Skip to content
Fallow home

Data processing addendum

This DPA applies to customers using Fallow hosted services where Fallow B.V. processes personal data on the customer's behalf.

Last updated:

  1. Scope

    This DPA applies where Fallow processes personal data on the customer's behalf in connection with hosted services. It forms part of the terms of service.
  2. Roles of the parties

    The customer is the controller for the Fallow Cloud data it sends: call counts, function inventories, source maps and the files of linked repositories. Fallow B.V. processes that data as processor under article 28 of the GDPR, only on the customer's documented instructions. The terms of service and the customer's use of the services are those instructions.

    Fallow B.V. is the controller for the account data it uses to run and improve the service, as the privacy policy describes.

  3. Processing details

    Processing is limited to operating the services, providing support, and related administrative activities.

    The personal data in scope is the account and team data of the customer's users: GitHub user ID, GitHub login, email address, role, invite email addresses, and the IP address and browser recorded in the audit log. Fallow Cloud coverage data holds function names, file paths, line numbers and call counts, not request data. Source maps and repository files that a customer uploads or links can contain source code, and with it any personal data that the code contains.

    Fallow Cloud is hosted in the EU: the API and database run in Amsterdam, and stored files and database backups stay in the EU. The subprocessor list names each vendor and where it processes data.

  4. Security measures

    We use reasonable and appropriate technical and organizational measures to protect personal data.
  5. Subprocessors

    The customer gives general authorization for the subprocessors on the subprocessor list. For Fallow Cloud data these are Fly.io, which runs the API and database, Cloudflare R2, which stores uploads, source maps and database backups, and Resend, which sends alert email.

    We update the list before a new subprocessor starts to process customer data. A customer can object to a change by email to hello@fallow.tools.

  6. International transfers

    Where a subprocessor transfers personal data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework or on Standard Contractual Clauses.
  7. Assistance with data subject requests

    We provide reasonable assistance to customers in responding to data subject requests.
  8. Incident notification

    We will notify customers of personal data breaches without undue delay.
  9. Deletion and return of data

    On termination, customer data is deleted or returned as required. An organization owner can also ask us by email to delete the organization and its coverage data.
  10. Audit rights

    Customers may request reasonable audit information on the processing activities.
  11. Contact

    To receive a signed copy of this DPA, email hello@fallow.tools.