Skip to content
Vallit
Pricing
  • Checks
  • Reports
  • Fixes
  • Monitoring
  • Trust page
  • Vera
  • Getting started
  • What we check
  • Reading a report
  • Fixing what we found
  • The guardian
  • Alerts
  • Privacy and safety
  • Troubleshooting
  • Browse all docs
  • Research
  • Updates1.15.236
  • Security
  • About
Check my appSign in

Product

ChecksEverything we look at, on your site and in your codeReportsYour score and every finding, in plain wordsFixesFix it yourself, or let our team do itMonitoringWe keep checking, every single dayTrust pageShow your customers what passedVeraOur AI, which checks its own work

Docs

Getting startedWhat we checkReading a reportFixing what we foundThe guardianAlertsPrivacy and safetyTroubleshootingBrowse all docs

Resources

ResearchUpdatesSecurityAbout
PricingSign inCheck my app

Data processing

How we process personal data on your behalf (Art. 28 GDPR).

DeutschEnglish
Version
2026-10-08
Last updated
8 October 2026
Subprocessors
List
Binding version
German
Questions
info@vallit.net

On this page

  1. 1Parties and subject matter
  2. 2Nature and purpose, data and data subjects
  3. 3Instructions
  4. 4Confidentiality
  5. 5Security of processing
  6. 6Subprocessors
  7. 7Transfers to third countries
  8. 8Assisting the customer
  9. 9Deletion and return
  10. 10Information and audits
  11. 11Liability and precedence
  12. 12Annex: technical and organisational measures
On this page
  1. 1Parties and subject matter
  2. 2Nature and purpose, data and data subjects
  3. 3Instructions
  4. 4Confidentiality
  5. 5Security of processing
  6. 6Subprocessors
  7. 7Transfers to third countries
  8. 8Assisting the customer
  9. 9Deletion and return
  10. 10Information and audits
  11. 11Liability and precedence
  12. 12Annex: technical and organisational measures

1Parties and subject matter

This English version is a courtesy translation. Only the German version is legally binding.

This agreement applies between the customer who uses Vallit under the Terms (“controller”) and Theo Reichert, Vallit, Parkstraße 1, 76131 Karlsruhe (“processor”, “we”). It is part of the contract and is accepted with the order in the app. It applies to the extent we process personal data on the customer’s behalf in providing the services (Art. 28 GDPR).

The subject matter is checking and monitoring the customer’s apps, storing reports and findings, notifications and fixes under the Terms. The agreement runs as long as the contract and ends with the deletion or return of the data under section 9.

2Nature and purpose, data and data subjects

Purpose: to provide the services under the Terms, not for purposes of our own.

Types of data: names and email addresses of members and of recipients of notifications; addresses, responses and content of the checked apps to the extent they contain personal data; code and configuration from connected repositories to the extent they contain personal data (such as names in commits); details in fix requests.

Data subjects: the customer’s staff and agents, users of checked apps whose data an app exposes, and people named in repositories. Special categories under Art. 9 GDPR are not processed as such; if they appear in a checked app, we record only the kind and the place, not the content.

3Instructions

We process the data only on the customer’s documented instructions. The Terms, this agreement and the settings the customer chooses in the app are the instructions; the customer gives further ones in text form to info@vallit.net. If a law requires other processing, we say so beforehand where the law allows. If we consider an instruction unlawful, we say so without delay and may suspend it until it is resolved.

4Confidentiality

Only people who need access for the service and are bound to confidentiality or a statutory duty of secrecy have access to the data. Today this is the owner alone.

5Security of processing

We take the technical and organisational measures under Art. 32 GDPR described in the annex and keep them in line with the state of the art. A change may not lower the level of protection.

6Subprocessors

The customer gives us general authorisation to engage subprocessors. The current ones are listed on the subprocessors page. We conclude a contract with each that imposes at least the obligations of this agreement on it, and we are liable for its conduct as for our own.

We announce a new or replaced subprocessor by email to the workspace’s admins at least 14 days before it is engaged and note it on the page. The customer may object within that period for an important reason of data protection. If we find no solution, the customer may cancel the plan concerned as of the engagement and receives a pro-rata refund of the amount prepaid.

7Transfers to third countries

The app and its database run in Frankfurt. Some subprocessors are based in the USA or access data from there. A transfer takes place only if the conditions of Art. 44 et seq. GDPR are met, in particular through certification under the EU-US Data Privacy Framework or Standard Contractual Clauses. The subprocessors page names the basis for each service.

8Assisting the customer

We assist the customer with appropriate measures in responding to data subjects (Art. 12 to 22 GDPR), with the security of processing, with notifications and communications under Art. 33 and 34 GDPR and with a data protection impact assessment, as far as our processing is concerned. If a data subject contacts us directly, we forward the request to the customer.

We report a personal data breach affecting the customer’s data to the customer without undue delay after becoming aware of it, with the information under Art. 33(3) GDPR as far as we have it, and add to it as we learn more.

9Deletion and return

When a paid plan ends, the customer’s apps stay on Free until the customer deletes the workspace (Terms section 9). If the customer deletes the workspace, or asks for it after the contract ends, we delete the customer’s data unless a law requires us to keep it; from check data without a workspace we remove the link to the customer at once and delete it after 90 days. Before deletion the customer receives, on request, its reports and findings in a common machine-readable format.

10Information and audits

We make available to the customer the information needed to demonstrate compliance with this agreement and answer questions about it. We allow an audit on site or by an auditor bound to confidentiality after notice with a reasonable period, during usual business hours and without access to other customers’ data. The customer bears the costs unless the audit reveals a material breach on our part.

11Liability and precedence

Liability is governed by Art. 82 GDPR and the Terms. In case of conflict with the Terms, this agreement takes precedence in matters of data protection. The German version is binding.

12Annex: technical and organisational measures

  • Encryption: every connection to the website and the app is encrypted with TLS, with HSTS. Database and hosting encrypt stored data.
  • Separation of customers: every query from the app runs with a role that, through row-level security, sees only the rows of its own workspace; queries across all workspaces are limited to named places and reviewed in development.
  • Access: sign-in through Clerk with confirmation codes and protection against automated sign-ins; only a workspace’s admins manage plans and members; only the owner has access to production systems.
  • Data minimisation: secrets we find are not stored, only their kind and place. Code is read into memory for a check, never cloned or executed. Only short excerpts go to a language model, with recognised credentials removed first; nothing is used for training.
  • Retention: checks without a workspace and monitoring measurements are deleted automatically after 90 days.
  • Integrity: changes to Vallit’s code go through pull requests with automated tests; fixes for customers are proposed as pull requests, never published directly.
  • Availability: hosting and database with the providers named, in Frankfurt; our own status page monitors the service.
  • Review: Vallit checks its own app regularly with its own checks; we review these measures at every material change.
Vallit

A clearer picture of
the app you built.

What's new

1.15.2369 October 2026

The update log shows what changes for you
  • Only changes that reach you
All updates

Product

  • Check my app
  • What we check
  • Fixes
  • Vera, our AI
  • Docs
  • Pricing
  • Updates
  • Sign in

Company

  • About
  • Research
  • Get in touch
  • Security
  • Status

Legal

  • Impressum
  • Privacy
  • Terms
  • DPA
  • Subprocessors

© 2026 Vallit