Data Processing Agreement (DPA)
Last updated: 20 July 2026
1. Scope & Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies where you, as a Business or Enterprise customer acting as a controller, use gitbuild.dev to process personal data of data subjects for which you are responsible. It implements the requirements of Art. 28 GDPR. Where your use of the service does not involve processing personal data on behalf of others, this DPA does not create additional obligations.
2. Roles
You are the controller. StennMedia acts as your processor for the personal data you store in the service in connection with your business use (for example, organisation member accounts and repository metadata that contains personal data). You remain responsible for lawfulness of processing and for instructions to us.
3. Subject Matter & Duration
The subject matter and duration of processing correspond to your use of the service and the term of your account under the Terms of Service. This DPA ends automatically when your account is terminated and relevant data is deleted in accordance with the Terms and Privacy Policy.
4. Nature & Purpose of Processing
Processing covers the storage and technical provision of your repositories, organisation accounts, issues, and related metadata that you upload to the service, solely to operate the service for you in accordance with your documented instructions.
5. Categories of Data & Data Subjects
Categories depend on the content you store, and may include identifiers, contact details, and account information of your organisation members or other individuals represented in your repositories. You are responsible for ensuring a lawful basis for any such data.
6. Processor Obligations
- Process personal data only on your documented instructions, including with regard to transfers, unless required by EU or member-state law.
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (TLS, hashed passwords, EU-only hosting, rate limiting).
- Assist you, insofar as possible, with data-subject rights requests and with your notification obligations.
- Notify you without undue delay after becoming aware of a personal data breach affecting data processed under this DPA.
- Delete or return personal data at the end of the service, subject to legal retention duties.
- Make information available to demonstrate compliance and allow for audits.
7. Sub-processors
StennMedia uses the sub-processors listed on the Infrastructure page (netcup for compute, Hetzner for backup storage, Mailgun for email, Mollie for payments). We remain liable for the performance of sub-processors. We will inform you of intended changes concerning the addition or replacement of sub-processors, giving you the opportunity to object.
8. International Transfers
Apart from the Have I Been Pwned password hash-prefix check (which transmits only a non-reversible hash prefix, not personal data), no personal data is transferred to a third country outside the EU / EEA.
9. Liability
The liability provisions of the Terms of Service, including the limitation for business users, apply to claims under or in connection with this DPA. Nothing in this DPA limits liability that cannot be limited under mandatory law.
10. Contact
For DPA-related matters, contact info@stennmedia.nl. Business and Enterprise customers may request a signed counterpart.
gitbuild.dev is operated by StennMedia, established in the Netherlands. These pages are published in English as the binding version. They are provided for information and do not constitute legal advice.