Data processing addendum
Last updated September 9, 2026. Plain words on purpose: if a sentence here is unclear, it is wrong, and you can tell us at hello@sigbound.com.
This addendum is part of the Terms for every customer who uses the hosted service at sigbound.com. It says who is responsible for what when personal data passes through the service. The contracting entity and governing law are stated in the Terms.
Parties and roles
Sigbound means Sigbound Inc, the operator of the hosted service. The customer is the controller: the customer decides which people, repositories and goals go into a space, and why. Sigbound is the processor: it stores and processes that data only to run the service the customer asked for. Where the customer is itself a processor for someone else, Sigbound is a sub-processor and the same terms apply.
Subject matter and duration
The subject matter is the operation of the hosted service for the customer's spaces. Processing lasts for as long as the customer holds an account or a space, and for the removal period after closure described under Deletion and return.
Nature and purpose
Sigbound runs a code forge. Processing means: storing and serving repositories over git and the web; recording goals, attempts and decisions; running CI in sandboxes; reading attempts with Sigbound AI; notifying the people who need to decide; signing merges and keeping the signed merge records; and keeping the audit log a space relies on. Nothing is processed for advertising, profiling, or resale.
Categories of data
- Account data: email addresses, display names, and the roles and grants each account holds in a space.
- Repository contents and history, including anything a person or an agent commits, and the names and addresses in commit metadata.
- CI logs and artifacts.
- Goals, attempts, comments, reads, decisions and signed merge records, each attributed to the account or agent that produced it.
- Audit log entries naming the actor, the subject and the act.
- IP addresses and user agents in request logs, kept for a limited time.
Data subjects
The customer's members: the people who hold accounts in the customer's spaces, and the agents those people run. Where a public repository is involved, anyone who contributes to it.
Instructions
Sigbound processes personal data on the customer's documented instructions. The Terms, this addendum, and the settings the customer chooses in the product are those instructions. If a law requires Sigbound to process data otherwise, Sigbound tells the customer first unless the law forbids it.
Confidentiality
Everyone at Sigbound who can reach customer data is bound to keep it confidential, and reaches it only to operate the service, answer a request the customer made, or respond to an incident.
Security measures
The technical and organisational measures are described on the Security page: encryption in transit and at rest, isolated CI sandboxes, sealed secrets, role-based access per space, the audit log, and signed merges. Sigbound keeps those measures current and does not weaken them for the term of the agreement.
Subprocessors
Sigbound uses the subprocessors listed at /subprocessors. The customer authorises them by accepting this addendum. Sigbound announces a new or replaced subprocessor by email to the owners of every space at least 30 days before it begins processing customer data. A customer who objects on reasonable grounds may close its spaces before the change takes effect, using the export and closure described below.
Sub-processing
Every subprocessor is bound by written terms at least as protective as this addendum. Sigbound remains responsible to the customer for the subprocessor's performance.
Assistance
Sigbound assists the customer in answering requests from data subjects, as far as the product does not already let the customer answer them itself: a member can export and close their own account, and a space owner can export the whole space. Sigbound assists with security assessments and with notifying authorities where the customer is required to, and reports a personal data breach affecting the customer's data to the space's owners without undue delay after becoming aware of it.
Deletion and return
Return is self-serve. Any member can download everything held about them from Settings → Account. A space owner can download the whole space as one file (members, goals, attempts, landings with their signed merge records, the audit log) and every repository as a git bundle. A member can close their own account; every membership, session, token, connection and key is revoked at once, and records that named the account keep naming a former member. A space owner can set a cap, in days, on how long the space keeps CI artifacts. Removal from live systems and from backups follows the periods stated in the Privacy page. The Export and closure page documents each of these.
Audits
Sigbound publishes a controls map that states, criterion by criterion, which control exists and where it lives in the code or the stack. A SOC 2 report is not yet available; Sigbound says so plainly rather than implying otherwise. On request, Sigbound makes the controls map and the evidence behind it available to a customer, and answers reasonable questions about it.
International transfers
Customer data is stored and processed in Amazon Web Services in the United States, region us-east-1. Sigbound AI reads are processed by Anthropic under its terms for the data sent. A customer outside the United States relies on this addendum and on the subprocessors' transfer terms for the transfer.
Liability
Liability under this addendum follows the Terms. Nothing here adds to or limits what the Terms already say.