Levr

Data Processing Addendum

Effective date: 21 July 2026 Last updated: 21 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between BitModern, Inc. ("BitModern", "Processor", "we") and the customer entity agreeing to those Terms ("Customer", "Controller", "you").

This DPA applies automatically — no signature is required — where you are subject to the GDPR, UK GDPR, Swiss FADP, the CCPA/CPRA, or a comparable data protection law, and we process Personal Data contained in Customer Data on your behalf. If your procurement process requires a countersigned copy, email privacy@bitmodern.com and we will execute one.

In the event of conflict between this DPA and the Agreement, this DPA controls as to the processing of Personal Data.


1. Definitions

Terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.


2. Roles and scope

You are the Controller (or, under the CCPA, the Business) of Personal Data in your Workspace. We are the Processor (or Service Provider) and process it only on your behalf.

Where you are yourself a processor acting for another controller, you warrant that you have the authority to appoint us as a sub-processor and to give the instructions in this DPA on that controller's behalf.

This DPA does not apply to data for which we are the controller — account, billing, and website data described in Section 1(a) of the Privacy Policy.


3. Processing instructions

We will process Personal Data only:

  1. on your documented instructions, which comprise the Agreement, this DPA, your configuration of the Services, and the operations you and your Agents initiate through the Services;
  2. as necessary to provide, secure, and support the Services; and
  3. as required by applicable law — in which case we will inform you before processing, unless the law prohibits it on important grounds of public interest.

We will notify you if, in our opinion, an instruction infringes Data Protection Law. We will not process Personal Data for our own purposes.

No model training. We will not use Personal Data to train, fine-tune, or otherwise improve any machine-learning model, and we contractually require our AI Sub-processors to process Personal Data on a no-training basis. This is a processing restriction, not merely a policy statement.

No sale or sharing. We will not sell or share Personal Data as those terms are defined by the CCPA, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the services specified in the Agreement, and will not combine it with personal information from other sources except as permitted to a service provider. We certify that we understand and will comply with these restrictions.


4. Confidentiality

We ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and are trained on their responsibilities. Access is granted on a least-privilege, need-to-know basis and is revoked promptly when no longer required.


5. Security

We implement and maintain the technical and organizational measures described in Annex II, appropriate to the risk under GDPR Article 32. We may update those measures provided they do not materially reduce overall security.

You are responsible for your own configuration of the Services — access controls, Agent permission scopes, credential rotation, and what data you allow Agents and Connected Services to reach — and for assessing that the measures in Annex II meet your requirements.


6. Sub-processors

General authorization. You give us general written authorization to engage Sub-processors. Our current Sub-processors are listed at Sub-processors.

Notice and objection. We will give at least ten (10) days' notice before a new Sub-processor begins processing Personal Data, by updating that page and notifying subscribers to its change feed. You may subscribe at privacy@bitmodern.com. If you reasonably object on data protection grounds within that period, we will work with you in good faith to provide an alternative; if we cannot, you may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid unused fees.

Flow-down and liability. We impose data protection obligations on each Sub-processor no less protective than those in this DPA, and we remain fully liable to you for each Sub-processor's performance.


7. Data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures — insofar as possible — to fulfil your obligations to respond to Data Subject requests to access, rectify, erase, restrict, port, or object to processing.

The Services give you direct ability to access, correct, export, and delete Personal Data in your Workspace, which will usually be sufficient. If we receive a request directly from a Data Subject relating to your Workspace, we will not respond substantively; we will promptly refer them to you and forward the request.


8. Personal Data Breach

We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data we process for you. The notice will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. We will supplement as further information becomes available, and will assist you with your own notification obligations under Articles 33 and 34.

Our notification is not an acknowledgement of fault or liability.


9. Data protection impact assessments

We will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under GDPR Articles 35 and 36, taking into account the nature of processing and the information available to us.


10. Deletion and return

On your instruction, we delete Personal Data immediately — deletion begins without undue delay and is complete in active systems within seven (7) days. Deleted data is purged from backups within thirty-five (35) days.

Where the Agreement terminates for a reason other than your deletion request, we retain Personal Data for thirty (30) days so you can export it, then delete it. You may end that window early by requesting immediate deletion.

You may export Personal Data in a structured, machine-readable format through the Services at any time. We will certify deletion in writing on request. We retain Personal Data beyond these periods only where required by law, and then only for that purpose and duration.


11. Audits

We will make available information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

Documentation first. We will satisfy this obligation in the first instance by providing our security documentation, completed security questionnaires, and any third-party audit reports or certifications we hold. You agree to accept these where they reasonably address your request.

On-site inspection. Only where that documentation is demonstrably insufficient to meet a specific requirement of Data Protection Law or of a supervisory authority may you request an on-site inspection, subject to all of the following:

  1. at least thirty (30) days' prior written notice, identifying the specific requirement the documentation did not satisfy;
  2. no more than once in any twelve-month period, except where a supervisory authority requires it or following a Personal Data Breach affecting your Personal Data;
  3. conducted during business hours, to a scope agreed in advance, and without unreasonably disrupting our operations;
  4. conducted by you or by an independent third-party auditor who is not a competitor of ours, bound by written confidentiality obligations at least as protective as those in the Agreement; and
  5. no access to other customers' data, to personnel or premises unrelated to the processing, or to any multi-tenant infrastructure in a manner that would compromise another customer's confidentiality or security. We may redact or withhold information to the extent necessary to protect those interests, our own security, or legal privilege.

