This Data Processing Addendum ("DPA") is entered into by Customer legal name ("Customer") and Recoilix LLC, a Delaware limited liability company, 4030 Wake Forest Road STE 349, Raleigh, NC 27609, United States, doing business as Anteproof ("Anteproof"), and forms part of the pilot agreement / order form dated date (the "Agreement"). It applies to the extent Anteproof processes Personal Data on Customer's behalf in providing the Service under the Agreement. If this DPA conflicts with the Agreement, this DPA prevails for the processing of Personal Data.
1. Definitions
"Data Protection Law" means all laws applying to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA"). "Personal Data", "Controller", "Processor", "Data Subject", "processing", "Personal Data Breach" and "Sub-processor" have the meanings given in Data Protection Law; under the CCPA, "Controller" reads as "Business" and "Processor" as "Service Provider". "Service" means the Anteproof website, API, MCP server and digest as described in the Agreement. "Customer Personal Data" means Personal Data that Anteproof processes on Customer's behalf under the Agreement, as described in Annex 1.
2. Roles
2.1 For Customer Personal Data, Customer is the Controller (or a Processor acting for its own controller) and Anteproof is the Processor. Customer instructs Anteproof to process Customer Personal Data only to provide the Service and as documented in the Agreement and this DPA; further instructions must be in writing and may be subject to reasonable fees if outside the Service.
2.2 Customer is responsible for the lawfulness of the Customer Personal Data it provides and for the instructions it gives. Anteproof will tell Customer if, in its opinion, an instruction infringes Data Protection Law, without being obliged to review Customer's compliance.
2.3 Anteproof is an independent Controller of (a) the account data of Customer's users as described in the Anteproof privacy policy, to the extent needed to operate their accounts, and (b) the public forecast archive, which concerns software projects and organisations and is not derived from Customer Personal Data. Nothing in this DPA transfers control of the public archive.
3. Subject matter, duration, nature and purpose
| Subject matter | Provision of the Service to Customer: accounts and API access for Customer's users, watchlists, metered API and MCP calls, and dependency-risk answers for package lists Customer submits. |
|---|---|
| Duration | The term of the Agreement plus the deletion period in section 9. |
| Nature | Collection, storage, retrieval, use for the Service, and deletion, by automated means on Anteproof's systems and those of the Sub-processors in Annex 2. |
| Purpose | To operate Customer's accounts and to return forecasts, scores and calibration data about the software projects and packages Customer asks about. Anteproof does not use Customer Personal Data to train models, to build profiles, for advertising, or for any purpose of its own. |
4. Categories of data subjects and data
| Data subjects | Customer's employees, contractors and other users authorised to use the Service under the Agreement. |
|---|---|
| Categories of Personal Data | Name and business email address; identity-provider user id; API key names and hashed keys; watchlist entries; per-day usage counts; product events (pages, endpoints, times, UTM attribution) with a keyed hash of IP address; server logs with IP address and user agent; correspondence. Package lists, lock files and SBOMs Customer submits are treated as Customer Confidential Information; they ordinarily contain no Personal Data. |
| Special categories | None. Customer will not submit special-category data, payment card data (handled by the merchant of record under its own terms), or data of children. |
5. Anteproof's obligations
Anteproof will: (a) process Customer Personal Data only on Customer's documented instructions, including for transfers, unless required by law, in which case it will inform Customer before processing unless the law forbids it; (b) ensure that persons authorised to process Customer Personal Data are bound by confidentiality; (c) implement the technical and organisational measures in Annex 3; (d) engage Sub-processors only under section 6; (e) taking into account the nature of the processing, assist Customer with appropriate measures to respond to Data Subject requests, and forward to Customer without undue delay any request it receives directly, without responding except to say the request has been forwarded; (f) assist Customer with security, breach notification, data protection impact assessments and prior consultations, taking into account the information available to it; (g) delete or return Customer Personal Data under section 9; and (h) make available the information needed to demonstrate compliance and allow audits under section 10.
6. Sub-processors
6.1 Customer gives general authorisation for Anteproof to engage the Sub-processors listed in Annex 2 and published at anteproof.com/privacy.
6.2 Anteproof will give Customer at least 30 days' written notice (email to the address in the Agreement) before adding or replacing a Sub-processor that processes Customer Personal Data. Customer may object on reasonable data-protection grounds within that period; the parties will discuss in good faith, and if no resolution is found within 30 days Customer may terminate the affected part of the Service on notice, with a pro-rated refund of prepaid fees.
6.3 Anteproof will impose data-protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable to Customer for the Sub-processor's performance.
7. Security
Anteproof will maintain the measures in Annex 3, review them at least annually, and not materially reduce them during the term. Customer is responsible for securing its users' credentials and API keys and for the security of its own systems.
8. Personal Data Breach
Anteproof will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information reasonably available at the time and updates as it learns more, and will take reasonable steps to contain and remedy the breach. Notification is not an admission of fault.
