Skip to content
Agent view: plain rendering of this page's content, without interface illustrations.Machine-readable index

Legal

Data Processing Addendum (DPA)

ArchivedVersion 2.2Published: 1 February 2026Effective from: 1 February 2026

PERSONAL DATA TRANSMISSION AND PROCESSING ANNEX

Version [2.2] — Publication date: 01/02/2026

This DPA supplements the Master Services Agreement (MSA) entered into between the SERVICE PROVIDER and the SERVICE RECIPIENT. When active, it constitutes the Personal Data transmission agreement between the Controller and the Processor under Law 1581 of 2012 and Decree 1074 of 2015 (which compiled Decree 1377 of 2013). Capitalized terms not defined here have the meaning given to them in the MSA.

1. ACTIVATION AND PURPOSE

1.1. Conditional activation. This DPA will enter into force and be binding only if, and to the extent that, the SERVICE PROVIDER processes Personal Data on behalf of and under the instructions of the SERVICE RECIPIENT in connection with the Services of a Service Order, in accordance with clauses 8.1, 8.3 and 8.4 of the MSA.

1.2. Purpose. To set out the conditions and the security, confidentiality and legal compliance obligations applicable to the Processing of such Personal Data.

1.3. Applicable law. “Data Protection Law” means Law 1581 of 2012, Decree 1074 of 2015, the instructions of the Superintendence of Industry and Commerce (SIC) and the rules amending or replacing them, as well as the laws of other jurisdictions that apply under the Annexes activated in accordance with clause 14.

2. DEFINITIONS

For the purposes of this DPA: Data Subject is the natural person whose Personal Data are Processed; Processing is any operation on Personal Data, such as collection, storage, use, circulation or deletion; Controller is whoever decides on the database or the Processing; Processor is whoever carries out the Processing on behalf of the Controller; Transmission is the communication of Personal Data to the Processor, inside or outside Colombia, so that it processes them on behalf of the Controller; Sub-processor is the third party engaged by the Processor to carry out part of the Processing; and Security Incident is the breach of security codes or the loss, theft or unauthorized access to the Personal Data processed under this DPA.

3. ROLES OF THE PARTIES

3.1. Roles. With respect to the Personal Data processed under this DPA, the SERVICE RECIPIENT acts as Controller and the SERVICE PROVIDER as Processor.

3.2. Controller’s obligations. The SERVICE RECIPIENT warrants that: (a) it holds the Data Subjects’ authorization or another legal basis for the Processing and the Transmission; (b) it informed the Data Subjects of the purposes of the Processing; (c) it has an information processing policy and, where applicable, has registered its databases in the National Database Registry; and (d) its instructions are lawful.

4. INSTRUCTIONS AND SCOPE OF PROCESSING

4.1. Instructions. The SERVICE PROVIDER will process the Personal Data exclusively to provide the Services described in the Service Order and in accordance with the SERVICE RECIPIENT’s documented instructions, including those contained in the Contract. It will not process them for other or its own purposes. If it considers that an instruction infringes Data Protection Law, it will inform the SERVICE RECIPIENT.

4.2. Description of the Processing. For the Managed Git Organizations Service, the Processing is described in Annex 1. For other Services, or when the Service Order extends that description, the types of Personal Data, categories of Data Subjects, purposes, processing operations, duration, location and Sub-processors are described in the Processing Description Annex to the Service Order.

4.3. Sensitive data and data of minors. The SERVICE RECIPIENT will not supply sensitive data or data of children or adolescents, unless the Service Order expressly provides for it together with the appropriate additional protection measures.

5. PROCESSOR’S OBLIGATIONS

The SERVICE PROVIDER undertakes to:

(a) process the Personal Data in accordance with the principles of Law 1581 of 2012 and comply with the duties that article 18 of that law imposes on Processors;

(b) ensure that the personnel authorized to process the Personal Data are subject to confidentiality obligations, contractual or statutory, and have received adequate training;

(c) apply the security measures set out in clause 6;

(d) not disclose the Personal Data to third parties, except to Sub-processors authorized under clause 7 or when required by law or a competent authority;

(e) allow access to the Personal Data only to the persons who need it to provide the Services;

(f) refrain from circulating information that is being disputed by the Data Subject and whose blocking has been ordered by the SIC; and

(g) cooperate with the SERVICE RECIPIENT in handling Data Subjects’ rights and authorities’ requests, in accordance with clauses 9 and 10.

