Privacy Policy

Data Processing Agreement (DevFlow)

Version 1.1 · Last updated: 2026-06-18

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the DevFlow Terms of Use between Fraway S.r.l. ("Fraway", the "Processor") and the customer (the "Customer", the "Controller"). It governs Fraway's processing of personal data contained in content the Customer submits to or connects with DevFlow ("Customer Content"), pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). It applies to the extent Fraway processes such personal data on the Customer's behalf. By accepting the DevFlow Terms of Use, the Customer enters into this DPA.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the meanings given in the GDPR.

"Customer Content" means task descriptions, prompts, chat messages, attachments, connected repository contents, source code and any data contained therein that the Customer submits to or connects with DevFlow.

"Sub-processor" means any third party engaged by Fraway to process Customer Content.

2. Roles, subject matter and details of processing

For personal data within Customer Content, the Customer is the controller and Fraway is the processor. The third-party AI/LLM and infrastructure providers engaged to perform the Customer's tasks act as sub-processors.

Subject matter and nature: provision of the DevFlow AI-assisted software-development service, including transmitting Customer Content to AI sub-processors so that automated agents can read, generate and modify source code in isolated working copies.

Purpose: performing the tasks the Customer submits and operating the service on the Customer's documented instructions.

Duration: for the term of the DevFlow Terms of Use, plus the retention and deletion periods set out in the Privacy Policy and in this DPA.

Types of personal data: any personal data the Customer chooses to include in Customer Content. Categories of data subjects: any data subjects whose personal data the Customer chooses to include. The Customer determines and controls both, and is advised not to include special categories of data (Art. 9 GDPR), data on criminal convictions (Art. 10 GDPR), or secrets and credentials.

3. Controller instructions

Fraway processes Customer Content only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by Union or Member State law (in which case Fraway informs the Customer before processing, unless that law prohibits it).

The Customer's instructions are constituted by the DevFlow Terms of Use, this DPA, the Privacy Policy and the Customer's configuration and use of the service (including the tasks, repositories and providers/models selected). Fraway informs the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law.

4. Confidentiality

Fraway ensures that persons authorised to process Customer Content are bound by an appropriate obligation of confidentiality and process the data only as instructed.

5. Security

Fraway implements appropriate technical and organisational measures pursuant to Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to data subjects. A description of the measures is set out in Annex 2.

6. No training on Customer Content

Fraway shall not, and shall require its sub-processors by contract not to, use Customer Content to train, fine-tune or improve any machine-learning model, except as strictly necessary to carry out the Customer's documented instructions. Fraway selects AI provider service tiers that disable provider-side training on Customer Content where such an option is offered.

7. Sub-processors

The Customer grants Fraway a general authorisation to engage the sub-processors listed in Annex 1, including the AI/LLM and infrastructure providers needed to deliver DevFlow.

Fraway imposes on each sub-processor, by contract, data protection obligations equivalent to those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Fraway remains fully liable to the Customer for the performance of each sub-processor's obligations.

Fraway informs the Customer of any intended addition or replacement of sub-processors at least 30 days in advance (by email to the registered address and/or in-product notice), giving the Customer the opportunity to object on reasonable, data-protection grounds. If an objection cannot be reasonably resolved, the Customer may terminate the affected part of the service.

8. Assistance with data subject rights

Taking into account the nature of the processing, Fraway assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights. Where a data subject contacts Fraway directly regarding Customer Content, Fraway refers them to the Customer.

9. Personal data breach

Fraway notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and provides the information reasonably available to enable the Customer to meet its obligations under Articles 33 and 34 GDPR.

10. Data protection impact assessment

Fraway assists the Customer, taking into account the nature of processing and the information available to Fraway, in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment and prior consultation).

11. International transfers

Where processing of Customer Content involves a transfer to a country outside the EEA, the transfer relies on an appropriate safeguard under Chapter V GDPR — an adequacy decision or the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) — flowed down to the relevant sub-processor. The Customer, as controller, authorises such transfers through its instructions and choice of providers/models.

For transfers by Fraway to sub-processors located outside the EEA, the applicable module of the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) is Module Three (processor-to-processor). Fraway flows these clauses (or an applicable adequacy decision) down to each such sub-processor, together with a transfer impact assessment where required. Where a Customer acts as controller from outside the EEA, Module Two applies to the Customer-to-Fraway transfer.

12. Return or deletion

At the Customer's choice, Fraway deletes or returns Customer Content after the end of the provision of the service, and deletes existing copies, unless Union or Member State law requires storage. Retention periods are set out in the Privacy Policy.

13. Audits and information

Fraway makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are subject to reasonable notice, confidentiality obligations, and reasonable frequency and scope so as not to disrupt the service.

14. Liability, precedence and governing law

In case of conflict between this DPA and the DevFlow Terms of Use regarding the processing of Customer Content, this DPA prevails. This DPA is governed by Italian law; the supervisory authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

Annex 1 — Sub-processors

Fraway engages the following sub-processors to process Customer Content, grouped by category. The current list is maintained by Fraway and available on request.

  • Infrastructure and hosting (within the EEA): Hetzner (Germany) for hosting and compute, including the isolated working copies; Google Cloud Storage (EU, europe-west) for encrypted backups; Amazon SES (Ireland) for authentication and transactional email.
  • Cloudflare, Inc. — DNS, CDN and WAF for the DevFlow application — USA — Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework where certified.
  • Repositories: GitHub (Microsoft), USA, for connecting and accessing the Git repositories you link — Standard Contractual Clauses (and EU–US Data Privacy Framework where certified).
  • AI / LLM providers: Anthropic, OpenAI, Google (Gemini API) and OpenRouter (and the model providers reachable through it), USA — Standard Contractual Clauses (and EU–US Data Privacy Framework where certified).
  • Optional, user-activated recipient (engaged only if you enable it): Telegram (Telegram FZ-LLC, United Arab Emirates), used to deliver task notifications you opt into. As the UAE has no EU adequacy decision and standard safeguards (e.g. SCCs) are not available, this transfer relies on the data subject's explicit consent under Art. 49(1)(a) GDPR; notification content is limited to the task title, status and a link. Kept distinct from the core sub-processors above.
  • Customer-configured integrations: where you enable integrations such as error monitoring (Sentry) or vulnerability data sources, you act as the controller for that processing and configure the recipients; these are not Fraway sub-processors and operate under your configuration and the provider's own terms.

Annex 2 — Technical and organisational measures

Fraway applies, at a minimum, the following measures (Article 32 GDPR):

  • Encryption in transit (TLS) and encryption at rest of credentials and other sensitive secrets;
  • Isolation of the working copies in which agents read, generate and modify code, separating processing between workspaces;
  • Access controls based on the principle of least privilege, restricting access to authorised personnel and systems;
  • Authentication via magic link and session management;
  • Logging of operational and security events;
  • Selection of sub-processors that provide sufficient guarantees of appropriate measures.