Data Processing Agreement
Last updated: June 30, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer”, the data controller) and Autonomy, operator of Descant (the data processor), and governs our processing of personal data contained in your Customer Content. It is available here at any time without manual request, and we will execute a countersigned copy on request.
Roles of the parties
The Customer is the controller of any personal data within Customer Content. Descant acts as the processor, processing that data only on the Customer’s documented instructions — namely, to provide the autonomous code-authoring and review service.
Subject matter and duration
The subject matter is the processing necessary to provide Descant. Processing continues for the duration of the Customer’s use of the service and until Customer Content is deleted or returned as described below.
Nature and purpose of processing
Descant accesses repositories the Customer connects and runs automated agents that plan, implement, and review changes to the Customer’s code. Processing is limited to what is necessary for that purpose.
Categories of data and data subjects
The data processed is primarily source code and repository metadata. Any personal data is incidental — for example, contributor names or email addresses embedded in code or commit history. Data subjects are the Customer’s personnel and any individuals referenced in the Customer Content.
Processor obligations
- Process personal data only on the Customer’s documented instructions.
- Ensure personnel authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures, including tenant isolation so a run uses only its tenant’s credentials and never reaches another tenant’s repository.
- Assist the Customer in responding to data-subject requests and in meeting security, breach-notification, and impact-assessment obligations.
- Delete or return Customer Content at the end of the service, save where retention is required by law.
Subprocessors
The Customer authorizes Descant to engage subprocessors to provide the service. Each subprocessor is bound by data-protection obligations no less protective than this DPA. Our subprocessor list identifies, by role, each subprocessor that may receive customer code; the specific identities of the large-language-model providers are disclosed in a confidential subprocessor list available on request. We will provide notice of changes so the Customer may object.
International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
Audit
On reasonable request, we will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by the Customer or an appointed auditor, subject to confidentiality and security constraints.
Liability
Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service.
Contact us
To request a countersigned DPA or to ask about data processing, email [email protected]. Descant is a product of Autonomy — meetautonomy.com.