Data Processing Agreement
Last updated: June 12, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Scanara UG (haftungsbeschränkt), represented by its managing director ("Processor", "we", "us") and the customer organization ("Controller", "you") for the use of the Scanara EU AI Act compliance platform (the "Service").
This DPA applies where and to the extent that Scanara processes personal data on behalf of the Controller in the course of providing the Service, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Scope of Processing
1.1 Subject Matter
The processing concerns the provision of the Scanara compliance platform, which analyzes source code repositories and documentation for EU AI Act compliance. Processing occurs when the Controller connects repositories, initiates scans, manages team members, and generates compliance documentation.
1.2 Categories of Data Subjects
- Employees and contractors of the Controller who use the Service
- Third parties whose personal data may be contained in scanned repositories or documentation (incidental processing)
1.3 Types of Personal Data
- Account data: name, email address, organization membership
- Authentication data: identity claims from SSO providers, session tokens
- Usage data: scan history, feature usage, timestamps
- Repository metadata and scan results: repository names, file paths, scan findings including short source code excerpts (flagged lines plus their immediate context)
- Incidental data in scanned code or documents (e.g., author names, comments containing personal data)
1.4 Duration
Processing continues for the duration of the service agreement. Upon termination, personal data is deleted within 30 days unless retention is required by law or by the Controller's documented instructions for audit trail retention. Audit trail records are anonymized upon contract termination so that they can no longer be attributed to the Controller (see § 5a of the Terms of Service). This 30-day period also constitutes the maximum transition period pursuant to Art. 25 of Regulation (EU) 2023/2854 (Data Act), enabling data export in accordance with § 5b of the Terms of Service. Where the Controller makes use of switching support under § 5b of the Terms of Service, retention of the exported data is extended by the retrieval period of at least 30 calendar days after the end of the transition period (Art. 25(2) Data Act); deletion takes place without undue delay after expiry of this retrieval period.
Upon written request by the Controller, Scanara will provide written confirmation of data deletion within 14 days of completion of the deletion process.
2. Obligations of the Processor
Scanara, as Processor, shall:
- Process personal data only on documented instructions from the Controller, unless required to do so by EU or Member State law. In such a case, Scanara shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
- Immediately inform the Controller if, in Scanara's opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (Art. 28(3), second sentence, GDPR).
- Ensure that persons authorized to process personal data have committed themselves to confidentiality. This confidentiality obligation survives termination of this DPA.
- To the extent that scanned source code contains trade secrets of third parties within the meaning of Art. 2(1) of Directive (EU) 2016/943 (Trade Secrets Directive), Scanara shall use such information exclusively for the performance of the assignment. No disclosure to third parties, use for own business purposes, or use for training AI systems shall take place.
- Implement appropriate technical and organizational security measures in accordance with Article 32 GDPR.
- Engage sub-processors only with prior general authorization and a written contract imposing equivalent data protection obligations.
- Assist the Controller in fulfilling its obligations regarding data subject requests, data protection impact assessments, and prior consultations with supervisory authorities. Assistance with data protection impact assessments (Art. 35 GDPR) and prior consultations (Art. 36 GDPR) includes in particular providing documentation of technical and organizational measures, information on the nature and scope of processing, and technical opinions — in each case within 20 business days of a written request by the Controller. Assistance exceeding a reasonable scope of 8 hours per calendar year may be charged by Scanara at reasonable, customary rates after prior notice; statutory assistance obligations remain unaffected.
- Delete or return all personal data at the end of the service agreement, at the Controller's choice.
- Make available all information necessary to demonstrate compliance and allow for audits.
2a. Documented Instructions
The Controller's documented instructions to the Processor within the meaning of Art. 28(3)(a) GDPR are derived from:
- The Provider's Terms of Service (AGB) in their respectively applicable version;
- The Service Description in its respectively applicable version;
- The Controller's active use of the platform's functionality (in particular: connecting repositories, initiating scans, managing team members, generating compliance documentation);
- Individual written instructions from the Controller, where agreed.
The Controller may issue additional or amended instructions in text form at any time. Instructions that go beyond the agreed scope of services are treated as change requests and may incur additional costs.
Only persons designated by the Controller as organization administrators or owners in the platform are authorized to issue instructions. Scanara is not required to follow instructions from other persons and will inform the Controller of any such attempted instructions.
