All legal documents

Data protection

Data Processing Addendum

Controller-to-processor terms for personal data customers submit to Mateality Releases.

Effective and last updated July 28, 2026

1. Scope and incorporation

This Data Processing Addendum (“DPA”) forms part of the Terms and Conditions or other agreement governing a customer’s use of Releases (“Agreement”). It applies where Mateality processes personal data on behalf of the customer in Customer Content or through customer-configured release delivery. Customer is the controller and Mateality is the processor, except where either party acts as a processor for another controller.

Capitalized terms not defined here have the meanings in the Agreement. “Data Protection Law” includes the GDPR, UK GDPR, ePrivacy rules, and other privacy laws applicable to the processing.

2. Details of processing

  • Subject matter and purpose: hosting, securing, managing, publishing, and delivering customer software releases, metadata, domains, support materials, and related usage reporting.
  • Duration: the term of the Agreement plus the limited deletion, backup, security, and legal-retention periods described in the Privacy Policy.
  • Data subjects: customer personnel, collaborators, application end users, downloaders, support contacts, and other people whose data the customer submits.
  • Data types: identifiers, contact and account data, online identifiers, coarse location, device and request data, release metadata, support content, and any personal data included by the customer in uploaded files or notes.
  • Sensitive data: not intended for the service. Customer must not submit special-category, criminal-offence, health, biometric, government-ID, financial-account, or children’s data unless expressly agreed in writing with appropriate safeguards.

3. Customer instructions and duties

Mateality will process customer personal data only on documented instructions in the Agreement, product configuration, support requests, and this DPA, including transfers, unless law requires otherwise. If legally allowed, we will inform the customer before legally required processing. We will notify the customer if we believe an instruction violates Data Protection Law.

Customer is responsible for lawful instructions, notices, legal bases, data minimization, accuracy, responding to data subjects, and ensuring its application and release content comply with law.

4. Confidentiality and security

Personnel authorized to process customer personal data are bound by confidentiality. Mateality maintains measures appropriate to risk, including access control and least privilege, tenant authorization, transport encryption, encryption at rest for stored artifacts, hashed API credentials, secure development practices, logging, rate limiting, backup controls, vulnerability remediation, and incident-response procedures.

Customer remains responsible for secure endpoints, account roles, API-key rotation, application signing and verification, local backups, and avoiding personal data in public fields.

5. Subprocessors

Customer gives general authorization for the subprocessors listed in the Subprocessor List. Mateality remains responsible for subprocessor performance to the extent required by Data Protection Law and imposes materially equivalent data-protection obligations.

We will post a new subprocessor at least 15 days before it begins materially processing customer personal data where practicable. Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on a solution; if none is reasonably available, customer may stop the affected feature or terminate it and receive a prorated refund of prepaid, unused fees for that feature.

6. Assistance

  • Taking into account the nature of processing, we will provide reasonable assistance for access, deletion, correction, restriction, portability, and objection requests.
  • We will provide reasonable information for data-protection impact assessments and prior consultations applicable to the service.
  • We will notify customer without undue delay after confirming a personal-data breach affecting customer personal data and provide available information about its nature, likely consequences, affected data, mitigation, and contact point.
  • Assistance beyond standard product functionality may be charged at reasonable rates where allowed, especially when driven by customer configuration or unlawful instructions.

7. Deletion and return

During the subscription, customer may access and delete data using product features where available. On termination or written request, Mateality will delete or return customer personal data within a reasonable period, unless law requires retention. Encrypted backups are isolated from ordinary use and deleted on a rolling schedule; retained data remains protected and is used only for recovery, security, or legal compliance.

8. Audits and compliance information

On reasonable request, we will provide information necessary to demonstrate compliance with this DPA. If that information is insufficient, customer may conduct one audit per year through a mutually agreed independent auditor, on at least 30 days’ notice, during business hours, without accessing other customers’ data or creating security risk. Customer bears its audit costs unless the audit identifies a material breach by Mateality.

9. International transfers

For restricted transfers from the EEA to a country without an adequate level of protection, the 2021 European Commission Standard Contractual Clauses are incorporated by reference: Module Two applies for controller-to-processor transfers and Module Three for processor-to-processor transfers. The optional docking clause applies; Clause 9 uses Option 2 with the notice period in section 5; Clause 17 uses the law of Ireland; and Clause 18 selects the courts of Ireland.

For UK restricted transfers, the UK International Data Transfer Addendum is incorporated with the corresponding SCCs. For Swiss transfers, references are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority. The DPA and service documentation complete the SCC annexes. The SCCs prevail over conflicting terms.

10. Contact and precedence

Privacy and DPA notices should be sent to privacy@mateality.com. This DPA prevails over the Agreement for customer personal-data processing. The SCCs prevail over both where they apply. All other Agreement terms, including liability limits to the extent lawful, remain in effect.

Questions or notices

Start with the right contact.

Privacy requests: privacy@mateality.com. Security reports: security@mateality.com. Other legal notices: legal@mateality.com.

Contact legal
Next documentSubprocessor List