Legal
Data processing
The data processing agreement for organisations that need one, and the sub-processors it names.
Updated September 6, 2026
Working draft. No agreement is signed today: the publisher is not incorporated and the text has not been reviewed by a lawyer. It is published so you know what it will contain.
Scope
The agreement covers the personal data we process on behalf of your organisation when you use the console and the platform: your members’ accounts, their devices, and the metadata of your servers.
It does not cover the data that lives on your servers. We have no access to it: there, you are not our customer, you are the only one at the controls.
Instructions
We process that data only to provide the service, on your documented instructions, and for nothing else. We do not sell it, we do not share it, and we train no model on it.
Security measures
Encryption in transit and at rest, access to production systems limited to the people who need it and logged, secrets kept out of the repository, agent distributed as a signed binary, no inbound connection to your machines. [Full list of technical and organisational measures to be annexed before signature.]
Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloudflare | Hosting of the site and the console, binary storage, transactional email delivery | Global network |
| Neon | Platform database: accounts, organisations, servers, subscriptions | United States at launch; eu-central-1 today |
| Stripe | Merchant of record: payment, invoicing, taxes | United States and Ireland |
| PostHog | Site analytics, only after consent | United States at launch; European Union today |
| GitHub | Distribution of the signed desktop app releases | United States |
You are told by email before a sub-processor is added, and you may object to it.
Transfers
The publisher will be a United States company and the platform will be hosted in the United States: your organisation’s data will be processed there, as Stripe and GitHub already process theirs. The database still lives in a European region today; it is migrated before the service takes its first customer.
For an organisation established in the European Union, the transfer will rely on the standard contractual clauses and on the guarantees each sub-processor publishes. [Exact references of the clauses and the transfer impact assessment to be annexed before signature.]
Assistance and audits
We help you answer requests from data subjects and meet the obligations that fall on you, and we tell you without undue delay about a data breach that affects you. The documents evidencing our measures are provided on request. [Audit terms and frequency to be settled before signature.]
Deletion
At the end of the contract, your organisation’s data is deleted within thirty days, except what accounting law requires us to keep. A copy of your data is handed to you on request before the deletion.
Getting a signed copy
When the service opens, the request will be made from the console and the agreement signed electronically. Until then, write to legal@pupitre.studio: we cannot sign anything before incorporation, but we will tell you where the text stands.