SourceTrust

Legal

Data Processing Agreement

How we process personal data on your behalf in the application when you are the controller.

Last updated: July 14, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer", "you", "controller" where applicable) and the operator of SourceTrust ("SourceTrust", "we", "processor" where applicable) for use of the SourceTrust application at https://app.sourcetrust.dev and related services.

The service is provided by SourceTrust, Dampfærgevej 14, 4.2, 2100 Copenhagen Ø, Denmark.

This DPA applies when SourceTrust processes personal data on your behalf in the application. It supplements our Terms of Service, Acceptable Use Policy, and privacy policy.

By using the application to process organizational or project data, you agree to this DPA. Enterprise customers may request a countersigned copy by email at hello@sourcetrust.dev.

Order of precedence. If there is a conflict regarding the processing of personal data: (1) applicable Standard Contractual Clauses incorporated under Section 12, where they apply; (2) this DPA; (3) the Terms; (4) the privacy policy - except where mandatory data protection law requires otherwise.

1. Roles and scope

Customer as controller. You determine the purposes and means of processing personal data you upload or cause to be processed through the service ("Customer Data" - for example, data in repositories, SBOMs, project metadata, or compliance materials that identifies individuals). For that processing, you are the controller and SourceTrust is the processor.

SourceTrust as controller for account and service data. We act as an independent controller for:

  • account and billing contact data, organization membership, and authentication events needed to operate your relationship with us;
  • security, abuse-prevention, and service logs relating to your use of the application; and
  • support communications and service administration.

as further described in the privacy policy. This DPA does not cover processing where we act solely as an independent controller, except where Standard Contractual Clauses apply as described in Section 12.

Scope. This DPA covers processor activities necessary to provide the service: Hosting, storage, backup, display of compliance pages you publish (including on customer-branded hostnames when you purchase the custom domain add-on), import and review workflows, license drift monitoring, optional security advisory monitoring when you enable that add-on, transactional notifications, and related support.

2. Subject matter, duration, and nature of processing

Subject matter: Provision of the SourceTrust compliance infrastructure service.

Duration: For as long as you maintain an account and we retain data in accordance with the Terms and this DPA, plus any legally required retention period thereafter (see Exhibit A).

Nature of processing: Collection, storage, organization, retrieval, use, disclosure by transmission (including publication of pages you approve), alignment, restriction, erasure, and deletion of personal data as directed by your use of the service.

Further details of processing are set out in Exhibit A.

3. Categories of data and data subjects

The types of personal data processed depend on your use of the service and may include:

  • names, email addresses, and identifiers in repository metadata, commit history, or SBOMs you import;
  • organization and project names;
  • user account and audit-trail data for your organization's users;
  • content you choose to publish on compliance pages; and
  • technical logs generated by your use of the application.

Data subjects may include your employees, contractors, contributors, and - depending on what you upload - third parties identified in your materials. You are responsible for ensuring you have a lawful basis to upload and publish such data.

4. Processor instructions

We process personal data only on your documented instructions as expressed through your use of the service and these agreements, unless required by EU or member-state law - in which case we inform you of that requirement unless prohibited by law.

You instruct us to process data to provide, secure, and maintain the service, publish content you approve, send service-related notifications, and comply with lawful requests you or regulators direct to us regarding your account.

5. Confidentiality and personnel

We ensure that persons authorized to process personal data are bound by confidentiality obligations.

6. Security

We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of processing and risks involved.

A summary of measures is set out in Exhibit B. We may update measures over time provided the overall level of security remains appropriate.

7. Sub-processors

You provide general written authorization for us to engage sub-processors to provide the service. The current authorized sub-processors are listed at https://app.sourcetrust.dev/legal/subprocessors and include:

  • Cloudflare - hosting, CDN, security, and CAPTCHA on the marketing site and public scan;
  • Convex - application database and backend hosting (stored in the European Union / Ireland);
  • Resend - transactional email (customer data stored in the United States; Resend's DPA includes Standard Contractual Clauses for EU transfers);
  • Paddle - payment processing and subscription billing;
  • GitHub - repository connections and code import;
  • GitLab - repository connections and code import;
  • Microsoft (Azure DevOps) - repository connections and code import;
  • WorkOS - authentication and organization sign-in;
  • Functional Software (Sentry) - application error monitoring and performance diagnostics;
  • OpenAI - AI-assisted classification of license text; and
  • Google (OSV.dev) - vulnerability advisory lookups for the optional security monitoring add-on.

We remain responsible to you for sub-processor performance of obligations under this DPA. We impose data protection obligations on sub-processors by contract comparable to those in this DPA.

Change notice. We will inform you at least fourteen (14) days in advance of any intended addition or replacement of a sub-processor that processes Customer Data on your behalf, by updating the sub-processor list and - where practicable - emailing organization administrators associated with your account.

Objection. You may object to a new or replaced sub-processor on reasonable grounds relating to data protection within fourteen (14) days of our notice. If we cannot accommodate the objection through a commercially reasonable alternative, you may terminate the affected paid services by written notice; termination does not relieve you of fees owed for the period before termination unless otherwise required by law.

If you do not object within fourteen (14) days of notice, the sub-processor is deemed authorized for purposes of this DPA.

8. Data subject rights and assistance

We assist you, taking into account the nature of processing, in responding to requests from data subjects to exercise their rights under applicable data protection law (access, rectification, erasure, restriction, portability, objection, and related rights).