2b. Deletion and Return
The Processor shall delete or return all personal data upon termination of the service agreement within 30 days and provide written confirmation of complete deletion within 14 days of completion (Art. 28(3)(g) GDPR). For sub-processors (§ 4), Scanara shall actively obtain and document deletion confirmation (see German Federal Court of Justice, judgment of 11 November 2025 — VI ZR 396/24 — active verification of deletion required).
2c. Obligations of the Controller
Within the scope of this DPA, the Controller is solely responsible for the lawfulness of the processing, in particular for the existence of a legal basis for the processing of personal data contained in the repositories and documentation it connects, and for the lawfulness of the instructions it issues. The Controller shall ensure that connecting repositories and initiating scans does not violate third-party rights or statutory processing prohibitions.
3. Technical and Organizational Measures
Scanara implements the following measures to protect personal data:
- Encryption: All data encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access control: Role-based access control with multi-tenant isolation at the application and database level. Every org-scoped record is tied to an
organization_id. - Authentication: AWS Cognito; Cognito supports MFA (optional for users, software-token TOTP; enforcing mode configurable for administrators), OIDC, and SAML enterprise SSO.
- Infrastructure: All infrastructure hosted in AWS eu-west-1 (Dublin, Ireland), managed via Infrastructure as Code (Terraform). No ad-hoc resources.
- Secrets management: All secrets stored in AWS Secrets Manager. No plaintext credentials in application code or configuration.
- Audit trail: Immutable, WORM-compliant audit trail for all compliance-relevant operations.
- Logging: Structured logging with no personally identifiable information in log output.
- Vulnerability management: Automated dependency scanning and regular security assessments.
- Availability and resilience: Automated database backups with defined retention periods, multi-AZ-capable infrastructure, and documented recovery procedures to restore availability promptly after an incident (Art. 32(1)(b), (c) GDPR).
- Effectiveness review: Regular testing, assessment, and evaluation of the effectiveness of the technical and organizational measures (Art. 32(1)(d) GDPR).
- Scan isolation: Repository contents are processed exclusively transiently in the RAM of the scan Lambda function during the scan; no full copy of the repository is persisted. Scan results (findings, scores) are stored, including short source code excerpts (the flagged lines plus their immediate context) as part of the findings; these are subject to the agreed retention periods. Beyond this, no code contents are persisted in databases, object storage, or log files.
The complete, versioned TOM list and AWS Shared Responsibility Mapping are documented in Annex 1 to this DPA and are available upon request.
4. Sub-processors
The Controller provides general authorization for Scanara to engage the following sub-processors. Scanara will notify the Controller of any intended changes to the sub-processor list at least 30 days prior to the change, giving the Controller an opportunity to raise a reasoned objection in text form (§ 126b German Civil Code — email suffices) within that period.
If the Controller raises a reasoned objection and the parties cannot reach agreement, the Controller is entitled to terminate the main agreement by written notice with 30 days' effect. Until termination takes effect, Scanara will provide the Service without the objected sub-processor to the extent technically feasible.
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud infrastructure: compute (Lambda, ECS, App Runner), storage (S3, RDS PostgreSQL), authentication (Cognito), workflow orchestration (Step Functions), transactional email delivery (SES), content delivery (CloudFront) | EU (Dublin, eu-west-1); CloudFront edge locations in the EU and North America | DPA with Amazon Web Services EMEA SARL; primary processing exclusively in the EU; SCCs incorporated in the AWS DPA serve as fallback safeguard for any incidental edge or support access from third countries |
| GitHub, Inc. (Microsoft) | Source code access via OAuth (initiated by Controller), merge gate integration (Checks API) | US | EU-US Data Privacy Framework (DPF) + SCC Module 3, DPA |
Note: Google Analytics (GA4) and Microsoft Clarity are used on the marketing website only, require user consent, and do not process data covered by this DPA. Stripe Payments Europe, Ltd. acts as an independent data controller for payment data (not a sub-processor) and is therefore not covered by this DPA.
