Sluiceway data processing agreement
This is the current data processing agreement of the hosted Sluiceway app, part of its terms. The free Sluiceway action is not covered by it: it is under the Apache-2.0 licence only.
Last updated
This agreement is part of the terms of service between the Customer (the controller) and Robbe Verhelst (sole proprietorship), Buisstraat 45, 2890 Sint-Amands, Belgium, company and VAT number BE 1024.261.897 (Sluiceway, the processor). It applies when Sluiceway processes personal data on the Customer's behalf through the hosted Sluiceway app, as article 28 of the GDPR requires.
The Customer accepts it together with the terms: at checkout when it subscribes to a paid plan, and by installing the app on the hosted free plan. It needs no separate signature.
1. The processing
| Subject | Running the hosted Sluiceway app for the Customer's GitHub organization. |
|---|---|
| Duration | As long as the app is installed, plus up to 31 days to delete, and up to 12 months in backups as they age out. |
| Nature and purpose | Reading the Customer's Sluiceway dashboards, deployment records and workflow runs through GitHub's API; keeping stack-level facts; showing the console's org-wide view, audit log and Insights; for a tick a person the repository's tick rule allows, opening the deployment record and starting the workflow; answering deployment protection rules for the required second approver; opening onboarding pull requests and pull requests that change a repository's Sluiceway settings; rescanning; flagging deploys that skipped the Customer's rules; emailing the billing email of the Customer's plan. |
| Personal data | GitHub usernames and numeric user ids of people who tick, merge, rescan, open a pull request from the command line, approve or reject a held deploy, or sign in to the console, next to the stacks, commits and times of what they did; the Customer's list of second approvers; the owners, names and dates of personal API tokens, with a hash of each token; sign-in sessions; the billing email, read from Stripe when an email is sent and not kept. |
| Not processed | Resource names, resource types, property paths, diffs, property values, the text of the dashboard issue, source code, cloud or infrastructure credentials. |
| Data subjects | The Customer's employees and contractors who use GitHub in the installed repositories, and its billing contact. |
| Special categories | None. |
2. Sluiceway's duties
Sluiceway:
- processes the personal data only on the Customer's documented instructions, which are these terms and the Customer's settings in the app, unless the law requires otherwise, and then tells the Customer first where it may;
- makes sure everyone who can reach the data is bound to confidentiality;
- takes the security measures in section 5;
- uses subprocessors only as in section 4;
- helps the Customer answer requests from data subjects, as far as the app's data allows;
- helps the Customer with its duties on security, breach notification and impact assessments, as far as the processing concerns it;
- deletes the personal data within 31 days after the app is uninstalled, or at once when an admin of the Customer's organization deletes everything from the console's settings, unless the law requires keeping it, and confirms the deletion on request. Backups keep a copy for up to 12 months, until they age out;
- gives the Customer the information needed to show that this agreement is kept, and allows an audit by the Customer or an auditor it mandates, once a year and with 30 days' notice, at the Customer's cost. A written answer to a security questionnaire is the first step.
3. Personal data breaches
Sluiceway tells the Customer without undue delay, and within 48 hours of becoming aware of it, of a breach that affects the Customer's personal data. It says what is known: what happened, which data, how many people, what is being done. It adds what it learns later.
4. Subprocessors
The Customer allows these subprocessors:
| Subprocessor | What for | Where |
|---|---|---|
| GitHub | The source of all data; the app works through GitHub's API | GitHub, Inc., United States and EU |
| Resend | Sending the app's emails; sees the recipient address and the text, which names the Customer's organization | Resend, Inc., United States, under the EU Standard Contractual Clauses |
| Cloudflare | Carrying traffic to the service | Global network; Cloudflare, Inc., United States, under the EU Standard Contractual Clauses |
| Cloudflare R2 | Storing the off-site copy of the nightly database backup, encrypted before it leaves Sluiceway's hardware with a key Cloudflare does not hold | Cloudflare, Inc., United States, storage location chosen by Cloudflare, under the EU Standard Contractual Clauses |
| Stripe | Taking payments and handling VAT; holds the billing contact, the payment method and the organization's username, never deploy facts | Stripe Payments Europe, Ireland, and Stripe, Inc., United States, under the EU Standard Contractual Clauses |
Sluiceway hosts the service, its database, its logs and its error tracker on hardware it owns and operates itself in Belgium; there is no hosting subprocessor. Sluiceway tells the Customer at least 30 days before adding or replacing a subprocessor. The Customer may object on reasonable grounds, and may cancel with a refund of the unused part of a prepaid period if the objection cannot be met. Sluiceway binds every subprocessor to data protection duties no weaker than these.
5. Security measures
- Minimal data. Only the stack-level facts in section 1 are kept. The data that would describe the Customer's infrastructure never leaves GitHub.
- No infrastructure credentials. Sluiceway holds no credential of the Customer's cloud or infrastructure. Its GitHub access is the app's installation tokens, limited to the permissions the Customer accepted at install. It starts a workflow only for a tick by a person the repository's tick rule allows, judged with the Sluiceway action's own code.
- Secrets. The app's private key and its payment provider key are kept in a password manager and given to the app as a Kubernetes Secret in the app's own namespace. They are not in the code or in the app's image.
- Transport. Traffic between the internet and the service is encrypted: TLS to Cloudflare, and Cloudflare's tunnel from there to Sluiceway's hardware. Traffic inside Sluiceway's own network, such as between the app and its database, is not encrypted.
- Access. Only Robbe Verhelst has administrative access to the hardware and the data.
- Separation. Each Customer's data is kept under its GitHub installation and shown only to members of that organization and to Sluiceway's administrator.
- Tokens and sessions. Personal API tokens and session ids are kept only as hashes. Sessions end after 8 hours.
- Backups. The database is backed up each night. The copy on Sluiceway's own hardware is not encrypted. The off-site copy is encrypted before it leaves that hardware. Backups are kept for up to 12 months.
- Logs. Service logs hold no property data and no IP addresses; they name usernames, organizations, repositories and stacks, and are kept for 30 days. Error reports have every such name replaced before they are sent, and are kept for 90 days.
6. Transfers outside the EU
The service runs in Belgium. Where a subprocessor handles data outside the EU or EEA, the transfer relies on that subprocessor's standard contractual clauses or on the EU–US Data Privacy Framework.
7. Order of precedence
Where this agreement and the terms of service disagree about personal data, this agreement wins.