If we receive a data subject request relating to Customer Data, we will advise the data subject to contact you unless prohibited by law. You are responsible for responding to requests about data you control; we provide reasonable tools and support when the data is in the application.

Requests about data we control directly (for example, your SourceTrust account profile or billing contact) may be sent to hello@sourcetrust.dev.

9. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data we process on your behalf, and provide information reasonably available to help you meet your obligations. We cooperate with your investigation and mitigation efforts.

10. Return and deletion

On termination of the service or upon your written request, we delete or return Customer Data within a reasonable period, except where retention is required by law or permitted by the Terms (for example, backup cycles or billing records).

You should export data you need before account closure. Public pages you published may be taken offline as described in the Terms.

11. Audits and information

We make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits mandated by applicable law, subject to reasonable notice, confidentiality, and frequency limits (not more than once per calendar year unless required by law or a supervisory authority).

We may satisfy audit requests through third-party certifications, security summaries, or responses to questionnaires where available. On-site audits require mutual agreement on scope, timing, and cost allocation.

12. International transfers

If Customer Data is transferred outside the European Economic Area or United Kingdom, we ensure appropriate safeguards such as EU Standard Contractual Clauses (2021/914), UK IDTA/addendum, or other mechanisms recognized by applicable law.

Application data hosted with Convex is stored in the European Union (Ireland). Some sub-processors - including Resend for transactional email - store customer data in the United States; for those transfers we rely on the sub-processor's published DPA and Standard Contractual Clauses where applicable.

Supplementary measures. Where a transfer requires additional safeguards under applicable law, we assess the laws of the destination country and implement supplementary measures reasonably necessary in the circumstances - which may include encryption in transit, access controls, contractual commitments limiting government access requests, and redirecting lawful access requests to you where permitted.

Government access. If we receive a legally binding request from a public authority for Customer Data, we will - where permitted by law - notify you promptly, challenge overbroad requests, and provide only what is legally required.

You acknowledge that sub-processors may process data in multiple jurisdictions as described on our sub-processor list.

13. Liability

Liability arising from processing under this DPA is subject to the limitations and indemnities in the Terms of Service, unless mandatory data protection law requires otherwise.

14. Governing law

This DPA is governed by the laws of Denmark. Disputes relating to this DPA are subject to the jurisdiction provisions in the Terms.

15. Changes and contact

We may update this DPA to reflect legal or service changes. Material updates will be posted at https://app.sourcetrust.dev/legal/dpa with an updated date.

Data protection and DPA inquiries: hello@sourcetrust.dev

Exhibit A - Details of processing

This exhibit describes processing performed by SourceTrust as processor on Customer's instructions.

A.1 Categories of data subjects

  • Customer's employees, contractors, and authorized users of the application;
  • individuals identified in repository metadata, commit history, SBOMs, or compliance materials Customer uploads; and
  • recipients or viewers of published compliance pages only where Customer chooses to include personal data in published content.

A.2 Categories of personal data

  • account identifiers (name, work email, organization membership, role, audit events);
  • project and inventory metadata that may identify contributors;
  • repository import content that may contain personal identifiers;
  • repository connection metadata for any provider you connect - GitHub, GitLab, or Azure DevOps (repository identifiers, watched branch configuration, webhook or sync event metadata);
  • security advisory metadata matched to Customer inventory when the optional security monitoring add-on is enabled (for example CVE or OSV identifiers and alert delivery metadata);
  • visitor request logs for published compliance pages, including customer-branded hostnames;
  • content Customer publishes on compliance pages; and
  • technical logs (IP address, user agent, timestamps) generated by application use.

A.3 Sensitive data

The service is not designed for special categories of personal data under Article 9 GDPR. Customer must not upload such data unless strictly necessary and lawful; if Customer does, Customer is responsible for appropriate safeguards and instructions.

A.4 Processing purposes

  • provide, maintain, and secure the application;
  • import, store, review, and publish compliance materials Customer approves;
  • sync repositories Customer authorizes (GitHub, GitLab, or Azure DevOps) and process webhook or sync event metadata;
  • monitor dependency and license drift Customer configures;
  • match Customer inventory against public security advisory databases and deliver optional vendor-only advisory notifications when Customer enables security monitoring;
  • send transactional service notifications; and
  • comply with legal obligations and enforce the Terms and Acceptable Use Policy.

A.5 Retention

Customer Data is retained while the Customer account is active and as needed to provide the service. After termination, Customer Data is deleted within a reasonable period except:

  • backup copies deleted on rolling backup cycles (typically within 90 days);
  • billing and transaction records retained as required for tax and accounting law; and
  • data we must retain to establish, exercise, or defend legal claims.

Retention periods for data SourceTrust controls directly as controller are described in the privacy policy.

Exhibit B - Security measures (summary)

We maintain technical and organizational measures appropriate to the risk, including:

  • encryption of data in transit (TLS) for connections to the application and website;
  • access controls limiting production access to authorized personnel with a need to know;
  • authentication through our identity provider and organization-scoped authorization in the application;
  • optional time-based one-time password (TOTP) multi-factor authentication for user accounts;
  • infrastructure hosted with established cloud providers with physical and environmental security controls;
  • logging and monitoring for security events and abuse on the marketing site and application;
  • regular dependency and infrastructure updates; and
  • confidentiality obligations for personnel with access to production systems.

Customer is responsible for securing its account credentials (including use of available multi-factor authentication where appropriate), managing user access within its organization, and configuring repository connections. Additional detail may be provided on reasonable request for security assessments.