Data Processing Agreement (DPA)
CUBES
Version: 2.0
Effective Date: 29 July 2026
Last Updated: 29 July 2026
1. Parties and incorporation
This Data Processing Agreement ("DPA") forms part of the Terms of Service or another agreement governing the Customer's use of CUBES (the "Agreement").
It is entered into between:
- the business or professional customer that determines the purposes and means of processing Customer Personal Data (the "Controller" or "Customer"); and
- CUBES, operated by an individual founder residing in Italy (the "Processor" or "CUBES").
This DPA applies when CUBES processes Customer Personal Data on behalf of the Customer. Capitalized terms not defined here have the meaning given in the Agreement or applicable data-protection law.
2. Definitions
- Applicable Data Protection Law means the GDPR and any other data-protection law applicable to the processing under the Agreement.
- Customer Personal Data means personal data contained in repositories, source code, documents, prompts, instructions, files, or other Customer Content processed by CUBES on behalf of the Customer.
- GDPR means Regulation (EU) 2016/679.
- Personal Data Breach, personal data, processing, controller, processor, and data subject have the meanings given in the GDPR.
- Subprocessor means a processor engaged by CUBES to process Customer Personal Data.
3. Roles and compliance
The Customer acts as controller and CUBES acts as processor for Customer Personal Data.
The Customer is responsible for:
- the lawfulness, fairness, and transparency of its instructions and processing;
- establishing and documenting a valid legal basis;
- providing required notices and obtaining any required permissions;
- ensuring that Customer Personal Data is accurate, relevant, and limited to what is necessary;
- configuring the Service appropriately for the intended data; and
- avoiding submission of prohibited or restricted data unless CUBES has approved the processing in writing and required safeguards are in place.
CUBES will comply with processor obligations applicable to it under Applicable Data Protection Law.
CUBES acts as an independent controller for account administration, legal acceptances, security, fraud prevention, service operations, billing or commercial administration, support, communications, and compliance records, as described in the Privacy Policy. This DPA does not govern those controller activities.
4. Processing instructions
CUBES will process Customer Personal Data only:
- on the Customer's documented instructions;
- as necessary to provide, secure, support, and maintain the Service;
- as described in the Agreement, this DPA, applicable repository authorization, and the Customer's configuration or written instructions; or
- where required by applicable law.
If CUBES is legally required to process Customer Personal Data other than on the Customer's instructions, CUBES will inform the Customer before processing unless the law prohibits notice.
CUBES will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. CUBES may suspend the affected processing until the instruction is clarified, modified, or confirmed as lawful.
5. Details of processing
The subject matter, duration, nature, purpose, categories of data subjects, and categories of Customer Personal Data are described in Annex A.
The processing continues for the duration of the Agreement and any limited period required to complete deletion, return, backup rotation, security investigation, legal retention, or transition obligations.
6. Confidentiality and personnel
CUBES will ensure that persons authorized to process Customer Personal Data:
- are bound by confidentiality obligations or an appropriate statutory duty of confidentiality;
- receive access only where necessary for their responsibilities; and
- are informed of relevant data-protection and security obligations.
Access will be removed or adjusted when no longer required.
7. Security measures
CUBES will implement and maintain technical and organizational measures appropriate to the risk, taking account of the state of the art, implementation costs, the nature and scope of processing, and the risks to individuals.
Current categories of measures are described in Annex B and may be supplemented by the Security Statement or service documentation.
CUBES may update security measures where the update does not materially reduce the overall protection of Customer Personal Data.
The Customer remains responsible for account permissions, repository scope, secret removal, lawful configuration, endpoint security, backups, and its users' handling of credentials and outputs.
8. Subprocessors
The Customer gives CUBES general written authorization to engage Subprocessors necessary to provide the Service.
CUBES will:
- maintain current information identifying relevant Subprocessors or categories of Subprocessors;
- impose data-protection obligations that provide substantially equivalent protection for Customer Personal Data;
- remain responsible for the performance of its Subprocessors to the extent required by law; and
- provide notice of a material new Subprocessor where required by the Agreement or Applicable Data Protection Law.
