Data processing
How we process personal data on your behalf (Art. 28 GDPR).
- Version
- 2026-10-08
- Last updated
- 8 October 2026
- Subprocessors
- List
- Binding version
- German
- Questions
- info@vallit.net
On this page
Parties and subject matter
This English version is a courtesy translation. Only the German version is legally binding.
This agreement applies between the customer who uses Vallit under the Terms (“controller”) and Theo Reichert, Vallit, Parkstraße 1, 76131 Karlsruhe (“processor”, “we”). It is part of the contract and is accepted with the order in the app. It applies to the extent we process personal data on the customer’s behalf in providing the services (Art. 28 GDPR).
The subject matter is checking and monitoring the customer’s apps, storing reports and findings, notifications and fixes under the Terms. The agreement runs as long as the contract and ends with the deletion or return of the data under section 9.
Nature and purpose, data and data subjects
Purpose: to provide the services under the Terms, not for purposes of our own.
Types of data: names and email addresses of members and of recipients of notifications; addresses, responses and content of the checked apps to the extent they contain personal data; code and configuration from connected repositories to the extent they contain personal data (such as names in commits); details in fix requests.
Data subjects: the customer’s staff and agents, users of checked apps whose data an app exposes, and people named in repositories. Special categories under Art. 9 GDPR are not processed as such; if they appear in a checked app, we record only the kind and the place, not the content.
Instructions
We process the data only on the customer’s documented instructions. The Terms, this agreement and the settings the customer chooses in the app are the instructions; the customer gives further ones in text form to info@vallit.net. If a law requires other processing, we say so beforehand where the law allows. If we consider an instruction unlawful, we say so without delay and may suspend it until it is resolved.
Confidentiality
Only people who need access for the service and are bound to confidentiality or a statutory duty of secrecy have access to the data. Today this is the owner alone.
Security of processing
We take the technical and organisational measures under Art. 32 GDPR described in the annex and keep them in line with the state of the art. A change may not lower the level of protection.
Subprocessors
The customer gives us general authorisation to engage subprocessors. The current ones are listed on the subprocessors page. We conclude a contract with each that imposes at least the obligations of this agreement on it, and we are liable for its conduct as for our own.
We announce a new or replaced subprocessor by email to the workspace’s admins at least 14 days before it is engaged and note it on the page. The customer may object within that period for an important reason of data protection. If we find no solution, the customer may cancel the plan concerned as of the engagement and receives a pro-rata refund of the amount prepaid.
Transfers to third countries
The app and its database run in Frankfurt. Some subprocessors are based in the USA or access data from there. A transfer takes place only if the conditions of Art. 44 et seq. GDPR are met, in particular through certification under the EU-US Data Privacy Framework or Standard Contractual Clauses. The subprocessors page names the basis for each service.
Assisting the customer
We assist the customer with appropriate measures in responding to data subjects (Art. 12 to 22 GDPR), with the security of processing, with notifications and communications under Art. 33 and 34 GDPR and with a data protection impact assessment, as far as our processing is concerned. If a data subject contacts us directly, we forward the request to the customer.
We report a personal data breach affecting the customer’s data to the customer without undue delay after becoming aware of it, with the information under Art. 33(3) GDPR as far as we have it, and add to it as we learn more.
Deletion and return
When a paid plan ends, the customer’s apps stay on Free until the customer deletes the workspace (Terms section 9). If the customer deletes the workspace, or asks for it after the contract ends, we delete the customer’s data unless a law requires us to keep it; from check data without a workspace we remove the link to the customer at once and delete it after 90 days. Before deletion the customer receives, on request, its reports and findings in a common machine-readable format.
Information and audits
We make available to the customer the information needed to demonstrate compliance with this agreement and answer questions about it. We allow an audit on site or by an auditor bound to confidentiality after notice with a reasonable period, during usual business hours and without access to other customers’ data. The customer bears the costs unless the audit reveals a material breach on our part.
Liability and precedence
Liability is governed by Art. 82 GDPR and the Terms. In case of conflict with the Terms, this agreement takes precedence in matters of data protection. The German version is binding.
Annex: technical and organisational measures
- Encryption: every connection to the website and the app is encrypted with TLS, with HSTS. Database and hosting encrypt stored data.
- Separation of customers: every query from the app runs with a role that, through row-level security, sees only the rows of its own workspace; queries across all workspaces are limited to named places and reviewed in development.
- Access: sign-in through Clerk with confirmation codes and protection against automated sign-ins; only a workspace’s admins manage plans and members; only the owner has access to production systems.
- Data minimisation: secrets we find are not stored, only their kind and place. Code is read into memory for a check, never cloned or executed. Only short excerpts go to a language model, with recognised credentials removed first; nothing is used for training.
- Retention: checks without a workspace and monitoring measurements are deleted automatically after 90 days.
- Integrity: changes to Vallit’s code go through pull requests with automated tests; fixes for customers are proposed as pull requests, never published directly.
- Availability: hosting and database with the providers named, in Frankfurt; our own status page monitors the service.
- Review: Vallit checks its own app regularly with its own checks; we review these measures at every material change.