Last updated: 21 August 2026
This agreement governs the personal data we process on your behalf. It is annexed to the terms and forms part of them: accepting the terms accepts this.
This agreement is entered into under article 28.3 of Regulation (EU) 2016/679 between Alexandre Ribes, the Publisher, and any client subscribing to Quiet Guard, the Client.
It supplements the terms, of which it forms an inseparable annex. No separate signature is required: acceptance of the terms, recorded when your team was created, carries acceptance of this agreement.
Where the terms and this agreement conflict on a data protection point, this agreement prevails.
For the monitoring data sent by the Client's applications, the Client is the controller and the Publisher acts as processor.
If the Client itself processes that data on behalf of a third party, for instance an agency running its own client's application, the Publisher acts as a sub-processor. The Client then warrants that it has obtained the authorisation required by article 28.2 GDPR.
Account, billing and site usage data fall outside this agreement: the Publisher is the controller for those, and they are described in the privacy policy.
The subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects are set out in Annex 1, as article 28.3 GDPR requires.
The Publisher processes the data only on the Client's documented instructions, including as regards transfers outside the European Union.
Those instructions consist of: the terms, this agreement, the service configuration the Client chooses, in particular its plan and therefore its retention period, and the settings of the client package installed in its application.
If the Publisher considers that an instruction infringes the GDPR or another data protection provision, it informs the Client immediately and may suspend performance until the instruction is confirmed or amended.
Where Union or Member State law requires the Publisher to process beyond those instructions, it informs the Client before doing so, unless that law prohibits it on important grounds of public interest.
Access to the data is limited to the people who need it to provide the service, and only to the extent of that need.
Those people are under a contractual duty of confidentiality, and that duty outlives their assignment.
The Publisher implements the appropriate technical and organisational measures required by article 32 GDPR. They are described in Annex 2.
Those measures may change as the state of the art moves. A change may not lower the level of protection already in place.
The Client gives the Publisher a general authorisation to engage sub-processors. Those currently engaged are named in Annex 3.
The Publisher informs the Client of any addition or replacement at least thirty days before it takes effect, at the team owner's email address. The Client has thirty days to object in writing on reasonable data protection grounds. If the objection stands, the Client may terminate at no cost and without penalty, and the unused part of the subscription is refunded.
The Publisher imposes on each sub-processor, by contract, the same obligations as those in this agreement, and remains fully liable to the Client for their performance.
The service gives the Client the means to consult, to export and to delete the data it entrusts to us, which lets it answer most rights requests itself. The export is available at any time from the team settings and produces a ZIP archive of CSV files, in a structured, commonly used and machine-readable format within the meaning of article 20 GDPR. The archive stays on the hosting described in article 10 and is reached through a private link sent by email; it is never attached to that email, so exporting transfers nothing outside the European Union.
Where those means are not enough, the Publisher assists the Client by appropriate technical and organisational measures, insofar as this is possible and taking the nature of the processing into account.
If a data subject approaches the Publisher directly, the Publisher does not answer in the Client's place: it directs the person to the Client and informs the Client without delay.
The Publisher notifies the Client of any personal data breach affecting data processed on its behalf, without undue delay and at the latest forty-eight hours after becoming aware of it. That window is set so the Client can still meet its own, which is seventy-two hours.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Where that information cannot be given at once, it is given in phases without further undue delay.
The Publisher assists the Client in meeting its obligations under articles 32 to 36 GDPR, including for an impact assessment and for prior consultation of the supervisory authority.
The application, the database and the backups are hosted in France. Monitoring data is not transferred outside the European Union. Transactional email addressed to the Client and its members is delivered from Switzerland, a country covered by an adequacy decision of the European Commission.
Should a sub-processor carry out processing outside the Union, that transfer would be covered by the standard contractual clauses adopted by the European Commission on 4 June 2021, together with a transfer impact assessment. The Client may obtain a copy on request at legal@quietsystems.dev.
Throughout the contract, the Client may consult, export and delete its data at any time, the export being available from the team settings without asking us.
When the contract ends, monitoring data is deleted according to the retention period of the Client's plan and, in any event, no later than sixty days after the account is closed. Existing copies are deleted within the same period.
Closure is requested by the Client from its team settings and carries an effective date, at the end of the period already committed to and never sooner than seven days. The deletion is carried out on that date: it takes the monitoring data, the encrypted backups held in the vault and the associated files.
Backups placed in the encrypted vault are deleted by the Client at any time, and failing that within the same period. The Publisher cannot decrypt them.
The Publisher keeps nothing beyond that except what a legal obligation requires it to keep, and only for as long as that obligation lasts.
The Publisher makes available to the Client the information needed to demonstrate compliance with the obligations of article 28 GDPR.
The Client may commission one audit a year, on thirty days' written notice, during business hours, at its own expense, by itself or by an independent auditor who is not a competitor of the Publisher and who is bound by confidentiality. The audit must not disrupt the service or give access to another client's data.
A further audit may be requested following an established breach affecting the Client.
Where the Publisher holds an independent audit report covering the measures concerned, providing it to the Client discharges this obligation.
As controller, the Client warrants that it has a lawful basis for the processing it entrusts to the Publisher and that it has informed the data subjects that a monitoring provider is used.
Each party bears the consequences of its own breaches of this agreement.
The limitation of liability set out in the terms applies to this agreement. It does not affect the application of article 82 GDPR as regards data subjects and the supervisory authority.
This agreement takes effect when the account is created and remains in force for as long as the Publisher processes data on the Client's behalf.
Any substantial change is notified to the Client at least thirty days before it takes effect. Continuing to use the service beyond that date constitutes acceptance. A change required by a change in applicable law takes effect when that law does.
This agreement is governed by French law.
Purpose: to provide the Client with monitoring of its applications, namely centralising and presenting exceptions and logs, reporting dependency vulnerabilities, watching availability and holding encrypted backups.
Nature of the operations: collection, recording, organisation, structuring, storage, consultation, disclosure to the Client and its members, and erasure.
Duration: the term of the contract, plus the retention period of the Client's plan, and at most sixty days after the account is closed.
Categories of data subjects: the end users of the applications the Client monitors, the members of the Client's team, and the people who contributed to the repositories the Client connects.
| Category | Detail | Source | Retention |
|---|---|---|---|
| User identifier | Technical identifier of the person signed in at the time of the incident | Client package, by default | Plan retention |
| Request URL | Full address, query string included | Client package, by default | Plan retention |
| Request body | Excluding password fields and masked keys | Client package, by default | Plan retention |
| Request headers | Visitor IP address masked by default; the Client may restore it | Client package, by default | Plan retention |
| Exception content | Message, stack trace, technical context | The Client's application | Plan retention |
| Application logs | Message and context | The Client's application | Plan retention |
| Contributors | Name and public handle from connected repositories | GitHub API, when enabled | Until the project is deleted |
| Backups | Blocks encrypted on the Client's own server | Backup command | Until deleted by the Client |
The service does not ask for, require or expect any data falling under article 9 GDPR, any data on criminal convictions, or any full payment card details.
Such data can only reach the service through what the Client's application logs. It is for the Client to prevent that, and article 13 says so expressly.
These are the measures actually in place at the date shown at the top of this page.
The Publisher holds no ISO 27001 certification, no SOC 2 report and no round-the-clock security rota. These are stated here rather than passed over, so the Client can take them into account in its own risk assessment.
Where the Client uses the server-side unlock rather than the browser one, its private key is rebuilt on the Publisher's servers and stays there for the duration of the session. The browser unlock does not have that characteristic.
The list as it stands at the date shown at the top of this page. Any change is notified under article 7.