Legal
Template version: September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Drubix ("Processor") and the customer agency ("Controller") for use of the Drubix service, and applies where the Controller's use of the Service involves the processing of personal data for which the Controller is responsible — most commonly, where a site the Controller submits for monitoring belongs to (or serves) the Controller's own end clients.
The Controller determines the purposes and means of processing personal data connected to the sites it submits (see Section 9 of the Privacy Policy — the Controller is responsible for having a basis to submit a given site). Drubix acts as Processor, processing data only as necessary to provide the Service and on the Controller's instructions.
This DPA covers the processing carried out by Drubix in connection with the Service for as long as the underlying service agreement between the parties remains in effect.
Drubix processes: site URLs, detected Drupal module names and versions, PHP version, configuration drift metadata, and (for account holders) name, email, and role. Processing is limited to what's needed to run scans, match security advisories, generate findings, alerts, and reports, and operate the account — see the Privacy Policy, Section 2, for the complete list.
Employees/contacts of the Controller who hold accounts, and — indirectly, where a monitored site is operated on behalf of the Controller's own client — that client's site administrators, to the extent their actions are reflected in scanned metadata (e.g. a config change attributed to a user role, not a name).
The Controller warrants it has a lawful basis for having each submitted site processed by Drubix, and is responsible for any onward notice or consent obligations toward its own end clients regarding that processing.
[Placeholder — list actual sub-processors here once finalized. Based on what's built: Paddle.com Market Ltd. (payment processing, billing) and the hosting provider running the application and database. Add/update as your actual infrastructure is finalized.]
Drubix will provide notice before adding a new sub-processor that would materially change the risk to the Controller's data, and the Controller may object on reasonable data-protection grounds.
Encryption in transit; sensitive values (connector authentication tokens) encrypted at rest; signed, verified communication for automated data submission (the connector module and payment webhooks); rate limiting and suspicious-activity monitoring on authentication endpoints. See the README's security-hardening section for the full technical detail, available on request.
[Placeholder — describe where data is actually hosted and, if the Controller or its end clients are in the EU/UK, what transfer mechanism applies (e.g. Standard Contractual Clauses) once confirmed with a lawyer and your actual hosting setup — same placeholder as the Privacy Policy, Section 7, since this needs the same real infrastructure detail to complete.]
Drubix provides self-service data export (GET /api/agencies/me/export) and account/data deletion (DELETE /api/agencies/me) directly in the product, so the Controller can fulfill most data subject requests without needing to contact Drubix directly. For anything these don't cover, contact hello@drubix.com.
Drubix will notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data, providing information reasonably available at the time and updating it as the investigation progresses.
On termination, the Controller may export its data (Section 9) and/or request deletion at any time; deletion cascades to all associated site, scan, and finding data automatically.
[Placeholder — should match the governing-law clause finalized in the Terms of Service.]
[This section intentionally left as a template — add signature blocks for both parties once the placeholders above are filled in and the document has been reviewed.]
Questions about this DPA: hello@drubix.com.