Effective date: September 10, 2026
The terms on which GateTest processes personal data as your processor when it scans your code — incorporated into the Terms of Service automatically, with the security measures we actually run set out in Annex II. Contact: GateTest, hello@gatetest.ai.
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between GateTest ("GateTest", "we") and the customer that accepts the Agreement ("Customer", "you"). It sets out the terms on which GateTest processes personal data on your behalf when you use the hosted service, the command-line tool in hosted mode, the GitHub App, the Gluecron integration, the MCP endpoint and every related feature (together, the "Service").
This DPA applies automatically, without signature, to every Customer whose use of the Service involves personal data. It is incorporated into the Agreement by reference and takes effect on the later of 2026-09-10 and the date you first use the Service. If your procurement or compliance process needs a countersigned copy, e-mail hello@gatetest.ai and we will return one; a countersigned copy has the same terms as this page.
Where this DPA uses a capitalised term that the Agreement defines, it has the meaning given there. Where the two conflict on a matter of data protection, this DPA prevails (clause 12).
Repository and scan data. For Personal Data contained in the repositories, archives, URLs, files and other inputs you submit for scanning, and in the findings, fixes and reports the Service produces from them ("Customer Data"), you are the Controller (or a Processor acting for another Controller) and GateTest is your Processor. You are responsible for having a lawful basis to submit that data to the Service and for the instructions you give.
Account, billing and telemetry data. For the Personal Data GateTest collects to run its own business — your account and sign-in identity, billing records, support correspondence, product analytics and the anonymous engine telemetry described in the Privacy Policy — GateTest is an independent Controller. That Processing is governed by the Privacy Policy, not by this DPA.
Git hosts. GitHub and Gluecron act on your instructions under your own agreements with them. When the Service reads a repository or writes a status, comment or branch back to a git host, it does so as your Processor using the access you granted at installation.
This Annex describes the Processing GateTest performs as your Processor and serves as Annex I to the SCCs where they apply (clause 7).
| Item | Description |
|---|---|
| Subject matter | Automated quality and security analysis of source repositories and web properties that the Customer submits to the Service, and the generation of proposed fixes. |
| Duration | The term of the Agreement, and thereafter until the Customer Data is deleted on request under clause 10. |
| Nature and purpose | Fetching source repositories from the Customer's git host; analysing them with deterministic rules and, on the tiers that include it, AI review; producing findings, verdicts and reports; generating proposed fixes; and posting results (statuses, comments, branches, pull requests) back to the git host. |
| Categories of Personal Data | Identifiers and contact data of developers that appear in code, commit metadata, comments, configuration and documentation (names, e-mail addresses, usernames, avatar URLs); and any Personal Data the Customer places in a repository, file or URL submitted for scanning. |
| Special categories | None expected. The Service is not designed for special-category data and the Customer must not submit it. |
| Categories of Data Subjects | The Customer's employees, contractors, developers and contributors; and any individual referenced in the code, data or web property submitted for scanning. |
| Frequency | Continuous for the term: once per scan the Customer requests, and once per push or pull-request event for repositories connected to Continuous scanning. |
| Sub-processor transfers | As set out in clause 6 and on the Sub-processors page; the subject matter, nature and duration of each transfer match this Annex. |
GateTest will:
GateTest will answer reasonable written information-security and data-protection questionnaires within 30 days. Where Data Protection Laws give you a right to audit and a written response is genuinely insufficient, you (or an independent auditor you appoint that is not a competitor of GateTest and is bound by confidentiality) may carry out an audit of the relevant controls no more than once in any 12-month period, on at least 30 days' written notice, during business hours, at your cost, and in a manner that does not disrupt the Service or expose other customers' data. Where a Sub-processor's controls are in question, GateTest will make available the Sub-processor's most recent audit report or certification in place of an on-site audit of that Sub-processor.
You give GateTest general written authorisation to engage Sub-processors. The current list — with each Sub-processor's legal entity, purpose, the data it receives, its location and its own data-protection terms — is published at Sub-processors. That page is the notice mechanism for this DPA: GateTest will update it at least 30 days before a new Sub-processor begins Processing Customer Data (the "objection window").
If you have reasonable data-protection grounds to object to a new Sub-processor, e-mail hello@gatetest.ai within the objection window, stating the grounds. GateTest will work with you in good faith to resolve the objection — for example by not routing your Customer Data to that Sub-processor, or by offering a configuration that avoids it. If no resolution is reached within 30 days of your objection, you may terminate the part of the Service that cannot be provided without the Sub-processor by written notice, and GateTest will refund any prepaid fees for the terminated part covering the period after termination.
GateTest imposes on each Sub-processor, by written contract, data-protection obligations that provide at least the level of protection required by this DPA, and remains responsible to you for the performance of each Sub-processor's obligations.
GateTest is operated from New Zealand and the Service is hosted with Sub-processors located predominantly in the United States. Customer Data will therefore be transferred to and Processed in the United States and in the locations listed on the Sub-processors page. GateTest will only make a transfer of Personal Data that Data Protection Laws restrict where a valid transfer mechanism applies.
GateTest will notify you of a Security Incident affecting your Customer Data without undue delay after becoming aware of it and, where the GDPR or UK GDPR applies, no later than 72 hours after becoming aware. Notification goes to the e-mail address on your account.
