Data processing addendum
This DPA applies to customers using Fallow hosted services where Fallow B.V. processes personal data on the customer's behalf.
Last updated:
Scope
This DPA applies where Fallow processes personal data on the customer's behalf in connection with hosted services. It forms part of the terms of service.Roles of the parties
The customer is the controller for the Fallow Cloud data it sends: call counts, function inventories, source maps and the files of linked repositories. Fallow B.V. processes that data as processor under article 28 of the GDPR, only on the customer's documented instructions. The terms of service and the customer's use of the services are those instructions.
Fallow B.V. is the controller for the account data it uses to run and improve the service, as the privacy policy describes.
Processing details
Processing is limited to operating the services, providing support, and related administrative activities.
The personal data in scope is the account and team data of the customer's users: GitHub user ID, GitHub login, email address, role, invite email addresses, and the IP address and browser recorded in the audit log. Fallow Cloud coverage data holds function names, file paths, line numbers and call counts, not request data. Source maps and repository files that a customer uploads or links can contain source code, and with it any personal data that the code contains.
Fallow Cloud is hosted in the EU: the API and database run in Amsterdam, and stored files and database backups stay in the EU. The subprocessor list names each vendor and where it processes data.
Security measures
We use reasonable and appropriate technical and organizational measures to protect personal data.Subprocessors
The customer gives general authorization for the subprocessors on the subprocessor list. For Fallow Cloud data these are Fly.io, which runs the API and database, Cloudflare R2, which stores uploads, source maps and database backups, and Resend, which sends alert email.
We update the list before a new subprocessor starts to process customer data. A customer can object to a change by email to hello@fallow.tools.
International transfers
Where a subprocessor transfers personal data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework or on Standard Contractual Clauses.Assistance with data subject requests
We provide reasonable assistance to customers in responding to data subject requests.Incident notification
We will notify customers of personal data breaches without undue delay.Deletion and return of data
On termination, customer data is deleted or returned as required. An organization owner can also ask us by email to delete the organization and its coverage data.Audit rights
Customers may request reasonable audit information on the processing activities.Contact
To receive a signed copy of this DPA, email hello@fallow.tools.