Last updated · June 25, 2026

Data Processing Agreement

This DPA forms part of the agreement between you (the “Customer”) and Vela Partners for the hosted Cairn service, and applies where Cairn processes personal data on your behalf. If you self-host Cairn, you act as your own controller and processor and this DPA does not apply.

1. Roles

For personal data contained in your repositories, environments, and test runs, the Customer is the controller and Vela Partners is the processor. Vela Partnersprocesses such data only on the Customer’s documented instructions, including those given through use of the service.

2. Subject matter & duration

The subject matter is the provision of the Cairn service. We process personal data for the duration of the agreement and as set out in Annex I.

3. Processor obligations

  • Process personal data only on the Customer’s documented instructions.
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational measures (Annex II).
  • Assist the Customer, taking into account the nature of processing, with data subject requests and with security, breach, and impact-assessment obligations.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits.

4. Subprocessors

The Customer authorizes Vela Partners to engage the subprocessors listed in Annex III. We impose data-protection obligations on each subprocessor no less protective than this DPA and remain liable for their performance. We will give notice of new subprocessors and a reasonable opportunity to object.

5. Data subject requests

Taking into account the nature of the processing, we will assist the Customer by appropriate measures to fulfil its obligation to respond to requests to exercise data subject rights. If we receive such a request directly, we will refer the data subject to the Customer.

6. Personal data breach

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and provide information reasonably available to help the Customer meet its notification obligations.

7. Deletion or return

On termination, we will delete or return the Customer’s personal data at the Customer’s choice, and delete existing copies unless retention is required by law.

8. International transfers

Where processing involves transfer of personal data outside the EEA, UK, or Switzerland, the parties rely on the EU Standard Contractual Clauses (and the UK Addendum, where applicable), which are incorporated by reference.

9. Liability

Each party’s liability under this DPA is subject to the limitations of liability in the agreement.

Annex I — Details of processing

Categories of data subjects

The Customer’s end users, employees, and any individuals whose personal data appears in the Customer’s application during a test run.

Categories of personal data

Account identifiers and emails; and any personal data incidentally present in repository content, test fixtures, captured API requests/responses, screenshots, videos, and logs produced during runs.

Nature & purpose

Mapping user flows, generating and executing end-to-end tests, tracking API contracts, security recon, filing issues, and drafting fixes.

Duration

For the term of the agreement and the retention periods in the Privacy Policy.

Annex II — Security measures

  • Encryption of data in transit.
  • Scoped, least-privilege access tokens and role-based access control.
  • Network isolation and secrets management for the runner and database.
  • Logging, monitoring, and alerting for anomalous activity.
  • Access to production limited to authorized personnel under confidentiality.
  • Regular review of dependencies and credentials.

Annex III — Subprocessors

  • GitHub, Inc. — repository access, authentication, issue/PR creation.
  • Anthropic, PBC — failure triage and fix drafting.
  • Google LLC — flow mapping and issue drafting.
  • Railway Corp. — application hosting and managed PostgreSQL.
  • Cloudflare, Inc. — object storage for run artifacts.
  • Resend — transactional and recap email.
  • Inngest, Inc. — background job orchestration.
  • Vercel Inc. — web application hosting.

Contact

For DPA or data-protection matters, contact privacy@cairn.dev.