Data Processing Agreement
The agreement under Article 28 GDPR for businesses that process personal data with Joyint. This is a translation for information; the German version is the binding one.
Data Processing Agreement pursuant to Article 28 GDPR
between the contractor
Joydev GmbH, Konrad-Zuse-Platz 8, 81829 Munich, Germany
hereinafter the “Processor”
and the User within the meaning of the Joyint Terms of Use who is an entrepreneur (Section 14 of the German Civil Code, BGB) and uses the Service to process personal data
hereinafter the “Controller”
Preamble
A processing relationship within the meaning of Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “GDPR”) exists between the Controller and the Processor.
This data processing agreement including all annexes (hereinafter together the “Agreement”) specifies the data protection obligations of the parties arising from the Joyint Terms of Use (hereinafter the “Main Contract”).
The Processor undertakes towards the Controller to perform the Main Contract and this Agreement in accordance with the following provisions:
§ 1 Scope and definitions
(1) The following provisions apply to all processing services within the meaning of Article 28 GDPR that the Processor renders to the Controller on the basis of the Main Contract.
(2) Where this Agreement uses the term “data processing” or “processing” of data, this generally means the use of personal data. Data processing or the processing of data means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
(3) Reference is made to the further definitions in Article 4 GDPR.
§ 2 Subject matter and duration of the processing
(1) The Processor processes personal data on behalf of and on the instructions of the Controller.
(2) The subject matter of the engagement is the provision of a product development platform (software toolchain) as software as a service within the scope agreed with the Processor, in accordance with the Main Contract.
(3) The duration of this Agreement corresponds to the term of the Main Contract.
§ 3 Nature and purpose of the processing
The Processor has no interest in the processing of personal data. Depending on the circumstances, however, processing carried out on behalf of the Controller may arise. The nature and purpose of the processing of personal data by the Processor follow from the Terms of Use and this Agreement. They comprise the following activities and purposes:
- Joy
- Product management: where an AI is optionally used to assist in defining and working on Joy items, users may decide individually whether to store an email address for the AI used. If they do, we process the email address temporarily, for no longer than 24 hours after the respective user has logged out, in order to transmit it to the connected forge. The user may, however, stop the transmission of the email address to the connected forge at any time with effect for the future.
- Within the repository, epics, stories, tasks, dependencies, milestones, releases and YAML files are processed, which may contain references to individual users.
- Joyint platform and apps (desktop, mobile and web)
- Customer feedback: users have the option of submitting customer feedback. The data left by the user is processed in the course of this. A direct response to customer feedback is not possible without a means of contact.
- User data is processed for registration or sign-in.
- After sign-in, user data is processed.
- When Joyint is used, project data and electronic communications data are processed.
- For diagnostic purposes, actions carried out on the Joyint platform are stored for no longer than 30 days, without names or email addresses and at most with pseudonymised technical IDs.
§ 4 Categories of data subjects
The categories of data subjects affected by the handling of personal data under this Agreement comprise in particular:
- Users of the Controller (e.g. employees, team members, contractors) who use Joyint via web, desktop or mobile
- Other persons whose data the Controller or its users contribute to project data
§ 5 Types of personal data
The processing concerns in particular the following types of data:
- User data (user name, role, status, subscription data, contact data, email address or forge account name, time of registration and of sign-in)
- Project data (timestamps, project and repository data, change data, tasks, processing status, budget approvals, version of the Joyint software used)
- Electronic communications data (feedback messages, temporary identification numbers for Joyint containers and projects)
§ 6 Rights and obligations of the Controller
(1) The Controller alone is responsible for assessing the lawfulness of the processing and for safeguarding the rights of data subjects, and is thus the controller within the meaning of Article 4(7) GDPR.
(2) The Controller is entitled to issue instructions on the nature, scope and method of the processing. At the Controller's request, the Processor must confirm oral instructions without undue delay in writing or in text form (e.g. by email).
(3) Where the Controller considers it necessary, persons authorised to issue instructions may be named. The Controller will notify the Processor of these persons in writing or in text form. If the persons authorised to issue instructions change at the Controller, the Processor will be notified of this in writing or in text form, naming the respective new person.
(4) The Controller will inform the Processor without undue delay if errors or irregularities are found in connection with the processing of personal data by the Processor.
