Data processing agreement
This agreement governs personal data that Thoughtgears Ltd processes on your behalf when you use Nodrik. It forms part of the terms of service and applies from the moment you connect a Google Cloud project. Last updated 15 September 2026.
1. Who is who
You are the controller. Thoughtgears Ltd, a company registered in England and Wales, is the processor. Where this agreement refers to data protection law it means the UK GDPR and the Data Protection Act 2018, and the EU GDPR where that applies to you.
2. What we process, and why
The honest summary is that Nodrik is built to hold as little of your data as it can. It reads your telemetry at the moment an alert fires and keeps no copy of it.
| Category | Purpose | Retention |
|---|---|---|
| Telemetry read during an investigation — log entries, metrics, error groups, admin audit entries, Kubernetes events, and Cloud Run revision configuration (the response carries environment-variable values; Nodrik keeps the names and discards the values) from the projects you connect. Where you grant an optional configuration role (clause 5): the settings of the Cloud SQL, Memorystore, GKE, Compute Engine or load-balancer resource the alert was about. Where you install our GitHub App: commit metadata, diffs and source files from the repositories you select. Where you connect a tool of your own: whatever it returns. May incidentally contain personal data if your logs, configuration or code do. | To determine the likely cause of an alert. | Not stored. Read transiently, in memory, during the investigation. |
| Investigation reports and transcripts — the conclusion, the evidence cited and the steps taken to reach it: excerpts of the telemetry above, service configuration where you granted a role to read it, Kubernetes event text, excerpts of Google's own documentation consulted during the investigation, and any follow-up question typed to Nodrik in Slack. Every tool result is redacted before the model sees it, and the transcript again before it is stored. | So you can re-read an answer, and so we can measure and improve accuracy. | While you are a customer. Deleted with your tenant (clause 9). |
| Account data — name, work email, company, and an identifier from your sign-in provider (Google or GitHub). | To create your tenant, authenticate you, contact you and bill you. | While you are a customer. Your tenant record, including your contact address, is deleted with your tenant (clause 9). The sign-in identity itself — name, email and provider identifier — is held by Firebase Authentication and is deleted when you ask us to delete it. The invoices Stripe issued for your subscription remain at Stripe, and in our accounting records, for the six years UK tax law requires. |
| Connection credentials — your Slack bot token, your GitHub App installation id, and any credential you issue for a tool of your own. | To post reports to your channel, read repository metadata, and call the tools you connect. | Held in Secret Manager (clause 7). Destroyed with your tenant. |
Categories of data subject: your personnel who use the console, and any individual whose personal data happens to appear in the telemetry we read.
Duration: for as long as your subscription is active, plus the deletion period in clause 9.
3. Our instructions are your instructions
We process personal data only on your documented instructions, which are these terms and your use of the product — the projects you connect, the channel you choose, the repositories you install us on. If we believe an instruction breaches data protection law we will tell you and may pause that processing rather than carry it out.
We will not use your telemetry, your reports or your transcripts to train a general-purpose model, ours or anyone else's, and we do not sell data.
4. Confidentiality
Everyone with access to your data is bound by a duty of confidentiality that survives the end of their engagement. Today that is a small, named group; access is granted per secret rather than per project, so no part of our system holds a blanket right to read customer credentials.
5. Security
The measures we take under Article 32 are the architecture, not a policy document:
- Read-only access, granted by you. Four Google-managed viewer roles on the projects you name and, per service and only if you choose to grant it, one custom role defined in your own project whose permissions are all
getorlist. Nodrik holds no role that could change anything in your infrastructure. - No telemetry at rest. We reach into your project at the moment of an alert and keep no copy.
- One identity per customer. Each tenant has a dedicated service account; no shared credential can cross a customer boundary.
- Per-secret access control. Your credentials are readable only by the services that need that specific secret.
- Redaction of report and transcript content before it is stored.
- Encryption in transit and at rest, using Google Cloud's managed encryption.
6. Sub-processors
You give general authorisation for the sub-processors below. We will give you at least30 days' notice by email before adding or replacing one, and you may terminate without penalty if you object.
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud Platform | Hosting, storage, sign-in, secret management, and documentation search during an investigation (a short query against Google's own documentation, and the pages it returned — no telemetry) | Firestore and Cloud Run in europe-west1 (Belgium); Secret Manager and Firebase Authentication under Google's own replication (clause 7); the documentation search API's serving region is not published by Google |
| Google Cloud Vertex AI | Model inference during an investigation | Vertex AI's global endpoint (clause 7) |
| Slack Technologies | Delivering the report to your workspace, and the follow-up questions and button presses you send back | United States |
| GitHub | Commit and diff metadata and source files, only if you install our app | United States |
| Cloudflare | Static hosting and request forwarding for our web surfaces; bot verification (Turnstile) on the signup form; cookieless page analytics on nodrik.dev | Global edge |
| Resend | Transactional email | United States |
| Stripe | Payment processing | United States / Ireland |
7. International transfers
Where your data sits depends on the Google service holding it, so we state it service by service rather than as one region:
- Firestore and Cloud Run — europe-west1 (Belgium). Your reports, transcripts, tenant record, notifications, mutes, grant history and workspace audit log are stored in Firestore in europe-west1, and every Nodrik service and job runs there.
- Secret Manager — Google-managed replication. Your connection credentials are held in Secret Manager secrets created with Google's automatic replication policy, which stores them in regions Google chooses rather than in one we pin.
- Firebase Authentication — United States. Sign-in identities (name, email, provider identifier) are held by Firebase Authentication, which Google operates from the United States.
- Pub/Sub — no region pin. The alert notifications your Cloud Monitoring policies send us transit Pub/Sub topics in our project that carry no message storage policy, so a notification may be held in any Google region while in transit.
- Vertex AI — global endpoint. Model inference uses Vertex AI's global endpoint, so the redacted telemetry excerpts in every model request may be processed outside the EEA. Nothing is stored there.
Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and on the transfer terms in our own agreements with the sub-processors above.
8. Helping you meet your obligations
- Data subject requests. Because we store almost nothing, most requests are answered from your own systems. Where a request reaches data we hold, we will help you respond within 10 working days of you asking.
- Breach notification. We will tell you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it.
- Impact assessments. We will give you the information you reasonably need for a DPIA or a consultation with a supervisory authority.
9. Deletion
When your subscription ends, or when you ask us to remove your tenant, we delete your service account, your topic and subscription, your stored credentials, and your investigation reports and transcripts within 30 days.
We also revoke our access at the source rather than only deleting our copy of it: our Slack app is uninstalled from your workspace and our GitHub App installation is deleted. You do not have to do either yourself, and you do not have to run the revoke script for any of this to happen — that script removes the permissions you granted in your own Google Cloud project, which is the one part we cannot reach once our service account is gone.
The invoices Stripe issued for your subscription are kept, at Stripe and in our accounting records, for the six years tax law requires. Your sign-in identity in Firebase Authentication is deleted when you ask us to delete it (clause 2). Backups cycle out on their own schedule and are not restored selectively; anything still present in a backup remains subject to this agreement until it expires.
10. Audits
We will make available the information you reasonably need to verify our compliance with this agreement, and will answer a security questionnaire once in any twelve-month period. We do not currently hold ISO 27001 or SOC 2, and will say so rather than imply otherwise.
11. Liability and precedence
Liability under this agreement is subject to the limits in the terms of service. Where this agreement and those terms conflict on the processing of personal data, this agreement wins.
Contact
Data protection questions, requests and breach reports:support@nodrik.dev. Thoughtgears Ltd, registered in England and Wales.