Triaged

Data-processing agreement

Version: 28 September 2026

Parties and scope

This agreement supplements the Triaged terms between the customer identified in the account and Jenny Sever, Bertholdstraße 5, 75015 Bretten, Germany (Triaged). It applies on the Free and Pro plans whenever Triaged processes repository personal data on the customer’s behalf. The customer acts as controller, or as a processor authorised by its controller; Triaged acts as processor or subprocessor. Account administration, security, billing and legal records processed for Triaged’s own purposes are described in the privacy policy.

Processing instructions

The subject is automated GitHub issue prioritisation for the duration of the service and its deletion process. Instructions consist of this agreement, repository linking, project settings and requested scoring runs. Processing includes retrieving, transmitting, analysing and labelling issue titles, bodies and labels with project context. Data may concern issue authors, contributors, employees, customers and other people mentioned in issues, including names, contact details and free-text content. Do not submit special-category data, criminal-offence data, passwords or credentials in issue content.

Triaged processes this data only on documented instructions, including instructions about international transfers, unless legally required otherwise. In that case Triaged informs the customer beforehand unless prohibited by law. Triaged will inform the customer if an instruction appears to infringe applicable data-protection law. The customer is responsible for a lawful basis, notices and authority to give instructions.

Confidentiality and security

Access is limited to persons who need it for service operation and are subject to confidentiality obligations. Triaged maintains measures appropriate to the risk, including HTTPS, authenticated account access, repository ownership checks, a non-public database, restricted server configuration files, an unprivileged application process, encrypted database backups and restore checks. Administrative server access uses SSH keys. Issue text is transmitted for scoring and is not stored in the usage database. These measures do not constitute a promise of uninterrupted availability or of end-to-end encryption through model providers.

Subprocessors and transfers

The customer generally authorises Datalix for hosting, Clerk for account and repository configuration, OpenRouter for the AI gateway, TypeSafe for model inference, and mailbox.org for service correspondence. Their roles and locations are listed in the privacy policy. GitHub is the customer’s chosen source system; Paddle acts separately as merchant of record.

Triaged will impose applicable data-protection obligations on subprocessors and remains responsible for their performance of those obligations. Triaged will notify affected customers of intended additions or replacements at least 30 days in advance, allowing an objection on reasonable data-protection grounds. If no reasonable alternative resolves an objection, the affected processing will stop and the customer may end the affected service.

Processing can involve countries outside the EEA. Transfers require a valid mechanism under GDPR Chapter V, such as an applicable adequacy decision or standard contractual clauses. The customer may request relevant safeguards at hi@tin.codes. This agreement is not consent to unrestricted transfers or model training.

Assistance and incidents

Taking account of the processing and information available, Triaged assists with data-subject requests, security obligations, breach assessment and notifications, impact assessments and regulator consultations. Triaged notifies the customer without undue delay after becoming aware of a personal-data breach, supplies available details and further updates, and cooperates in mitigation. Triaged does not respond to a repository data-subject request on the customer’s behalf without instructions, unless required by law.

Return, deletion and audits

At the end of processing, the customer may choose return or deletion of personal data processed on its behalf, except where law requires retention. Contact hi@tin.codes with instructions. Repository content remains under the customer’s control in GitHub; unlinking removes Triaged’s webhook. Deleted data in the encrypted application backup cycle expires within 14 days and must not be restored to active use without reapplying deletions. Any provider-specific backup deletion period will be disclosed when handling the request.

Triaged supplies information needed to demonstrate compliance and permits and contributes to proportionate audits, including inspections by the customer or its authorised auditor, subject to confidentiality and security arrangements that do not prevent statutory rights. Contact hi@tin.codes to arrange assistance or an audit.

Order of precedence

This agreement takes precedence over conflicting Triaged terms concerning processing on behalf of the customer. Applicable standard contractual clauses and mandatory law take precedence over this agreement. Changes to processing scope require documented agreement.