GGateTest

Data Processing Addendum

Effective date: September 10, 2026

The terms on which GateTest processes personal data as your processor when it scans your code — incorporated into the Terms of Service automatically, with the security measures we actually run set out in Annex II. Contact: GateTest, hello@gatetest.ai.

1. Introduction

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between GateTest ("GateTest", "we") and the customer that accepts the Agreement ("Customer", "you"). It sets out the terms on which GateTest processes personal data on your behalf when you use the hosted service, the command-line tool in hosted mode, the GitHub App, the Gluecron integration, the MCP endpoint and every related feature (together, the "Service").

This DPA applies automatically, without signature, to every Customer whose use of the Service involves personal data. It is incorporated into the Agreement by reference and takes effect on the later of 2026-09-10 and the date you first use the Service. If your procurement or compliance process needs a countersigned copy, e-mail hello@gatetest.ai and we will return one; a countersigned copy has the same terms as this page.

Where this DPA uses a capitalised term that the Agreement defines, it has the meaning given there. Where the two conflict on a matter of data protection, this DPA prevails (clause 12).

2. Definitions

  • Personal Data means any information relating to an identified or identifiable natural person that GateTest processes on your behalf under the Agreement.
  • Processing means any operation performed on Personal Data, whether or not by automated means, including collection, retrieval, analysis, storage, disclosure by transmission and erasure. "Process" and "Processed" are read accordingly.
  • Controller means the party that determines the purposes and means of Processing; Processor means the party that Processes Personal Data on the Controller's behalf. The equivalent terms under other Data Protection Laws (for example "business" and "service provider" under the CCPA, or "agency" under the NZ Privacy Act) are read into these definitions.
  • Sub-processor means a third party engaged by GateTest to Process Personal Data in connection with the Service.
  • Data Subject means the natural person to whom Personal Data relates.
  • Data Protection Laws means all laws applying to the Processing of Personal Data under the Agreement, including, to the extent applicable: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as retained in the law of the United Kingdom and the Data Protection Act 2018 (the "UK GDPR"); the New Zealand Privacy Act 2020; and the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA").
  • Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data Processed by GateTest or a Sub-processor.
  • SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
  • UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.

3. Roles of the parties

Repository and scan data. For Personal Data contained in the repositories, archives, URLs, files and other inputs you submit for scanning, and in the findings, fixes and reports the Service produces from them ("Customer Data"), you are the Controller (or a Processor acting for another Controller) and GateTest is your Processor. You are responsible for having a lawful basis to submit that data to the Service and for the instructions you give.

Account, billing and telemetry data. For the Personal Data GateTest collects to run its own business — your account and sign-in identity, billing records, support correspondence, product analytics and the anonymous engine telemetry described in the Privacy Policy — GateTest is an independent Controller. That Processing is governed by the Privacy Policy, not by this DPA.

Git hosts. GitHub and Gluecron act on your instructions under your own agreements with them. When the Service reads a repository or writes a status, comment or branch back to a git host, it does so as your Processor using the access you granted at installation.

4. Annex I — Details of Processing

This Annex describes the Processing GateTest performs as your Processor and serves as Annex I to the SCCs where they apply (clause 7).

ItemDescription
Subject matterAutomated quality and security analysis of source repositories and web properties that the Customer submits to the Service, and the generation of proposed fixes.
DurationThe term of the Agreement, and thereafter until the Customer Data is deleted on request under clause 10.
Nature and purposeFetching source repositories from the Customer's git host; analysing them with deterministic rules and, on the tiers that include it, AI review; producing findings, verdicts and reports; generating proposed fixes; and posting results (statuses, comments, branches, pull requests) back to the git host.
Categories of Personal DataIdentifiers and contact data of developers that appear in code, commit metadata, comments, configuration and documentation (names, e-mail addresses, usernames, avatar URLs); and any Personal Data the Customer places in a repository, file or URL submitted for scanning.
Special categoriesNone expected. The Service is not designed for special-category data and the Customer must not submit it.
Categories of Data SubjectsThe Customer's employees, contractors, developers and contributors; and any individual referenced in the code, data or web property submitted for scanning.
FrequencyContinuous for the term: once per scan the Customer requests, and once per push or pull-request event for repositories connected to Continuous scanning.
Sub-processor transfersAs set out in clause 6 and on the Sub-processors page; the subject matter, nature and duration of each transfer match this Annex.