§ 7 Obligations of the Processor
(1) Processing
The Processor will process personal data exclusively in accordance with this Agreement and/or the underlying Main Contract and on the instructions of the Controller.
(2) Rights of data subjects
- The Processor will, within the limits of what is possible for it, assist the Controller in fulfilling the rights of data subjects, in particular with regard to rectification, restriction of processing and erasure, notification and the provision of information. If the Processor processes the personal data referred to in § 5 of this Agreement on behalf of the Controller and that data is the subject of a request for data portability under Article 20 GDPR, the Processor will make the data set concerned available to the Controller in a structured, commonly used and machine-readable format within a reasonably set period, and otherwise within seven working days.
- On the instructions of the Controller, the Processor must rectify or erase the personal data referred to in § 5 of this Agreement that is processed on behalf of the Controller, or restrict its processing. The same applies where this Agreement provides for rectification, erasure or restriction of the processing of data.
- Where a data subject contacts the Processor directly for the purpose of rectification, erasure or restriction of the processing of the personal data referred to in § 5 of this Agreement, the Processor will forward that request to the Controller without undue delay after receipt.
(3) Control obligations
- The Processor ensures by means of suitable controls that the personal data processed on behalf of the Controller is processed exclusively in accordance with this Agreement and/or the Main Contract and/or the corresponding instructions.
- The Processor will organise its operating procedures in such a way that the data it processes on behalf of the Controller is secured to the extent required in each case and protected against unauthorised access by third parties.
- The Processor monitors compliance with the provisions on data protection and data security. The Processor's contact for data protection is currently: Joydev GmbH, attn. Data Protection, Konrad-Zuse-Platz 8, 81829 Munich, Germany, datenschutz@joyint.com
(4) Information obligations
- The Processor will draw the Controller's attention without undue delay to any instruction issued by the Controller that, in the Processor's opinion, infringes statutory provisions. The Processor is entitled to suspend the execution of the instruction concerned until it is confirmed or amended by the Controller.
- The Processor will assist the Controller in complying with the obligations set out in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Processor.
(5) Place of processing
The data is in principle processed in the territory of the Federal Republic of Germany, in a Member State of the European Union or in another State party to the Agreement on the European Economic Area. Any relocation to a third country may take place only if the specific requirements of Articles 44 et seq. GDPR are met.
(6) Erasure of personal data
- Users may erase processed data at any time with effect for the future. Such erasure has no effect on the data transmitted to the connected repository up to that point, because personal data stored elsewhere via Joyint cannot be erased automatically. The Controller may, however, have that data erased via the provider of the connected repository. The Processor will assist with this where required. Depending on the repository, data to be erased may also be irreversibly anonymised.
- After termination of the Main Contract, the Processor will, at the choice of the Controller, either erase or return all personal data processed on behalf of the Controller, unless statutory retention obligations or legitimate interests of the Processor preclude the erasure of that data.
§ 8 Audit rights of the Controller
(1) The Controller is entitled, after giving timely prior notice, during normal business hours, without disrupting the Processor's business operations or jeopardising the security measures for other controllers, and at its own expense, to verify compliance with the data protection provisions and the contractual agreements to the extent required, either itself or through third parties. The audits may also be carried out by reference to existing industry-standard certifications of the Processor, current attestations or reports by an independent body (such as an auditor, external data protection officer, internal auditor or external data protection auditor) or self-declarations. The Processor will offer the support necessary for carrying out the audits.
(2) The Processor will inform the Controller of inspection measures carried out by the supervisory authority to the extent that they concern processing operations that the Processor carries out for the Controller.
§ 9 Sub-processing
(1) The Controller authorises the Processor to engage further processors in accordance with the following paragraphs of § 9 of this Agreement. This authorisation constitutes a general written authorisation within the meaning of Article 28(2) GDPR.
(2) In performing the engagement, the Processor currently works with the sub-processors named in Annex 2, to whose engagement the Controller agrees.
(3) The Processor is entitled to engage further processors or to replace those already engaged. The Processor will inform the Controller in advance of any intended change concerning the addition or replacement of a further processor. The Controller may object to an intended change.
(4) The objection to the intended change must be raised with the Processor within 2 weeks of receipt of the information about the change. In the event of an objection, the Processor may, at its own choice, render the service without the intended change or propose an alternative further processor and agree it with the Controller. If rendering the service without the intended change cannot reasonably be expected of the Processor, for instance because of disproportionate expenditure for the Processor associated with it, or if no agreement on a further processor is reached, the Controller and the Processor may terminate this Agreement and the contractual obligations arising from the Terms of Use with effect from the end of the subscription period booked.
