.3 Neither party is a joint controller with the other, and this DPA does not create a controller-to-processor relationship in the reverse direction.

2.4 The processing described in this DPA is carried out by Atyk alone. No other entity within the same group processes Customer Personal Data.

3. Instructions

3.1 Git.eu processes Customer Personal Data only on the Customer's documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law. In that case, Git.eu informs the Customer of that legal obligation before processing, unless applicable law prohibits this on important grounds of public interest.

3.2 The Agreement, this DPA, and the Customer's use of the Service's functions constitute the entirety of the Customer's documented instructions. Any additional instruction requires a written agreement and may be chargeable if it is not covered by the Service as it stands.

3.3 Git.eu informs the Customer within the applicable statutory deadlines if, in its opinion, an instruction constitutes a breach of the GDPR or of another provision of Union or Member State data protection law, and may suspend performance of that instruction until it is confirmed or withdrawn.

3.4 Git.eu does not read, inspect, index or otherwise access the content of the Customer's repositories, issues or merge requests, except where strictly necessary to provide the Service, to respond to a support request made by the Customer, or to comply with a legal obligation. Any such access is limited to what its purpose requires.

3.5 It is the Customer's responsibility to ensure that its instructions comply with the GDPR and any other law applicable to it, and that processing Customer Personal Data in accordance with those instructions does not cause Git.eu to breach any law.

3.6 Git.eu is not responsible for determining which laws or regulations apply to the Customer's activity, nor for determining whether the Service meets the requirements of those laws. Clause 3.3 is a duty to flag what Git.eu observes; it is not an undertaking to monitor the Customer's compliance.

4. Confidentiality

4.1 Git.eu ensures that every person authorised to process Customer Personal Data is bound by a confidentiality obligation, whether contractual or statutory, and that this obligation survives the end of their engagement.

4.2 Access to Customer Personal Data is limited to persons who need it to carry out the tasks entrusted to Git.eu.

5. Security

5.1 Git.eu implements the technical and organisational measures described in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.

5.2 Git.eu may evolve these measures over time, provided the level of security is not reduced. Annex II reflects the measures in force as at the date of this version.

5.3 The Customer is responsible for the choices the Service places in its hands: who it grants access to, what it uploads, and whether it keeps its own copies of its repositories.

6. Sub-processors

6.1 The Customer gives Git.eu a general authorisation to use the sub-processors listed in Annex III.

6.2 Git.eu contractually imposes on each sub-processor the same data protection obligations as those set out in this DPA, to the extent that they relate to the processing carried out by that sub-processor, and remains fully liable to the Customer for the performance of that sub-processor's obligations.

6.3 Git.eu gives the Customer at least 30 days' notice before adding or replacing a sub-processor. Notice is given by email to the account's administrative address and by updating Annex III of this DPA. Where a change is required urgently — a security incident, a provider ceasing operations or becoming insolvent, or a legal obligation — Git.eu informs the Customer as soon as it is able to do so, and in any event no later than the date the change takes effect.

6.4 The Customer may object to the change, on reasonable data-protection grounds, within that 30-day period. Failing agreement between the parties on a solution, the Customer may terminate the Agreement with effect from the date the change takes effect and obtain a refund of amounts paid in advance for the unused period. Export of the Customer's data remains available and free of charge throughout this period.

6.5 The list in Annex III is exhaustive. Git.eu does not use any undisclosed sub-processor and does not consider analytics, error-monitoring or advertising providers to fall outside this clause, since it uses none.

7. International transfers

7.1 Customer Personal Data is processed within the European Union, with a single exception: the hosting of @git.eu mailboxes and the processing of email sent to them, handled by a sub-processor established in Switzerland, a country covered by an adequacy decision of the European Commission adopted in 2000 and confirmed in January 2024.

7.2 No transfer of Customer Personal Data takes place to a country located outside the European Economic Area that is not covered by an adequacy decision. Should such a transfer become necessary, Git.eu would inform the Customer beforehand under the conditions of clause 6.3 and would not proceed without an appropriate transfer mechanism under Chapter V of the GDPR.

7.3 Git.eu selects its sub-processors so that none of them is, to its knowledge, subject to the law of a third country that would require it to disclose Customer Personal Data to the authorities of that country. Backup copies are held by Git.eu itself and are not entrusted to any third party.