5. GateTest's obligations as Processor

GateTest will:

  • Process only on documented instructions. The Agreement, this DPA, the settings you choose in the product (including which repositories are connected, which modules run and whether AI features are enabled) and each scan request you make constitute your complete documented instructions. GateTest will not Process Customer Data for any other purpose, except where required by law, in which case it will tell you first unless the law forbids it.
  • Inform you of unlawful instructions. If GateTest believes an instruction infringes Data Protection Laws it will tell you without undue delay and may suspend the affected Processing until the instruction is confirmed or changed.
  • Keep personnel bound by confidentiality. Access to Customer Data is limited to people who need it to operate the Service, and each is bound by a contractual or statutory duty of confidentiality.
  • Maintain the security measures in Annex II (clause 14), and not reduce their overall level of protection during the term.
  • Assist you with Data Subject requests (clause 9) and, taking into account the nature of the Processing and the information available to GateTest, with data-protection impact assessments and prior consultations with supervisory authorities.
  • Delete or return Customer Data at the end of the Service on request (clause 10), subject to any retention a law requires.
  • Make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, as set out below.

Audits

GateTest will answer reasonable written information-security and data-protection questionnaires within 30 days. Where Data Protection Laws give you a right to audit and a written response is genuinely insufficient, you (or an independent auditor you appoint that is not a competitor of GateTest and is bound by confidentiality) may carry out an audit of the relevant controls no more than once in any 12-month period, on at least 30 days' written notice, during business hours, at your cost, and in a manner that does not disrupt the Service or expose other customers' data. Where a Sub-processor's controls are in question, GateTest will make available the Sub-processor's most recent audit report or certification in place of an on-site audit of that Sub-processor.

6. Sub-processors

You give GateTest general written authorisation to engage Sub-processors. The current list — with each Sub-processor's legal entity, purpose, the data it receives, its location and its own data-protection terms — is published at Sub-processors. That page is the notice mechanism for this DPA: GateTest will update it at least 30 days before a new Sub-processor begins Processing Customer Data (the "objection window").

If you have reasonable data-protection grounds to object to a new Sub-processor, e-mail hello@gatetest.ai within the objection window, stating the grounds. GateTest will work with you in good faith to resolve the objection — for example by not routing your Customer Data to that Sub-processor, or by offering a configuration that avoids it. If no resolution is reached within 30 days of your objection, you may terminate the part of the Service that cannot be provided without the Sub-processor by written notice, and GateTest will refund any prepaid fees for the terminated part covering the period after termination.

GateTest imposes on each Sub-processor, by written contract, data-protection obligations that provide at least the level of protection required by this DPA, and remains responsible to you for the performance of each Sub-processor's obligations.

7. International transfers

GateTest is operated from New Zealand and the Service is hosted with Sub-processors located predominantly in the United States. Customer Data will therefore be transferred to and Processed in the United States and in the locations listed on the Sub-processors page. GateTest will only make a transfer of Personal Data that Data Protection Laws restrict where a valid transfer mechanism applies.

  • EU transfers. Where the GDPR applies to a transfer from you to GateTest, the SCCs are incorporated into this DPA by reference and take effect on the date of this DPA, completed as follows: Module Two (controller to processor) applies; Clause 7 (docking) is included; in Clause 9 Option 2 (general authorisation) applies with the 30-day period in clause 6 of this DPA; the optional language in Clause 11 is not included; in Clause 13 and Annex I.C the supervisory authority is that of the EU member state in which you are established; in Clause 17 Option 1 applies with the law of Ireland; in Clause 18 the courts of Ireland. The parties' details are the details in this DPA and the Agreement; Annex I of the SCCs is clause 4 of this DPA; Annex II of the SCCs is clause 14 of this DPA; Annex III is the Sub-processors page.
  • UK transfers. Where the UK GDPR applies, the SCCs as completed above apply as amended by the UK Addendum, which is incorporated by reference; Table 4 of the UK Addendum permits either party to end the Addendum as set out in its section 19.
  • New Zealand. Where the Privacy Act 2020 applies, GateTest discloses Personal Data to overseas Sub-processors only where Information Privacy Principle 12 is satisfied — in each case because the Sub-processor is contractually bound to protect the information in a way that, overall, provides comparable safeguards to the Act.
  • Transfer assessment. Before engaging each Sub-processor GateTest reviews its data-protection terms, the data it will receive, its location and its published security measures, and records the outcome. GateTest will provide you with reasonable information to support your own transfer impact assessment on request.

