Data Processing Agreement
The terms on which we process personal data for you. In force automatically — no signature needed.
Effective · Enyon Software Limited
This agreement is already in force. It forms part of our Terms of Service and applies automatically to every customer, so you do not need to sign anything to be covered. If your procurement process needs a countersigned copy, email legal@enyon.dev and we will sign one.
This agreement is between Enyon Software Limited ("Processor") and the organization subscribing to BulbQA ("Controller"), and governs personal data the Processor handles on the Controller's behalf. It is made under Article 28 of the UK GDPR and the EU GDPR.
1. Subject matter and duration
The Processor processes personal data to provide BulbQA as described in the Terms of Service, for as long as the Controller's subscription is in place, plus the retention periods set out in clause 8.
2. Nature and purpose
Hosting, storing, organising and transmitting test management data so the Controller's members can author test cases, plan regression cycles, record results, and read their history.
3. Categories of data subject
- The Controller's employees, contractors and other authorised users of the service.
- Any individual the Controller's members choose to identify in free-text content — for example a name written into a test note. The Controller decides what goes there.
4. Types of personal data
- Identity and contact data — name, email address, profile image.
- Organizational data — membership, role, invitation status.
- Activity data — which user recorded which verdict, when, and with what note.
- Any personal data the Controller's members enter into free-text fields or upload as run artifacts.
No special category data is expected. BulbQA is not designed to hold health, biometric, or other Article 9 data, and the Controller should not put it there. Nor does the Processor receive the Controller's source code, which is executed locally and never transmitted.
5. Processor obligations
The Processor will:
- process personal data only on the Controller's documented instructions, which include the Terms of Service and use of the service's own features — and tell the Controller if an instruction appears to breach data protection law;
- ensure everyone authorised to process the data is bound by an appropriate duty of confidentiality;
- implement the technical and organisational measures described in clause 6, and in Article 32;
- assist the Controller, so far as reasonably possible, with data subject requests, data protection impact assessments, and consultations with a supervisory authority;
- at the Controller's choice, delete or return personal data at the end of the service, and delete existing copies unless the law requires retention;
- make available the information needed to demonstrate compliance with Article 28, and allow and contribute to audits under clause 9.
6. Security measures
- Encryption of data in transit (TLS) and at rest.
- Tenancy enforced on every request: access is decided by project, then organization, then membership. A user who is not a member of an organization cannot read its data.
- Uploaded run artifacts are stored privately and reached only by short-lived presigned URLs, so an old link expires rather than standing open.
- Access to production systems limited to personnel who need it, and authenticated by SSO.
- Backups of production data, held by our infrastructure provider, so service data can be restored following an incident.
- Architectural minimisation: because execution is local, the Processor never holds the Controller's source code, secrets or runtime environment. The safest data is the data we do not have.
Details are on the Security page, which forms part of this agreement.
7. Subprocessors
The Controller gives general authorisation for the Processor to engage subprocessors. The current list is published at /subprocessors and today comprises Amazon Web Services, Supabase, Google LLC, Stripe, Resend, Better Stack.
One of them, Better Stack, receives error reports rather than service data. Reports are rebuilt from a fixed allowlist: the request that caused an error is never attached, no user or organization identifier is sent, and the desktop Runner's reports carry no message or file paths at all. The Processor does not treat that as a reason to leave it off the list.
The Processor will give notice before a new subprocessor begins processing, and the Controller may object on reasonable data protection grounds within 30 days. Each subprocessor is bound by written terms no less protective than this agreement, and the Processor remains liable for their performance.
8. Retention and deletion
Deleted suites and cases are recoverable for 90 days, after which an automated job destroys them permanently. On termination the Processor retains the Controller's data for 30 days to allow export, then deletes it. Backups are retained on their own cycle and are overwritten in the ordinary course; deletion from live systems is not instantaneous in backups.
9. Audit
The Processor will respond to reasonable security questionnaires and provide documentation of its measures. On no less than 30 days' notice, and no more than once a year unless a supervisory authority or a personal data breach requires otherwise, the Controller may audit compliance — at its own cost, during business hours, and without disrupting the service or accessing other customers' data.
10. Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notice will describe what is known: the nature of the breach, the categories and approximate number of records, the likely consequences, and the measures taken or proposed. The Processor will keep the Controller updated as more is established, and will not delay an initial notice in order to make it complete.
11. International transfers
Processing takes place in AWS eu-west-1 (Ireland). Where personal data is transferred outside the UK or EEA to a subprocessor, the transfer relies on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision.
12. Order of precedence
If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.
13. Contact
Data protection matters: privacy@enyon.dev. Contract matters: legal@enyon.dev.