Data processing addendum

Last updated September 1, 2026. Demo text for a Framer template: replace it with your own before you publish.

Scope

This addendum applies when Quorum processes personal data on your behalf, under the GDPR, the UK GDPR and the CCPA.

Roles

You are the controller of the personal data in your repos and accounts. Quorum is the processor and acts only on your documented instructions.

What is processed

Names and work emails of the people who use Quorum, and commit author names that appear in findings, for as long as you use Quorum.

Security measures

Encryption in transit and at rest, least-privilege access for our staff, a SOC 2 Type II program and a yearly outside penetration test. Details are on our Security page.

Subprocessors

The current list is on our Security page. We give 30 days notice before adding one, and you can object in that time.

Breach notice

We tell you within 48 hours of confirming a breach that affects your personal data, with what we know and what we are doing about it.

Transfers

Transfers of EU and UK personal data rely on the Standard Contractual Clauses, which are part of this addendum.

Deletion

When you stop using Quorum, we delete or return your personal data within 90 days, unless the law requires us to keep it.

Signed copy

Email legal@quorumscan.dev for a countersigned copy of this addendum.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.