8. Security Incidents

GateTest will notify you of a Security Incident affecting your Customer Data without undue delay after becoming aware of it and, where the GDPR or UK GDPR applies, no later than 72 hours after becoming aware. Notification goes to the e-mail address on your account.

The notification will describe, to the extent then known, the nature of the incident and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures GateTest has taken or proposes to take to address it and mitigate its effects; and a contact point. Information may be provided in phases as it becomes available. GateTest will cooperate reasonably with your investigation and with any notifications you are required to make.

Notification of, or response to, a Security Incident under this clause is not an acknowledgement by GateTest of fault or liability.

9. Data Subject requests

If GateTest receives a request from a Data Subject to exercise a right under Data Protection Laws in respect of Customer Data (access, rectification, erasure, restriction, portability or objection), it will not respond except to direct the Data Subject to you, unless a law requires otherwise, and will forward the request to you without undue delay.

Because the Service does not retain source code after a scan, and because you control what is in your repositories, most requests are met by changing the repository and, if you wish, deleting the affected findings. Where you cannot fulfil a request through the product, e-mail hello@gatetest.ai and GateTest will provide reasonable assistance, at no charge for occasional requests and otherwise at its then-current rates.

10. Return and deletion of Customer Data

Source code is not retained after a scan in any case. The Service fetches a repository, analyses it in a temporary workspace, and deletes that workspace when the scan completes; an in-memory copy of the fetched archive expires within 120 seconds. What persists is the scan record: findings (message, file path and line number), the verdict, the score and the summary, plus the account and billing records described in the Privacy Policy.

On termination or expiry of the Agreement, or at any time on request, e-mail hello@gatetest.ai from your account address and GateTest will delete your account records and scan findings, or return the findings to you in a machine-readable export first if you ask. Deletion is completed within 30 days of the request. Copies held in Sub-processor backups age out on those providers' own schedules (see the Sub-processors page) and are not restored to production. GateTest may retain records that a law requires it to keep — for example tax and billing records, and the audit log described in Annex II for 7 years — and will keep them confidential and Process them only for that purpose.

11. Liability

Each party's liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, and GateTest's total aggregate liability to you under this DPA and the Agreement together will not exceed the greater of US$100 and the fees you paid to GateTest in the 12 months before the event giving rise to the claim. Nothing in this clause limits either party's liability to Data Subjects under the SCCs, or any liability that cannot be limited by law.

12. Term and precedence

This DPA takes effect when the Agreement does and continues for as long as GateTest Processes Customer Data on your behalf, including after the Agreement ends until deletion under clause 10 is complete.

In the event of a conflict between this DPA and the Agreement, this DPA prevails on matters of data protection. In the event of a conflict between this DPA and the SCCs or the UK Addendum, the SCCs or UK Addendum prevail. Nothing in this DPA limits any right a Data Subject has under the SCCs.

GateTest may update this DPA to reflect changes in Data Protection Laws, in the Service or in the measures in Annex II. A change that materially reduces your protection will be notified by e-mail at least 30 days before it takes effect; other changes take effect when published.

13. Governing law

This DPA is governed by the laws of New Zealand, and the parties submit to the courts of Auckland, New Zealand, in the same way as the Agreement — except that the SCCs and the UK Addendum are governed by the law, and subject to the courts, that they themselves specify (clause 7), and nothing in this clause overrides a choice of law or forum that Data Protection Laws mandate.

14. Annex II — Technical and organisational measures

The measures below are the controls GateTest operates to protect Customer Data. They serve as Annex II to the SCCs where the SCCs apply. They describe what is in place, not what is planned: GateTest holds no third-party certification or audit report at this time, and the Security page says so plainly.

Transport and perimeter

  • All traffic to the Service is served over TLS. HTTP Strict Transport Security is set for two years with includeSubDomains and preload.
  • Every response carries a Content-Security-Policy, X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, a strict-origin-when-cross-origin referrer policy and a restrictive Permissions-Policy.
  • URL scans pass through a server-side request-forgery guard that refuses private, loopback and link-local address ranges, so the scanner cannot be pointed at internal infrastructure.

Authentication and sessions

  • Customers sign in through their git host's OAuth flow with a one-time anti-forgery state token. Signing in with GitHub uses the OAuth scopes read:user and user:email — your login and e-mail address only; sign-in never grants repository access.
  • The session cookie is encrypted with AES-256-GCM and authenticated with an HMAC, is HttpOnly, SameSite=Lax and Secure, and expires after 30 days.
  • Operator (staff) console access uses a separate, shorter-lived credential and is limited to GateTest personnel.