5. International Transfers
All primary data processing occurs within the EU (AWS eu-west-1, Dublin). Where personal data is transferred to sub-processors outside the EEA (GitHub), the following safeguards apply:
- Standard Contractual Clauses (SCCs): Module 3 (Processor to Sub-Processor) SCCs adopted by the European Commission Decision (EU) 2021/914 are incorporated by reference.
- Supplementary measures: Encryption in transit and at rest, access controls, and contractual restrictions on data access by third-country authorities.
- Transfer Impact Assessment: Available upon request for each sub-processor.
6. Data Subject Requests
If Scanara receives a request from a data subject regarding personal data processed on behalf of the Controller, Scanara will promptly redirect the data subject to the Controller and notify the Controller of the request. Scanara will assist the Controller in responding to data subject requests to the extent technically feasible.
7. Data Breach Notification
Scanara will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will include, to the extent available at the time of notification: the nature of the breach, categories of data affected, approximate number of data subjects, likely consequences, and measures taken or planned to address the breach. Where information is not yet fully available at the time of initial notification, Scanara will provide it without undue delay thereafter.
Note: As Processor, Scanara is obligated to notify the Controller without undue delay. The Controller's own obligation to notify the supervisory authority within 72 hours under Article 33 GDPR remains the Controller's sole responsibility.
8. Audit Rights
Scanara will make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller. Audit requests must be submitted in writing with at least 10 business days' advance notice. Audits shall be conducted during normal business hours (Mon–Fri, 09:00–17:00 CET), shall not unreasonably disrupt Scanara's operations, and are limited to one audit per calendar year unless there is substantiated cause for an additional audit.
Audits shall primarily be satisfied through the provision of meaningful documentation (in particular Annex 1, TOM evidence, and any existing audit reports or certifications); an on-site inspection takes place only where the documentation provided is insufficient in the individual case. A mandated auditor must not be a competitor of Scanara and must be bound to confidentiality before the audit begins. Each party bears its own costs in connection with an audit.
9. Conclusion of the DPA
This DPA is concluded in electronic form upon acceptance of the Terms of Service (Art. 28(9) GDPR) and applies to all plans, including free use. No separate execution is required.
For B2B customers on Team, Business, or Enterprise plans, a signed copy of this DPA is additionally available upon request:
- Email: support@scanara.io
- Response time: We aim to provide a signed DPA within 5 business days.
- Custom DPA addenda: Enterprise customers may request custom DPA addenda for specific regulatory requirements.
10. Liability
Scanara's liability under this DPA is governed by the liability provisions in § 9 of the Terms of Service (AGB). The liability limitations and exclusions set out therein apply correspondingly to all claims arising from or in connection with this DPA, including claims for breach of data protection obligations, to the extent permitted by applicable law. Claims under this DPA and under the Terms of Service count toward a single aggregate liability cap; the caps do not apply cumulatively.
As between the parties, each party is liable in proportion to its share of responsibility for the damage (reflecting Art. 82(5) GDPR). The Controller shall indemnify Scanara against third-party claims to the extent they arise from (a) unlawful instructions issued by the Controller or (b) personal data introduced into the repositories or documentation connected by the Controller without a sufficient legal basis, where Scanara processed such data in accordance with instructions.
Note: Liability under Art. 82 GDPR cannot be excluded by contractual agreement (mandatory law). The above liability limitations do not affect claims by data subjects under Art. 82 GDPR against the Controller or the Processor.
11. Governing Law and Jurisdiction
This DPA is governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG). Applicable data protection law of the European Union, in particular the GDPR and the BDSG, remains unaffected.
The exclusive place of jurisdiction for all disputes arising from or in connection with this DPA is Munich, Germany, provided the Customer is a merchant (Kaufmann) within the meaning of the German Commercial Code (HGB), a legal entity under public law, or a special fund under public law.
For customers established in another EU or EEA Member State acting in the exercise of their commercial or independent professional activity, Munich is also agreed as the place of jurisdiction. Mandatory consumer protection rights applicable in the Customer's country of establishment within the EU are not affected by this jurisdiction clause.
The contract may be concluded in German or English (§ 3 of the Terms of Service). English translations are provided for informational purposes only; in case of dispute, the German version shall prevail (§ 24 of the Terms of Service).
12. Contact
Data Protection Contact: support@scanara.io DPA requests: support@scanara.io Enterprise sales: support@scanara.io