Data Processing Agreement
Effective 2026-07-12
1 · Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies where Crux processes personal data contained in repositories or accounts you connect. For that data you (or your organisation) act as controller and Crux acts as processor within the meaning of the GDPR. For your own account data (profile, usage), Crux acts as controller, see the Privacy Policy.
2 · Processed data
Processing under this DPA may include:
- Repository content: source code, commit history, file trees, and metadata of repositories you authorise, which may incidentally contain personal data (author names, emails in commit metadata, data in code or fixtures);
- GitHub account data: login, display name, avatar, and OAuth tokens needed to access authorised repositories.
Purpose: generating learning material and comprehension checks from the connected repositories. Duration: for as long as the repository remains connected, plus a short deletion window.
3 · Instructions
We process the data only on your documented instructions (connecting a repository, requesting course generation, and using the resulting material constitute such instructions), unless required otherwise by law, in which case we will inform you unless prohibited.
4 · Confidentiality and security
Persons authorised to process the data are bound by confidentiality. We apply appropriate technical and organisational measures, including encryption in transit, access controls scoped to your authorisation, server-side-only storage of OAuth tokens, and isolation of customer data.
5 · Subprocessors
You authorise the following subprocessors:
- Google Cloud / Firebase: hosting, authentication, and database (Firestore);
- Anthropic: large-language-model processing of repository excerpts to generate learning material;
- GitHub: source of the repository data you authorise us to access.
We will notify you of intended changes to this list and you may object on reasonable data-protection grounds. Subprocessors are bound by data-protection obligations no less protective than this DPA.
6 · Assistance and rights
Taking into account the nature of the processing, we will assist you with data-subject requests and with your obligations regarding security, breach notification, and impact assessments. We will notify you without undue delay after becoming aware of a personal data breach affecting your data.
7 · International transfers
Where processing involves transfers outside the EEA/UK, we rely on adequacy decisions or standard contractual clauses with the relevant subprocessors.
8 · Deletion and audit
On disconnection of a repository or termination of the Service we delete or return the processed data within 30 days, unless retention is required by law. We will make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as required by Article 28 GDPR.