evonx

Legal

Data Processing Agreement

Last updated: August 24, 2026

This DPA forms part of the Terms of Service and applies automatically whenever Evonx processes personal data on your behalf — you do not have to sign anything to be covered by it. If your procurement process needs a countersigned copy, or your own paper instead of ours, email [email protected] and we will turn it around.

1. Roles

For the personal data inside the repositories, stores, and content you connect to Evonx, you are the controller and Evonx is the processor. For the account and usage data you give us directly — your name, email, sign-in details, and platform logs — Evonx is the controller, and our Privacy Policy governs that processing rather than this DPA.

2. What we process

Subject matter and purpose. Providing the Evonx platform: analysing a codebase, planning and generating changes, running live previews, and delivering the result as a pull request.

Duration. For as long as your account is active, plus the short retention window described in section 9.

Categories of data. Whatever personal data happens to sit in the material you connect or submit — typically developer identifiers in commit history, sample or seed data in a repository, content in prompts and uploaded images, and any personal data inside a connected store theme.

Data subjects. Your staff and collaborators, and any individuals whose data appears in the material you connect.

3. Your instructions

We process personal data only on your documented instructions. Using the platform is itself an instruction: when you ask for a change, you instruct us to process what is needed to make it. We will tell you if an instruction appears to breach applicable data protection law, and if we are ever required by law to process data beyond your instructions, we will inform you first unless the law forbids it.

You are responsible for having a lawful basis for the data you connect, and for not connecting categories of data the platform is not built for — production health, financial, or biometric records should be redacted or synthesised before a repository or dataset is connected.

4. Confidentiality

Access to customer data is limited to the people who need it to run and support the platform. They are bound by confidentiality obligations that survive the end of their engagement.

5. Security

We maintain technical and organisational measures appropriate to the risk, including encryption of traffic in transit with TLS, server-side storage of credentials for connected services, per-workspace separation of customer data, isolated preview environments with their own short-lived databases, and role-based access control with audit logging. Our current measures are described on the Security & Trust page, which is incorporated into this DPA. We may change a measure, but not in a way that materially weakens overall protection.

6. Sub-processors

You give us general authorisation to engage the sub-processors listed at /subprocessors. Each is bound by data protection terms no less protective than this DPA, and we remain fully liable to you for their performance. Before a new sub-processor starts handling your personal data we update that page and give at least 30 days notice; you may object on reasonable data protection grounds, and if we cannot resolve the objection you may terminate the affected part of the service.

7. Data subject requests

Taking the nature of the processing into account, we assist you in responding to requests from data subjects exercising their rights. Where a request reaches us directly and relates to data we process on your behalf, we forward it to you rather than answering it ourselves.

8. Personal data breaches

We notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting data we process for you. The notice describes what happened, the categories and approximate volume of data involved, the likely consequences, and the steps taken or proposed. We assist you with your own notification duties under Articles 33 and 34 of the GDPR.

9. Deletion and return

You can export or delete your data at any time while your account is active. When the service ends, we delete personal data processed on your behalf within 30 days, except where storage is required by law. Preview environments and their databases are short-lived and removed as soon as they are no longer needed.

10. Audits and information

We make available the information needed to demonstrate compliance with Article 28 and, on reasonable notice and no more than once a year, respond to a security questionnaire or an audit conducted by you or an independent auditor you appoint, subject to confidentiality and to not disrupting the service or exposing other customers. Where an audit report or certification covers the point in question, we may offer it in place of an on-site audit.

11. International transfers

Where personal data leaves the EEA or the United Kingdom, we rely on a transfer mechanism recognised under the GDPR: an adequacy decision where one applies, and otherwise the European Commission Standard Contractual Clauses together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference with Evonx acting as data importer.

12. Türkiye

Where Turkish law applies, this DPA operates as the data processing arrangement required under the KVKK, with you as veri sorumlusu and Evonx as veri işleyen. Transfers abroad are made on the basis permitted by Article 9 of the KVKK. Our Turkish-language disclosure is at /tr/kvkk.

13. Precedence and changes

Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. We may update it to reflect changes in law or in the service; material changes are announced on this page with an updated date. Questions and signature requests go to [email protected].