7.4 For a Customer subject to the FADP under clause 1.5, Customer Personal Data transferred to the European Union is transferred to a jurisdiction the Swiss Federal Council recognises as ensuring an adequate level of protection under Article 16 of the FADP. No additional transfer mechanism is required at this time. Clause 7.1 applies in the same way to the sub-processor established in Switzerland.

8. Requests from authorities and third parties

8.1 If Git.eu receives a request from a public authority or a third party for access to Customer Personal Data, it discloses nothing, unless legally required to do so.

8.2 Git.eu informs the Customer of the request without undue delay and, whenever lawful, before responding to it, so that the Customer may challenge its merits.

8.3 Git.eu challenges requests that are manifestly unlawful, excessive, or that do not follow the procedure required by Union or Member State law, and discloses only the minimum required by the binding instrument.

8.4 Git.eu makes no voluntary disclosure of Customer Personal Data to any authority, in any country.

9. No secondary use

9.1 Git.eu does not use Customer Personal Data, nor the content of the Customer's repositories, to train machine learning models — whether its own or a third party's — and does not make them available to anyone for that purpose.

9.2 Git.eu does not sell, rent or share Customer Personal Data, and does not use it for advertising or profiling purposes of any kind.

9.3 This clause constitutes a contractual undertaking. It survives any change of ownership or control of Atyk, as well as any assignment of the Agreement.

9.4 This commitment governs Git.eu's own conduct. It cannot bind a third party that accesses, independently of the Service, the content of a repository the Customer has made public.

10. Data subject rights

10.1 Taking into account the nature of the processing, Git.eu assists the Customer, through appropriate technical and organisational measures and insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.

10.2 The Service gives the Customer the means to access, rectify, export and delete the personal data held in its account.

10.3 If Git.eu receives a request from a data subject relating to Customer Personal Data, it does not respond to it on the merits. It forwards the request to the Customer within 5 business days and, on request, assists the Customer in responding to it.

10.4 Assistance under this clause is provided free of charge, except where a request requires manifestly disproportionate work; in that case, Git.eu informs the Customer of the cost before undertaking it.

11. Assistance with the Customer's other obligations

11.1 Git.eu assists the Customer, taking into account the nature of the processing and the information available to it, in complying with its obligations under Articles 32 to 36 of the GDPR — security of processing, notification of personal data breaches, data protection impact assessment, and prior consultation.

11.2 Git.eu provides this assistance taking into account the nature of the processing and the information available to it. Annex II, together with the information git.eu publishes about its infrastructure, its sub-processors and its backup practices, is drafted so as to allow the Customer to carry out an impact assessment based on it. Where an element is missing, git.eu supplies it on reasonable request.

12. Personal data breaches

12.1 Git.eu notifies the Customer of any personal data breach affecting Customer Personal Data without undue delay from the moment it becomes aware of it. An unsuccessful attempt that had no effect, or an activity that does not compromise the security of Customer Personal Data, does not constitute a breach for the purposes of this Article.

12.2 The notification describes, to the extent of the information known at that time: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to remedy it and mitigate its effects; and a point of contact. Where all this information is not available at the same time, it is communicated in stages, without further undue delay.

12.3 Git.eu does not notify the supervisory authority or data subjects on the Customer's behalf, except on the Customer's written instruction.

12.4 Git.eu documents every personal data breach affecting Customer Personal Data, including the facts, their effects and the remedial measures taken, and makes this documentation available to the Customer on request.

12.5 Notification of a personal data breach, or the response given to it, does not constitute an acknowledgement by git.eu of fault or liability in respect of that breach.

13. Audit and information

13.1 Git.eu makes available to the Customer all information necessary to demonstrate compliance with Article 28 of the GDPR. Documentary requests are answered within 30 business days.

13.2 The Customer may audit this compliance once per 12-month period, on 30 business days' written notice, by written questionnaire and by review of the documentation and certifications held by git.eu. An on-site inspection may be carried out where a supervisory authority requires it, during business hours, without disrupting the Service or compromising the confidentiality of other customers' data, and subject to the auditor entering into a confidentiality undertaking.

13.3 Where a sub-processor is concerned, git.eu provides the information and certifications it holds. Physical inspection of a sub-processor's facilities is subject to that sub-processor's own procedures.

13.4 The Customer bears the cost of the audit, including expenses incurred by git.eu and the time it spends on it, charged at its standard rate. git.eu provides an estimate before undertaking the work, and no charge is due where the audit follows a personal data breach attributable to it.

