Back to PlanToCode

Legal document

Data Processing Addendum

Published version: July 25, 2026

Execution notice: This published text is not executed merely because a visitor opens this page or continues using PlanToCode. It applies only when the customer and helpful bits GmbH expressly accept it or incorporate it into another executed agreement. Contact Email to confirm the applicable version, controller/processor roles, and any region-specific terms before relying on it.

1. Definitions and Interpretation

This Data Processing Addendum ("DPA") supplements an agreement between helpful bits GmbH and the customer only when the parties expressly accept or incorporate it. References to "Controller" and "Processor" apply only where the applicable data-protection law assigns those roles to the parties for the processing at issue.

  • "Personal Data" means any information relating to an identified or identifiable natural person processed through the Service
  • "Processing" has the meaning given in the GDPR
  • "Data Protection Laws" means GDPR and any other applicable data protection legislation
  • "Sub-processor" means any third party engaged by Processor to process Personal Data

2. Processing of Personal Data

2.1 Processor's Obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country or an international organization, unless Union or Member State law to which the Processor is subject requires the Processing; in that case, inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest
  • Ensure persons authorized to process Personal Data are subject to confidentiality obligations
  • Implement appropriate technical and organizational measures per Article 32 GDPR
  • Comply with the conditions in Article 28(2) and (4) GDPR and Section 3 of this DPA when engaging another processor
  • Assist the Controller in responding to data subject rights requests
  • Assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the Processing and the information available to the Processor
  • At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of services relating to Processing, and delete existing copies, unless Union or Member State law requires storage of the Personal Data
  • Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller
  • Immediately inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other Union or Member State data-protection law

2.2 Details of Processing

Subject Matter: Coding-agent workspace, mobile companion, browser-assisted, transcription, review, account, billing, notification, and support services selected by the Customer

Duration: For the term of the Agreement

Nature and Purpose: Hosting, transmitting, storing, retrieving, and processing data as needed to provide the features requested by the Customer

Categories of Data: Account and device identifiers; project and workflow content; prompts, outputs, files, diffs, command output, browser results, audio, video, support content, notification tokens, and billing or entitlement records, depending on the selected feature

Categories of Data Subjects: Customer's employees, contractors, and end users

2.3 Controller's Obligations and Rights

The Controller shall ensure that the covered Processing, the Personal Data it provides, and its documented instructions comply with applicable Data Protection Laws. This includes lawfulness, accuracy, data minimization, an applicable lawful basis, and required notices to data subjects. The Controller shall provide the information and cooperation necessary for the Processor to perform its obligations under the executed DPA and shall not instruct the Processor to violate applicable law.

Subject to this DPA and applicable law, the Controller may issue documented instructions; receive the assistance and information described in this DPA; authorize sub-processors and object to intended changes under Section 3; conduct or mandate audits, including inspections; and choose deletion or return of Personal Data at termination.

3. Sub-processors

3.1 Authorized Sub-processors

By executing this DPA, the Controller gives the Processor general written authorization to engage the providers identified on the public provider list, solely to the extent they act as sub-processors for the covered Processing. The Processor shall not engage any other sub-processor without the Controller's prior specific or general written authorization. The list is available at plantocode.com/legal/eu/subprocessors. Whether a listed provider acts as a sub-processor, independent controller, or service provider depends on the feature and applicable agreement.

3.2 New Sub-processors

Under the general written authorization, the Processor shall inform the Controller in writing of any intended addition or replacement of a sub-processor before the change takes effect and shall give the Controller a reasonable opportunity to object to the intended change. The public provider list will also be updated.

3.3 Sub-processor Obligations and Liability

Where the Processor engages another processor to carry out specific Processing activities on behalf of the Controller, the Processor shall impose on that other processor, by contract or other legal act under Union or Member State law, the same data-protection obligations set out in this DPA, in particular sufficient guarantees that appropriate technical and organizational measures will be implemented so that the Processing meets GDPR requirements. If that other processor fails to fulfill its data-protection obligations, the Processor shall remain fully liable to the Controller for the performance of those obligations.

4. Security Measures

Security measures must be confirmed for the selected deployment in the executed DPA. The checked PlanToCode implementation supports these concrete controls:

  • HTTPS and WSS for supported production service paths; the checked Nginx configuration permits TLS 1.2 and TLS 1.3
  • Auth0-backed account access, authenticated relay connections, and server-side user or device authorization checks
  • Local desktop storage for workspace state and diagnostics
  • Operating-system credential storage or application encryption for selected local secrets where implemented; this is not a claim that every field uses AES-256
  • Data-minimizing mobile permissions and backup exclusions where implemented

This public page does not promise a particular audit cadence, penetration-test schedule, backup objective, staffing control, or certification. Any additional control must be recorded in an executed agreement.

5. International Transfers

Provider processing locations and transfer mechanisms vary by feature, account, provider, and contract. Any Standard Contractual Clauses, UK addendum, transfer-impact assessment, adequacy decision, or supplementary measure that the parties rely on must be identified in the executed DPA or applicable provider agreement. This public page does not, by itself, execute or populate Standard Contractual Clauses or establish that a transfer-impact assessment has been completed.

6. Data Breach Notification

Where helpful bits GmbH acts as Processor, it will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the processing covered by the executed DPA. Information will be supplied as it becomes available and as required by applicable law, including where available:

  • Nature of the breach and categories of data affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact point for more information

7. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

8. Liability and Indemnification

Each party's liability, remedies, and any indemnity are governed by the executed agreement and mandatory law. This public page does not create a separate uncapped or reciprocal indemnity.

9. Term and Termination

An executed DPA remains in effect while the covered Processing continues. At termination, the Processor shall, at the Controller's choice, delete or return all Personal Data to the Controller and delete existing copies, unless Union or Member State law requires storage of the Personal Data.

10. Governing Law

Governing law and forum are those stated in the executed customer agreement, subject to mandatory law. This public page does not select a different governing law or forum by itself.

Execution

Execution requires express acceptance or incorporation into another executed agreement. Continued use alone does not execute this DPA in the checked product flow.

Data Protection Contact: Email