TickPax — Data Processing Addendum
Effective date: 26 September 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between TickPax ("Processor", "we") and the customer that registers an Azure DevOps organization with TickPax ("Controller", "you"). It applies where we process personal data on your behalf under the EU General Data Protection Regulation (GDPR), the UK GDPR, or comparable law.
It is accepted automatically when you accept the Terms of Service. If your procurement process requires a signed copy, contact privacy@tickpax.com.
Where this DPA conflicts with the Terms of Service on data protection, this DPA prevails.
1. Roles
You are the controller and we are the processor in respect of the personal data TickPax processes from your Azure DevOps organization.
You determine that TickPax is deployed, which projects it tracks, which people are Authorized Users, and for what purpose the resulting records are used. We process only to provide the Service.
2. Subject matter, duration, nature and purpose
| Subject matter | Provision of the TickPax AI time-tracking service |
| Duration | The term of your subscription, plus the deletion period in §10 |
| Nature and purpose | Collecting engineering activity from Azure DevOps; generating AI time estimates; storing time records approved by your people; writing approved time values back to Azure DevOps work items |
| Type of personal data | See §3 |
| Categories of data subject | Your personnel and contractors who use Azure DevOps in your organization — engineers, reviewers, work item authors and assignees — and your TickPax administrators |
| Special category data | None is requested or required. TickPax does not solicit special category data. Free-text fields could contain such data if your people write it there. Commit messages, pull request review comments, work item comments, descriptions, acceptance criteria and repro steps are discarded at the point of receipt and never stored; work item titles are retained. None of it is ever sent to the AI provider. You control what your people write |
3. Personal data processed
Processed:
- Identifiers — display name, email address, Azure DevOps user ID, Azure AD object ID
- Activity metadata — commit IDs, authorship, timestamps, push times; pull request IDs, authors, reviewers, timestamps; work item IDs, types, states, assignees, iterations, area paths; state-transition history
- Changed file paths and change type — never file contents
- Free text retained — work item titles only, because the Service displays them back to you
- Free text read but not retained — commit messages, pull request review comments, work item comments, descriptions, acceptance criteria and repro steps. Read in transit to measure how much was written and to extract work item references, then discarded before storage. Not sent to the AI provider on any path
- Records created in the Service — time logs, categories, AI proposals, approvals, settings, and a user-management audit trail
Not processed under any circumstance: source code or file contents; line-level diffs; build, release or pipeline data; wikis, test plans or dashboards; any Microsoft 365 data. TickPax requests no Microsoft Graph permission.
4. Your instructions
We process personal data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration of the Service (project selection, user approvals, settings).
We will tell you if, in our opinion, an instruction infringes data protection law. We may process where required by law that applies to us, and will inform you first unless that law forbids it.
You warrant that you have a lawful basis for the processing, that you have given the required transparency information to your personnel, and that you have completed any consultation or co-determination required — including works council agreement where the law of your jurisdiction requires it before deploying a system capable of monitoring employee performance. This obligation is yours; we do not assess it for you.
5. Confidentiality
We ensure that everyone authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality, and we limit access to those who need it to provide or support the Service.
6. Security measures (Article 32)
We implement and maintain the following technical and organisational measures:
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS on all connections to the Service and to Azure DevOps |
| Encryption of credentials at rest | OAuth access and refresh tokens are encrypted at rest with a key held outside the database |
| Secrets management | Application secrets held in Azure Key Vault, not in configuration files or source control |
| Identity integrity | Every request is bound to the caller's verified Azure AD object ID; requests failing this check are rejected, so one user cannot act as another |
| Webhook authenticity | Inbound Azure DevOps webhooks are authenticated against a shared secret before processing |
| Access control | Role separation between Admin and Member; users are inactive until an administrator approves them; production access restricted to authorised personnel |
| Data minimisation | Only the fields in §3 are retrieved; source code and diffs are never fetched; AI prompts are masked as described in §8 |
| Storage limitation | Raw webhook payloads purged after 7 days; deletion and anonymisation per §10 |
| Payment data isolation | Card data is handled solely by the payment provider and never reaches our systems |
| Resilience | Backups held in the same EU jurisdiction as production |
We may update these measures provided the level of security is not reduced.
7. Sub-processors
You give general written authorisation for the sub-processors below. We remain fully liable for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting; backups | Falkenstein, Germany (EU) |
| Google LLC / Google Ireland Ltd | AI inference (Gemini API) for generating Proposals | May process outside the EEA |
| Microsoft (Azure Key Vault) | Secrets management | West Europe (EU) |
| Dodo Payments | Payment processing as Merchant of Record; billing personal data only, no engineering activity data | Per their terms |
We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your administrators or by notice in the Service. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none is available, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused term. This refund right is an exception to the no-refund rule in the Terms of Service.
8. International transfers
Customer Data is stored in the European Union (Germany).
The only routine transfer outside the EEA is to Google for AI inference. That transfer is made under the European Commission's Standard Contractual Clauses, supplemented by substantial technical measures applied before any request leaves our servers:
- Commit messages, pull request review comments, work item comments, descriptions, acceptance criteria and repro steps are removed at the point of receipt. No path transfers them.
- On the primary estimation path, work item titles, descriptions, comment bodies and user identities are replaced with opaque tokens (
TASK-TITLE,TASK-DESCRIPTION,COMMENT-1,USER-1, …), so that path transfers no names and no free text. - Work item matching for untracked commits transfers nothing at all: it uses only the work item number the author wrote in the commit message or branch name, and runs on our own servers with no model involved.
The result is that no free text written by your personnel leaves the EEA on any path. What is transferred is timings, counts, file counts, work item state values, and opaque tokens.
Content sent to the AI provider is not used to train models.
9. Assistance to you
We will assist you, taking into account the nature of processing and the information available to us:
- Data subject rights — where a data subject contacts us directly about data we process for you, we will refer them to you and notify you without undue delay. We will help you respond to access, correction, deletion, restriction, objection and portability requests. Administrators can already export, correct and delete time records directly in the Service.
- Article 32 security, and Articles 35–36 data protection impact assessments and prior consultation — we will provide the information reasonably available to us.
Assistance is included at no charge unless a request is manifestly excessive or repetitive, in which case we may charge a reasonable fee agreed in advance.
10. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — providing information in phases where it is not all available at once.
We will not make public statements identifying you in connection with a breach without your prior consent, unless legally required.
11. Deletion and return
On termination of your subscription, or on your written request:
- Access ends and collection stops immediately.
- You may export your time log data before termination takes effect, and we will assist with a reasonable export request made within 30 days after termination.
- We delete or anonymise the personal data within 90 days, except to the extent law requires us to retain it, in which case we isolate it and keep protecting it.
- Backups age out on their normal cycle.
- Revoking TickPax's authorisation in Azure DevOps or Entra ID stops all further collection immediately, at any time, without contacting us.
12. Audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will allow and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Audits are limited to once per twelve months unless a breach or a supervisory authority requires otherwise, must be requested at least 30 days in advance, must take place during business hours without unreasonable disruption, and are subject to confidentiality. Where available, we will first offer documentation, security-measure descriptions and written responses, which often satisfy the request without an on-site visit.
13. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where those limits are unenforceable under applicable data protection law. Nothing here limits a data subject's rights against either party under GDPR.
14. Term
This DPA takes effect when you accept the Terms of Service and continues while we process personal data on your behalf, plus the deletion period in §11.
Contact for data protection matters: privacy@tickpax.com TickPax, https://tickpax.com