The short version
- You control the personal data in your workspaces. We process it only to provide Spectrace and on your instructions.
- This addendum is part of the Terms of Service, so there is nothing to sign.
- We tell you 30 days before a new sub-processor handles your data, and you can object.
- We tell you without undue delay, and where we can within 48 hours, after we learn of a breach affecting your data.
- Data leaves the UK and the EU only under legal safeguards, such as the standard contractual clauses.
This summary is not part of the Addendum. The full text below applies.
1Scope
1.1
This Data Processing Addendum (the Addendum) forms part of the Terms of Service, or of any other written agreement under which Spectrace Ltd (Spectrace) provides the Service to a customer (the Customer) (in each case, the Agreement). Capitalised words not defined here have the meaning the Terms of Service give them.
1.2
It applies when Spectrace processes Customer Personal Data. Customer Personal Data means personal data in Customer Content that Spectrace processes on the Customer's behalf in providing the Service.
1.3
Data Protection Laws means the laws on data protection and privacy that apply to the processing of Customer Personal Data under the Agreement, including the UK GDPR and the Data Protection Act 2018, the EU General Data Protection Regulation (Regulation (EU) 2016/679, the EU GDPR), the Swiss Federal Act on Data Protection, and US state privacy laws, each as amended or replaced. Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given in the UK GDPR or the EU GDPR, as applicable.
1.4
The Customer does not need to sign this Addendum; it takes effect when the Customer accepts the Agreement. If the Customer needs a signed copy, email hello@spectrace.io.
2Roles
2.1
The Customer is the controller of Customer Personal Data, or a processor acting for its own controllers. Spectrace is the Customer's processor, or sub-processor.
2.2
Spectrace is a separate controller of the personal data it processes for its own purposes, such as running accounts, billing, security and improving the Service, as its Privacy Policy describes. This Addendum does not apply to that processing.
2.3
The Customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis, giving notices and obtaining any consents, and for the accuracy of Customer Personal Data. If the Customer is itself a processor, it confirms that its instructions, including its appointment of Spectrace, are authorised by its controller.
3Processing on the Customer's instructions
3.1
Spectrace will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless the law of the United Kingdom, or of the European Union or a member state where applicable, requires it to do otherwise. In that case Spectrace will tell the Customer before processing, unless that law prohibits it.
3.2
The Customer's instructions are the Agreement, including this Addendum; the Customer's and its Users' use and configuration of the Service, such as connecting services, using AI Features and sharing review links; and any other reasonable written instructions the parties agree.
3.3
Spectrace will tell the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.
3.4
The details of the processing are in Annex 1.
4Confidentiality of personnel
4.1
Spectrace will ensure that everyone it authorises to process Customer Personal Data is bound by an obligation of confidentiality, and that access is limited to those who need it to provide, secure or support the Service.
5Security
5.1
Spectrace will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to individuals. Annex 2 describes the current measures. Spectrace may change them, provided the overall level of protection is not reduced.
5.2
The Customer is responsible for its own use of the Service, including keeping sign-in details and API keys secure, choosing its Users' roles, and deciding what content to put into the Service and what to share through review links.
6Sub-processors
6.1
The Customer gives Spectrace general authorisation to engage sub-processors. The current sub-processors are listed in Annex 3.
6.2
Spectrace will give the Customer at least 30 days' notice before a new sub-processor starts processing Customer Personal Data, by updating the list in Annex 3 and emailing the owners of the Customer's workspaces.
6.3
The Customer may object to a new sub-processor on reasonable data protection grounds by emailing hello@spectrace.io within that notice period. The parties will discuss the objection in good faith. If Spectrace cannot resolve it, the Customer may end the affected subscription before the change takes effect, and Spectrace will refund what the Customer prepaid for the unused part of the billing period.
6.4
Spectrace will put a written contract in place with each sub-processor that imposes data protection obligations no less protective than those in this Addendum, to the extent they apply to the services the sub-processor provides. Spectrace remains liable to the Customer for each sub-processor's performance of those obligations.
7Requests from data subjects
7.1
Taking into account the nature of the processing, Spectrace will help the Customer, by appropriate technical and organisational measures and insofar as possible, to respond to requests from data subjects to exercise their rights. The Customer can do much of this itself in the Service, for example by editing, deleting or exporting content.
