Data processing agreement

This agreement governs personal data that Thoughtgears Ltd processes on your behalf when you use Bobbin. It forms part of the terms of service and applies from the moment you connect a Google Cloud project. Last updated 19 August 2026.

1. Who is who

You are the controller. Thoughtgears Ltd, a company registered in England and Wales, is the processor. Where this agreement refers to data protection law it means the UK GDPR and the Data Protection Act 2018, and the EU GDPR where that applies to you.

2. What we process, and why

The honest summary is that Bobbin is built to hold as little of your data as it can. It reads your telemetry at the moment an alert fires and keeps no copy of it.

CategoryPurposeRetention
Telemetry read during an investigation — log entries, metrics, error groups, Cloud Run revision configuration and admin audit entries from the projects you connect. May incidentally contain personal data if your logs do.To determine the likely cause of an alert.Not stored. Read transiently, in memory, during the investigation.
Investigation reports and transcripts — the conclusion, the evidence cited and the steps taken to reach it. Redacted before storage.So you can re-read an answer, and so we can measure and improve accuracy.While you are a customer. Deleted with your tenant (clause 9).
Account data — name, work email, company, Google account identifier.To create your tenant, authenticate you, contact you and bill you.While you are a customer, then six years for tax records.
Connection credentials — your Slack bot token, your GitHub App installation.To post reports to your channel and read repository metadata.Held in Secret Manager. Destroyed with your tenant.

Categories of data subject: your personnel who use the console, and any individual whose personal data happens to appear in the telemetry we read.

Duration: for as long as your subscription is active, plus the deletion period in clause 9.

3. Our instructions are your instructions

We process personal data only on your documented instructions, which are these terms and your use of the product — the projects you connect, the channel you choose, the repositories you install us on. If we believe an instruction breaches data protection law we will tell you and may pause that processing rather than carry it out.

We will not use your telemetry, your reports or your transcripts to train a general-purpose model, ours or anyone else's, and we do not sell data.

4. Confidentiality

Everyone with access to your data is bound by a duty of confidentiality that survives the end of their engagement. Today that is a small, named group; access is granted per secret rather than per project, so no part of our system holds a blanket right to read customer credentials.

5. Security

The measures we take under Article 32 are the architecture, not a policy document:

6. Sub-processors

You give general authorisation for the sub-processors below. We will give you at least30 days' notice by email before adding or replacing one, and you may terminate without penalty if you object.

Sub-processorWhat it doesWhere
Google Cloud PlatformHosting, storage, secret managementeurope-west1 (Belgium)
Google Cloud Vertex AIModel inference during an investigationEU endpoint where available — otherwise Vertex's global endpoint (clause 7)
Slack TechnologiesDelivering the report to your workspaceUnited States
GitHubCommit and diff metadata, only if you install our appUnited States
CloudflareStatic hosting and request forwarding for our web surfacesGlobal edge
ResendTransactional emailUnited States
StripePayment processingUnited States / Ireland

7. International transfers

Storage and routing are pinned to europe-west1. One exception is worth stating plainly rather than burying:

Model inference may leave the EEA. Bobbin selects the model best suited to an investigation, and the newest tiers are sometimes served only from Vertex AI's global endpoint. When that happens, the telemetry excerpts in that request are processed outside the EEA. Nothing is stored there, and no other part of the product moves.

Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and on the transfer terms in our own agreements with the sub-processors above.

8. Helping you meet your obligations

9. Deletion

When your subscription ends, or when you ask us to remove your tenant, we delete your service account, your topic and subscription, your stored credentials, and your investigation reports and transcripts within 30 days.

We also revoke our access at the source rather than only deleting our copy of it: our Slack app is uninstalled from your workspace and our GitHub App installation is deleted. You do not have to do either yourself, and you do not have to run the revoke script for any of this to happen — that script removes the permissions you granted in your own Google Cloud project, which is the one part we cannot reach once our service account is gone.

Account and billing records are kept for six years, because tax law requires it. Backups cycle out on their own schedule and are not restored selectively; anything still present in a backup remains subject to this agreement until it expires.

10. Audits

We will make available the information you reasonably need to verify our compliance with this agreement, and will answer a security questionnaire once in any twelve-month period. We do not currently hold ISO 27001 or SOC 2, and will say so rather than imply otherwise.

11. Liability and precedence

Liability under this agreement is subject to the limits in the terms of service. Where this agreement and those terms conflict on the processing of personal data, this agreement wins.

Contact

Data protection questions, requests and breach reports:support@getbobbin.dev. Thoughtgears Ltd, registered in England and Wales.