Legal

Data Processing Addendum

This addendum forms part of the Terms of Service and applies where Elisha processes personal data on your behalf. It's written to be read, not to be survived.

Last updated: July 12, 2026

1. Roles of the parties

You are the controller of personal data contained in the repositories, boards, messages, and documents Elisha accesses on your instruction. Elisha is the processor, and processes that data only to provide the service.

2. Scope and purpose of processing

Processing is limited to what is necessary to complete the tasks you assign: cloning the repositories you selected, reading the boards and channels you connected, running the work in an isolated sandbox, and opening a pull request. We do not use your content to train models.

  • Categories of data subjects. Your personnel and any individuals whose personal data happens to appear in the content Elisha accesses.
  • Categories of data. Account and contact details, integration identifiers, and whatever personal data is present in the source code, tickets, messages, and documents in scope.
  • Duration. For the term of your subscription, plus the deletion window in section 8.

3. Your instructions

We process personal data only on your documented instructions, which include your use of the service and the tasks you assign. If we believe an instruction breaches applicable data protection law, we will tell you rather than carry it out quietly.

4. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations and receive access on a need-to-know basis only.

5. Security measures

We maintain technical and organisational measures appropriate to the risk, including encryption of credentials at rest, encryption in transit, per-organization scoping of credentials and storage, ephemeral per-task sandboxes destroyed at the end of each run, and least-privilege access to third-party systems. Detail is on the security page.

6. Sub-processors

You give general authorisation for the sub-processors listed on the sub-processors page. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data protection grounds — in which case you may terminate the affected part of the service.

7. Data subject rights and assistance

Taking into account the nature of the processing, we will assist you with requests from data subjects, with data protection impact assessments, and with consultations with supervisory authorities. If a request reaches us directly, we will forward it to you rather than answer it on your behalf.

8. Deletion and return

On termination, you may export your data. We delete customer content within 30 days of termination, and stored integration credentials immediately on disconnection, except where retention is required by law. Note that pull requests Elisha opened live in your own repositories and are unaffected — they are yours.

9. Personal data breach

We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations.

10. International transfers

Where personal data is transferred out of the EEA, the UK, or Switzerland, the transfer is made under the applicable Standard Contractual Clauses, incorporated into this addendum by reference, together with any supplementary measures required.

11. Audits

On reasonable notice and no more than once a year, we will make available the information necessary to demonstrate compliance with this addendum, and cooperate with audits conducted by you or an independent auditor you appoint.

12. Signing a copy

Need this executed as a signed document for your procurement process? Email legal@elisha.dev and we'll send one over.

This addendum is provided for information and does not constitute legal advice. Please have your own counsel review it against your obligations.