The Customer may object to a new Subprocessor on reasonable, documented data-protection grounds within the notice period provided. The parties will work in good faith to identify a commercially reasonable alternative. If no reasonable alternative is available, CUBES may suspend the affected processing or the Customer may terminate the affected Service before the new Subprocessor processes Customer Personal Data.
9. International transfers
CUBES will not transfer Customer Personal Data to a country outside the European Economic Area unless the transfer is permitted by Applicable Data Protection Law.
Where required, CUBES will rely on an appropriate transfer mechanism, such as:
- an adequacy decision;
- the European Commission's Standard Contractual Clauses under Decision (EU) 2021/914;
- binding corporate rules; or
- another lawful safeguard or derogation.
Where the 2021/914 Standard Contractual Clauses are used, the appropriate module will apply according to the parties' roles, and this DPA and applicable service documentation may complete the required annex information.
CUBES will provide reasonable information necessary for the Customer to assess relevant transfer safeguards, subject to confidentiality and security limitations.
10. Data subject requests
Taking into account the nature of the processing, CUBES will provide reasonable assistance to enable the Customer to respond to requests by data subjects exercising rights under Applicable Data Protection Law.
If CUBES receives a request relating to Customer Personal Data for which the Customer is controller, CUBES will, where legally permitted:
- notify the Customer;
- not respond substantively except on the Customer's instructions or as required by law; and
- direct the requester to the Customer where appropriate.
The Customer is responsible for determining the validity and scope of the request.
11. Personal Data Breaches
CUBES will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notification will include information reasonably available to CUBES concerning:
- the nature of the breach;
- affected data or data-subject categories where known;
- likely consequences;
- measures taken or proposed; and
- a contact point for follow-up.
Information may be provided in phases where it is not available at the same time.
CUBES will take reasonable steps to contain, investigate, mitigate, and remediate the breach. Notification is not an admission of fault or liability.
The Customer is responsible for determining whether notification to authorities or data subjects is required, except to the extent law places a direct obligation on CUBES.
12. Assistance with compliance
Taking into account the nature of processing and information available to it, CUBES will provide reasonable assistance with:
- security obligations;
- breach assessment and notification;
- data-protection impact assessments;
- prior consultation with supervisory authorities; and
- records or information reasonably necessary to demonstrate compliance.
Assistance beyond the standard Service may be subject to reasonable fees where permitted by the Agreement, unless the need for assistance results from CUBES's breach of this DPA.
13. Deletion and return
At the Customer's choice, and subject to technical capability and the Agreement, CUBES will delete or return Customer Personal Data after termination of the affected Service.
CUBES may retain limited copies where required by law or reasonably necessary for security, audit, dispute resolution, legal claims, or compliance, provided that retained data remains protected and is not used for another purpose.
Data in backups may remain until overwritten through the normal backup cycle and will remain protected during that period.
The Customer is responsible for exporting any Customer Personal Data it requires before termination where an export feature or reasonable process is available.
14. Audit and information rights
CUBES will make available information reasonably necessary to demonstrate compliance with this DPA.
The Customer may request an audit no more than once in any twelve-month period, unless a Personal Data Breach, supervisory-authority request, or credible evidence of material non-compliance justifies an additional audit.
Audits must:
- be limited to systems and processing relevant to the Customer;
- protect other customers, security information, and confidential information;
- occur during normal business hours with reasonable advance notice;
- use existing reports, certifications, questionnaires, or remote review first where sufficient; and
- avoid unreasonable disruption.
An independent auditor must be bound by confidentiality and must not be a competitor of CUBES. The Customer bears its audit costs unless the audit identifies material non-compliance by CUBES.
15. Government and third-party requests
Unless prohibited by law, CUBES will notify the Customer of a binding request by a public authority for Customer Personal Data.
CUBES will review requests for legal validity, disclose only what is legally required, and use reasonable efforts to challenge overbroad or unlawful requests where appropriate.