6. SECURITY MEASURES

The SERVICE PROVIDER will implement and maintain appropriate technical, human and administrative measures to protect the Personal Data against alteration, loss, consultation, use or unauthorized or fraudulent access, which will include at a minimum: (a) encryption of data in transit and, where the SERVICE PROVIDER stores them, at rest; (b) access control based on the principle of least privilege, with named accounts; (c) multi-factor authentication for all administrative access; (d) recording and retention of access logs; (e) vulnerability management and timely patching; (f) separation of environments; (g) incident management procedures; and (h) periodic staff training. The SERVICE PROVIDER will make a description of these measures available to the SERVICE RECIPIENT upon request.

7. SUB-PROCESSORS

7.1. General authorization. The SERVICE RECIPIENT grants a general authorization for the SERVICE PROVIDER to engage Sub-processors. The current list is published at [URL] or included in the Processing Description Annex. The SERVICE PROVIDER will impose on each Sub-processor data protection obligations substantially equivalent to those in this DPA and will be liable for their compliance.

7.2. New Sub-processors. The SERVICE PROVIDER will give [thirty (30)] calendar days’ notice of any addition or replacement of Sub-processors. The SERVICE RECIPIENT may object on reasonable grounds related to data protection within [fifteen (15)] calendar days. The Parties will seek a solution in good faith; if they do not reach one, the SERVICE PROVIDER may (a) offer the Service without the objected Sub-processor, with the corresponding price adjustments; or (b) either Party may terminate the affected part of the Service, with a pro rata refund of amounts prepaid and unused.

7.3. Platforms contracted by the SERVICE RECIPIENT. Third-Party Platforms that the SERVICE RECIPIENT contracts directly, such as its Git platform or its Artificial Intelligence model provider when it uses its own keys, are not Sub-processors of the SERVICE PROVIDER. The Processing relationship with those third parties exists directly between them and the SERVICE RECIPIENT.

8. INTERNATIONAL TRANSMISSIONS

The SERVICE RECIPIENT authorizes Transmissions of Personal Data to the countries listed in the Processing Description Annex. The SERVICE PROVIDER will ensure that every international Transmission it or its Sub-processors carry out has the safeguards required by Data Protection Law. The SERVICE RECIPIENT will ensure that it holds the Data Subjects’ authorizations necessary for such Transmissions.

9. DATA SUBJECTS’ RIGHTS

The SERVICE PROVIDER will assist the SERVICE RECIPIENT, to the extent technically possible, in handling the exercise of Data Subjects’ rights to know, update, rectify and delete their data, revoke their authorization and access their Personal Data free of charge. To that end: (a) it will forward to the SERVICE RECIPIENT, within [two (2)] business days of receipt, any query or complaint it receives directly from a Data Subject, without answering it unless instructed by the SERVICE RECIPIENT; and (b) it will provide the information or take the actions requested by the SERVICE RECIPIENT within [five (5)] business days, so that the latter can respond within the legal terms of ten (10) business days for queries and fifteen (15) business days for complaints.

10. SECURITY INCIDENTS

10.1. Notification. The SERVICE PROVIDER will notify the SERVICE RECIPIENT in writing, without undue delay and no later than forty-eight (48) hours after becoming aware of a Security Incident affecting the Personal Data processed under this DPA.

10.2. Content. The notification will include, to the extent available: the nature of the incident, the categories and approximate number of Data Subjects and records affected, its likely consequences, the containment and mitigation measures taken or proposed, and a point of contact. Information not initially available will be provided progressively.

