Data Processing Addendum
Last updated: 2026-04-06
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Migra-check ("Processor") and the customer ("Controller") and governs the processing of personal data submitted to the Migra-check service in accordance with Article 28 of the EU/UK GDPR, Canada's PIPEDA, and Quebec's Law 25.
1. Definitions
"Personal Data", "Data Subject", "Processing", "Controller", and "Processor" have the meanings given in the GDPR. "Customer Personal Data" means any personal data contained in Customer Data that is processed by us on your behalf.
2. Roles of the Parties
You act as the Controller of Customer Personal Data. We act as the Processor and will process Customer Personal Data only on your documented instructions, including those reflected in the Service itself and your account configuration.
3. Scope and Purpose of Processing
The subject matter is the provision of the Service. The duration is the term of your subscription. The nature and purpose is performing AI-based risk analysis of database migration scripts. The types of personal data and categories of data subjects are determined by you and should be limited because migra-check is not designed to process personal data — see Section 9.
4. Confidentiality
We ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
5. Security Measures
We implement appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure, including: encryption in transit (TLS), encryption at rest for databases and object storage, access controls and least-privilege administration, audit logging, and regular security reviews.
6. Subprocessors
You authorize us to engage the subprocessors listed in our Privacy Policy (AWS, Anthropic, Stripe, Auth0). We will impose data protection obligations on each subprocessor no less protective than those in this DPA. We will notify you of any intended additions or replacements so you may object on reasonable grounds.
7. International Transfers
Migra-check operates from the Province of Québec, Canada, and engages subprocessors in the United States. Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a third country without an adequacy decision, the parties agree to rely on the European Commission's Standard Contractual Clauses (and the UK Addendum, as applicable), which are incorporated by reference. For personal information subject to Quebec's Law 25, Migra-check has conducted a privacy impact assessment for transfers outside Quebec and relies on contractual safeguards to ensure an equivalent level of protection.
8. Data Subject Rights and Assistance
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to data subject requests and to comply with your obligations under Articles 32–36 of the GDPR.
9. Important Notice — Do Not Submit Personal Data in SQL
migra-check is intended to analyze DDL and schema-level SQL migrations. You should not submit actual production row data, personal data, or secrets in SQL scripts submitted to the Service. If you choose to do so, you do so at your own risk and remain the sole Controller responsible for the lawfulness of that processing.
10. Personal Data Breach Notification
We will notify you without undue delay after becoming aware of a personal data breach (or "confidentiality incident" under Quebec's Law 25) affecting Customer Personal Data and will provide information reasonably necessary to enable you to meet your breach notification obligations, including those owed to the Commission d'accès à l'information du Québec (CAI) where applicable.
11. Deletion and Return of Data
Upon termination of the Service, we will delete or return Customer Personal Data within a reasonable period, except where retention is required by applicable law.
12. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports where available.
13. Contact
For DPA-related requests, contact [email protected].