7.2
If Spectrace receives a request from a data subject about Customer Personal Data, it will refer the data subject to the Customer where it can identify the Customer, and will not otherwise respond unless the Customer instructs it to or the law requires it.
8Help with the Customer's obligations
8.1
Taking into account the nature of the processing and the information available to it, Spectrace will give the Customer reasonable help with its obligations on security, data protection impact assessments and prior consultation with supervisory authorities. Spectrace may charge a reasonable fee, agreed in advance, for help beyond the information it publishes or provides as standard.
9Personal data breaches
9.1
Spectrace will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. It will email the owners of the affected workspaces.
9.2
The notice will describe, as far as known at the time: the nature of the breach, including the categories and approximate number of data subjects and records concerned; its likely consequences; the measures taken or proposed to address it and reduce its effects; and a contact for more information. Spectrace will provide information in stages as it becomes available.
9.3
Spectrace will take reasonable steps to contain, investigate and mitigate the breach. Notifying a breach is not an admission of fault or liability.
10Return and deletion
10.1
The Customer can export Customer Content during the Agreement, as the Documentation describes, and Spectrace will help with reasonable export requests.
10.2
When a workspace is deleted, or the Agreement ends and any export period under the Terms of Service has passed, Spectrace will delete the Customer Personal Data it holds for that workspace within 90 days, unless the law requires Spectrace to keep it. Until deletion, this Addendum continues to protect it.
11Information and audits
11.1
Spectrace will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR or EU GDPR and with this Addendum, including answers to reasonable security questionnaires.
11.2
If that information is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may audit Spectrace's compliance itself or through an independent auditor bound by confidentiality. Audits take place no more than once in any 12 months (unless after a personal data breach or at an authority's request), on at least 30 days' written notice, during business hours, with a scope agreed in advance, without undue disruption, and at the Customer's cost.
12International transfers
12.1
Spectrace is established in the United Kingdom. Customer Personal Data is stored in the European Union, in Frankfurt, Germany, and processed in the other countries Annex 3 lists.
12.2
Transfers of Customer Personal Data from the European Economic Area or Switzerland to Spectrace in the United Kingdom rely on the adequacy decisions recognising the United Kingdom. If that recognition ends, the standard contractual clauses approved by the European Commission in Decision (EU) 2021/914 (the EU SCCs), Module 2, or Module 3 where the Customer is a processor, are incorporated into this Addendum, with the Customer as data exporter and Spectrace as data importer, on the terms in clause 12.4.
12.3
Spectrace transfers Customer Personal Data to sub-processors outside the United Kingdom and the European Economic Area only under a safeguard Data Protection Laws recognise: an adequacy decision or regulation (including, for certified recipients, the EU-US Data Privacy Framework and its UK Extension), or the EU SCCs together with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement.
12.4
Where the EU SCCs apply between the Customer and Spectrace: Clause 7 of the EU SCCs (the docking clause) applies; under Clause 9, Option 2 (general written authorisation) applies, with the notice period in clause 6.2 of this Addendum; the optional wording in Clause 11 does not apply; under Clause 13, the competent supervisory authority is the one that is competent for the Customer under the EU GDPR; under Clauses 17 and 18, the EU SCCs are governed by the law of Ireland and disputes go to the courts of Ireland; and Annexes 1, 2 and 3 of this Addendum complete Annexes I, II and III of the EU SCCs. For transfers subject to Swiss law, references to the EU GDPR are read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
12.5
If a safeguard on which a transfer relies is found invalid or ceases to apply, the parties will cooperate to put a valid alternative in place.
12.6
If a public authority asks Spectrace to disclose Customer Personal Data, or any of the Customer's data held in the European Union, Spectrace will check that the request is legally valid, challenge it where there are reasonable grounds, disclose only the minimum the request requires, and tell the Customer before disclosing, unless the law prohibits that.
13US state privacy laws
13.1
Where Customer Personal Data is subject to US state privacy laws, such as the California Consumer Privacy Act, Spectrace acts as the Customer's service provider or processor. It will: process that data only to provide the Service under the Agreement; not sell or share it, as those laws define selling and sharing; not retain, use or disclose it for any other purpose, or outside its direct business relationship with the Customer, except as those laws permit; not combine it with personal information it receives from anyone else, except as those laws permit; provide the level of privacy protection those laws require; tell the Customer if it can no longer meet these obligations; and let the Customer take reasonable steps to stop and remedy any unauthorised use. Spectrace certifies that it understands and will comply with these restrictions.