14. Return and deletion

14.1 From 1 December 2026, the Customer will be able to export its repositories at any time during the term of the Agreement, free of charge and without having to give a reason. Export is a function of the Service and requires no intervention by Git.eu.

14.2 At the end of the Agreement, Git.eu deletes all Customer Personal Data within 30 calendar days, unless a longer recovery period has been published for a given phase of the Service, in which case deletion takes place at the end of that period. For accounts opened during the open beta, the published recovery period runs until 31 January 2027.

14.3 Backup copies are deleted through the normal rotation of the backup cycle and, in any event, within 30 calendar days of the deletion under clause 14.2. Until then, they remain subject to this DPA and are not accessible for any other purpose.

14.4 Git.eu does not retain Customer Personal Data beyond these periods except where required by Union or Member State law, for the period required by that law and for no other purpose. Billing records are retained for the period required by accounting and tax law.

14.5 Git.eu certifies deletion in writing on request submitted via the internal ticketing tool.

15. Term

15.1 This DPA takes effect when the Customer opens an account and remains in force for as long as Git.eu processes Customer Personal Data.

15.2 Clauses 4, 8, 9, 12.4 and 14 survive the end of the Agreement.

16. Amendment of this DPA

16.1 Git.eu may amend this DPA where a change in the law, in its sub-processors, or in the Service requires it. Each version carries a number and a date.

16.2 Material amendments are notified by email to the account's administrative address at least 30 days before they take effect. Changes to the list of sub-processors follow clause 6.3.

16.3 Previous versions remain available at git.eu/dpa. The Customer may ask which version applied on a given date, and Git.eu will answer.

17. Liability and governing law

17.1 The Agreement's provisions on liability apply to this DPA. Nothing in this clause limits the rights Article 82 of the GDPR grants to data subjects.

17.2 This DPA is governed by French law. The courts of Strasbourg have exclusive jurisdiction, without prejudice to any mandatory rule of jurisdiction applicable to the Customer.

17.3 If any provision of this DPA is held invalid, the others remain in force.

Annex I — Description of the processing

ItemDescription
Subject matterProvision of the hosted software forge operated by Git.eu and the account, billing and support functions attached to it.
DurationThe term of the Agreement, plus the retention and deletion periods set out in clause 14.
Nature and purposeHosting, storage, transmission, backup, access control and display of the repositories and associated records the Customer places in the Service; management of the Customer's account; billing; support; security monitoring.
Categories of data subjectsThe Customer's users (paying accounts, administrators, viewers); persons whose personal data appears in content uploaded by the Customer, including author and committer identities recorded in Git history; persons who contact support regarding the Customer's account; the Customer's billing contacts.
Categories of personal dataAccount identity data (name, username, email address, password hash, public keys, authentication token fingerprints); Git history metadata (author and committer names and email addresses, timestamps); the content of repositories, issues, merge requests, reviews and comments, insofar as it contains personal data determined by the Customer; billing identity and transaction data; technical logs, including IP addresses, user agents and access timestamps.
Special categoriesNone are requested, required or expected. The Customer must not place in the Service personal data falling within the special categories under Article 9 GDPR.
Frequency of processingContinuous, throughout the term of the Agreement.

The Customer decides what it places in its repositories. Personal data may therefore appear in the content of repositories, in commit messages, and in the author and committer fields of Git history, without Git.eu having any means of knowing in advance what is there. The categories above describe what the Service structurally processes, not an inventory of the Customer's content.

Annex II — Technical and organisational measures

Measures in force as at the date of this version. Where a measure is not in place, this annex says so rather than describing an intention. Nothing here is aspirational.

MeasureImplementation
Location of processingAll production processing takes place on infrastructure located in Paris, France, operated by Scaleway SAS. Backup copies are held in France, at a second site, on hardware owned and operated by Git.eu itself. No third party holds a copy of Customer Personal Data.
Encryption in transitAll access to the Service — web, Git over HTTPS and Git over SSH — is encrypted in transit. No unencrypted protocol is offered.
Encryption at restBackup copies are encrypted at rest. The keys are held outside the machines hosting the copies, in an end-to-end encrypted secrets vault that its provider cannot read.