10.3. Cooperation with authorities. The SERVICE PROVIDER will support the SERVICE RECIPIENT in the reports and communications it must make to the SIC and, when it is subject to the supervision of another authority, such as the Financial Superintendence of Colombia, to that authority, within the terms set by applicable regulation, as well as in any communication to Data Subjects. Where the SERVICE RECIPIENT’s sector regulation requires shorter notification periods, additional content or other obligations, these will be set out in a Regulatory Requirements Annex incorporated into the Service Order, and the SERVICE PROVIDER will comply with them to the extent technically and reasonably feasible. The SERVICE PROVIDER will not notify Data Subjects or authorities on behalf of the SERVICE RECIPIENT without its instruction, unless required by law.

11. VERIFICATION AND AUDIT

The SERVICE PROVIDER will make available to the SERVICE RECIPIENT the information reasonably necessary to demonstrate compliance with this DPA, through questionnaires, certifications or reports. If that information proves insufficient, the SERVICE RECIPIENT may carry out, by itself or through an independent auditor bound by confidentiality, one audit per twelve (12) month period, with [fifteen (15)] business days’ prior notice, at its own cost and without compromising the security or confidentiality of the SERVICE PROVIDER’s other clients. Additional audits may be carried out in the event of a Security Incident or at the request of a competent authority.

12. RETURN AND DELETION OF DATA

Upon termination of the Service Order that gave rise to the Processing, or when the Personal Data are no longer necessary to provide the Services, the SERVICE PROVIDER, at the SERVICE RECIPIENT’s choice communicated within [fifteen (15)] calendar days after termination, will return the Personal Data in a standard format or securely delete them within [thirty (30)] calendar days. Absent a choice, it will delete them. At the SERVICE RECIPIENT’s request, it will issue a certificate of deletion. Data whose retention is required by law are excepted and will remain protected under this DPA. Copies in backup systems will be deleted in the ordinary rotation cycles, not exceeding [ninety (90)] calendar days.

13. LIABILITY AND PRECEDENCE

13.1. Liability. The Parties’ liability under this DPA is governed by clause 12 of the MSA, including the special cap in its clause 12.3. The SERVICE RECIPIENT will hold the SERVICE PROVIDER harmless against claims and sanctions arising from the lack of Data Subjects’ authorization or from unlawful instructions.

13.2. Term and precedence. This DPA will remain in force for as long as the SERVICE PROVIDER processes Personal Data on behalf of the SERVICE RECIPIENT and its obligations will survive until the data are returned or deleted. With respect to the Processing of Personal Data, this DPA prevails over the Service Order and the MSA, without prejudice to clause 14.2.

14. JURISDICTION ANNEXES

14.1. Activation. When data protection laws other than Colombian law apply to the Processing, the corresponding Annexes will apply in addition to this DPA: Annex 2 (European Union and European Economic Area), Annex 3 (United Kingdom), Annex 4 (Brazil) and Annex 5 (United States of America). The Service Order will state the Annexes activated, without prejudice to an Annex applying whenever the corresponding law applies.

14.2. Precedence. In the event of conflict, the Annex for the relevant jurisdiction will prevail and, within it, the standard contractual clauses it incorporates.

14.3. Law applicable to the standard clauses. The standard contractual clauses incorporated in the Annexes will be governed by the law and jurisdiction they themselves establish, as an exception to clause 18 of the MSA.

ANNEX 1 — STANDARD DESCRIPTION OF THE PROCESSING: MANAGED GIT ORGANIZATIONS SERVICE

Types of Personal Data Names, usernames, email addresses, profile photos, team membership and roles, commit metadata (author, email and date), audit and access logs (including IP addresses) and Personal Data incidentally contained in code, issues or pull requests.
Categories of Data Subjects Employees, contractors, outside collaborators and guests of the SERVICE RECIPIENT with access to the managed organizations.
Purposes Access and permissions administration; platform operation and support; security and audit; deployment control, when contracted.
Processing operations Consultation, organization, modification of permissions, temporary storage in support tools and deletion.
Duration Term of the Service Order and the deletion period in clause 12.
Location That of the SERVICE RECIPIENT’s Git platform and that of the SERVICE PROVIDER’s Sub-processors.
Sub-processors [List or URL]
Sensitive data or data of minors Not envisaged.

