Last updated · June 25, 2026
Data Processing Agreement
This DPA forms part of the agreement between you (the “Customer”) and Vela Partners for the hosted Cairn service, and applies where Cairn processes personal data on your behalf. If you self-host Cairn, you act as your own controller and processor and this DPA does not apply.
1. Roles
For personal data contained in your repositories, environments, and test runs, the Customer is the controller and Vela Partners is the processor. Vela Partnersprocesses such data only on the Customer’s documented instructions, including those given through use of the service.
2. Subject matter & duration
The subject matter is the provision of the Cairn service. We process personal data for the duration of the agreement and as set out in Annex I.
3. Processor obligations
- Process personal data only on the Customer’s documented instructions.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational measures (Annex II).
- Assist the Customer, taking into account the nature of processing, with data subject requests and with security, breach, and impact-assessment obligations.
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
4. Subprocessors
The Customer authorizes Vela Partners to engage the subprocessors listed in Annex III. We impose data-protection obligations on each subprocessor no less protective than this DPA and remain liable for their performance. We will give notice of new subprocessors and a reasonable opportunity to object.
5. Data subject requests
Taking into account the nature of the processing, we will assist the Customer by appropriate measures to fulfil its obligation to respond to requests to exercise data subject rights. If we receive such a request directly, we will refer the data subject to the Customer.
6. Personal data breach
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and provide information reasonably available to help the Customer meet its notification obligations.
7. Deletion or return
On termination, we will delete or return the Customer’s personal data at the Customer’s choice, and delete existing copies unless retention is required by law.
8. International transfers
Where processing involves transfer of personal data outside the EEA, UK, or Switzerland, the parties rely on the EU Standard Contractual Clauses (and the UK Addendum, where applicable), which are incorporated by reference.
9. Liability
Each party’s liability under this DPA is subject to the limitations of liability in the agreement.
Annex I — Details of processing
Categories of data subjects
The Customer’s end users, employees, and any individuals whose personal data appears in the Customer’s application during a test run.
Categories of personal data
Account identifiers and emails; and any personal data incidentally present in repository content, test fixtures, captured API requests/responses, screenshots, videos, and logs produced during runs.
Nature & purpose
Mapping user flows, generating and executing end-to-end tests, tracking API contracts, security recon, filing issues, and drafting fixes.
Duration
For the term of the agreement and the retention periods in the Privacy Policy.
Annex II — Security measures
- Encryption of data in transit.
- Scoped, least-privilege access tokens and role-based access control.
- Network isolation and secrets management for the runner and database.
- Logging, monitoring, and alerting for anomalous activity.
- Access to production limited to authorized personnel under confidentiality.
- Regular review of dependencies and credentials.
Annex III — Subprocessors
- GitHub, Inc. — repository access, authentication, issue/PR creation.
- Anthropic, PBC — failure triage and fix drafting.
- Google LLC — flow mapping and issue drafting.
- Railway Corp. — application hosting and managed PostgreSQL.
- Cloudflare, Inc. — object storage for run artifacts.
- Resend — transactional and recap email.
- Inngest, Inc. — background job orchestration.
- Vercel Inc. — web application hosting.
Contact
For DPA or data-protection matters, contact privacy@cairn.dev.