skip to content
// legal

Data processing addendum

Effective September 16, 2026

This Data Processing Addendum ("DPA") forms part of the Midkernel Terms of Service (the "Agreement") between Midkernel, Inc., a Delaware corporation ("Midkernel," "Processor") and the customer accepting the Agreement ("Customer," "Controller").

If there is a conflict between this DPA and the Agreement on the subject of personal data processing, this DPA controls for that subject. Capitalized terms not defined here have the meaning in the Agreement or Privacy Policy.

1. Roles

1.1 For Customer Personal Data processed in the Service on Customer's documented instructions, Customer is the controller (or a processor for its own end customers) and Midkernel is the processor (or sub-processor).

1.2 "Customer Personal Data" means personal data contained in Customer Content or account/workspace data that Midkernel processes to provide the Service to Customer.

1.3 Midkernel may also process certain data as an independent controller (for example billing contacts, fraud/security logs, and Service-improvement data as described in the Agreement and Privacy Policy). That independent-controller processing is governed by the Privacy Policy and Agreement, not by Customer's controller instructions under this DPA.

2. Scope and Customer instructions

2.1 Midkernel will process Customer Personal Data only: (a) to provide, maintain, secure, and support the Service; (b) as described in the Agreement and Privacy Policy (including Service improvement where Customer has agreed under the Terms); (c) to comply with law; and (d) on other documented instructions from Customer that Midkernel can reasonably carry out.

2.2 Customer instructs Midkernel to process Customer Personal Data as needed to operate Scan, Threat Intel, plugins/marketplace features Customer enables, credits/billing, and related support — including transmitting Customer Content to subprocessors necessary for a run (for example hosting/compute, OpenRouter and model providers, and GitHub when Customer connects a repository).

2.3 Customer represents that it has a lawful basis and all notices/consents required for Midkernel and its subprocessors to process Customer Personal Data as described, including for white-box security testing of repositories Customer connects.

3. Subprocessors

3.1 Customer authorizes Midkernel to use subprocessors. Current categories include: sandbox/compute (including cloud providers such as AWS); hosting (Vercel); DNS/edge (Cloudflare); managed database; OpenRouter and underlying model providers; email (Resend); blockchain data access for native USDC payment verification on Base; analytics; and scheduling tools when Customer books with Midkernel.

3.2 Midkernel will impose data-protection terms on subprocessors no less protective than this DPA in substance, to the extent Midkernel can obtain them contractually. Midkernel remains responsible to Customer for subprocessors' performance under this DPA, except as limited in Section 8 and in the Agreement regarding third parties Midkernel does not control.

3.3 Connecting a repository or starting a Scan necessarily involves processing by third parties in the run path (including GitHub, Midkernel compute/hosting, OpenRouter, and model providers). Those parties may retain or process data under their own terms and retention schedules. Midkernel does not control and is not responsible for third parties' independent retention, training, logging, or security practices beyond Midkernel's contractual and technical controls described in the Trust page, Privacy Policy, and this DPA.

4. Confidentiality and personnel

Midkernel will ensure personnel who process Customer Personal Data are bound by confidentiality obligations and access Customer Personal Data only as needed for their role. Midkernel staff access to customer runs is limited to support Customer requests and is recorded, as described on the Trust page.

5. Security

Midkernel will implement appropriate technical and organizational measures for the Service, including isolated single-use sandboxes for Scan runs where applicable, access controls, and encryption in transit for standard Service interfaces. Security measures may evolve. Midkernel does not claim SOC 2 or ISO 27001 certification at this time.

6. Retention and deletion

6.1 Midkernel designs the Service for short retention of Scan reports, logs, and artifacts (default 90 days, then deletion on request or project delete, subject to short-lived backups), as described in the Privacy Policy.

6.2 Customer acknowledges that: (a) Midkernel may retain data as needed for security, abuse prevention, dispute, legal, and Service-improvement purposes described in the Agreement; and (b) subprocessors and third parties in the run path may retain copies under their own policies for periods Midkernel does not control. Midkernel will, on Customer request after termination or as required by law, delete or return Customer Personal Data in Midkernel's possession that Midkernel is not required or permitted to retain, except residual backup copies that age out on Midkernel's backup cycle.

7. Assistance; rights requests; breach notice

7.1 Midkernel will provide reasonable assistance to Customer, taking into account the nature of processing, for data-subject requests, DPIAs, and security questionnaires, at Midkernel's then-current support channels. Midkernel may charge reasonable fees for disproportionate requests.

7.2 If Midkernel receives a data-subject request relating to Customer Personal Data, Midkernel will direct the individual to Customer where appropriate, unless law requires Midkernel to respond directly.

7.3 Midkernel will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data in Midkernel's possession, and will provide information reasonably available to Midkernel to help Customer meet its obligations.

8. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Midkernel is not liable for: (a) Customer's instructions; (b) Customer's failure to have a lawful basis; or (c) acts or omissions of third parties outside Midkernel's reasonable control, including GitHub, OpenRouter, model providers, cloud hosts, and other subprocessors acting outside Midkernel's instructions or under their own independent terms.

9. International transfers

Customer Personal Data may be processed in the United States and other countries where Midkernel and its subprocessors operate. Where a legally required transfer mechanism is needed (for example standard contractual clauses), the parties will use that mechanism, and Customer authorizes Midkernel to enter into such clauses with subprocessors on Customer's behalf as needed to provide the Service.

10. Term

This DPA lasts as long as Midkernel processes Customer Personal Data under the Agreement, and survives for provisions that by nature should survive (including confidentiality, liability, and deletion).

11. Governing law

This DPA follows the governing law and venue in the Agreement (New York law; courts in New York, New York), except where data-protection law requires otherwise for a specific mandatory right.