9. Deletion and return on termination
Within 30 days after the end of the Agreement, or earlier on Customer's written request, Anteproof will delete Customer Personal Data from its production systems and, within 90 days, from backups, unless retention is required by law (in which case the data is kept only for that purpose and remains protected by this DPA). Before deletion Customer may export its users' watchlists and usage records through the Service or by request. Uploaded package lists, lock files and SBOMs are deleted within 24 hours of processing in the ordinary course.
10. Audit
10.1 Once in any 12 months, and additionally after a Personal Data Breach or on a supervisory authority's request, Customer may audit Anteproof's compliance with this DPA. Anteproof will first respond to a written questionnaire and provide relevant documentation (the Annex 3 measures, Sub-processor agreements' data-protection terms, and any third-party assessment it holds). If those are reasonably insufficient, Customer or an independent auditor bound by confidentiality may conduct an on-site or remote audit on 30 days' notice, during business hours, without disrupting operations and at Customer's cost.
10.2 Findings are Confidential Information. Anteproof will address material findings within a reasonable time agreed by the parties.
11. International transfers
11.1 Anteproof is established in the United States; the production database is hosted in Germany. Customer Personal Data may be transferred to the United States and to the locations of the Sub-processors in Annex 2.
11.2 For transfers of Customer Personal Data subject to the GDPR from the EEA to a country without an adequacy decision, the parties enter into the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (the "SCCs"), Module Two (Controller to Processor) or, where Customer is a Processor, Module Three, which are incorporated by reference with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorisation) with the notice period in section 6.2; Clause 11 optional language not included; Clause 13 and Clause 17 the law of Ireland and Clause 18 the courts of Ireland, unless Customer's Member State is specified in the Agreement; Annex I.A and I.B completed by the head of this DPA and by sections 3 and 4; Annex II by Annex 3; Annex III by Annex 2. For UK transfers the International Data Transfer Addendum to the SCCs issued by the Information Commissioner (version B1.0) applies, with the tables completed as above. For Swiss transfers the SCCs apply with the adaptations required by the Federal Data Protection and Information Commissioner.
11.3 Where a Sub-processor is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), Anteproof may rely on that certification for the onward transfer. Anteproof will inform Customer if it can no longer comply with the transfer mechanism and the parties will cooperate on an alternative; failing that, Customer may suspend the affected transfer.
12. CCPA
To the extent the CCPA applies, Anteproof is a Service Provider. It will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purpose in the Agreement, or combine it with Personal Data from other sources except as the CCPA permits. Anteproof certifies that it understands these restrictions, and will notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorised use.
13. Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except that nothing limits a party's liability to Data Subjects or authorities under Data Protection Law. This DPA lasts as long as Anteproof processes Customer Personal Data. It is governed by the law of the Agreement, save that the SCCs are governed as stated in section 11.
Annex 1 — Description of processing
As set out in sections 3 and 4. Frequency: continuous during the term. Retention: as in section 9 and the retention table in the privacy policy.
Annex 2 — Sub-processors
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Clerk, Inc. | Sign-in and identity | United States | SCCs / DPF |
| Stripe, Inc. | Checkout, subscriptions, invoicing and tax, as merchant of record | United States, EU | SCCs / DPF; Stripe is an independent controller for payment data |
| Cloudflare, Inc. | Network edge, TLS, DNS, DDoS protection, email routing | Global edge; United States | SCCs / DPF |
| Hetzner Online GmbH | Hosting of the serving plane, database and product-event store | Germany | Within the EEA |
| Resend, Inc. | Transactional email | United States | SCCs |
| Beehiiv, Inc. | Digest newsletter (only for users who subscribe) | United States | SCCs |
Annex 3 — Technical and organisational measures
- Encryption. TLS 1.2 or higher for all traffic in transit, terminated at the network edge and again to origin; disk encryption at rest at the hosting provider; API keys stored only as SHA-256 hashes; IP addresses in product events stored only as a keyed hash with key rotation at most every 90 days.
- Segregation. The public forecast archive is served from a read-only replica; customer account data lives in a separate database with its own credentials; production runs in containers with least-privilege database roles.
- Access control. Production access limited to named operators over authenticated private networking (no public SSH), with key-based authentication; identity provider sign-in for customers with email verification and optional Google SSO; every API call authenticated and metered per key.
- Integrity and auditability. Forecast and event tables are append-only, enforced by database triggers; the forecast log is hash-chained and its head anchored daily to public timestamp services.
- Availability. Daily database backups retained 30 days; hourly replication to the serving plane; DDoS protection and rate limiting at the edge; security headers (HSTS, nosniff, frame-deny) on every response.
- Logging and monitoring. Server logs retained at most 90 days; alerting on error rates and failed jobs; changes deployed from version control only.
- Sub-processor management. Written data-protection terms with each; list published and change notice given as in section 6.
- Data minimisation and deletion. Only the data in section 4 is collected; uploaded package lists are deleted within 24 hours; account deletion on request within 30 days and from backups within 90.
- Organisational. Confidentiality obligations for everyone with access; documented incident response with the 48-hour customer notification in section 8; annual review of these measures.