Bolvrk
DocsFeaturesPricingSecuritygithub-logo
Sign in Open app
Legal

Data processing agreement

Last updated 2 September 2026

This agreement under Article 28 of the GDPR applies by default to every customer of the hosted Bolvrk service. It is incorporated by reference into the terms of service and needs no signature. A countersigned copy is available on request from hello@bolvrk.com.

1. Parties and roles

The customer — the organisation on whose behalf a team is created — is the controller. Simon ApS, CVR DK38213458, Gersonsvej 40, 1., 2900 Hellerup, Denmark (the operator of Bolvrk) is the processor. Account, billing and operational data for which Simon ApS is itself the controller is covered by the privacy policy, not this agreement.

2. Subject matter and duration

The processor processes personal data on behalf of the controller to provide the hosted service under the terms of service, for as long as the controller has a team on the service and until the data has been deleted under section 10.

3. Nature and purpose

Verification of Postgres migration SQL and related metadata: parsing and analysing submitted migrations, reading schema structure from a database the controller connects or introspects locally, storing the resulting findings as the team's history, delivering notifications the controller configures, and — only when the controller requests it — obtaining an advisory AI review of a specific check.

4. Types of data and data subjects

  • Data subjects: the controller's engineers and other staff who use the service, and any individual whose personal data appears in submitted content.
  • Types of data: GitHub identities (user ID and login name) of the controller's engineers as they appear in team membership, invites and check metadata; git metadata (repository, branch, commit, pull-request number); and whatever personal data the controller places inside migration SQL, migration file names, findings feedback or notification configuration. The service is designed for schema changes, and the controller should avoid submitting personal data in migration content; no special categories of data (art. 9) are intended to be processed.

5. Processor obligations

  • Instructions only. The processor processes personal data only on the controller's documented instructions — these being the terms of service, this agreement, and the controller's use of the service — unless EU or member-state law requires otherwise, in which case the processor informs the controller before processing where the law permits. The processor informs the controller if it considers an instruction to infringe data protection law.
  • Confidentiality. Persons authorised to process the data are bound by confidentiality. Access to production systems is limited to the operator.
  • Security measures (art. 32), as further described on the security page: all traffic encrypted in transit; database connection strings and notification channel secrets sealed-box encrypted at rest with the secret key held outside the database and opened per check; team, refresh and invite tokens stored as SHA-256 hashes with the plaintext shown once; database introspection inside a read-only transaction against system catalogs only, with the snapshot discarded after the check; credentials found in migration content masked before storage; GitHub sign-in with an empty scope list; hosting in the EU on a single service and database with no third-party analytics.
  • Records. The processor keeps a record of the processing carried out on behalf of the controller and makes it available on request.

6. Sub-processors

The controller gives general authorisation for the sub-processors listed in the privacy policy, at the date of this agreement:

  • Hetzner Online GmbH — hosting (Germany / Finland, EU).
  • GitHub, Inc. (Microsoft) — sign-in identity (United States).
  • Stripe Payments Europe, Ltd. with its United States affiliates — billing (Ireland / United States).
  • Anthropic, PBC — AI review, only when the controller requests one (United States).

The processor gives at least 30 days' notice of any addition or replacement by email to the team's billing contact and in the changelog. The controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the controller may terminate the service without penalty before the change takes effect. The processor imposes data-protection obligations on each sub-processor equivalent to those in this agreement and remains liable to the controller for the sub-processor's performance.

7. Assistance to the controller

Taking into account the nature of the processing, the processor assists the controller with appropriate technical and organisational measures in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection), and — insofar as the information is available to it — with the controller's obligations on security, breach notification, data protection impact assessments and prior consultation (art. 32–36). A request from a data subject received directly by the processor about content of the controller is forwarded to the controller without undue delay and not answered on the merits. Assistance that goes beyond what the service already provides may be charged at a reasonable rate agreed in advance.

8. Personal data breaches

The processor notifies the controller of a personal data breach affecting the controller's data without undue delay, and in any event within 72 hours of becoming aware of it, by email to the team's billing contact or, where none is on file, through the app. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point; information not yet available follows without undue delay.

9. International transfers

The processor stores personal data in the EU. Transfers to sub-processors in the United States rely on the EU–US Data Privacy Framework where the sub-processor is certified under it, and otherwise on the European Commission's Standard Contractual Clauses (2021/914). No personal data is transferred to any other third country.

10. Deletion and return

At the end of the service — when the controller deletes its team, or when the terms are terminated — the processor deletes the controller's stored personal data within 30 days, with backups rolling over within a further 30 days, unless EU or member-state law requires storage. Before deletion the controller may request a copy of its check history in a machine-readable format. Invoices and bookkeeping records are retained by the processor as controller under the Danish Bookkeeping Act.

11. Audit

The processor makes available all information necessary to demonstrate compliance with Article 28, in writing, on request. The controller may carry out, or mandate an independent auditor bound by confidentiality to carry out, an audit or inspection no more than once a year, with at least 30 days' written notice, during business hours, at the controller's cost, and without disrupting the service or exposing other customers' data.

12. Liability, law and venue

Each party's liability under this agreement follows the liability section of the terms of service, without prejudice to Article 82 of the GDPR. This agreement is governed by Danish law and disputes are brought before the Copenhagen City Court (Københavns Byret) as the court of first instance. If this agreement conflicts with the terms of service on a data protection matter, this agreement prevails.

13. Changes

The processor may update this agreement to reflect changes in the service, its sub-processors or the law, with at least 30 days' notice by email or in the app. Changes never reduce the protection the controller receives under Article 28.

Contact

Simon ApS, Gersonsvej 40, 1., 2900 Hellerup, Denmark · hello@bolvrk.com · security matters: security@bolvrk.com.

Bolvrk

The bulwark between your migrations and production.

Bolvrk is a product of Simon ApS · CVR DK38213458 · Gersonsvej 40, 1. · 2900 Hellerup · Denmark

ProductFeaturesPricingSecurityChangelogRoadmap
ResourcesGetting startedRule referenceGitHubnpmReport a vulnerability
CompanyAboutContactJobs
LegalPrivacyTermsData processing
© 2026 Bolvrk. Free CLI, hosted corpus.