This baseline DPA is available before signature. A signed customer-specific DPA controls if it conflicts with this page.
1. Scope and instructions
The customer is the controller and Pillion is the processor for personal data the customer puts into repositories, issues, pull requests, comments, attachments, workflow records, and organization administration surfaces. Pillion processes that data only to provide, secure, support, and improve the service as documented by the customer, including storing, indexing, backing up, transmitting, displaying, and deleting it. The documented instructions are the Terms of Service, the order, use of the service, and later written instructions that do not require a material change to the service.
2. Customer responsibilities
The customer is responsible for having a lawful basis and notices for the personal data it submits, responding to data-subject requests where it is the controller, and configuring users, repositories, runners, retention, and webhooks appropriately.
3. Confidentiality and personnel
Pillion keeps Customer Data confidential and gives access only to personnel who need it to operate or support the service. Those personnel are bound by confidentiality obligations. Pillion does not use repository contents, issues, pull requests, or comments to train models.
4. Security measures
Pillion maintains measures appropriate to the risk, including encryption at rest for Git objects, blobs, Postgres, caches, artifacts, and backups; TLS in transit; access control and authentication; audit logging; vulnerability and change management; backups and restore drills; rate limiting; and break-glass operator access. Workflow secrets are encrypted in storage and are not written to logs. Hosted jobs run in an isolated microVM and attached runners remain customer-operated.
5. Subprocessors
The current list is published at /subprocessors. Pillion gives at least 30 days’ notice before adding or replacing a subprocessor. Customers may object on reasonable data-protection grounds during that period. Pillion will either avoid the change for that customer, provide a commercially reasonable alternative, or allow the customer to terminate the affected service. Objections may be sent to info@pillion.dev.
Mollie B.V. is disclosed as the payment provider for billing data. Mollie acts as an independent controller for payment transactions under its published privacy position, not as a processor of repository or product data for Pillion. Mollie’s current DPA names Google Cloud Platform for Disputes and Invoicing, while the general payment-service IaaS chain is incomplete. Because ADR 0009 does not accept a US hyperscaler’s EU region as sufficient, Pillion makes no claim that Mollie payment data is EU-resident.
6. Data-subject and regulator assistance
Taking account of the processing, Pillion will reasonably assist the customer with access, correction, deletion, restriction, portability, objection, and security-obligation requests. Pillion will provide information reasonably needed to demonstrate compliance and will notify the customer without undue delay after confirming a personal-data breach affecting Customer Data.
7. International transfers
Pillion’s core Git and product stores are operated in allowed geography under ADR 0009. A customer must not use the service to send personal data to an external integration unless it has a lawful basis and appropriate transfer mechanism. Payment processing is a separate path: Mollie’s own privacy terms govern its processing and may permit processing outside the EEA with an appropriate transfer mechanism.
8. Return and deletion
On request or termination, Pillion will make Customer Data export available through the service and delete it according to the retention and deletion controls in the Terms of Service, unless law requires retention. Backups are reaped according to the configured retention window and are not used to restore deleted customer data except for disaster recovery before expiry.
9. Audits
Pillion will make available information reasonably necessary to show compliance with this DPA. Once per year, and after a material incident, the customer may request a remote audit or independent report on reasonable notice, subject to confidentiality and security controls. Audits may not expose another customer’s data or materially disrupt the service.
10. Term and order of precedence
This DPA starts when the customer uses the service or signs an order and ends when Pillion has deleted or returned Customer Data, subject to lawful retention. The confidentiality, security, deletion, and audit obligations continue for as long as Pillion retains Customer Data. The Terms of Service control on service and commercial matters; this DPA controls on processing of personal data.
DPA requests: info@pillion.dev.