Data processing agreement
This agreement governs personal data that Thoughtgears Ltd processes on your behalf when you use Bobbin. It forms part of the terms of service and applies from the moment you connect a Google Cloud project. Last updated 19 August 2026.
1. Who is who
You are the controller. Thoughtgears Ltd, a company registered in England and Wales, is the processor. Where this agreement refers to data protection law it means the UK GDPR and the Data Protection Act 2018, and the EU GDPR where that applies to you.
2. What we process, and why
The honest summary is that Bobbin is built to hold as little of your data as it can. It reads your telemetry at the moment an alert fires and keeps no copy of it.
| Category | Purpose | Retention |
|---|---|---|
| Telemetry read during an investigation — log entries, metrics, error groups, Cloud Run revision configuration and admin audit entries from the projects you connect. May incidentally contain personal data if your logs do. | To determine the likely cause of an alert. | Not stored. Read transiently, in memory, during the investigation. |
| Investigation reports and transcripts — the conclusion, the evidence cited and the steps taken to reach it. Redacted before storage. | So you can re-read an answer, and so we can measure and improve accuracy. | While you are a customer. Deleted with your tenant (clause 9). |
| Account data — name, work email, company, Google account identifier. | To create your tenant, authenticate you, contact you and bill you. | While you are a customer, then six years for tax records. |
| Connection credentials — your Slack bot token, your GitHub App installation. | To post reports to your channel and read repository metadata. | Held in Secret Manager. Destroyed with your tenant. |
Categories of data subject: your personnel who use the console, and any individual whose personal data happens to appear in the telemetry we read.
Duration: for as long as your subscription is active, plus the deletion period in clause 9.
3. Our instructions are your instructions
We process personal data only on your documented instructions, which are these terms and your use of the product — the projects you connect, the channel you choose, the repositories you install us on. If we believe an instruction breaches data protection law we will tell you and may pause that processing rather than carry it out.
We will not use your telemetry, your reports or your transcripts to train a general-purpose model, ours or anyone else's, and we do not sell data.
4. Confidentiality
Everyone with access to your data is bound by a duty of confidentiality that survives the end of their engagement. Today that is a small, named group; access is granted per secret rather than per project, so no part of our system holds a blanket right to read customer credentials.
5. Security
The measures we take under Article 32 are the architecture, not a policy document:
- Read-only access, granted by you. Four Google-managed viewer roles, on the projects you name. Bobbin holds no role that could change anything in your infrastructure.
- No telemetry at rest. We reach into your project at the moment of an alert and keep no copy.
- One identity per customer. Each tenant has a dedicated service account; no shared credential can cross a customer boundary.
- Per-secret access control. Your credentials are readable only by the services that need that specific secret.
- Redaction of report and transcript content before it is stored.
- Encryption in transit and at rest, using Google Cloud's managed encryption.
6. Sub-processors
You give general authorisation for the sub-processors below. We will give you at least30 days' notice by email before adding or replacing one, and you may terminate without penalty if you object.
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud Platform | Hosting, storage, secret management | europe-west1 (Belgium) |
| Google Cloud Vertex AI | Model inference during an investigation | EU endpoint where available — otherwise Vertex's global endpoint (clause 7) |
| Slack Technologies | Delivering the report to your workspace | United States |
| GitHub | Commit and diff metadata, only if you install our app | United States |
| Cloudflare | Static hosting and request forwarding for our web surfaces | Global edge |
| Resend | Transactional email | United States |
| Stripe | Payment processing | United States / Ireland |
7. International transfers
Storage and routing are pinned to europe-west1. One exception is worth stating plainly rather than burying:
Model inference may leave the EEA. Bobbin selects the model best suited to an investigation, and the newest tiers are sometimes served only from Vertex AI's global endpoint. When that happens, the telemetry excerpts in that request are processed outside the EEA. Nothing is stored there, and no other part of the product moves.
Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and on the transfer terms in our own agreements with the sub-processors above.
8. Helping you meet your obligations
- Data subject requests. Because we store almost nothing, most requests are answered from your own systems. Where a request reaches data we hold, we will help you respond within 10 working days of you asking.
- Breach notification. We will tell you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it.
- Impact assessments. We will give you the information you reasonably need for a DPIA or a consultation with a supervisory authority.
9. Deletion
When your subscription ends, or when you ask us to remove your tenant, we delete your service account, your topic and subscription, your stored credentials, and your investigation reports and transcripts within 30 days.
We also revoke our access at the source rather than only deleting our copy of it: our Slack app is uninstalled from your workspace and our GitHub App installation is deleted. You do not have to do either yourself, and you do not have to run the revoke script for any of this to happen — that script removes the permissions you granted in your own Google Cloud project, which is the one part we cannot reach once our service account is gone.
Account and billing records are kept for six years, because tax law requires it. Backups cycle out on their own schedule and are not restored selectively; anything still present in a backup remains subject to this agreement until it expires.
10. Audits
We will make available the information you reasonably need to verify our compliance with this agreement, and will answer a security questionnaire once in any twelve-month period. We do not currently hold ISO 27001 or SOC 2, and will say so rather than imply otherwise.
11. Liability and precedence
Liability under this agreement is subject to the limits in the terms of service. Where this agreement and those terms conflict on the processing of personal data, this agreement wins.
Contact
Data protection questions, requests and breach reports:support@getbobbin.dev. Thoughtgears Ltd, registered in England and Wales.