Production volumes are not encrypted at rest. Production runs on dedicated hardware, for Git.eu's exclusive use, installed in the hosting sub-processor's data centre; the host does not offer encryption at rest as a managed feature, and a self-managed arrangement would require the key to reside on the machine it protects. Storage media are wiped by Git.eu before any hardware is returned or decommissioned.

Two-factor authentication secrets are an exception and are protected at the application layer, independently of the volume that carries them. The TOTP secret is encrypted with AES-256-GCM, with a random initialisation vector unique to each record; the encryption key is held outside the database, in the service configuration. Recovery codes are stored neither in clear text nor in any reversible form, but as HMAC-SHA256 digests.

Production data is otherwise protected by the access controls, physical security and segregation measures described below.
Access control — Customer sideEach user holds an individual account. Write access is separate from read access, and administration from both. Two-factor authentication is available to user accounts from the opening of the open beta, 8 September 2026. The secrets that make it work — TOTP secret and recovery codes — are protected as indicated in the "Encryption at rest" row above.
Access control — Git.eu sideOne named individual holds administrative access to production. This access is individually assigned, never shared, and logged. No other person, and no sub-processor, holds administrative access.
Confidentiality of personnelEvery person authorised to process Customer Personal Data is bound by a written confidentiality obligation that survives the end of their engagement.
Backup and restorationFull daily backups of repositories and the database, held at a second site in France, on hardware owned and operated by Git.eu. Copies are encrypted at rest. The backup cycle overwrites copies after 30 days. Backups cover a loss occurring on Git.eu's side; they are not a substitute for the Customer's own copies, and there is no self-service restore — a restore is carried out by Git.eu on request. No restore has been tested to date; this annex will be updated once one has been.
Logging and monitoringSite access, and connections through both the web interface and the Git protocol, are logged. Every write is recorded against the individual account that made it. Two retention periods apply. The IP address a connection originated from and the protocol used are retained for one year, as required by the decree of 20 October 2021 of anyone hosting content made available to the public, and are used for no purpose other than responding to a judicial requisition. The rest of the log is kept for 30 days on live systems; the backups containing it are overwritten on the 30-day cycle. Logs are held on production infrastructure, to which only the named administrator has access.
Vulnerability managementUpdates to the platform and its dependencies are applied during low-traffic windows, with repositories locked beforehand so that no write is lost. No external security assessment has been carried out to date.
Physical securityProvided by the hosting sub-processor at its Paris facility. [Certifications held by the facility to be confirmed before any written reference to them.]
SegregationCustomer data is logically segregated by account and by organisation. Access from one account to another is only possible through a permission granted by the Customer.
Incident responseSecurity incidents are handled under clause 12. Detection and escalation outside business hours are on a best-effort basis: Git.eu does not provide a permanent on-call rota during the open beta and makes no availability commitment for that period. Clause 12.1 requires notification without undue delay from the moment Git.eu becomes aware of the breach.
Data minimisation by designNo third-party analytics, no advertising tracker and no duplicate metering are deployed in the Service. Storage is measured by a single counter.

Annex III — Sub-processors

Six companies, and here they all are. The list is exhaustive as at the date of this version. It is not published anywhere else: this annex is its sole source.

Sub-processorCountry of establishmentService providedPersonal data concerned
Scaleway SASFranceHosting and operation of the infrastructure on which the Service runs (Paris)All Customer Personal Data stored in the Service
Billit NV/SABelgiumIssuing of invoices to customers established in the European UnionBilling identity, address, VAT number, invoice contents
Mollie B.V.NetherlandsCard paymentsBilling identity, email address, transaction data. No card number is transmitted to or held by Git.eu
Wise Europe SABelgiumBank transfersBilling identity, bank details, transaction data
o2Switch SASFranceSending of transactional and service emails (sign-up confirmations, password resets, notifications).Name, email address, and content of the messages we send you.
Infomaniak Network SASwitzerlandHosting of @git.eu mailboxes and processing of email sent to those addresses; sending of the newsletter.Messages sent to a @git.eu address, together with their sender and content. Email addresses of newsletter recipients and its content.

Five of the six are established in the European Union. The sixth, which hosts @git.eu mailboxes, processes the email sent to them and sends the newsletter, is established in Switzerland, a country the European Commission has recognised as offering an adequate level of protection since 2000, a decision confirmed in January 2024. None of the six is, to our knowledge, subject to the law of a third country requiring it to hand over Customer Personal Data to that country's authorities.

Contact for any question relating to this agreement: dpo@git.eu.