ANNEX 2 — EUROPEAN UNION AND EUROPEAN ECONOMIC AREA

A2.1. Application and roles. This Annex applies when Regulation (EU) 2016/679 (GDPR) applies to the Processing. For the purposes of the GDPR, the SERVICE RECIPIENT acts as controller and the SERVICE PROVIDER as processor.

A2.2. Article 28 of the GDPR. The obligations in this DPA will be interpreted in accordance with article 28 of the GDPR. In particular, the SERVICE PROVIDER will: (a) process the data only on documented instructions, including with regard to international transfers; (b) immediately inform the SERVICE RECIPIENT if an instruction infringes the GDPR; (c) apply the measures in article 32 of the GDPR, described in clause 6; (d) assist the SERVICE RECIPIENT in complying with articles 32 to 36 of the GDPR, including impact assessments and prior consultations; and (e) notify personal data breaches in accordance with clause 10, so that the SERVICE RECIPIENT can meet the seventy-two (72) hour deadline in article 33 of the GDPR.

A2.3. Transfers. Colombia does not have an adequacy decision from the European Commission. Transfers of Personal Data from the European Union or the European Economic Area to the SERVICE PROVIDER will be governed by the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (the “SCCs”), module two (controller to processor), which are incorporated by reference with the following choices: (a) clause 7 is included; (b) clause 9, option 2 (general authorization), with the notice period in clause 7.2 of this DPA; (c) the option in clause 11 is not included; (d) clause 13: the supervisory authority will be the one determined under that clause; (e) clauses 17 and 18: the SCCs will be governed by the law of [Ireland] and disputes will be submitted to the courts of [Ireland]; and (f) annex I of the SCCs is deemed completed with the Service Order and the applicable description of the Processing, annex II with clause 6 of this DPA and annex III with the list of Sub-processors in clause 7.

A2.4. Precedence. In the event of conflict between the SCCs and any other document of the Contract, the SCCs will prevail.

A2.5. Representative. [If the SERVICE PROVIDER is required to appoint a representative in the Union under article 27 of the GDPR, its details will be published at the web address indicated by the SERVICE PROVIDER.]

ANNEX 3 — UNITED KINGDOM

This Annex applies when the UK GDPR and the Data Protection Act 2018 apply. Transfers from the United Kingdom will be governed by the SCCs on the terms of Annex 2, supplemented by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner’s Office (version B1.0), which is incorporated by reference. Tables 1 to 3 of the Addendum are deemed completed with the information in Annex 2 and the Service Order; in table 4, [neither Party] may terminate the Addendum under its section 19.

ANNEX 4 — BRAZIL

This Annex applies when the Lei Geral de Proteção de Dados Pessoais (Law 13,709 of 2018, “LGPD”) applies. The SERVICE RECIPIENT acts as controller and the SERVICE PROVIDER as operator. International transfers will be governed by the standard contractual clauses approved by the National Data Protection Authority (ANPD) [through Resolution CD/ANPD No. 19 of 2024], which are incorporated by reference, or by the mechanism recognized by the ANPD from time to time. Data subjects’ rights and incident notification will be handled within the deadlines of the LGPD and ANPD regulations.

ANNEX 5 — UNITED STATES OF AMERICA

This Annex applies when the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), or other U.S. state privacy laws apply. The SERVICE PROVIDER acts as a “service provider” or “processor”, as applicable, and: (a) will not sell or share the personal information; (b) will not retain, use or disclose it for purposes other than providing the Services or outside the direct business relationship with the SERVICE RECIPIENT; (c) will not combine it with personal information received from other sources, except as permitted by law; (d) will provide the level of protection required by those laws; (e) will notify the SERVICE RECIPIENT if it determines it can no longer meet these obligations; and (f) acknowledges the SERVICE RECIPIENT’s right to take reasonable steps to stop and remediate unauthorized use. The SERVICE PROVIDER certifies that it understands and will comply with these restrictions.