DATA PROCESSING
You are the controller. On the managed service, we are your processor.
This page maps the roles, the sub-processors, and the measures behind them — so your own record of processing can be completed without a discovery call.
You are the controller. On the managed service, we are your processor.
Roles
Who plays which part depends on who operates the workspace. Find your row before reading the rest.
- Managed service
- You are the controller. We are your processor: we hold and process your incident data on your instructions, for the purpose of running the service, and for nothing else.
- Self-hosted
- You are both controller and processor. We supply the software, receive no data, and have no access to your deployment.
- Sub-processors
- On the managed service, the providers listed below. Self-hosted, whichever providers you configure.
The agreement itself
Managed customers sign a data-processing agreement before any data is connected. It is not optional and it is not an upsell — we cannot act as your processor without one. It records:
- the categories of data, the purposes, and the duration of processing;
- the retention period, and what happens to your data when the service ends;
- the sub-processors in use, and how you are told before that list changes;
- our obligation to assist with access, correction, and deletion requests;
- the breach-notification timeline;
- the transfer basis, where a provider processes data outside your jurisdiction.
Ask for the current version before you commit to anything. Self-hosted deployments need no agreement with us, because there is no processing on our side to govern.
Sub-processors
On the managed service these providers may process your data. The signed agreement carries the current, named list; this page describes the categories so you know what to expect.
- Infrastructure
- The hosting, database, and queue services the workspace runs on.
- Model provider
- Receives redacted issue and event context for analysis. Named in your agreement, and changed only with notice.
- Delivery channels
- The email, chat, or messaging services that carry incident summaries to the destinations you nominate.
Git hosting and any file-transfer target are yours, not ours: we act on them with credentials you supply and permissions you set.
Categories of data processed
Account records, customer and project configuration, issue and event payloads, analyses, and operational history. Event payloads are the category most likely to contain personal data, because they carry whatever your application attached to an error.
Deciding what your application puts into an error payload remains the single most effective control available to you, on either operating model.
Technical measures
In the software: key-based redaction before analysis, AES-256-CBC encryption of stored integration tokens, JWT sessions with optional two-factor and passkey authentication, role-gated privileged routes, a request rate limit, and approval-gated file changes with backups. Each measure and its source file is listed on the security page.
On the managed service, add the organisational measures recorded in your agreement: who on our side may access your workspace, how that access is reviewed, and how it is revoked.
International transfers
Where your data is processed is agreed with you and recorded before the service starts; regional hosting is available where a jurisdiction requires it. If a sub-processor processes data outside that region, the transfer basis is named in the agreement rather than left to be discovered later.