Scope and parties
This Data Processing Addendum ("DPA") applies when Smoketest processes personal data on behalf of a customer through the Smoketest service. It supplements the Smoketest Terms of Service and Privacy Policy.
Smoketest is operated by Sayfun Studio, registered in the Netherlands under KvK number 42034313 and VAT ID NL005445100B28. In this DPA, “Customer” means the person or organization using Smoketest, and “Smoketest”, “we”, “us”, and “our” refer to Sayfun Studio and any entity that operates the service on its behalf, including any successor trade name or operating entity.
This page is a public working DPA for standard self-service use. If you need a separately signed agreement, contact us.
Roles
For customer content submitted to or retrieved through authorized Connections to run tests, including issue content, comments, supported attachment content and metadata, linked pull request context, tests, target URLs, page content captured during runs, credentials, environment variables, and run artifacts, Customer is generally the controller and Smoketest is generally the processor.
Smoketest remains an independent controller for account administration, billing, service security, product analytics, support, legal compliance, and communications as described in the Privacy Policy.
Processing details
Customer instructions
Smoketest will process customer personal data only to provide, secure, support, and maintain the service; to follow Customer's documented instructions through product configuration, API calls, authorized Jira, Linear, and repository Connections, integrations, and support requests; and as required by law.
Customer is responsible for ensuring that it has all rights, permissions, notices, and legal bases necessary to use Smoketest with the Jira or Linear workspaces, repositories, systems, accounts, URLs, credentials, attachments, and personal data it provides or instructs Smoketest to retrieve.
Security measures
Smoketest uses technical and organizational measures designed to protect customer personal data, including:
- encryption in transit for service connections;
- AES-256-GCM encryption for stored customer credentials, issue Jira and Linear OAuth tokens, and environment variables;
- signature or token verification before accepted provider webhook events are processed;
- sanitization, length limits, attachment allowlists, and recognized-secret redaction for issue and linked pull request context;
- signed URLs/private access for run artifacts;
- 90-day lifecycle deletion for run artifacts stored in Cloudflare R2;
- workspace scoping for customer data access;
- structured log redaction for authorization and cookie headers;
- server backups, monitoring, and operational logging;
- limited access to production systems based on operational need.
No system is perfectly secure. Customer should use dedicated test accounts and avoid real credentials or unnecessary production personal data whenever possible.
Subprocessors
Customer authorizes Smoketest to use the subprocessors below to provide the service. Smoketest remains responsible for its subprocessors' processing of customer personal data as required by applicable data protection law.
| Subprocessor | Purpose | Typical data involved |
|---|---|---|
| Hetzner Online GmbH | Hosting and backups | Application data, database records, server backups |
| Cloudflare | R2 artifact storage | Recordings, screenshots, traces, transcripts, and other run artifacts |
| Browser Use | Cloud browser execution and provider recording processing | Target URLs/pages, browser sessions, browser actions, page observations, and provider recordings |
| OpenAI | AI-assisted test execution and outcome evaluation | Tests, prompts, target URLs, page observations, tool outputs, summaries |
| Polar Software, Inc. | Merchant of record, checkout, billing, tax/payment metadata | Email, customer IP, workspace/customer IDs, subscription/order/product metadata, usage/cost events |
| Plunk | Transactional, operational, lifecycle, and consent-based marketing email | Email, template data, message metadata, marketing consent metadata |
| PostHog | Essential product-health analytics | Product events, user/workspace/run IDs, usage metrics, browser/device metadata |
| OAuth and Google Workspace email | OAuth profile data, account identifiers, support/privacy/security email content | |
| GitHub | OAuth authentication and optional repository/deployment integrations | OAuth profile data, account identifiers, GitHub App installation metadata, repository metadata, webhook delivery metadata, deployment webhook check metadata, branch/PR/SHA metadata, check run IDs/status |
| Atlassian | Customer-directed Jira Connection, issue intake, comments, and status updates | OAuth account/site identifiers, encrypted connection credentials, scopes, project/workflow metadata, issue content, comments, bounded supported attachment content/metadata/URLs, webhook metadata, Test Request state, results, synchronization records |
| Linear | Customer-directed Linear Connection, issue intake, comments, and status updates | OAuth account/workspace identifiers, encrypted connection credentials, scopes, team/workflow metadata, issue content, comments, bounded supported attachment content/metadata/URLs, webhook metadata, Test Request state, results, synchronization records |
| Grafana Cloud | Logs and monitoring | Logs, errors, request metadata, user/workspace IDs, possible customer references in logs |
| c15t | Cookie consent management | Consent preferences, consent identifiers, browser/device metadata, and related consent records |
| Slack | Optional customer-directed notifications | Webhook/channel metadata, run/project/test names, triggers, failure/error summaries |
| Discord | Optional customer-directed notifications | Webhook/channel/guild metadata, run/project/test names, triggers, failure/error summaries |
Jira, Linear, GitHub, Slack, and Discord are customer-directed services configured by Customer. If Customer enables them, Customer instructs Smoketest to retrieve from or send the selected data to those services. Customer's own agreement with each provider also governs that provider's handling of data in the provider's service.
International transfers
Smoketest and its subprocessors may process personal data outside the European Economic Area. Where required, Smoketest will rely on lawful transfer mechanisms such as adequacy decisions, standard contractual clauses, data processing terms, or other safeguards recognized by applicable law.
Security incidents
If Smoketest becomes aware of a personal-data breach affecting customer personal data processed on Customer's behalf, Smoketest will notify Customer without undue delay after becoming aware of the incident.
The notice will include available information reasonably needed for Customer to meet its own breach-notification obligations. Smoketest may provide information in phases as investigation progresses.
Assistance and requests
Smoketest will provide reasonable assistance for data subject requests, deletion or export requests, security questions, and data protection inquiries relating to customer personal data processed through the service. Structured exports may include issue-derived records and provider provenance, but do not include OAuth tokens, webhook secrets, or third-party data the requester is not authorized to receive.
Deletion is currently handled manually. Contact [email protected] for privacy requests, or [email protected] for security issues.
Return and deletion
Upon request or account termination, Smoketest will delete or anonymize customer personal data within a commercially reasonable period unless retention is required for legal, accounting, billing, fraud-prevention, security, backup, dispute-resolution, or similar legitimate reasons.
Run artifacts stored in Cloudflare R2 are generally deleted after 90 days. Database run metadata may be retained longer until Smoketest defines and implements a formal metadata retention policy.
Disconnecting Jira or Linear removes stored provider credentials and its Connection registration but does not by itself delete historical Test Requests, Attempts, Results, frozen issue or supported attachment content, linked pull request context, synchronization records, or audit history. Those records are included when the related workspace data is deleted upon a valid request, subject to the exceptions above.
Audits and information
Smoketest will make reasonable information available to demonstrate compliance with this DPA. For self-service customers, this may include this DPA, the Privacy Policy, security documentation, subprocessor information, and written responses to reasonable privacy or security questions.
Changes
Smoketest may update this DPA and subprocessor list from time to time. If we make a material change that meaningfully affects processing of customer personal data, we will update this page and provide additional notice where required by applicable law or contract.
Need clarification?
Email [email protected]. A founder answers, usually the same day.
See also Terms of Service, Privacy Policy, and Security.