Why this one is short
Most data processing addendums are long because the vendor holds the customer’s data. We do not.
Pithy provisions databases, buckets, indexes and Workers into your Cloudflare account, under credentials you hold. Your records, your files and your users’ personal data stay there. They are not copied to us, they do not pass through our systems, and there is no request you could make that would cause us to produce them.
What we do process is the metadata of you having an account: who your team is, and where your Workers are so the dashboard can reach them. That is the entire subject of this addendum.
If your procurement process needs this signed on paper rather than accepted by use, write to support@help.pithy.sh.
Who this is between
This addendum forms part of the Terms and Conditions between Pithy, LLC, registered in TKTK-STATE with its principal place of business at TKTK-REGISTERED-ADDRESS (“Pithy”, “we”), and the customer accepting those terms (“you”). Where it conflicts with the terms, this addendum wins on data protection and the terms win on everything else.
“Data protection law” means the UK GDPR, the EU GDPR, and any other law about personal data that applies to the processing described here.
Which of us is which
- For the personal data of your end users — everything your application stores — you are the controller and we are not a processor, because we do not process it at all. It sits in your Cloudflare account. Cloudflare is your processor for it, under your agreement with them, not ours.
- For the personal data of your team members using our dashboard — names, email addresses, roles, and the connection metadata described below — you are the controller and we are your processor.
- For our own business records — billing, our security logs, mail you send us — we are a controller in our own right, as described in the Privacy Notice.
Category 2 is what the rest of this document is about.
What we process for you
Subject matter. Providing the hosted dashboard.
Duration. For as long as your account exists, plus the retention periods in the Privacy Notice.
Nature and purpose. Storing and displaying account, organization and connection records so your team can see and manage their environments.
Categories of data subject. The people on your team who use the dashboard, and anyone you invite to it.
Categories of personal data. Email address; display name and avatar where set; organization membership and role; and the connection metadata for each environment — worker URL, base path, granted scopes, last contact time, reported version, and the keys used to authenticate the connection.
Special category data. None. Do not put any into the dashboard; it is not built for it.
What we will do
- Only what you tell us to. We process this personal data only on your documented instructions, which for most customers means using the service as documented. If we believe an instruction breaks data protection law, we will tell you rather than carry it out.
- Confidentiality. Everyone we let near it is bound to keep it confidential.
- Security. We keep technical and organizational measures appropriate to the risk — encryption in transit and at rest, least-privilege access, sealed rather than plaintext private keys, and credential rotation.
- Breach notice. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and give you what you need to meet your own notification duties.
- Help with your obligations. We will give you reasonable assistance with data subject requests, data protection impact assessments, and consultations with a supervisory authority, taking into account how little we hold.
- Deletion. On termination we delete this personal data on the schedule in the Privacy Notice, unless the law requires us to keep it. There is no export step, because there is nothing of your application’s to export.
- Audit. We will make available the information reasonably needed to show we are meeting these obligations, and will accept an audit no more than once a year, on 30 days’ notice, at your cost, subject to confidentiality.
Sub-processors
You give us general authorization to use the sub-processors below. We will tell you before adding or replacing one, and you may object on reasonable data protection grounds — in which case, if we cannot resolve it, you may terminate the affected part of the service.
| Sub-processor | What for | Where |
|---|---|---|
| Cloudflare | Hosting, delivery and security for the dashboard | Global network |
| Paddle | Merchant of record — billing and tax; a controller in its own right, not our processor | United Kingdom, United States |
| Our email provider | Account, security and support mail | United States |
We remain responsible to you for a sub-processor’s performance of these obligations.
International transfers
We process this data in the United States. Where personal data is transferred out of the United Kingdom or the European Economic Area, the transfer relies on the UK International Data Transfer Agreement or the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies. Those clauses are incorporated into this addendum by reference, with Pithy as data importer.
Your side of it
You confirm that you have a lawful basis for the personal data you put into the dashboard, that you have given your team whatever notice they are owed, and that your instructions to us comply with data protection law. What your application does with your users’ data in your own Cloudflare account is yours to get right — we have no visibility into it and no ability to affect it.