Last updated: 2026-05-16
This page summarizes the terms of CodeDig's Data Processing Agreement (DPA) — the contract that governs how we process personal data on your behalf as your processor under GDPR Article 28 (and equivalent regulations). The binding signed DPA is available on request — email security@codedig.ai and we'll send the current PDF within 1 business day.
Summary only — not a binding instrument. This page is a summary for evaluation purposes. The binding agreement is the signed DPA we send on request. It is not a contract and creates no legal obligations on either party.
CodeDig acts as data processor; you (the customer) act as data controller. The DPA covers all Team, Business, and Enterprise customers.
CodeDig processes personal data solely to provide its pull-request analysis service for the duration of your subscription. After subscription end we retain data for up to 30 days for inactive accounts before deletion. Data deletion may be requested at any time under GDPR Article 17 and is supported via Settings → Compliance in the product.
CodeDig does not process customer credentials or payment-card data — payment processing is handled exclusively by Stripe.
Customer employees and collaborators who hold CodeDig accounts, and repository contributors whose names or email addresses appear in code or commit metadata submitted to the service.
We maintain a complete, up-to-date list of third-party subprocessors at /subprocessors. We provide at least 30 days' written notice before adding a new subprocessor, except where a change is required urgently for security reasons.
Most data resides in the United States (Fly.io IAD region and Neon US). For EU-origin personal data we rely on Standard Contractual Clauses (SCCs) executed with US-based subprocessors. EU data-residency options are available for Enterprise customers on request.
Full details are available at /security-overview. In summary: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, MFA enforcement, audit logs, and SAML/OIDC/LDAP SSO for Enterprise customers.
We support access, export (CSV), and deletion of personal data via Settings → Compliance in the product. Rights requests routed to security@codedig.ai receive a response within one business day.
We notify affected customers within 72 hours of discovery of any personal data breach, via email to the primary contact and a status-page incident. Notifications include the nature of the incident, data categories affected, and remediation steps taken or planned.
Enterprise customers may request our current SOC 2 Type II report (currently in audit, target Q3 2026) under NDA, and we will respond to one CAIQ or SIG questionnaire per year within 5 business days. Reasonable on-site audits may be coordinated with at least 30 days' notice for large engagements.
DPA obligations apply for the duration of your subscription plus the 30-day post-termination retention period. You may request immediate deletion of all personal data at any time via Settings → Compliance or by emailing security@codedig.ai.
The binding Data Processing Agreement is not self-serve. To receive the current signed PDF:
We respond to CAIQ, SIG, and custom security questionnaires within 5 business days. Email security@codedig.ai with the questionnaire format you need and we will coordinate from there.