intentic
Create your workspace
Legal

Data Processing Agreement

Effective 2026-08-13. This agreement applies when we process personal data on your behalf, in practice, when you use a sandbox we host. It is concluded between you (the controller) and us (the processor) as part of the Terms of Service, and satisfies Article 28 of the GDPR. No signature is needed; accepting the Terms concludes it.

When this applies

It applies to personal data that ends up inside a sandbox we host for you: in repositories, files, databases or logs in that workspace, where you decide what is there and why.

It does not apply to your account, membership or sandbox records: for those we decide the purposes ourselves and act as controller, governed by the Privacy Policy. It also does not apply to a sandbox you run on your own infrastructure, because nothing of its contents reaches us.

The processing, in the terms Article 28 asks for

ItemWhat it is here
Subject matterHosting a development workspace on a virtual machine and disk we provide
DurationFor as long as the hosted sandbox exists; it ends when you delete the sandbox or your account
Nature and purposeStorage, and the operations needed to run a machine: creating, stopping, starting, restoring and destroying it
Type of personal dataWhatever you place in the workspace: we neither select nor inspect it, so you determine it entirely
Categories of data subjectsDetermined by you; typically your own users, customers, employees or test data
Our roleProcessor, acting only on your instructions

What we undertake

As your processor we will:

  • Process the data only on your documented instructions. Your instructions are: run the machine as the service describes. Creating, starting, stopping, restoring and destroying it are those instructions carried out. We will tell you if we believe an instruction breaches data protection law.
  • Not access the contents of your workspace. The platform provides us no path into a running machine, and we will not build one: including to respond to an abuse report, which we answer by stopping or destroying the machine instead.
  • Bind everyone with any access to our systems to confidentiality.
  • Keep the security measures described below, and not weaken them for the duration of this agreement.
  • Use only the sub-processors listed on our sub-processors page, tell you before adding or replacing one, and give you a chance to object: your remedy if you object is to stop using the hosted sandbox and delete it.
  • Help you respond to data subject requests. Since we cannot read the workspace, that help is practical rather than substantive: we cannot find, export or erase an individual's data inside your machine, and you must do that yourself with the access you have.
  • Help you with security, breach notification and impact assessments under Articles 32 to 36, so far as our role allows, and tell you without undue delay if we learn of a breach affecting data we process for you.
  • Delete the data at the end: destroying the sandbox destroys the machine and its disk immediately. Our infrastructure provider's automatic snapshots of that disk then expire on their own schedule, currently five days, which is when erasure is complete. We keep no copy of our own and run no backup service.
  • Give you the information you need to demonstrate compliance with Article 28, and accept an audit: in practice, answering your questions and passing on what our infrastructure provider publishes, since we cannot audit the inside of your own machine.

What you undertake

You decide what goes into the workspace, and you are the controller for it. You confirm that you have a lawful basis for the personal data you put there, that you have given the notices your own data subjects are owed, and that your instructions to us comply with data protection law.

Given that we run no backup service and cannot see inside, you are responsible for your own copies: desktop sync mirrors the workspace to your own computer if you want one, for your own retention decisions inside the workspace, and for judging whether a free, best-effort hosted machine is an appropriate place for the data you are considering putting on it. Special category data under Article 9 is your call to make and your risk to carry.

Security measures

The technical and organisational measures we maintain (GDPR Art. 32):

  • Each hosted sandbox is a separate machine, with its own disk, in its own private network at our infrastructure provider. Two users' sandboxes never share a machine, a disk or a network.
  • The machine is reachable only through a tunnel provisioned for that sandbox; nothing on it is exposed by us to the public internet by default.
  • Traffic between your browser and your sandbox is encrypted in transit.
  • Access to a sandbox is bound at first connection to the Google identity that created it. Connection tokens are stored encrypted in our database.
  • No standing access path exists from the platform into a running machine, which is a structural limit rather than a policy one.
  • Access to our own production systems is limited to the operator, over authenticated channels.
  • Deletion is immediate: destroying the sandbox destroys the machine and the disk together. The only residue is our provider's automatic disk snapshots, which we neither read nor restore and which expire on their retention schedule.
  • Disks at our infrastructure provider are encrypted at rest by that provider.

Sub-processors and transfers

The current list, with what each does and where, is on our sub-processors page. The one that matters here is Fly.io, which provides the machine and disk.

Where you provision a hosted sandbox from the EEA, the UK or Switzerland, the machine and disk are created in the European Union and its contents are not transferred out of the EU by us. Where a transfer to a provider outside the EEA does occur, it is covered by the EU–US Data Privacy Framework or by Standard Contractual Clauses under that provider's data processing agreement.

Liability and precedence

The liability provisions of the Terms of Service apply to this agreement. In case of conflict between this agreement and the Terms on the processing of personal data, this agreement prevails. It is governed by Polish law.

If you need this agreement as a signed document, or your organisation requires its own form, write to contact@intentic.dev.