Legal

Data processing

The data processing agreement for organisations that need one, and the sub-processors it names.

Updated September 6, 2026

Working draft. No agreement is signed today: the publisher is not incorporated and the text has not been reviewed by a lawyer. It is published so you know what it will contain.

Scope

The agreement covers the personal data we process on behalf of your organisation when you use the console and the platform: your members’ accounts, their devices, and the metadata of your servers.

It does not cover the data that lives on your servers. We have no access to it: there, you are not our customer, you are the only one at the controls.

Instructions

We process that data only to provide the service, on your documented instructions, and for nothing else. We do not sell it, we do not share it, and we train no model on it.

Security measures

Encryption in transit and at rest, access to production systems limited to the people who need it and logged, secrets kept out of the repository, agent distributed as a signed binary, no inbound connection to your machines. [Full list of technical and organisational measures to be annexed before signature.]

Sub-processors

Sub-processor Purpose Region
Cloudflare Hosting of the site and the console, binary storage, transactional email delivery Global network
Neon Platform database: accounts, organisations, servers, subscriptions United States at launch; eu-central-1 today
Stripe Merchant of record: payment, invoicing, taxes United States and Ireland
PostHog Site analytics, only after consent United States at launch; European Union today
GitHub Distribution of the signed desktop app releases United States

You are told by email before a sub-processor is added, and you may object to it.

Transfers

The publisher will be a United States company and the platform will be hosted in the United States: your organisation’s data will be processed there, as Stripe and GitHub already process theirs. The database still lives in a European region today; it is migrated before the service takes its first customer.

For an organisation established in the European Union, the transfer will rely on the standard contractual clauses and on the guarantees each sub-processor publishes. [Exact references of the clauses and the transfer impact assessment to be annexed before signature.]

Assistance and audits

We help you answer requests from data subjects and meet the obligations that fall on you, and we tell you without undue delay about a data breach that affects you. The documents evidencing our measures are provided on request. [Audit terms and frequency to be settled before signature.]

Deletion

At the end of the contract, your organisation’s data is deleted within thirty days, except what accounting law requires us to keep. A copy of your data is handed to you on request before the deletion.

Getting a signed copy

When the service opens, the request will be made from the console and the agreement signed electronically. Until then, write to legal@pupitre.studio: we cannot sign anything before incorporation, but we will tell you where the text stands.

Legal