14Liability, precedence and term
14.1
Each party's liability under this Addendum is subject to the limits in the Terms of Service, except where Data Protection Laws or the EU SCCs do not allow liability to be limited.
14.2
If this Addendum conflicts with the Agreement, this Addendum prevails on data protection matters. If it conflicts with the EU SCCs or the UK International Data Transfer Addendum, where they apply, they prevail.
14.3
This Addendum continues for as long as Spectrace processes Customer Personal Data.
15Annex 1: Details of the processing
- Subject matter and duration: providing the Service under the Agreement, for as long as the Agreement continues and until deletion under clause 10.
- Nature and purpose: hosting, storing, organising, analysing (including with AI models), transmitting to Connected Services on the Customer's instructions, displaying, exporting and deleting Customer Content, to provide the Service as the Agreement and the Documentation describe, including AI Features and pull request verification.
- Data subjects: the Customer's Users and people it invites; people named or referred to in Customer Content, such as colleagues, stakeholders, end users, issue assignees, Slack message authors and authors of source code and pull requests; and external reviewers who comment on or approve requirements through review links.
- Personal data: names, email addresses, user names and identifiers in Connected Services, profile pictures, job titles and roles; the content of requirements, comments, documents, issues and messages that refer to people; authorship details in source code and pull requests; reviewers' names, email addresses, comments and approvals; and any other personal data the Customer chooses to put into the Service.
- Special categories: none intended. The Customer should not put special categories of personal data into the Service.
- Frequency: continuous, while the Customer uses the Service.
16Annex 2: Security measures
- Encryption: data is encrypted in transit between users and the Service and between the Service and its database. Data at rest is encrypted by Spectrace's hosting providers. Access tokens for Connected Services are also encrypted by Spectrace with AES-256-GCM. API keys and one-time codes are stored only as cryptographic hashes.
- Access control: each workspace has role-based access (owner, admin, member), and every request is checked on the server against the requester's membership. Access to production systems is limited to authorised personnel who need it.
- Separation: each customer's data is logically separated within the database.
- Application security: limits on repeated sign-in and API requests; secrets held in the hosting providers' secret stores, not in code; credentials and sign-in headers removed from error reports.
- Data minimisation: the original files of imported documents are not kept; pull request changes are read for each check and not stored; recognisable credentials are removed from most content before it is sent to the AI provider.
- Monitoring and records: error monitoring, and audit logs of significant actions in each workspace.
- Sub-processors: chosen for their security practices and bound by written data protection terms.
- Incidents: a process to assess, contain and respond to security incidents and to notify customers under clause 9.
17Annex 3: Sub-processors
These are Spectrace's current sub-processors. The same list, with the personal data each one processes, is under Our service providers in the Privacy Policy, which also names Stripe, which handles billing data for Spectrace's own purposes and does not process Customer Content. Spectrace updates both before a change takes effect, as clause 6 sets out.
| Sub-processor | Entity | Function | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Supabase Pte. Ltd. (Singapore) | Sign-in, the database and file storage | European Union (Frankfurt, Germany), with support access from the United States and Singapore | Standard contractual clauses, with the UK International Data Transfer Addendum |
| Vercel | Vercel Inc. (United States) | Hosting the website, the app and its API | United States and European Union (Frankfurt, Germany) | Data Privacy Framework, including the UK Extension; standard contractual clauses as a fallback |
| Trigger.dev | API Hero Ltd, trading as Trigger.dev (United Kingdom) | Background jobs, such as indexing code, AI processing, verification and email | United States | UK company; its own transfers covered by standard contractual clauses |
| OpenAI | OpenAI OpCo, LLC (United States) | AI models and embeddings for the AI features | United States | Standard contractual clauses, with the UK International Data Transfer Addendum |
| Brevo | Sendinblue SAS, trading as Brevo (France) | Sending service emails | European Union (France and Belgium) | Within the EU, which UK law recognises as adequate |
| Sentry | Functional Software, Inc., trading as Sentry (United States) | Error monitoring | European Union (Frankfurt, Germany) | Data Privacy Framework, including the UK Extension; standard contractual clauses as a fallback |
| Upstash | Upstash, Inc. (United States) | Caching | United States | Data Privacy Framework, including the UK Extension; standard contractual clauses as a fallback |