1. Scope and Parties
This Data Processing Addendum ("DPA") forms part of the Rubic Terms of Service or another written agreement that incorporates it (the "Agreement"). It applies when a customer uses the Service to process personal data on behalf of that customer or another controller ("Customer Personal Data").
The customer identified by the Rubic account or applicable Order Form is "Customer" or the "Data Exporter." Upmoni LLC, doing business as Rubic, is "Rubic" or the "Data Importer." This DPA becomes effective when Customer accepts the Agreement or first submits Customer Personal Data to the Service, whichever occurs first. A signed MSA, Order Form, or negotiated DPA controls to the extent it expressly conflicts with this DPA.
Capitalized terms not defined here have the meanings given in the Agreement. "Data Protection Laws" means privacy and data protection laws applicable to the processing, including the EU GDPR, UK GDPR, and the California Consumer Privacy Act as amended, where applicable.
2. Roles and Instructions
Customer is the controller and Rubic is the processor when Customer determines the purposes and means of processing Customer Personal Data. If Customer is a processor for another controller, Customer appoints Rubic as its subprocessor. Each party will comply with the obligations applicable to its role under Data Protection Laws.
Rubic will process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's use and configuration of the Service, support requests, and other written instructions that are consistent with the Agreement. Rubic may also process Customer Personal Data when required by law and, unless legally prohibited, will inform Customer before doing so. Rubic will promptly tell Customer if, in Rubic's reasonable opinion, an instruction infringes Data Protection Laws.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; providing required notices; obtaining required rights and consents; and ensuring that its instructions comply with Data Protection Laws. Customer must not intentionally submit special-category data, regulated health data, payment-card data, government identifiers, or similarly sensitive data unless Rubic has expressly agreed in writing to process it.
3. Processing Details
Rubic processes Customer Personal Data to provide, secure, support, and maintain the Service, including repository analysis, task execution, generated work, application previews, collaboration, support, and authorized integrations. Processing may include collecting, recording, organizing, storing, retrieving, consulting, using, transmitting, making available, restricting, deleting, and destroying data.
Processing continues for the term of the Agreement and any limited period needed to return or delete data, maintain backups, resolve disputes, meet legal obligations, or protect the Service. Annex I provides additional processing details.
4. Confidentiality and Personnel
Rubic will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed for their responsibilities. Rubic remains responsible for its personnel's compliance with this DPA.
5. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Rubic will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures currently maintained are summarized in Annex II.
Customer is responsible for securely configuring and using the Service, protecting its credentials, limiting user access, reviewing generated work, and avoiding the submission of production secrets or data that the Agreement does not permit.
6. Subprocessors
Customer gives Rubic general written authorization to use subprocessors to process Customer Personal Data. Rubic's current subprocessors, their functions, and processing locations are listed on the Subprocessor List. Rubic will impose data protection obligations on each subprocessor that are no less protective in substance than the obligations applicable to the same processing under this DPA, and Rubic remains responsible for each subprocessor's performance of those obligations.
Rubic will provide at least 15 days' advance notice before authorizing a new core subprocessor to process Customer Personal Data, normally by email to the account owner or an in-product notice. Customer may object during that period on reasonable data protection grounds. The parties will work in good faith on a commercially reasonable solution. If no solution is reasonably available, Customer may stop using the affected feature or terminate the affected Service without penalty before the new subprocessor begins processing.
A service that Customer chooses and directs Rubic to connect, such as a source code host, is a Customer-authorized third-party service and is not converted into a Rubic core subprocessor merely because the Service provides the connection.
7. Assistance and Requests
Taking into account the nature of processing and the information available to Rubic, Rubic will provide reasonable assistance so Customer can respond to data-subject requests and meet applicable obligations relating to security, breach notifications, data protection impact assessments, and regulatory consultations. If Rubic receives a request concerning Customer Personal Data, Rubic will direct the requester to Customer unless Rubic is legally required to respond.
8. Personal Data Breaches
Rubic will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available to Rubic about the nature of the breach, the likely consequences, affected data and individuals, and measures taken or proposed. Where complete information is not available at the same time, Rubic may provide it in phases without undue further delay as the investigation progresses. Rubic's notification is not an admission of fault or liability. Customer is responsible for notifications to individuals and authorities unless Data Protection Laws require Rubic to notify them directly.
9. Return and Deletion
During the Agreement, Customer may retrieve Customer Personal Data through available Service functionality. Following termination or a verified deletion instruction, Rubic will delete or return Customer Personal Data, at Customer's choice where reasonably available. Rubic targets deletion from active systems within 30 days. Data may remain temporarily in backups until overwritten under the applicable backup cycle, or longer where law requires retention, provided it remains protected and is not processed for another purpose.
10. Information and Audits
Rubic will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request relevant questionnaires, summaries, policies, or independent reports that Rubic has available. If that information is insufficient, Customer may conduct one audit per 12-month period through an independent auditor, with reasonable advance notice, during normal business hours, and subject to confidentiality, security, and non-disruption requirements. Additional audits are permitted after a confirmed Personal Data Breach or when required by a competent authority. Customer bears its audit costs unless the audit identifies material non-compliance by Rubic.
11. International Transfers
Customer authorizes Rubic and its subprocessors to process Customer Personal Data in the United States and the other locations shown on the Subprocessor List. The transfer terms below apply only when a transfer requires them under Data Protection Laws.
