Skip to main content
Stubsmith
  • Pricing
  • Security
  • Docs
Dashboard →
  • Pricing
  • Security
  • Docs
  • Dashboard →
Draft — contact us for the current version.This DPA is a working draft. If you require a signed DPA (common for GDPR compliance and enterprise procurement), please contact legal@stubsmith.dev and we will issue a countersigned version.

Data Processing Agreement

Last updated: July 2026 • Draft

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Stubsmith ("Processor") and governs the processing of personal data by Stubsmith on your behalf when you use the SDK to capture API traffic.

1. Definitions

Terms used here carry the meanings given in the EU General Data Protection Regulation (GDPR, Regulation 2016/679). "Personal data" means any information relating to an identified or identifiable natural person contained in API traffic captured by the SDK.

2. Roles

You are the data controller of any personal data contained in API samples you capture. Stubsmith is the data processor: it processes that data solely to provide the Service as instructed by you.

Note on encryption: Stubsmith's SDK encrypts samples at the edge before they leave your infrastructure. Stubsmith stores only ciphertext; we cannot access plaintext sample content. For practical purposes, personal data in sample bodies is inaccessible to us. This DPA covers the residual processing (storing ciphertext, structural fingerprints, and metadata) and your obligations as controller.

3. Subject matter, nature, and purpose of processing

  • Subject matter: API request/response data captured by the Stubsmith SDK.
  • Nature: storage of encrypted blobs and structural fingerprints; generation of stub artefacts.
  • Purpose: generating privacy-safe API stubs for use in development and testing.
  • Duration: for the term of your subscription plus the applicable sample retention window.
  • Categories of data: any personal data contained in your API traffic (you determine this as controller).
  • Categories of data subjects: any individuals whose data appears in your API traffic.

4. Processor obligations

Stubsmith will:

  • Process personal data only on documented instructions from you (these Terms and your configuration).
  • Ensure persons authorized to process the data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see Security page).
  • Assist you in fulfilling your GDPR obligations regarding data subject rights (access, erasure, etc.).
  • Delete or return personal data at the end of the service relationship as you instruct.
  • Provide all information necessary to demonstrate compliance and cooperate with audits.
  • Notify you without undue delay (and within 72 hours where feasible) of any personal data breach.

5. Controller obligations

You agree to:

  • Ensure you have a lawful basis to capture and process the personal data transmitted through the SDK.
  • Configure the SDK anonymizer rules to mask or exclude sensitive personal data before capture where appropriate.
  • Comply with applicable data protection laws in your jurisdiction.
  • Not instruct Stubsmith to process personal data in a way that would violate applicable law.

6. Sub-processors

Stubsmith uses the following sub-processors. By accepting this DPA, you authorize their use. We will notify you of any changes at least 14 days in advance.

  • Scaleway SAS (France) — infrastructure hosting, managed PostgreSQL, object storage, key management
  • Mollie B.V. (Netherlands) — payment processing (billing metadata only; no sample data)
  • Bunny.net (Slovenia) — CDN and DNS (no persistent customer data stored)

7. International transfers

All processing takes place within the EU/EEA. No personal data is transferred to third countries. Scaleway, Mollie, and Bunny.net are all EU-based entities.

8. Security measures (Article 32 GDPR)

Technical and organizational measures include:

  • Edge-only encryption: sample payloads encrypted by SDK before transmission; server stores only ciphertext
  • Per-organization KMS wrapping keys (dedicated keys for Business tier)
  • PostgreSQL row-level security (fail-closed; zero-row result on missing context)
  • TLS 1.2+ for all data in transit
  • Private-network-only database access (no public endpoint)
  • EU-only infrastructure (Scaleway nl-ams / fr-par)
  • Access logging and audit trail for staff actions

9. Governing law

This DPA is governed by the laws of the Netherlands and is interpreted consistent with the GDPR.

10. Contact

For DPA inquiries or to request a countersigned copy: legal@stubsmith.dev

Stubsmith

Privacy-safe API stubs from real traffic.

Product

  • Pricing
  • Security
  • Documentation
  • Dashboard

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement

© 2026 Stubsmith. All rights reserved.

EU-sovereign infrastructure — compute in the EU, keys in Amsterdam.