Data Processing Agreement

Effective as of


This Data Processing Agreement (“Agreement”) is part of, and is governed by, the terms and conditions set forth in the Terms and Conditions of Sourcery.AI Limited (“Sourcery”). Terms not defined in this Agreement shall have the meaning given to them in the Terms and Conditions.

If Sourcery makes any changes to this Agreement that materially affect how personal data is processed or reduce your rights, you will be notified (e.g., by email). If you have questions about this Agreement, wish to know more about our data protection practices, or need to exercise your rights regarding the processing of your personal data, contact our Data Protection Officer, Tim Gilboy, at privacy@sourcery.ai.

1. Definitions and Interpretation

Unless otherwise defined herein, terms and expressions in this Agreement shall have the meanings assigned in the GDPR.

2. Processing of Personal Data

Roles and Scope: Sourcery will process Client Personal Data solely to deliver the agreed Services, in accordance with documented instructions provided by the Client.

Nature of Processing:

3. Processor Obligations

Sourcery shall comply with all applicable Data Protection Laws, ensuring that:

4. Subprocessing

Sourcery may engage the following Subprocessors:

Large Language Model providers — process source code and message content sent to the Services. None of these providers use Client data to train their models, and none retain it for more than 30 days. Zero-retention options are available on request.

Where a Client configures their own model endpoint, source code is sent to whichever provider that Client selects, under the Client’s own agreement with that provider, rather than to the providers listed above.

Infrastructure

Product and business operations

All Subprocessors will comply with terms no less stringent than those set forth in this Agreement.

5. Data Transfers

Account data and product usage data are stored in the United Kingdom and the European Economic Area. Some Subprocessors listed above process data outside the UK and EEA; where they do, transfers are made under an adequacy decision or Standard Contractual Clauses. Data processed for LLM services may involve transfers outside the UK and EEA, subject to Client configuration and choice of provider.

6. Data Subject Rights

Sourcery will assist the Client in responding to Data Subject requests, including access, rectification, or deletion of personal information. Sourcery shall not respond to such requests without Client instructions unless legally required.

7. Data Breach Notification

Sourcery will notify the Client without undue delay upon becoming aware of a personal data breach, providing sufficient details for compliance with GDPR obligations.

8. Data Retention

Upon termination of the Services, all Client Personal Data will be deleted promptly unless required by law. Data deletion will be confirmed upon Client request.