This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between Prometix Solutions Ltd (“Prometix”, “we”, “us”, “our”, the “Processor”) and the customer entering into those Terms (“you”, the “Controller”). It applies wherever Prometix processes personal data on your behalf as a processor in connection with the content you submit to or connect through the Service (“Customer Personal Data”) — for example, names or email addresses of your own contributors appearing in repository, commit, or issue/work item metadata that Nexus accesses via the GitHub API or Azure DevOps API, as applicable to your connected provider.

This DPA does not apply to personal data that Prometix processes as controller (such as your own account, billing, and usage data) — that processing is described in our Privacy Policy. Capitalised terms not defined here have the meaning given in the Terms of Service.

1. Roles of the parties

As between the parties, you are the controller and Prometix is the processor of Customer Personal Data, within the meaning of UK GDPR and, where applicable, EU GDPR. Prometix will process Customer Personal Data only in accordance with your documented instructions, which include the instructions given by configuring and operating the Service, unless required to do otherwise by law — in which case Prometix will inform you of that legal requirement first, unless the law prohibits this. The discretionary law enforcement disclosure right described in Section 3 (Acceptable Use) of the Terms of Service applies only to data Prometix processes as controller, as described in our Privacy Policy, and does not extend to Customer Personal Data; Customer Personal Data is disclosed to a third party only on your documented instruction or where required by law, in accordance with this Section 1.

2. Details of processing

Detail Description
Subject matter Prometix’s provision of the Nexus agentic AI orchestration platform to you
Duration For the term of the Terms of Service, and thereafter as set out in Section 9 (Return or deletion of data)
Nature and purpose of processing Accessing, transmitting, and processing repository, issue, and agent-run content solely to operate and provide the Service, including routing relevant content to your configured AI model provider
Categories of data subjects Your employees, contractors, and other individuals whose personal data appears in the repositories, issues or work items, or other content you connect to the Service (e.g. commit authors, issue or work item participants)
Types of personal data Names, email addresses, and GitHub or Azure DevOps usernames appearing in commit metadata, issue or work item text, or pull request content; no special category data is intentionally processed

3. Processor obligations

Prometix shall:

  • Process Customer Personal Data only on your documented instructions, including as necessary to provide the Service;
  • Ensure that personnel authorised to process Customer Personal Data are subject to a duty of confidentiality;
  • Implement the technical and organisational security measures described in our Privacy Policy, Section 8, taking into account the state of the art, costs of implementation, and the risk to data subjects;
  • Not engage a new sub-processor to process Customer Personal Data except as permitted under Section 4 (Sub-processors) below;
  • Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, at your reasonable cost, in responding to requests from data subjects seeking to exercise their rights under applicable data protection law;
  • Assist you, at your reasonable cost, in ensuring compliance with your obligations relating to the security of processing, personal data breach notification, and data protection impact assessments, taking into account the information available to Prometix;
  • At your election, delete or return all Customer Personal Data after the end of the provision of the Service relating to processing, and delete existing copies, as set out in Section 9;
  • Make available to you information reasonably necessary to demonstrate compliance with this Section 3, and allow for and contribute to audits as set out in Section 7.

4. Sub-processors

You authorise Prometix to engage the sub-processors listed in the table below to process Customer Personal Data in connection with providing the Service. This list mirrors, and will be kept in sync with, the sub-processor table in our Privacy Policy.

Sub-processor Purpose Location
Microsoft Azure Cloud hosting, data storage, message queuing (Service Bus) UK South / West Europe
GitHub (Microsoft) OAuth authentication, repository and issue API access United States
Microsoft (Azure DevOps) OAuth authentication, repository and work item API access Varies by your Azure DevOps organisation’s configured region
Stripe Payment processing and billing United States
Anthropic AI inference when Claude is selected as your model provider United States
OpenAI AI inference when a GPT model is selected as your model provider United States
Microsoft (GitHub Copilot) AI inference when a Copilot model is selected as your model provider United States
Google AI inference when a Gemini model is selected as your model provider United States

Prometix will give you at least 30 days’ notice (via email or an in-app notice) before engaging any new sub-processor to process Customer Personal Data. If you reasonably object to a new sub-processor on data protection grounds, you may terminate the Terms of Service before the change takes effect. Prometix remains liable for the acts and omissions of its sub-processors to the same extent Prometix would be liable if performing their services directly, and will impose data protection obligations on each sub-processor that are no less protective than those set out in this DPA.

5. International transfers

Where Prometix or a sub-processor transfers Customer Personal Data outside the United Kingdom or the European Economic Area, the parties agree that such transfers are made subject to appropriate safeguards, incorporated into this DPA by reference: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses (Module 2: Controller to Processor) issued by the European Commission, as applicable to the transfer in question.

6. Personal data breach notification

Prometix will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to Prometix to assist you in meeting any obligation to notify a supervisory authority or affected data subjects.

7. Audit rights

On reasonable prior written notice, and no more than once in any 12-month period (except following a personal data breach affecting Customer Personal Data, or where required by a supervisory authority), Prometix will make available information reasonably necessary to demonstrate compliance with this DPA, and permit and contribute to audits, including inspections, conducted by you or an independent auditor mandated by you, subject to reasonable confidentiality restrictions and conducted in a manner that minimises disruption to Prometix’s business.

8. Confidentiality

Prometix shall treat Customer Personal Data as Confidential Information under Section 5 of the Terms of Service, and shall not disclose it to any third party except as permitted under this DPA or the Terms of Service.

9. Return or deletion of data

Following termination of the Terms of Service, Prometix will, at your election, delete or return all Customer Personal Data, and delete existing copies, within 30 days, save to the extent applicable law requires Prometix to retain some or all of that data, in which case Prometix will isolate and protect it from further processing except as required by that law.

10. Liability

Each party’s liability arising out of or in connection with this DPA, including under the Standard Contractual Clauses or UK Addendum incorporated by reference in Section 5, is subject to the limitations and exclusions of liability set out in Section 9 (Limitation of Liability) of the Terms of Service, including the carve-outs described there for data processing obligations.

11. Term

This DPA takes effect on, and remains in force for as long as, the Terms of Service remain in effect, and thereafter for so long as Prometix processes Customer Personal Data in accordance with Section 9 (Return or deletion of data).

12. Contact

Questions about this DPA, or requests to execute a countersigned copy for your own records? Contact us:

Prometix Solutions Ltd
Email: legal@prometix.io