TickPax — Data Processing Addendum

Effective date: 26 September 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between TickPax ("Processor", "we") and the customer that registers an Azure DevOps organization with TickPax ("Controller", "you"). It applies where we process personal data on your behalf under the EU General Data Protection Regulation (GDPR), the UK GDPR, or comparable law.

It is accepted automatically when you accept the Terms of Service. If your procurement process requires a signed copy, contact privacy@tickpax.com.

Where this DPA conflicts with the Terms of Service on data protection, this DPA prevails.


1. Roles

You are the controller and we are the processor in respect of the personal data TickPax processes from your Azure DevOps organization.

You determine that TickPax is deployed, which projects it tracks, which people are Authorized Users, and for what purpose the resulting records are used. We process only to provide the Service.


2. Subject matter, duration, nature and purpose

Subject matterProvision of the TickPax AI time-tracking service
DurationThe term of your subscription, plus the deletion period in §10
Nature and purposeCollecting engineering activity from Azure DevOps; generating AI time estimates; storing time records approved by your people; writing approved time values back to Azure DevOps work items
Type of personal dataSee §3
Categories of data subjectYour personnel and contractors who use Azure DevOps in your organization — engineers, reviewers, work item authors and assignees — and your TickPax administrators
Special category dataNone is requested or required. TickPax does not solicit special category data. Free-text fields could contain such data if your people write it there. Commit messages, pull request review comments, work item comments, descriptions, acceptance criteria and repro steps are discarded at the point of receipt and never stored; work item titles are retained. None of it is ever sent to the AI provider. You control what your people write

3. Personal data processed

Processed:

Not processed under any circumstance: source code or file contents; line-level diffs; build, release or pipeline data; wikis, test plans or dashboards; any Microsoft 365 data. TickPax requests no Microsoft Graph permission.


4. Your instructions

We process personal data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration of the Service (project selection, user approvals, settings).

We will tell you if, in our opinion, an instruction infringes data protection law. We may process where required by law that applies to us, and will inform you first unless that law forbids it.

You warrant that you have a lawful basis for the processing, that you have given the required transparency information to your personnel, and that you have completed any consultation or co-determination required — including works council agreement where the law of your jurisdiction requires it before deploying a system capable of monitoring employee performance. This obligation is yours; we do not assess it for you.


5. Confidentiality

We ensure that everyone authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality, and we limit access to those who need it to provide or support the Service.


6. Security measures (Article 32)

We implement and maintain the following technical and organisational measures:

MeasureImplementation
Encryption in transitTLS on all connections to the Service and to Azure DevOps
Encryption of credentials at restOAuth access and refresh tokens are encrypted at rest with a key held outside the database
Secrets managementApplication secrets held in Azure Key Vault, not in configuration files or source control
Identity integrityEvery request is bound to the caller's verified Azure AD object ID; requests failing this check are rejected, so one user cannot act as another
Webhook authenticityInbound Azure DevOps webhooks are authenticated against a shared secret before processing
Access controlRole separation between Admin and Member; users are inactive until an administrator approves them; production access restricted to authorised personnel
Data minimisationOnly the fields in §3 are retrieved; source code and diffs are never fetched; AI prompts are masked as described in §8
Storage limitationRaw webhook payloads purged after 7 days; deletion and anonymisation per §10
Payment data isolationCard data is handled solely by the payment provider and never reaches our systems
ResilienceBackups held in the same EU jurisdiction as production

We may update these measures provided the level of security is not reduced.


7. Sub-processors

You give general written authorisation for the sub-processors below. We remain fully liable for their performance.

Sub-processorPurposeLocation
Hetzner Online GmbHApplication and database hosting; backupsFalkenstein, Germany (EU)
Google LLC / Google Ireland LtdAI inference (Gemini API) for generating ProposalsMay process outside the EEA
Microsoft (Azure Key Vault)Secrets managementWest Europe (EU)
Dodo PaymentsPayment processing as Merchant of Record; billing personal data only, no engineering activity dataPer their terms

We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your administrators or by notice in the Service. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none is available, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused term. This refund right is an exception to the no-refund rule in the Terms of Service.


8. International transfers

Customer Data is stored in the European Union (Germany).

The only routine transfer outside the EEA is to Google for AI inference. That transfer is made under the European Commission's Standard Contractual Clauses, supplemented by substantial technical measures applied before any request leaves our servers:

The result is that no free text written by your personnel leaves the EEA on any path. What is transferred is timings, counts, file counts, work item state values, and opaque tokens.

Content sent to the AI provider is not used to train models.


9. Assistance to you

We will assist you, taking into account the nature of processing and the information available to us:

Assistance is included at no charge unless a request is manifestly excessive or repetitive, in which case we may charge a reasonable fee agreed in advance.


10. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — providing information in phases where it is not all available at once.

We will not make public statements identifying you in connection with a breach without your prior consent, unless legally required.


11. Deletion and return

On termination of your subscription, or on your written request:


12. Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will allow and contribute to audits, including inspections, conducted by you or an auditor you mandate.

Audits are limited to once per twelve months unless a breach or a supervisory authority requires otherwise, must be requested at least 30 days in advance, must take place during business hours without unreasonable disruption, and are subject to confidentiality. Where available, we will first offer documentation, security-measure descriptions and written responses, which often satisfy the request without an on-site visit.


13. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where those limits are unenforceable under applicable data protection law. Nothing here limits a data subject's rights against either party under GDPR.


14. Term

This DPA takes effect when you accept the Terms of Service and continues while we process personal data on your behalf, plus the deletion period in §11.


Contact for data protection matters: privacy@tickpax.com TickPax, https://tickpax.com