Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Hackerman AB ("Processor", "we", "us"), a Swedish limited company (org. nr. 559079-1918), and the organisation subscribing to the Codebahn service ("Controller", "you").
This DPA governs our processing of personal data on your behalf pursuant to Article 28 GDPR.
1. Definitions
"Customer Data" means all personal data that Controller uploads to or creates within the Service, including repository content, issues, pull requests, CI artifacts, user profiles, and any other content processed on Controller's behalf. Other terms have the meaning given in the GDPR or the Terms of Service.
2. Roles and scope
2.1. Controller determines the purposes and means of processing Customer Data. Processor processes Customer Data solely to provide the Service as described in the Terms of Service.
2.2. The categories of data subjects, types of personal data, and nature of processing are described in Annex 1.
2.3. The duration of processing corresponds to the term of Controller's subscription, plus the retention periods in section 10.
3. Processing instructions
3.1. Processor shall process Customer Data only on documented instructions from Controller (Article 28(3)(a)), unless required by EU or Swedish law, in which case Processor shall inform Controller before processing (unless the law prohibits such information).
3.2. The Terms of Service and this DPA constitute Controller's documented instructions. Additional written instructions may be sent to legal@codebahn.net.
4. Confidentiality
Processor shall ensure that all persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b)).
5. Security measures
Processor shall implement appropriate technical and organisational measures as required by Article 32 GDPR (Article 28(3)(c)). The current measures are described in Annex 2.
6. Sub-processors
6.1. Controller grants Processor general written authorisation to engage sub-processors (Article 28(2)).
6.2. The current list of sub-processors is maintained at codebahn.net/docs/reference/subprocessors. All sub-processors are EU-incorporated.
6.3. Processor shall notify Controller at least 30 days before adding or replacing a sub-processor, by email and by updating the list. Controller may object within 30 days by emailing legal@codebahn.net.
6.4. If an objection cannot be resolved, either party may terminate the subscription with 30 days' notice and a pro-rata refund.
6.5. Processor shall impose on each sub-processor the same data protection obligations as this DPA and remains liable for each sub-processor's performance (Article 28(4)).
7. Data subject rights
Processor shall assist Controller in responding to data subject requests under Articles 15 to 22 GDPR (Article 28(3)(e)). Requests requiring Processor's assistance may be sent to privacy@codebahn.net.
8. Breach notification
8.1. Processor shall notify Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data (Article 33(2)).
8.2. The notification shall include the information required by Article 33(3) GDPR, to the extent known. Details not available within 48 hours shall be supplemented as they become known.
8.3. Processor shall assist Controller in fulfilling its obligations under Articles 33 and 34 GDPR.
9. Compliance assistance
Processor shall assist Controller with data protection impact assessments and prior consultations with supervisory authorities where required (Articles 35 and 36 GDPR, Article 28(3)(f)).
10. Data return and deletion
10.1. On termination, Controller may export all Customer Data using standard export tools (Git clone, Forgejo export) during a 30-day read-only period. No ticket or approval is required. After the export window, Processor shall delete all Customer Data within 90 days. Backups are rotated out within 90 days of deletion (Article 28(3)(g)).
10.2. Processor shall delete all copies unless EU or Swedish law requires continued storage, in which case Processor shall inform Controller and limit processing to what is strictly necessary.
10.3. Billing records are retained for 7 years as required by Swedish bookkeeping law (BFL 7:2).
11. Audit rights
11.1. Processor shall make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits conducted by Controller or its mandated auditor (Article 28(3)(h)).
11.2. On-site audits require at least 30 days' written notice, are limited to once per 12-month period (unless required by a supervisory authority or following a breach), and are conducted at Controller's cost. The auditor must agree to reasonable confidentiality obligations.
11.3. Processor shall immediately inform Controller if an instruction from Controller infringes the GDPR (Article 28(3), final paragraph).
12. International data transfers
12.1. All processing of Customer Data takes place within the EU/EEA. Processor does not transfer Customer Data outside the EU/EEA.
12.2. No sub-processor is incorporated outside the EU/EEA, and no sub-processor is a subsidiary of a company incorporated outside the EU/EEA.
13. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except that neither party's liability for breaches of the GDPR is limited to the extent such limitation is not permitted under applicable law.
14. Term and termination
14.1. This DPA takes effect when Controller begins using the Service and remains in effect for the duration of processing.
14.2. Sections 4, 8, 10, 11, and 13 survive termination.
15. Governing law
15.1. This DPA is governed by Swedish law.
15.2. Disputes shall be resolved by the courts of Gothenburg, Sweden.
16. Changes
We may update this DPA to reflect changes in the GDPR or our processing practices. Material changes are notified at least 30 days before they take effect. Controller may terminate without penalty before a material change takes effect.
Annex 1: Description of processing
| Element | Description |
|---|---|
| Subject matter | Provision of the Codebahn managed Git hosting service |
| Duration | Duration of the subscription, plus retention periods in section 10 |
| Nature and purpose | Hosting Git repositories, issue tracking, CI/CD, container/package registries, and related collaboration tools |
| Categories of data subjects | Controller's employees, contractors, and other users granted access to Controller's organisation |
| Types of personal data |
|
| Processing operations | Storage, retrieval, transmission, display, backup, deletion |
Annex 2: Technical and organisational measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all connections (TLS 1.3 where supported); SSH for Git |
| Encryption at rest | Scaleway managed encryption (block storage, object storage, managed PostgreSQL) |
| Backup | Daily encrypted backups via Restic to Hetzner Object Storage (Falkenstein, Germany), a separate EU location from primary infrastructure |
| Access control | SSH key + IP allowlist for production. Individual access keys, no shared credentials. Audit logging. |
| Authentication | Passwordless email verification codes for web access, SSH key authentication for Git |
| CI isolation | Per-tenant ephemeral VMs (max 6h lifetime), one tenant per VM, jobs in Docker containers |
| Data location | Primary: Scaleway fr-par (Paris, France). Backups: Hetzner fsn1 (Falkenstein, Germany). No data outside EU/EEA. |
Hackerman AB
Drakenbergsgatan 33, 412 69 Gothenburg, Sweden
Org. nr: 559079-1918, VAT: SE559079191801
hello@codebahn.net legal@codebahn.net privacy@codebahn.net security@codebahn.net