1. Parties and scope
This Data Processing Agreement (the “DPA”) is entered into between [Customer legal name] (the “Customer”, acting as controller) and pgsenpai (the “Provider”, acting as processor). It forms part of the agreement under which the Provider analyses the performance of the Customer's PostgreSQL databases (the “Service”).
It applies to the extent the Provider processes personal data on behalf of the Customer in the course of providing the Service, and is intended to satisfy Article 28 of the GDPR and equivalent provisions of the UK GDPR and comparable laws.
2. Nature and purpose of the processing
The Provider connects to the database endpoints the Customer supplies, reads statistics about statements (pg_stat_statements, table and index statistics, execution plans) and produces reports. Statement text can contain literal values; execution plans can contain filter values. The Provider does not read table contents except where EXPLAIN (ANALYZE) is explicitly enabled by the Customer, and in that case only within transactions that are rolled back.
The purpose is limited to producing the reports, recommendations, trends and notifications the Customer requests through the Service.
3. Categories of data and data subjects
Account data: names, email addresses and hashed passwords of the Customer's staff who use the Service. Connection metadata: host names, ports, database and role names. Report contents: SQL text, execution plans and statistics from the Customer's databases, which may incidentally contain personal data of the Customer's own end users where it appears in statement literals.
Database passwords are used for the duration of a run and are not stored, except where the Customer explicitly saves a connection, in which case the password is stored encrypted.
4. Duration
Processing lasts for the term of the agreement. Report files are retained for the period the Customer selects in the Service (30, 90 or 365 days, or until deleted, subject to the Customer's plan) and removed thereafter as described in Section 9.
5. Obligations of the Provider
The Provider shall process personal data only on documented instructions from the Customer, which are given through the Service; ensure that persons authorised to process the data are bound by confidentiality; implement the technical and organisational measures in Section 7; assist the Customer with data subject requests and with its obligations under Articles 32 to 36 of the GDPR; and make available the information necessary to demonstrate compliance with this DPA.
6. Sub-processors
The Customer gives general authorisation for the Provider to use the sub-processors listed on the Provider's compliance page for hosting, object storage, transactional email and payments. The Provider shall inform the Customer of intended changes at least 30 days in advance, giving the Customer the opportunity to object.
Model providers used for optional AI recommendations are chosen and contracted by the Customer, who supplies its own API token; they are not sub-processors of the Provider.
7. Security measures
The Provider maintains the measures described on its security page at the time of processing, including: encryption in transit (TLS) and of stored secrets; hashed passwords; role-based access within organisations; read-only, time-limited database access; separation of customer report files by customer in object storage; and static security analysis of every change before deployment.
8. Personal data breach
The Provider shall notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Customer's data, at the contact address registered on the Customer's account, and shall provide the information reasonably required for the Customer to meet its own notification obligations.
9. Return and deletion
The Customer may delete any analysis, any saved connection or its whole account from within the Service at any time; deletion takes effect immediately in the Service. Copies of report files in object storage are removed under the Provider's storage lifecycle within 30 days of deletion or expiry, and from backups within 90 days.
On termination the Provider shall delete all personal data unless law requires its retention.
10. Audits
The Provider shall make available on request its most recent security documentation and, once obtained, its SOC 2 report. Where these do not reasonably satisfy the Customer, the Customer may audit the Provider once per year on 30 days' notice, at the Customer's cost, subject to reasonable confidentiality and scheduling constraints.
11. International transfers
Report files are stored in the region the Customer selects in the Service where the Provider offers a choice. Where personal data is transferred outside the region of origin, the parties rely on the European Commission's Standard Contractual Clauses (or the UK Addendum, as applicable), which are incorporated by reference.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the main agreement. In case of conflict, this DPA prevails over the main agreement with respect to the processing of personal data.
Questions about this DPA go to the contact address published on the site.
Signed for the Customer: ____________________ Date: __________
Signed for pgsenpai: ____________________ Date: __________