(5) Where a further processor is engaged, a level of protection comparable to that of this Agreement must always be ensured. The Processor is responsible to the Controller for all acts and omissions of the further processors it engages.
§ 10 Confidentiality
(1) The Processor is obliged to maintain confidentiality when processing data for the Controller.
(2) The Processor undertakes to use, in performing the engagement, only employees or other vicarious agents who have been committed to confidentiality in handling the personal data provided and who have been suitably familiarised with the requirements of data protection. The Processor will provide the Controller with evidence of these commitments on request.
(3) If the Controller is subject to other rules on the protection of secrets, it will inform the Processor of this. The Processor will commit its employees to those rules in accordance with the Controller's requirements.
§ 11 Technical and organisational measures
(1) The technical and organisational measures described in Annex 1 are agreed to be appropriate. The Processor may update and change these measures, provided that the level of protection is not materially reduced by such updates and/or changes.
(2) The Processor observes the principles of proper data processing pursuant to Article 32 in conjunction with Article 5(1) GDPR. It ensures the data security measures agreed by contract and required by law. It will take all measures necessary to secure the data and the security of the processing, in particular also taking into account the state of the art, and to mitigate possible adverse consequences for data subjects. The measures to be taken comprise in particular measures to protect the confidentiality, integrity, availability and resilience of the systems and measures that ensure the continuity of processing after incidents. In order to be able to ensure an appropriate level of security of the processing at all times, the Processor will regularly evaluate the measures implemented and make adjustments where necessary.
§ 12 Liability / indemnification
(1) The Processor's liability to the Controller arising from and in connection with this Agreement is governed by clause 15 of the Terms of Use. Liability to data subjects under Article 82 GDPR remains unaffected. The Processor is not obliged to pay compensation if it proves that it processed the Controller's data provided to it exclusively on the Controller's instructions and complied with the obligations of the GDPR specifically directed at processors.
(2) The Controller indemnifies the Processor against all third-party claims asserted against the Processor on the grounds of a culpable breach by the Controller of the obligations under this Agreement or of applicable data protection provisions.
§ 13 Miscellaneous
(1) In the event of contradictions between the provisions of this Agreement and those of the Main Contract, the provisions of this Agreement take precedence.
(2) Amendments and supplements to this Agreement require the consent of both parties, with specific reference to the provision of this Agreement to be amended. There are no oral side agreements, and they are also excluded for future amendments to this Agreement.
(3) This Agreement is governed by German law.
(4) If access to the data that the Controller has transmitted to the Processor for processing is jeopardised by measures of third parties (e.g. measures by an insolvency administrator, seizure by tax authorities, etc.), the Processor must notify the Controller of this without undue delay.
List of annexes
Annex 1: Technical and organisational measures
Annex 2: Sub-processors
Annex 1 – Technical and organisational measures
The Processor warrants that it has taken the following technical and organisational measures:
A. Measures for pseudonymisation / anonymisation
- Projects can be operated in anonymous mode. In that case the repository contains random member IDs instead of names and email addresses, and the mapping to the address can be decrypted only by project members.
- Diagnostic data (logs, traces, metrics) contains no names or email addresses, at most pseudonymised technical IDs.
- App telemetry is switched off by default for each account.
B. Measures for encryption
- Transport encryption of all access to the web app and API exclusively with TLS 1.3. Older protocol versions are rejected.
- Access tokens for connected forges (including refresh tokens) are stored in the database encrypted with AES-256-GCM.
- Chat content is end-to-end encrypted for the project members; the server holds no key for it.
- Sign-in links and the session tokens of the desktop app are stored only as SHA-256 hashes.
- Database backups are stored GPG-encrypted.
- Administrative server access exclusively via SSH with key authentication. Password login and direct root login are disabled.
C. Measures to ensure confidentiality
1. Physical access control
- The systems of the platform on which personal data is processed and backed up are located exclusively in data centres of OVH SAS within the European Union. The Processor operates no server rooms of its own for this purpose. Email is sent via the service provider in Germany named in Annex 2.
- The platform server is located in the OVH data centre in Warsaw (Poland).
