Data Processing Addendum
Last updated 11 October 2026
This Data Processing Addendum (“DPA”) is part of the Terms of Service between the customer (“you”) and ARUS ENTERPRISES LLC (“we”). It applies when we process personal data in your content for you, and it takes effect when you accept the Terms; you don't need to sign anything. If you need a countersigned copy, ask at support@bugsmash.dev.
“Data Protection Laws” means the laws that apply to that processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP and US state privacy laws such as the CCPA. Terms like “controller”, “processor”, “personal data” and “personal data breach” have the meanings those laws give them.
1. Roles and instructions
- You are the controller (or a processor acting for your own client) and we are your processor (or subprocessor) for personal data in your content (“Customer Personal Data”).
- We process Customer Personal Data only on your documented instructions. The Terms, this DPA and how you configure and use the Service are your instructions. We'll tell you if we think an instruction breaks Data Protection Laws. We don't sell or share Customer Personal Data, use it for our own purposes, or combine it with other data, except as the CCPA allows service providers to.
- You are responsible for having a lawful basis and giving any notices needed to collect Customer Personal Data and to have us process it, and for following the Acceptable Use Policy's rules on sensitive data.
2. Details of the processing (Annex I)
- Subject matter and duration: providing the Service for as long as the Terms last, plus the deletion periods in section 9.
- Nature and purpose: storing, displaying, transmitting and deleting your content so you can test your software and track bugs.
- Data subjects: your users and staff and anyone else whose data appears in pages you test; your workspace's members.
- Categories of data: whatever appears in screenshots, videos, traces, console logs, page addresses and notes, typically names, contact details, account identifiers and usage data. Special category data is not intended (see the Acceptable Use Policy).
- Frequency: continuous, as you use the Service.
3. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality, and we give access only to those who need it to run and support the Service.
4. Security (Annex II)
We maintain appropriate technical and organisational measures, which we may improve but won't weaken materially, including:
- encryption in transit (TLS) and at rest (by our database and storage providers);
- private file storage reachable only through short-lived signed links;
- tenant isolation: every data access is scoped to the workspace and project that owns it, covered by automated tests;
- passwords and API tokens stored only as hashes; tokens revocable at any time; sessions expire;
- role-based access inside workspaces (owner, member, viewer);
- production access limited to the people who run the Service, with multi-factor authentication on provider accounts;
- error monitoring configured not to collect user details, cookies, headers or request bodies;
- automated, encrypted database backups and point-in-time restore;
- automatic deletion of files after the plan's retention window.
5. Subprocessors
- You authorise us to use the subprocessors on our subprocessors page. We bind each one by written contract to data protection obligations at least as protective as this DPA, and we remain responsible for them.
- We'll give at least 30 days' notice by email to workspace owners before adding or replacing one. You may object on reasonable data-protection grounds within that period; if we can't resolve it, you may terminate the affected Service and we'll refund prepaid fees for the remaining period.
6. Helping you
- Data subject requests: the Service lets you find, correct and delete content yourself, and we export it on request. If we receive a request about your content, we'll pass it to you and not answer it ourselves unless you ask us to. We'll help with requests you can't handle in the Service.
- Assessments: we'll give reasonable information you need for data protection impact assessments and consultations with authorities.
7. Personal data breaches
We'll notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data, by email to workspace owners. We'll tell you what we know (nature, likely consequences, data and people affected, and what we are doing), update you as we learn more, and take reasonable steps to contain it. Notifying doesn't mean we accept fault.
8. International transfers
We process data in the United States. To the extent a transfer of Customer Personal Data to us needs a transfer mechanism:
- EU/EEA: the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference, with you as data exporter and us as data importer: Module Two (controller to processor) or Module Three (processor to processor), as applicable. Clause 7 (docking) applies; under Clause 9, option 2 (general authorisation) with the notice period in section 5; Clause 11's optional language does not apply; for Clauses 17 and 18, the law and courts of Ireland. Annexes I and II are sections 2 and 4 of this DPA, and the competent supervisory authority is the one for your establishment or representative.
- UK: the UK International Data Transfer Addendum (version B1.0) to those Clauses applies, completed with the details above; either party may end it as Section 19 of the Addendum allows.
- Switzerland: the same Clauses apply, with the FDPIC as the competent authority and references to the GDPR read as the FADP.
If those Clauses conflict with this DPA or the Terms, the Clauses win.
9. Deletion and return
You can delete your content in the Service, or ask us for an export, at any time. When the Terms end, or when you delete a workspace or your account, we delete Customer Personal Data from our live systems and from backups within 30 days, unless the law requires us to keep it. Files expire earlier under your plan's retention window.
10. Audits
We'll answer reasonable written security questionnaires once a year (or after a breach, or when an authority requires it), and give you the information needed to show we meet this DPA. If that isn't enough to meet a legal requirement, you may audit at your expense with 30 days' notice, during business hours, under confidentiality, in a way that doesn't expose other customers' data.
11. General
This DPA lasts as long as we process Customer Personal Data for you. The Terms' limitation of liability applies to it, except where Data Protection Laws or the Standard Contractual Clauses don't allow that. If this DPA conflicts with the Terms, this DPA wins on data protection.
ARUS ENTERPRISES LLC (ArusLogic)
30 N Gould St Ste N
Sheridan, WY 82801
United States
support@bugsmash.dev