Access and least privilege

The GitHub App requests exactly the scopes the shipped code needs, and a test in the engine fails if the code ever calls an endpoint outside them:

PermissionAccessWhy we need it
ContentsRead & writeRead your code to scan it, and push the auto-fix branch — code is never stored
Pull requestsRead & writeOpen the auto-fix PR and leave inline review comments
Commit statusesRead & writeGreen ✅ or red ❌ on each commit
IssuesRead & writePost the scan summary as a PR comment
MetadataReadKnow which repos to watch

The App subscribes to 4 webhook events: push, pull_request, workflow_run, issue_comment. No other event reaches us.

Gluecron repositories are connected through a push contract authenticated by a shared secret (bearer token or HMAC signature); no standing credential to the customer's Gluecron account is held beyond the token the customer issues for scanning.

Data handling during a scan

  • The repository archive is fetched from the git host, memoised in memory for at most 120 seconds, unpacked into a temporary workspace on the scanning server, analysed, and the workspace is deleted when the scan ends.
  • Source code is not written to the database, to logs or to error reports. Findings are stored with a message, file path and line number; the surrounding code is not stored.
  • Findings are retained until the Customer requests deletion (clause 10).

Customer code is never executed on GateTest infrastructure

The hosted engine analyses code statically. Modules that would have to run the Customer's code are refused on GateTest servers and run only inside the Customer's own CI (via the GitHub Action) or on the Customer's machine (via the CLI). There is no sandbox; the control is that the code is not executed. The refused modules are:

  • mutation — runs your own test suite repeatedly against mutated copies of your code.
  • chaos — drives a headless browser against your application and fuzzes its inputs.
  • unitTests — executes your unit-test runner and whatever it loads.
  • integrationTests — executes your integration-test runner, which typically starts your services.
  • e2e — executes your end-to-end test runner and a browser.
  • lint — runs your project's linter, which loads plugins from your dependency tree.

Integrity of inbound events

  • Webhooks from Stripe, GitHub and Gluecron are verified fail-closed: a missing or invalid signature or bearer token is rejected before any processing, using a constant-time comparison.
  • Configuration is checked for placeholder secrets; an integration whose secret is still a placeholder is treated as unconfigured rather than trusted.
  • Scheduled (cron) endpoints require a dedicated secret and cannot be triggered anonymously.
  • All database access uses parameterised queries.

Encryption

  • In transit: TLS for every connection to the Service and from the Service to each Sub-processor.
  • Session cookie: AES-256-GCM with HMAC authentication, as above.
  • Integration tokens (git-host access tokens the Customer connects): encrypted at rest with AES-256-GCM using a key held only in the server environment.
  • Database: encryption at rest is provided by the managed database Sub-processor and inherited by every table.

Logging and monitoring

  • Security-relevant actions are written to an append-only, hash-chained audit log — each entry commits to the hash of the previous one, so alteration is detectable — retained for 7 years.
  • Application errors are reported to an error-monitoring Sub-processor with request bodies, source code, prompts, API keys and cookies scrubbed before sending.

AI provider handling

  • The deterministic scan uses no AI. Only the AI review and auto-fix paths send data to an AI provider (Anthropic, and OpenAI only where the Customer opts in to consensus review on a Forensic scan), and those paths send the complete contents of the files under review together with the finding text.
  • The provider retains API inputs for 30 days under its standard commercial terms and does not use them to train models. This is standard retention, not a zero-data-retention arrangement.
  • Customers who supply their own provider API key (bring-your-own-key) have it used for that request only; it is never stored, logged or echoed back.
  • Repository content is screened for prompt-injection patterns before it is included in a prompt, and model output is screened for leaked secrets before it is used in a fix or shown to a user.

Rate limiting

  • Request rate limits are enforced per server instance, keyed on client IP address held in memory only.

Vendor management

  • Every Sub-processor is listed at Sub-processors with its data-protection terms; each is engaged under a written DPA or equivalent terms and reviewed before engagement (clause 7).

Personnel

  • Access to production systems and Customer Data is limited to the operators who need it to run the Service, each bound by confidentiality.

15. Contact

Questions about this DPA, requests for a countersigned copy, Sub-processor objections, deletion requests and Security Incident correspondence all go to GateTest at hello@gatetest.ai. Please send data-protection requests from the e-mail address on your account so we can verify them.