The notification will describe, to the extent then known, the nature of the incident and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures GateTest has taken or proposes to take to address it and mitigate its effects; and a contact point. Information may be provided in phases as it becomes available. GateTest will cooperate reasonably with your investigation and with any notifications you are required to make.
Notification of, or response to, a Security Incident under this clause is not an acknowledgement by GateTest of fault or liability.
If GateTest receives a request from a Data Subject to exercise a right under Data Protection Laws in respect of Customer Data (access, rectification, erasure, restriction, portability or objection), it will not respond except to direct the Data Subject to you, unless a law requires otherwise, and will forward the request to you without undue delay.
Because the Service does not retain source code after a scan, and because you control what is in your repositories, most requests are met by changing the repository and, if you wish, deleting the affected findings. Where you cannot fulfil a request through the product, e-mail hello@gatetest.ai and GateTest will provide reasonable assistance, at no charge for occasional requests and otherwise at its then-current rates.
Source code is not retained after a scan in any case. The Service fetches a repository, analyses it in a temporary workspace, and deletes that workspace when the scan completes; an in-memory copy of the fetched archive expires within 120 seconds. What persists is the scan record: findings (message, file path and line number), the verdict, the score and the summary, plus the account and billing records described in the Privacy Policy.
On termination or expiry of the Agreement, or at any time on request, e-mail hello@gatetest.ai from your account address and GateTest will delete your account records and scan findings, or return the findings to you in a machine-readable export first if you ask. Deletion is completed within 30 days of the request. Copies held in Sub-processor backups age out on those providers' own schedules (see the Sub-processors page) and are not restored to production. GateTest may retain records that a law requires it to keep — for example tax and billing records, and the audit log described in Annex II for 7 years — and will keep them confidential and Process them only for that purpose.
Each party's liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, and GateTest's total aggregate liability to you under this DPA and the Agreement together will not exceed the greater of US$100 and the fees you paid to GateTest in the 12 months before the event giving rise to the claim. Nothing in this clause limits either party's liability to Data Subjects under the SCCs, or any liability that cannot be limited by law.
This DPA takes effect when the Agreement does and continues for as long as GateTest Processes Customer Data on your behalf, including after the Agreement ends until deletion under clause 10 is complete.
In the event of a conflict between this DPA and the Agreement, this DPA prevails on matters of data protection. In the event of a conflict between this DPA and the SCCs or the UK Addendum, the SCCs or UK Addendum prevail. Nothing in this DPA limits any right a Data Subject has under the SCCs.
GateTest may update this DPA to reflect changes in Data Protection Laws, in the Service or in the measures in Annex II. A change that materially reduces your protection will be notified by e-mail at least 30 days before it takes effect; other changes take effect when published.
This DPA is governed by the laws of New Zealand, and the parties submit to the courts of Auckland, New Zealand, in the same way as the Agreement — except that the SCCs and the UK Addendum are governed by the law, and subject to the courts, that they themselves specify (clause 7), and nothing in this clause overrides a choice of law or forum that Data Protection Laws mandate.
The measures below are the controls GateTest operates to protect Customer Data. They serve as Annex II to the SCCs where the SCCs apply. They describe what is in place, not what is planned: GateTest holds no third-party certification or audit report at this time, and the Security page says so plainly.
includeSubDomains and preload.X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, a strict-origin-when-cross-origin referrer policy and a restrictive Permissions-Policy.read:user and user:email — your login and e-mail address only; sign-in never grants repository access.HttpOnly, SameSite=Lax and Secure, and expires after 30 days.The GitHub App requests exactly the scopes the shipped code needs, and a test in the engine fails if the code ever calls an endpoint outside them:
| Permission | Access | Why we need it |
|---|---|---|
| Contents | Read & write | Read your code to scan it, and push the auto-fix branch — code is never stored |
| Pull requests | Read & write | Open the auto-fix PR and leave inline review comments |
| Commit statuses | Read & write | Green ✅ or red ❌ on each commit |
| Issues | Read & write | Post the scan summary as a PR comment |
| Metadata | Read | Know which repos to watch |
The App subscribes to 4 webhook events: push, pull_request, workflow_run, issue_comment. No other event reaches us.
Gluecron repositories are connected through a push contract authenticated by a shared secret (bearer token or HMAC signature); no standing credential to the customer's Gluecron account is held beyond the token the customer issues for scanning.
The hosted engine analyses code statically. Modules that would have to run the Customer's code are refused on GateTest servers and run only inside the Customer's own CI (via the GitHub Action) or on the Customer's machine (via the CLI). There is no sandbox; the control is that the code is not executed. The refused modules are:
mutation — runs your own test suite repeatedly against mutated copies of your code.chaos — drives a headless browser against your application and fuzzes its inputs.unitTests — executes your unit-test runner and whatever it loads.integrationTests — executes your integration-test runner, which typically starts your services.e2e — executes your end-to-end test runner and a browser.lint — runs your project's linter, which loads plugins from your dependency tree.Questions about this DPA, requests for a countersigned copy, Sub-processor objections, deletion requests and Security Incident correspondence all go to GateTest at hello@gatetest.ai. Please send data-protection requests from the e-mail address on your account so we can verify them.