Legal

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and BugBrain (“Processor”). It governs the processing of personal data BugBrain performs on the Controller’s behalf when providing the service, and reflects the requirements of GDPR Article 28.

1. Subject matter & duration

BugBrain processes personal data to provide automated software testing and related services, for the duration of the agreement and as needed to fulfill the deletion/return obligations below.

2. Nature & purpose of processing

Executing test runs against the Controller’s applications and capturing artifacts (screenshots, logs, snapshots) for analysis and reporting, including analysis by AI model providers acting as our subprocessors.

3. Types of data & categories of data subjects

Any personal data the Controller’s applications expose during testing, typically the Controller’s end users and their content. The Controller controls what data its applications surface, and should avoid directing the service at unnecessary special-category data.

4. Processor obligations

  • Instructions: process personal data only on the Controller’s documented instructions.
  • Confidentiality: ensure personnel are bound by confidentiality.
  • Security (Art 32): implement appropriate technical and organizational measures: encryption at rest and in transit, tenant isolation, least-privilege access, audit logging, and log redaction.
  • Subprocessors (Art 28(2)/(4)): the Controller grants general authorization for the subprocessors listed on our Subprocessors page; we notify of changes and impose equivalent obligations by contract.
  • Data-subject requests: assist the Controller in responding to access, erasure, rectification, portability, and objection requests.
  • Breach notification: notify the Controller without undue delay after becoming aware of a personal-data breach affecting their data.
  • Deletion/return: on termination, delete or return personal data at the Controller’s choice, subject to retention required by law.
  • Audits: make available information necessary to demonstrate compliance and allow for audits within reasonable limits.

5. International transfers

Where processing involves transfers outside the EEA/UK, the parties rely on the EU–US Data Privacy Framework (where the recipient is certified) and/or the European Commission’s Standard Contractual Clauses, incorporated by reference, together with a transfer impact assessment and supplementary measures.

6. How to execute this DPA

To countersign this DPA for your organization, contact privacy@bugbrain.tech. We will provide an executable copy.