16. Restricted and high-risk data
The Customer must not submit special-category, health, biometric, payment-card, government-identifier, children's, employee-monitoring, criminal-offence, or similarly regulated data unless:
- CUBES has approved the processing in writing;
- the Customer has completed the required data-eligibility review;
- appropriate technical and organizational measures are configured; and
- any additional agreement or impact assessment is complete.
Production secrets, credentials, access tokens, private keys, or live authentication material must be removed before repository connection.
CUBES may block or suspend processing where data classification is incomplete or indicates elevated legal or security risk.
17. Liability
Liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent such limitation is prohibited by Applicable Data Protection Law.
Nothing in this DPA limits data-subject rights or regulatory powers that cannot lawfully be limited by contract.
18. Term and termination
This DPA takes effect when the Customer accepts or signs it, or when the Agreement incorporates it, and remains in force while CUBES processes Customer Personal Data on behalf of the Customer.
Termination does not affect obligations that by their nature survive, including confidentiality, security, audit cooperation, deletion, transfer safeguards, and lawful retention.
19. Conflict and governing law
If this DPA conflicts with the Agreement, this DPA controls for the processing of Customer Personal Data.
If applicable Standard Contractual Clauses conflict with this DPA, those clauses control for the relevant transfer or processing.
This DPA is governed by the law governing the Agreement, subject to mandatory requirements of Applicable Data Protection Law.
Annex A — Processing details
A1. Subject matter and purpose
Processing Customer Personal Data to provide AI-assisted software-repository and document analysis, technical diagnostics, reports, support, security, and related Service functions requested by the Customer.
A2. Nature of processing
Collection, access, retrieval, organization, transmission, hosting, storage, temporary caching, analysis, comparison, classification, transformation, generation of outputs, logging, support, deletion, and other processing necessary to provide and secure the Service.
A3. Duration
For the term of the Agreement and the limited deletion, backup, security, legal, or transition period described in this DPA.
A4. Categories of data subjects
May include:
- Customer users, personnel, contractors, founders, and representatives;
- contributors, authors, committers, reviewers, and maintainers identified in repository or document metadata;
- customers, prospects, suppliers, or other individuals whose information is included in Customer Content; and
- other individuals determined by the Customer through its use of the Service.
A5. Categories of personal data
May include:
- names, usernames, email addresses, business roles, and account identifiers;
- repository, commit, branch, issue, pull-request, and contributor metadata;
- source-code comments, configuration, documentation, tickets, and uploaded documents;
- prompts, instructions, generated reports, and support communications;
- technical, network, device, audit, and security data; and
- other personal data included by the Customer in Customer Content.
A6. Special categories
Not intended for standard private-beta processing. Processing requires prior written approval and additional safeguards.
A7. Processing frequency
Continuous or episodic, depending on Customer use, repository connection, scheduled analysis, and support activity.
Annex B — Technical and organizational measures
Measures may include, as appropriate to the Service and risk:
- identity and access management, authentication, authorization, and least-privilege controls;
- restricted administrative access and role separation;
- encryption in transit and provider-managed encryption at rest where supported;
- secure credential and secret handling;
- logging, audit trails, monitoring, and security-event review;
- vulnerability, dependency, and configuration management;
- backup, recovery, availability, and continuity controls appropriate to the beta environment;
- incident detection, response, containment, and notification procedures;
- secure development, change management, and deployment controls;
- subprocessor review and contractual safeguards;
- personnel confidentiality and access termination processes;
- data minimization, retention, deletion, and environment-separation measures; and
- periodic review and improvement of security controls.
No measure guarantees absolute security. The specific controls available may depend on the Customer's selected configuration and the private-beta architecture.
Annex C — Subprocessor categories
CUBES may use Subprocessors for:
- cloud hosting, storage, database, and content delivery;
- authentication and repository integrations;
- AI and software-analysis processing;
- email and operational communications;
- monitoring, logging, diagnostics, and security; and
- customer support and business operations.
Current provider information will be made available through the Privacy Policy, Security Statement, subprocessor notice, or applicable service documentation.
End of Data Processing Agreement