DebtDetect Sign in to accept
Version 2026-09-27 · Article 28 GDPR

Data-processing agreement

DebtDetect, at debtdetect.org, is the processor for personal data a workspace submits so DebtDetect can scan, report, and bill. The workspace is the controller for that data. DebtDetect is the controller of its own tax invoices, this acceptance record, and its security logs. This is not a joint-controller arrangement, not a handwritten deed, and not a law-firm opinion.

What the processing is

DebtDetect hosts the workspace, scans repositories the workspace authorizes, stores findings and reports, and sends an email or Slack message only when a person turns that on. It follows the product and a later written instruction to hello@debtdetect.org. It does not sell the data and does not use it to train a model. If an instruction would break the law, DebtDetect will say so and will not follow it.

People and data

The people are workspace members, connected GitHub accounts, and people named in repository metadata the workspace chooses to scan. The data is name, email, GitHub identifier, role, session, an encrypted repository credential, repository names, findings, scan times, billing name, and a VAT ID if saved. Card numbers stay at Stripe. DebtDetect does not ask for special-category data. If such data is inside a scanned repository, the workspace must already have a lawful basis.

Security

The application and database run in Frankfurt, over HTTPS, with an httpOnly session cookie. GitHub and Slack credentials are encrypted before they are saved. A clone exists only for the scan and is then removed. Fly.io states that its volumes are encrypted at rest. DebtDetect does not hold an ISO 27001 certificate or a SOC report.

Subprocessors

Acceptance authorizes Fly.io (hosting in Frankfurt), GitHub (sign-in and authorized repositories), Stripe (payment and VAT), Resend in Ireland (a report overview only when someone asks), Slack (only after that workspace installs the app), and Spaceship (the hello@debtdetect.org mailbox). Report files are in the Frankfurt database. Tigris is not a current report store.

DebtDetect emails the owner before a new subprocessor handles personal data, or as soon as it reasonably can if the change is urgent. The owner may object at hello@debtdetect.org and may stop the feature if the objection is not resolved. The database stays in Frankfurt. Where GitHub, Stripe, or Slack process outside the EEA, that transfer uses the subprocessor’s own Chapter V tool. DebtDetect has not signed a separate transfer contract with each of them.

People’s requests, breaches, and deletion

DebtDetect helps the workspace answer an access, correction, deletion, or objection request. It does not decide that request. After it becomes aware of a personal-data breach, it emails the owner without undue delay, with what it knows then, so the owner can meet a regulator duty, including 72 hours where Article 33 applies. DebtDetect does not notify the owner’s regulator in the owner’s name.

Shown history is 90 days on Starter, 365 on Pro, 1,095 on Business, and 1,825 on Enterprise. When the workspace ends, or the owner asks in writing, DebtDetect deletes personal data it holds as processor, except a tax invoice or this acceptance record where the law requires the copy. Removing a member revokes that person’s sessions. The audit row can remain.

Questions

The owner may send reasonable written questions once a year, and also after a breach or if a regulator requires it. DebtDetect answers in writing. An on-site audit is not included.

The service terms still apply. If they disagree with this agreement on an Article 28 duty, this agreement wins for that duty. The workspace owner accepts the current version in Settings. That record executes it. An earlier acceptance does not.