Data processing addendum
Last updated September 1, 2026. Demo text for a Framer template: replace it with your own before you publish.
Scope
This addendum applies when Quorum processes personal data on your behalf, under the GDPR, the UK GDPR and the CCPA.
Roles
You are the controller of the personal data in your repos and accounts. Quorum is the processor and acts only on your documented instructions.
What is processed
Names and work emails of the people who use Quorum, and commit author names that appear in findings, for as long as you use Quorum.
Security measures
Encryption in transit and at rest, least-privilege access for our staff, a SOC 2 Type II program and a yearly outside penetration test. Details are on our Security page.
Subprocessors
The current list is on our Security page. We give 30 days notice before adding one, and you can object in that time.
Breach notice
We tell you within 48 hours of confirming a breach that affects your personal data, with what we know and what we are doing about it.
Transfers
Transfers of EU and UK personal data rely on the Standard Contractual Clauses, which are part of this addendum.
Deletion
When you stop using Quorum, we delete or return your personal data within 90 days, unless the law requires us to keep it.
Signed copy
Email legal@quorumscan.dev for a countersigned copy of this addendum.