- Only authorised persons of the operator, identified by badge, have physical access to the data centres. The sites are under video surveillance around the clock and protected by a security service.
- The OVH services used are certified to ISO/IEC 27001, 27017 and 27018.
2. System access control
- Sign-in only via personal accounts, by forge OAuth (GitHub, GitLab, Gitea/Codeberg) or one-time link by email. The platform stores no passwords.
- Sign-in links are valid for 15 minutes, can be used once and are rate-limited per email address.
- Sessions are managed on the server, expire after 30 days and use cookies with HttpOnly, Secure and SameSite.
- Users can view and end their sessions on other devices.
- Administration and monitoring interfaces can be reached only with two-factor authentication and membership of the administrators group.
- Measures for the Processor's workstations:
- Personalised user login when signing in to the computer or network
- Password policy (minimum length of 12 characters, consisting of at least one upper-case letter, one lower-case letter, one special character and one digit, and a ban on trivial passwords)
- Automatic screen lock after 5 minutes
- Encrypted hard drives
- Regular updating of antivirus and spyware filters
- VPN for remote access to other systems
- IT security policies
3. Data access control
- Only persons entered as members of a project have access to it. This is checked on every load, and removing a member ends that member's access.
- Administrative functions are limited to expressly authorised accounts.
- AI jobs run in isolated containers without forge credentials and act only under an attributable technical authorisation granted by a member, subject to a separate approval.
- The server process runs without root privileges.
- Server access is held exclusively by administrators specified by name, each with an individual, automatically issued SSH key.
- Every user login is personalised.
- The firewall protects access to Joyint against unauthorised access.
4. Separation control
- Separate test and production environments with their own databases, data directories and sign-in configurations.
- Tenant separation per project: a separate working copy and separate containers per project and job.
- Personal data is held only in the operational database, separate from the diagnostic data.
D. Measures to ensure integrity
1. Data integrity
- Changes reach production only via the test environment.
- Automated format, lint and test checks run before every build.
- What is delivered are versioned images assigned to a commit (logbook).
- Security updates of the operating system are installed automatically. Larger (security) updates are carried out in announced maintenance windows.
2. Transmission control
- TLS for all external connections: user access, connections to the forges and the sending of email (SMTP over TLS).
- Remote access by administrators takes place only via VPN.
3. Transport control
- Database and monitoring can be reached only in the internal container network or behind the reverse proxy.
- The host firewall admits only HTTP/HTTPS and the administration access from outside. Repeated failed sign-in attempts lead to an automatic block of the sender address.
- Data transport during remote access always takes place via a VPN connection.
- Where data is transported over a Wi-Fi connection, that connection is encrypted (WPA3).
4. Input control
- Every change to project data is recorded as a Git commit (logbook) with the acting member. For AI changes, the commissioning member is named in addition.
- The history lies in the Controller's repository and can be traced there.
E. Measures to ensure availability and resilience
1. Availability control and rapid recoverability
- Daily backup of the database and data directories to a separate system, keeping 7 daily, 4 weekly and 6 monthly states.
- Daily automatic check of the backup with alerting by email.
- The authoritative copy of the project data is the Controller's repository at the Controller's forge. The copy on the platform can be restored at any time.
- Restoration from the backup is tested at least once a year on a separate environment.
- The server's storage media are mirrored (RAID 1).
2. Reliability
- Monitoring via OpenTelemetry and OpenObserve with health checks of the services. Diagnostic data (without personal reference) is erased after 30 days and is not backed up.
F. Measures for the regular evaluation of the security of the processing
1. Review procedures
- Instructions of the Controller are documented at least in text form.
- Designation of a contact for data protection.
- Maintenance of a record of processing activities for personal data processed for the Processor's own purposes and on behalf of others.
- Carrying out risk assessments (in particular data protection impact assessments).
- Training of employees in data protection matters.
- Processes for handling data protection incidents and data subject requests.
2. Order control
- Contract management.
- Role and task descriptions for employees.
- Commitment of all employees to confidentiality.
Annex 2 – Sub-processors
In performing the engagement, the Processor currently works with the following further processors, to whose engagement the Controller agrees:
Cloud, hosting and server services
OVH SAS, 59100 Roubaix, France
Sending of email
Heinlein Hosting GmbH (mailbox.org), Schwedter Straße 8/9a, 10119 Berlin, Germany
Last updated: