Data Processing Agreement
Last updated: 19 July 2026 · Nayeri Consulting AB (“Processor”) and the Customer (“Controller”).
1. Roles and scope
For personal data contained in the code and data you submit for analysis, you are the controller and Untangly is the processor. For your account data, we are the controller (see our Privacy Policy). We process personal data only on your documented instructions — which include your use of the service and its configuration.
2. Subject matter and duration
Subject matter: automated analysis of submitted source code to produce rules, findings, coverage and suggested changes. Duration: for the term of your subscription and until deletion per §7.
3. Nature and purpose; categories of data
We process whatever personal data happens to be present in the code/data you connect (e.g. identifiers, comments, seed/test data). We do not seek out special-category data; do not submit it unless necessary. We do not sell personal data and do not use submitted code to train generalized models.
4. Sub-processors
You authorize the sub-processors listed on our sub-processors page (hosting, AI model processing, payments, email). We impose data-protection obligations on each and remain responsible for their performance. We give notice of changes and you may object on reasonable data-protection grounds.
5. Security measures
We apply appropriate technical and organizational measures, including: encryption in transit and at rest, access on a need-to-know basis, secret redaction before code reaches an AI model, isolation of customer data, and least-privilege service credentials. Details available on request.
6. Data subject requests & assistance
Taking into account the nature of processing, we assist you in responding to data-subject requests and with your obligations under GDPR Articles 32–36 (security, breach notification, DPIAs). We notify you without undue delay after becoming aware of a personal-data breach affecting your data.
7. Return and deletion
On termination or your request, we delete or return submitted code and derived artifacts within the period stated in our Terms (§8), backup cycles excepted. You can trigger deletion by disconnecting a project or closing your account.
8. Audits
We make available information necessary to demonstrate compliance with Article 28 and allow for audits, subject to reasonable confidentiality and scheduling.
9. International transfers
Where a sub-processor processes data outside the EEA, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses).
To execute a countersigned copy for your organization, contact us via the contact page.