Data processing agreement
This is a translation for convenience. The binding version of this document is the Spanish one: the Spanish version. In case of discrepancy, the Spanish text prevails.
When it applies
Only when Aseptic stores data on the Customer's behalf: the Team plan with the hosted catalogue option.
It does not apply —and nothing needs signing— if:
- You use the Free or Pro plan. Everything runs on the user's machine.
- You use the Team plan with the catalogue in your own git repository: scenarios live in the Customer's infrastructure and Aseptic never touches them.
That second option exists, among other reasons, so that a customer who does not want to sign a processing agreement does not have to and still gets the whole product.
1. Parties
- Controller: the Customer (the organisation subscribing to the plan).
- Processor: Juan García Valero (“Aseptic”), info@aseptic.dev.
2. Subject matter, duration, nature and purpose
| Subject matter | Hosting the Customer's catalogue of development scenarios |
|---|---|
| Duration | That of the subscription contract |
| Nature | Storage and retrieval. No access to the content (see §4) |
| Purpose | Letting the Customer's team share local development environment configuration |
3. Categories of data and data subjects
Data subjects: the Customer's employees or collaborators with access to Aseptic.
| Category | Status |
|---|---|
| Scenario content (hosts, service names, repository paths) | End-to-end encrypted. Aseptic cannot read it |
| Scenario name and description | In the clear |
| Customer's organisation code | In the clear |
| Email of whoever published it | In the clear |
| Publication date and size | In the clear |
No special categories of data (art. 9) are processed. The Customer undertakes not to introduce any: a catalogue of development scenarios is no place for them.
4. End-to-end encryption: what it means here
The content of each scenario is encrypted on the Customer's machine (AES-256-GCM) with a key the Customer generates and keeps. Aseptic stores the result and does not hold the key. The consequences, stated for clarity and not as a disclaimer:
- Aseptic cannot access the content, neither on its own account nor at a third party's request. Faced with a legal request it can only hand over ciphertext.
- Aseptic cannot alter a scenario undetected: the encryption is authenticated and tampering is discovered on opening.
- If the Customer loses the key, the content is unrecoverable. Aseptic cannot help. That impossibility is the safeguard, and the Customer expressly accepts it.
5. Processor's obligations (art. 28(3))
- a) Process the data only on documented instructions from the Customer, including as regards international transfers. This agreement and the product's configuration constitute those instructions.
- b) Ensure the confidentiality of anyone accessing the data.
- c) Apply the measures of art. 32 (see §7).
- d) Not engage sub-processors without authorisation (see §6).
- e) Assist the Customer in responding to data subjects' rights. The product includes deletion on request with no manual intervention.
- f) Assist in complying with arts. 32 to 36.
- g) At the Customer's choice, delete or return all data at the end, and delete copies unless legally required to keep them.
- h) Make available to the Customer the information needed to demonstrate compliance and allow audits.
Aseptic does not use this data for any purpose of its own: it does not analyse it, train models on it or derive statistics from it. Given §4, as far as the content is concerned it could not anyway.
6. Sub-processors
The Customer authorises the listed sub-processors. Aseptic will give 30 days' notice of any addition or change, and the Customer may object and terminate without penalty if the objection is reasonable and cannot be resolved.
Current sub-processor for this processing: Cloudflare, Inc. (storage under EU jurisdiction and database in Western Europe).
7. Security measures (art. 32)
| Measure | How |
|---|---|
| Encryption at rest | End-to-end, Customer's key (AES-256-GCM) |
| Encryption in transit | TLS 1.3 |
| Authenticity | Authenticated encryption: tampering is detected on decryption |
| Access control | Per organisation, derived from a token signed by the identity provider. Never from a request parameter |
| Isolation | Each organisation in its own storage prefix |
| No intermediate caching | All responses with no-store and Vary: Authorization |
| Minimisation | Only what is needed to list and retrieve is stored |
| Resilience | Cloudflare's distributed infrastructure |
8. Location and transfers
Data is stored in the European Union. Cloudflare, Inc. is a US company: access by its staff may constitute an international transfer, covered by Standard Contractual Clauses and the EU-US Data Privacy Framework.
9. Personal data breaches
Aseptic will notify the Customer without undue delay and within 48 hours at the latest of becoming aware of a breach affecting their data, with the information of art. 33(3) available at that time. Those 48 hours leave the Customer room within the 72 it has towards the authority.
10. Audit
The Customer may request, once a year and with 30 days' notice, the information needed to verify compliance. It will be met with documentation and reports; an on-site inspection will require prior agreement on scope and cost.
11. End of the contract
At the Customer's choice, communicated within the following 30 days: return of the data (encrypted, as it is: only the Customer can decrypt it) or deletion. Absent instructions, it is deleted after 60 days.
12. Liability and governing law
Governed by what is agreed in the Terms of use. Spanish law and the GDPR; jurisdiction of the courts of the Processor's domicile, save mandatory rules to the contrary.
Acceptance. By subscribing to the Team plan with hosted catalogue, the Customer accepts this agreement. If you need a signature on your own template, write to info@aseptic.dev.