Data processing agreement
The Article 28 GDPR agreement under which Permenta processes the personal data in your workspace on your behalf.
Last updated .
1. Parties, subject matter and precedence
This data processing agreement (“DPA”) is concluded between the customer that has accepted the Terms of service (the “Customer”) and the operator of Permenta (the “Processor”):
- Legal name
- Patchgate, LLC
- Address
- 651 N Broad St, Suite 201Middletown, DE 19709United States
- Privacy contact
- privacy@permenta.com
It applies whenever the Processor processes personal data on the Customer’s behalf in the course of providing the Service, and it implements Article 28 of Regulation (EU) 2016/679 (“GDPR”). The Customer acts as controller or, where it uses the Service for its own clients, as a processor acting on its own controllers’ instructions. In case of conflict this DPA prevails over the Terms of service for matters of data protection.
2. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Customer Data” means personal data that the Customer or its users submit to the Service or that the Service generates from it on the Customer’s behalf. “Subprocessor” means a third party engaged by the Processor to process Customer Data.
3. Details of the processing
- Subject matter and purpose
- Provision of the Permenta Service: product registry, scope assessment, obligation tracking, Article 14 case handling, software-bill-of-materials and vulnerability tracking, document drafting, trust pages and the evidence ledger, with related support.
- Duration
- The term of the Terms of service, plus the deletion period in section 12.
- Nature of the processing
- Storage, hosting, retrieval, transmission, backup, display, export and deletion.
- Categories of data subjects
- The Customer’s staff and contractors who use the Service; people named in product records, reports, advisories and documents (for example security contacts, approvers, researchers who reported a vulnerability); recipients of user notices; and the Customer’s own customers only where the Customer records them.
- Categories of personal data
- Names, business contact details, roles and organisational affiliation, user identifiers and IP addresses in audit trails, and any personal data the Customer includes in free-text fields and uploaded files.
- Special categories of data
- None are intended; the Customer will not submit special categories of data without a prior written agreement on additional measures.
4. Instructions and the Processor’s obligations
The Processor will:
- process Customer Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law, in which case it informs the Customer before processing, unless the law forbids that on important grounds of public interest. This DPA, the Terms of service and the Customer’s use of the Service’s functions are the documented instructions;
- inform the Customer immediately if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law;
- ensure that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement the measures required by Article 32 GDPR, as described in section 6;
- respect the conditions for engaging subprocessors set out in section 7;
- assist the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to requests by data subjects exercising their rights;
- assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Processor;
- at the Customer’s choice, delete or return all Customer Data after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage;
- make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, as set out in section 11.
5. Confidentiality and personnel
Access to Customer Data is limited to personnel who need it to provide, support or secure the Service. Staff sign in to a separate administrative realm with passkeys, can only read tenant data, and every access is recorded in a hash-chained audit log. Personnel are bound by written confidentiality obligations that survive the end of their engagement.
6. Security of processing
The Processor maintains the following technical and organisational measures and may update them provided the level of protection does not decrease. The current description is published on the Security page.
- Hosting and physical security: Microsoft Azure data centres in the European Union (region Sweden Central), operated under Microsoft’s certified controls.
- Access control: role-based permissions per workspace, email verification, breached-password checks, rate limits, passkeys and one-time codes; least-privilege database roles; secrets in a key vault accessed through managed identity.
- Tenant separation: PostgreSQL row-level security forced on every tenant table and set per transaction; integration tests attempt cross-tenant access.
- Encryption: TLS for all connections; platform-managed encryption at rest for the database, backups and file storage.
- Integrity and logging: append-only evidence ledgers and audit logs with hash chains; versioned file storage; security headers and a nonce-based content security policy.
- Availability and recovery: daily backups with 35-day point-in-time restore, forward-only migrations, documented rollback.
- Secure development: locked and scanned dependencies, commit-pinned CI, reviewed production deployments, a threat model reviewed with every new integration, and a coordinated vulnerability disclosure policy.
- Pseudonymisation and minimisation: API keys and passwords stored as hashes; only the data needed for a function is collected.
7. Subprocessors
The Customer gives general authorisation to the Processor to engage the subprocessors listed below and on the Subprocessors page, which forms part of this DPA:
- Microsoft Azure: Hosting: application containers, the PostgreSQL database, blob storage, secrets, logs and backups. Location: European Union (Azure region Sweden Central).
- Stripe: Payments, invoicing, tax calculation and the billing portal. Location: European Union and United States.
- Resend: Transactional email: verification, invitations, reporting-deadline reminders and account notices. Location: European Union data region; the provider is established in the United States.
The Processor will inform the Customer of any intended addition or replacement at least 30 days in advance by email to workspace owners and on that page. The Customer may object on reasonable data protection grounds within that period; the parties will then seek a solution in good faith, and if none is found the Customer may terminate the affected part of the Service without penalty. The Processor imposes on each subprocessor data protection obligations equivalent to those in this DPA and remains fully liable to the Customer for the subprocessor’s performance.
8. International transfers
Customer Data is stored and processed in the European Union. Where a subprocessor transfers personal data to a country without an adequacy decision, the transfer is governed by the European Commission’s standard contractual clauses (Decision (EU) 2021/914) or another transfer mechanism under Chapter V GDPR, and the Processor will provide the Customer with the relevant documentation on request.
9. Data subject requests, impact assessments and authorities
If the Processor receives a request from a data subject concerning Customer Data, it will forward the request to the Customer promptly and will not respond itself except on the Customer’s instruction or where the law requires. The Service’s export, correction and deletion functions let the Customer answer most requests directly. The Processor will assist with data protection impact assessments and prior consultations to the extent the information is not already available on the Security page, and will inform the Customer of a request from a supervisory authority concerning Customer Data unless the law prohibits it.
10. Personal data breaches
The Processor will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, by email to the workspace owners. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, the measures taken or proposed, and a contact point, and will be supplemented as information becomes available. The Processor will cooperate with the Customer in the Customer’s own notifications under Articles 33 and 34 GDPR.
11. Audits and information
The Processor demonstrates compliance first through documentation: this DPA, the Security page, the subprocessor list, and on request further written answers and any third-party audit reports or certifications it holds. Where that is not sufficient to satisfy a legal requirement or a supervisory authority, the Customer or an independent auditor bound by confidentiality may audit the Processor once per calendar year, with at least 30 days’ written notice, during business hours, without disrupting the Service, and at the Customer’s cost unless the audit reveals a material breach of this DPA. Findings are confidential.
12. Deletion and return
During the term the Customer can export Customer Data at any time. After the Terms of service end or a workspace is deleted, the export functions remain available for 30 days. The Processor then deletes Customer Data from the live systems; copies in backups expire within a further 35 days. On request the Processor confirms deletion in writing. Data whose storage is required by Union or Member State law is retained only for as long as that law requires and is otherwise isolated from processing.
13. Liability, term and governing law
Each party is liable under Article 82 GDPR for the damage it causes. As between the parties, the limitations of liability in the Terms of service apply to this DPA, except to the extent the GDPR does not allow them. This DPA runs for as long as the Processor processes Customer Data and is governed by the same law and jurisdiction as the Terms of service.
14. How this DPA is concluded
This DPA forms part of the agreement between the parties from the moment the Customer accepts the Terms of service. A countersigned copy on the Customer’s paper, or a version that adds the Customer’s own controllers and instructions, is available on request from privacy@permenta.com.