11.1. European Economic Area
For a restricted transfer from the EEA, the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA by reference. Module Two applies when Customer is a controller and Rubic is a processor. Module Three applies when Customer is a processor and Rubic is a subprocessor.
- Clause 7 (Docking Clause) applies.
- For Clause 9, Option 2 applies and the notice period is the 15-day period in Section 6.
- The optional language in Clause 11 does not apply.
- For Clause 17, Option 1 applies and the governing law is the law of Ireland.
- For Clause 18(b), disputes will be resolved by the courts of Ireland.
- Annexes I through III of this DPA complete the corresponding annexes of the EU SCCs.
11.2. United Kingdom
For a restricted transfer governed by the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, template Addendum B.1.0 issued by the UK Information Commissioner's Office ("UK Addendum"), is incorporated into this DPA. Part 1 of the UK Addendum is completed as follows:
- Table 1: The parties, contact details, roles, and electronic signatures are identified in Section 1 and Annex I.A of this DPA and in the applicable Rubic account or Order Form.
- Table 2: The Approved EU SCCs are the EU SCCs identified in Section 11.1, using Module Two or Module Three according to the parties' roles and the selections stated in that Section.
- Table 3: The information required by the EU SCC appendices appears in Annex I, Annex II, and Annex III of this DPA.
- Table 4: The Data Importer may end the UK Addendum as permitted by Section 19 of its mandatory clauses.
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, is incorporated by reference.
11.3. Transfer Cooperation
The parties will reasonably cooperate on transfer assessments and supplementary measures required by Data Protection Laws. If a valid transfer mechanism ceases to be available, the parties will work in good faith to implement another lawful mechanism.
12. United States Privacy Terms
To the extent a United States state privacy law applies to Customer Personal Data, Rubic acts as a service provider or processor and will:
- process Customer Personal Data only for the business purposes described in the Agreement and this DPA, or as otherwise permitted by applicable law;
- not sell or share Customer Personal Data or retain, use, or disclose it outside Rubic's direct business relationship with Customer, except as permitted by applicable law;
- not combine Customer Personal Data with personal data received from another person or collected through Rubic's own interaction with an individual, except as permitted to provide the Service under applicable law;
- provide the same level of privacy protection required of service providers or processors and notify Customer if Rubic determines it can no longer meet an applicable obligation; and
- allow Customer to take reasonable and appropriate steps to verify, stop, and remediate unauthorized use of Customer Personal Data.
13. General
If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls. The EU SCCs or UK Addendum control over this DPA to the extent of a conflict concerning a restricted transfer. The liability limitations in the Agreement apply to this DPA to the maximum extent permitted by applicable law. Changes to this DPA will follow the material-change notice process in the Agreement.
Annex I — Parties and Processing
A. Parties
Data Exporter: The Customer identified by the Rubic account or applicable Order Form, at the contact details associated with that account. The Data Exporter's role is controller or processor as described in Section 2.
Data Importer: Upmoni LLC, doing business as Rubic, 9450 SW Gemini Dr PMB 84485, Beaverton, OR 97008-7105, United States. [email protected]. The Data Importer's role is processor or subprocessor as described in Section 2.
Accepting the Agreement constitutes each party's electronic signature and agreement to be bound by this DPA and the incorporated transfer terms.
B. Transfer and Processing Description
- Data subjects: Customer users, personnel, contractors, customers, prospects, end users, and other individuals whose data Customer submits to the Service.
- Personal data: Names, business contact information, account identifiers, repository and project content, source code and metadata, task prompts and messages, attachments, generated work, application and terminal logs, IP addresses, device and usage information, and other personal data Customer chooses to submit.
- Sensitive data: None intentionally required. Customer must not submit sensitive data unless Rubic expressly agrees in writing and the parties document appropriate safeguards.
- Frequency: Continuous or as initiated by Customer during use of the Service.
- Nature and purpose: The operations and purposes described in Sections 2 and 3.
- Duration: The Agreement term plus the limited retention and deletion periods described in Section 9 and the Privacy Policy.
- Subprocessor subject matter and duration: As described on the Subprocessor List, for as long as needed to provide the applicable function.
C. Competent Supervisory Authority
For the EU SCCs, the competent supervisory authority is determined under Clause 13 based on the Data Exporter's establishment. If the Data Exporter is not established in the EEA but falls within the territorial scope of the EU GDPR, it is the authority for the Data Exporter's representative or, where no representative is required, an authority in an EEA country where affected data subjects are located.
Annex II — Technical and Organizational Measures
Rubic's measures include, as appropriate to the Service:
- authenticated accounts, role and project-scoped authorization, project filters for customer resources, and least-privilege practices;
- TLS for public Service connections and encryption at rest provided by managed infrastructure, database, storage, and backup services;
- task-scoped managed workspaces, resource and lifecycle controls, separation between customer projects, and time-limited signed attachment URLs;
- schema-based redaction for designated sensitive agent-tool inputs, provider privacy controls, logging and monitoring, error redaction, security review, and incident response procedures;
- managed database backups and point-in-time recovery, restore practices, data deletion workflows, and account-access procedures designed for the Service's availability and data lifecycle;
- confidentiality obligations and access restrictions for persons authorized to process Customer Personal Data; and
- vendor review and written data protection obligations for subprocessors.
These measures describe current safeguards and may evolve as Rubic improves the Service, provided the overall level of protection is not materially reduced.
Annex III — Subprocessors
The current list of authorized subprocessors is available at rubic.io/subprocessors and is incorporated into this DPA.