Data Processing Agreement
Last updated 2026-07-18
This page summarizes how DevDocs processes personal data in connection with hosted.devdocs.ai, and the terms on which a data processing agreement (a "DPA") is offered. It is written to be read alongside the Privacy Policy and the subprocessor list, so that a security or procurement reviewer can see the controller and processor picture in one place.
If your organization requires a signed DPA before or during use of the Service, contact privacy@devdocs.ai and we will countersign these terms. Where you already have a master agreement with us, these terms are incorporated into it by reference. This page is a summary; the operative terms are those in the signed DPA or in the Terms of Service that incorporate them.
1. Roles: who is the controller and who is the processor
The split follows the two roles set out in our Privacy Policy, and it is described here because it is legally load-bearing. For account data and the marketing site (the people who sign up for, administer, or are invited to a workspace), DevDocs is the controller and decides why and how that data is processed.
For a workspace's Customer Content (published packages and connected sources) and the personal data of visitors who use that workspace's documentation site (questions, aggregate analytics, feedback), the workspace operator is the controller and DevDocs is the processor, acting only on the operator's documented instructions to provide the Service. This DPA governs that processor relationship.
2. Scope, purpose, and instructions
As processor, DevDocs processes Customer Content solely to operate the Service: to store, cache, index, embed for retrieval, and serve documentation; to answer visitor questions grounded in that workspace's own content; and to provide the operator with aggregate analytics, content-gap signals, feedback, and usage meters for that workspace. DevDocs does not process Customer Content for any independent commercial purpose of its own, and does not sell it.
Customer's documented instructions are these terms together with Customer's configuration of the Service (including which sources to connect, which packages to publish or promote, and which members may access private material). DevDocs will not process Customer Content outside those instructions unless required by law, in which case it will inform Customer where legally permitted before processing.
The essential details of the processing, for the purposes of the transfer clauses referenced below, are:
- Categories of data subjects: a workspace's named users and administrators, and the visitors who read documentation or ask questions on that workspace's site.
- Types of personal data: account identifiers (name and email) of workspace users where they appear in operator-facing features; documentation and source content the workspace publishes or connects; free-text questions and short feedback excerpts; aggregate analytics attributes (country, path, referrer host) without raw IP storage in the analytics path.
- Nature and purpose of processing: hosting published documentation, indexing authorized sources for grounded chat and search, answering visitor questions, and providing operator analytics and usage meters, on the operator's behalf.
- Duration: for the life of the workspace, after which content is deleted or returned as described in section 8.
3. Subprocessors
DevDocs uses the subprocessors listed at hosted.devdocs.ai/legal/subprocessors to provide the Service. By entering into this DPA, Customer authorizes the use of the subprocessors on that list.
DevDocs remains responsible for its subprocessors' processing of Customer Content and imposes on each of them data protection obligations no less protective than those in this DPA. DevDocs will update the subprocessor list before a new subprocessor begins processing Customer Content and, where Customer has a standing notification requirement in its agreement, will notify Customer directly so that a reasonable objection can be raised.
4. No training on Customer Content
DevDocs does not train, fine-tune, or otherwise improve any machine learning model on Customer Content, and does not permit its subprocessors to do so. This commitment is stated the same way in our Terms of Service, our Privacy Policy, and on our security page, without qualifiers.
5. International transfers and the Standard Contractual Clauses
Where Customer or a workspace's visitors are located in the European Economic Area, the United Kingdom, or Switzerland, and personal data is transferred to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (the controller to processor module), with the United Kingdom International Data Transfer Addendum and the Swiss amendments applied where they are relevant. Those clauses are incorporated into this DPA by reference and prevail over it in the event of a conflict.
DevDocs does not currently make a data residency commitment (a promise that data is stored only in a specific geography). The governing law and venue set out in the Terms of Service is a choice of forum, not a residency guarantee, and we state that plainly rather than imply one.
6. Security measures
DevDocs maintains the technical and organizational measures described on our security page at hosted.devdocs.ai/security, including tenant isolation derived server side from the request hostname, encryption of Customer Content in transit and at rest, role-based access control, and a tamper-evident audit trail. Those measures are the technical and organizational measures for the purposes of this DPA. They may be updated over time provided the level of protection is not reduced.
7. Assistance, data subject requests, and breach notification
Taking into account the nature of the processing, DevDocs will provide reasonable assistance to Customer in responding to data subject requests and in meeting Customer's own obligations for security, breach notification, and data protection assessments. Because DevDocs acts as processor for visitor data, a visitor's request is directed to the workspace operator first, and DevDocs assists the operator in fulfilling it.
If DevDocs becomes aware of a personal data breach affecting Customer Content, it will notify Customer without undue delay and share the information Customer reasonably needs to meet its own notification obligations.
8. Return and deletion on termination
On termination, DevDocs deletes or returns Customer Content as described in the Terms of Service, within a commercially reasonable period, except where retention is required by law. Deletion covers the stores used to operate the Service, including published packages, the per-workspace knowledge index and embeddings, and operator-facing analytics exports held for that workspace, subject to backup and log retention windows that are then aged out.
9. How to put a DPA in place
To execute a countersigned DPA, or for any question about DevDocs's role as controller or processor, contact privacy@devdocs.ai.