Legal · Effective March 2026

Data Processing Addendum.

The standard terms ScanDrix offers for processing customer personal data as a processor.

Template summary, not the executed agreement. The legally binding document is the DPA countersigned by both parties, which includes the correct contracting entities, governing law, and signature blocks. If your review needs the signed version or has amendments, contact us and we will send it.

1.Scope and roles

This Data Processing Addendum ("DPA") forms part of the agreement between ScanDrix AI Inc. ("ScanDrix") and the customer ("Customer") for the ScanDrix code review service. It applies where Customer processes personal data through the service and ScanDrix processes that data on Customer's behalf.

For that personal data, Customer is the controller and ScanDrix is the processor. For account and billing data where ScanDrix determines the purposes, ScanDrix acts as an independent controller and the parties' respective privacy notices apply.

The parties' main agreement governs in the event of conflict, except that this DPA governs the processing of personal data.

2.Processing details

Subject matter and purpose: automated analysis of pull-request diffs, security scanning, and generation of code review comments at Customer's instruction.

Duration: for the term of the agreement, plus the limited period required to delete or return data as described in section 7.

Categories of data subjects: Customer's developers, contractors, and other authorised personnel who author commits or receive review comments.

  • Source code in pull-request diffs (processed ephemerally — see section 3)
  • Repository, commit, and pull-request metadata
  • Names and email addresses of committers appearing in that metadata
  • Account, organisation, billing, and support correspondence

3.Zero code retention

Source code submitted for review is processed in ephemeral workers for the sole purpose of producing the review. ScanDrix does not store customer source code or diffs to persistent disk, does not use them to train any model, and evicts in-memory buffers when a review is complete.

The processors listed in the subprocessors page receive no customer source code. The only text that may reach a third-party inference provider is customer-submitted chat text sent to the website assistant, with credentials redacted before transmission; this is not part of the code review pipeline.

4.Security measures

ScanDrix maintains administrative, technical, and organisational measures appropriate to the risk, including the following, designed in accordance with AICPA SOC 2 Trust Services Criteria:

  • Encryption in transit (TLS 1.3) and at rest for persistent customer data
  • Access control based on least privilege with role-based permissions
  • SAML single sign-on and SCIM provisioning for enterprise plans
  • Immutable audit logging of reviews, rule changes, and administrative actions
  • Secure development lifecycle with code review and dependency scanning
  • Incident response plan tested on a defined schedule
  • Optional customer-managed encryption keys and self-hosted deployment

5.Subprocessing

ScanDrix may engage the subprocessors listed on our subprocessors page. ScanDrix notifies Customer of any intended addition of a subprocessor that will process Customer personal data, and Customer may object on reasonable data-protection grounds within 30 days of notice.

If the parties cannot resolve the objection, Customer may terminate the affected service without penalty. ScanDrix remains responsible for each subprocessor's performance of its processing obligations.

6.International transfers

ScanDrix may process personal data in countries other than the Customer's location, including the United States and India. Where personal data is transferred outside the EEA, UK, or Switzerland, ScanDrix relies on an appropriate transfer mechanism, such as the Standard Contractual Clauses together with a transfer impact assessment, or the UK Addendum where applicable.

Customers who require processing to remain within a specific jurisdiction can use our self-hosted VPC or on-premise plan, which keeps processing inside their own network.

7.Security incidents

ScanDrix notifies Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data. The notification describes the nature of the breach, the categories of data and data subjects affected, likely consequences, and measures taken or proposed.

ScanDrix makes information available to Customer as reasonably requested to satisfy its own regulatory notification obligations, and cooperates with Customer's investigation and remediation.

8.Return and deletion

On termination, ScanDrix returns or deletes Customer personal data at Customer's election, except for data retained where required by law. Because source code is never persisted, deletion of code data is satisfied through the eviction described in section 3 rather than a separate backup purge cycle.

9.Audit

ScanDrix makes available information reasonably necessary to demonstrate compliance with this DPA, including its security architecture documentation under NDA. Customer may conduct one audit per year, on 30 days' notice, at Customer's cost, and may use an independent auditor subject to confidentiality obligations. ScanDrix may satisfy a request by offering documentation rather than an on-site audit where the documentation reasonably addresses the request.

10.Liability and termination

Liability arising under this DPA is subject to the liability provisions of the parties' main agreement. Either party may terminate this DPA if the other materially breaches it and fails to remedy within 30 days of written notice.

Request the executed DPA

Send us your entity details and required jurisdiction and we will return the countersigned DPA, usually within one business day.