Skip to main content
Stubsmith
  • Pricing
  • Security
  • Guides
  • Docs
Dashboard ↗
  • Pricing
  • Security
  • Guides
  • Docs
  • Dashboard ↗
Need a signed copy? If you require a countersigned DPA (common for GDPR compliance and enterprise procurement), contact legal@stubsmith.dev and we will issue one.

Data Processing Agreement

Last updated: August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Bram Hoven, a sole trader established in the Netherlands and trading as Stubsmith ("Processor"), and governs the processing of personal data by Stubsmith on your behalf when you use the SDK to capture API traffic.

1. Definitions

Terms used here carry the meanings given in the EU General Data Protection Regulation (GDPR, Regulation 2016/679). "Personal data" means any information relating to an identified or identifiable natural person contained in API traffic captured by the SDK.

2. Roles

You are the data controller of any personal data contained in API samples you capture. Stubsmith is the data processor: it processes that data solely to provide the Service as instructed by you.

Note on masking: The SDK masks samples at the edge, inside your infrastructure, before anything is transmitted. Stubsmith receives masked bodies plus field and path names, never raw values; we cannot access original sample content. This DPA covers the residual processing (storing masked bodies, structural fingerprints, and metadata) and your obligations as controller.

3. Subject matter, nature, and purpose of processing

  • Subject matter: API request/response data captured by the Stubsmith SDK.
  • Nature: storage of masked bodies and structural fingerprints; generation of stub artefacts.
  • Purpose: generating privacy-safe API stubs for use in development and testing.
  • Duration: for the term of your subscription plus the applicable sample retention window.
  • Categories of data: any personal data contained in your API traffic (you determine this as controller).
  • Categories of data subjects: any individuals whose data appears in your API traffic.

4. Processor obligations

Stubsmith will:

  • Process personal data only on documented instructions from you (these Terms and your configuration).
  • Ensure persons authorized to process the data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see Security page).
  • Assist you in fulfilling your GDPR obligations regarding data subject rights (access, erasure, etc.).
  • Delete or return personal data at the end of the service relationship as you instruct (see section 9).
  • Provide all information necessary to demonstrate compliance and cooperate with audits.
  • Notify you without undue delay (and within 72 hours where feasible) of any personal data breach.

5. Controller obligations

You agree to:

  • Ensure you have a lawful basis to capture and process the personal data transmitted through the SDK.
  • Configure the SDK anonymizer rules to mask or exclude sensitive personal data before capture where appropriate.
  • Comply with applicable data protection laws in your jurisdiction.
  • Not instruct Stubsmith to process personal data in a way that would violate applicable law.

6. Sub-processors

Stubsmith uses the following sub-processors. By accepting this DPA, you authorize their use. We will notify you of any changes at least 14 days in advance.

  • UpCloud Ltd (Finland), infrastructure hosting (compute and database)
  • Scaleway SAS (France), object storage
  • Armitage Labs OÜ, trading as Creem (Estonia), merchant of record and payment processing (billing metadata only; no sample data)
  • Bunny.net d.o.o. (Slovenia), DNS and CDN for public static surfaces (visitor IP addresses and request metadata for static content; no persistent customer data)
  • Infomaniak Network SA (Switzerland), email hosting (correspondence only; no sample data)

7. International transfers

Processing takes place within the EU/EEA, or in Switzerland, which the European Commission recognises as providing an adequate level of protection (adequacy decision of 15 January 2024, following the revised Swiss Federal Act on Data Protection). Transfers to Switzerland therefore require no additional safeguards. No personal data is transferred to a country without such recognition, and we rely on no standard contractual clauses. UpCloud, Scaleway, Creem, and Bunny.net are EU-based entities. Infomaniak is Swiss and hosts exclusively in its own datacentres in Switzerland.

8. Security measures (Article 32 GDPR)

Technical and organizational measures include:

  • Edge-only masking: sample values replaced by the SDK before transmission; server stores masked bodies and structural fingerprints, and no raw value except on fields for which the controller has approved a keep rule
  • PostgreSQL row-level security (fail-closed; zero-row result on missing context)
  • TLS 1.2+ for all data in transit
  • Private-network-only database access (no public endpoint)
  • EU-only infrastructure (UpCloud nl-ams, Scaleway nl-ams)
  • Access logging and audit trail for staff actions

9. Deletion and return of data

You can delete a workspace and all personal data in it at any time, without asking us: the owner does it from Settings → Account in the dashboard. Doing so revokes access for every member immediately and cancels any active subscription at the same moment.

The data itself is erased 30 days after the request. The delay exists so that a deletion made in error can be reversed by contacting support@stubsmith.dev inside that window; after it passes, the data is removed from the database and from object storage and cannot be restored. If you require immediate erasure rather than the 30-day window, tell us and we will carry it out.

Two things deliberately survive a deletion. Invoices and billing records are retained for 7 years under Dutch tax law, which is a legal obligation rather than a choice. And we keep a record that the deletion occurred, holding the workspace name, the address that requested it, and the dates, so that the request itself remains provable. Neither contains captured request data.

Export your stubs and fixtures before deleting, using the replay bundle endpoint. We cannot produce them for you afterwards.

10. Governing law

This DPA is governed by the laws of the Netherlands and is interpreted consistent with the GDPR.

11. Contact

For DPA inquiries or to request a countersigned copy: legal@stubsmith.dev

Stubsmith

Integration tests from real API behavior.

Product

  • Pricing
  • Security
  • Guides
  • Documentation
  • Dashboard

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement

Support

  • support@stubsmith.dev
  • privacy@stubsmith.dev
  • legal@stubsmith.dev

We reply within 3 business days.

© 2026 Stubsmith. All rights reserved.

EU-sovereign infrastructure: compute and storage in Amsterdam.