Costs. You bear your own costs and reimburse our reasonable costs for time, personnel, and resources expended in supporting an on-site inspection, at our then-current professional services rates. Exception: if an inspection reveals our material non-compliance with this DPA, we bear our own costs and will remediate at our expense.


12. International transfers

We process Personal Data in the United States and in other countries where our Sub-processors operate.

EEA transfers. The SCCs are incorporated by reference and apply to transfers of Personal Data from the EEA to a country without an adequacy decision, on the following basis:

UK transfers. The UK International Data Transfer Addendum to the SCCs applies, with Tables 1–3 populated by the Annexes to this DPA and Table 4 selecting "neither party" as the party that may end the Addendum.

Swiss transfers. The SCCs apply with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as supervisory authority, and "member state" not limiting Data Subjects' rights in their place of habitual residence.


13. General

This DPA is governed by the law stated in the Agreement, except that the SCCs are governed as set out in Section 12. If any provision is unenforceable, the remainder stands. This DPA terminates automatically when the Agreement terminates and we have completed deletion under Section 10; Sections 4, 10, and 13 survive.


Annex I — Description of processing

A. Parties. Data exporter: Customer, acting as Controller, whose identity and contact details are those of the account holder in the Services. Data importer: BitModern, Inc., 8921 Northlake Hills Drive, Jonestown, Texas 78645, USA; contact privacy@bitmodern.com; acting as Processor.

B. Categories of Data Subjects. Customer's personnel and contractors who use the Services as Users; and any individuals whose personal data Customer or its Agents choose to include in Customer Data — which may include Customer's own employees, customers, end users, or third parties named in issues, comments, test records, repository content, or agent transcripts.

C. Categories of Personal Data. Identification and contact data (name, email address, username, avatar); professional data (role, team, workspace membership); authentication and device data (IP address, session and device identifiers, sign-in timestamps, SSO identifiers); activity and attribution data (actions performed, by which human or Agent, and when); and any Personal Data Customer or its Agents include in Customer Data — including free-text content in issues, requirements, comments, test records, exploratory-testing sessions, attachments, repository and code context, agent transcripts, and prompts.

D. Sensitive data. The Services are not intended for special categories of Personal Data under GDPR Article 9, or for data subject to HIPAA, PCI-DSS, GLBA, or FERPA. Customer agrees not to submit such data (Agreement §5.6). If Customer does so despite that restriction, the measures in Annex II apply, and Customer remains responsible for assessing their sufficiency.

E. Frequency. Continuous, for the duration of the Agreement.

F. Nature and purpose. Hosting, storage, transmission, indexing, retrieval, and computation necessary to provide the Services described in the Agreement — including issue and test management, agent orchestration and execution, integration with Connected Services the Customer configures, and AI features the Customer invokes.

G. Duration. For the term of the Agreement, plus the deletion periods in Section 10.

H. Sub-processor processing. As described at Sub-processors, for the duration of each Sub-processor's engagement.

I. Competent supervisory authority. Determined under Clause 13 of the SCCs by reference to the data exporter's establishment or representative.


Annex II — Technical and organizational measures

This Annex must be kept accurate. It is a contractual representation, and customers will test it during security review.

Encryption. Personal Data is encrypted in transit using TLS and encrypted at rest in our primary data stores and object storage.

Access control. Role-based access control with least-privilege provisioning; unique named accounts for personnel; multi-factor authentication required for administrative access to production; access reviewed periodically and revoked promptly on role change or departure.

Tenancy isolation. Customer Data is segregated by workspace, with tenant scoping enforced at the data-access layer so that queries are constrained to the requesting workspace.

Pseudonymization and minimization. Aggregated operational statistics are de-identified. We collect only the data needed to operate the Services.

Resilience. The Services run on redundant, managed infrastructure. Regular encrypted backups are taken and their restoration is periodically tested.

Logging and monitoring. Access to production and to Personal Data is logged; logs are monitored for anomalous activity and retained for a period appropriate to incident detection and investigation. Every action in the Services is attributed to the human or Agent that performed it.

Vulnerability management. Dependencies are monitored for known vulnerabilities; security patches are applied on a risk-prioritized basis; code changes are peer-reviewed and pass automated checks before release.

Incident response. A documented process for detecting, escalating, investigating, and remediating security incidents, including the notification obligations in Section 8.

Personnel. Confidentiality obligations, background checks where permitted by law, and security-awareness training.

Sub-processor governance. Security and privacy review before engagement, and contractual flow-down of the obligations in this DPA.


Annex III — Sub-processors

The current list of authorized Sub-processors, including each one's name, processing activity, and location, is maintained at [Sub-processors](https://levr.one/subprocessors) and is incorporated into this DPA by reference. Changes are governed by Section 6.


Contact

BitModern, Inc. — 8921 Northlake Hills Drive, Jonestown, Texas 78645, USA Privacy and DPA requests: privacy@bitmodern.com

See also Terms of Service, Privacy Policy and Sub-processors. Questions? Email legal@bitmodern.com.