Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Six Colors AB ("Six Colors", "we", "us") and the organization that has agreed to those Terms ("Customer", "you").

1. Definitions

"Data Protection Law" means Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, and any other data protection law applicable to the processing under this DPA.

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR.

"Customer Personal Data" means Personal Data that Six Colors processes on your behalf under this DPA, as described in Annex 1.

"Subprocessor" means a third party engaged by Six Colors to process Customer Personal Data.

"Notification Address" means the email addresses of the administrator members of your organization. You are responsible for keeping them current.

"Services" means the hex.pm, hexdocs.pm and hexorgs.pm websites, the hex.pm API, and the package repository.

2. Roles and scope

For Customer Personal Data, you are the Controller and Six Colors is the Processor.

Customer Personal Data is limited to your organization: the organization record, the identities and roles of its members in their capacity as members, the contents of the private packages and documentation you publish to it, and your organization's audit log.

Six Colors acts as a Controller, not a Processor, for everything else it processes in connection with the Services. That includes:

  1. The account records of individual users. A hex.pm account exists independently of any organization, is created by the individual, and survives their leaving your organization. Those records are governed by the Privacy Policy.
  2. Public packages and their metadata, which are published to the world by the user who publishes them.
  3. Server and request logs, and security telemetry, which Six Colors retains to operate and secure the Services and to prevent abuse. This includes logs recording access to your private packages and documentation.
  4. Billing, payment and tax records. Six Colors determines these purposes itself in order to invoice you and to meet its own legal obligations under Swedish law.

Where this DPA conflicts with the Terms of Service in respect of Customer Personal Data, this DPA prevails.

3. Processing instructions

Six Colors will process Customer Personal Data only on your documented instructions, including in respect of transfers to a third country, unless required to do otherwise by Union or Member State law to which Six Colors is subject. Where such a legal requirement applies, Six Colors will inform you before processing unless that law prohibits it.

Your use of the Services, including requests made through the website and the API using your organization's credentials, constitutes your documented instructions.

Six Colors will immediately inform you if, in its opinion, an instruction infringes Data Protection Law.

You are responsible for the lawfulness of your instructions, for having a legal basis for the processing, and for giving Data Subjects the information Data Protection Law requires you to give them.

4. Confidentiality

Six Colors will ensure that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to provide the Services or to comply with law.

5. Security

Six Colors will implement and maintain the technical and organizational measures required by Article 32 of the GDPR to protect Customer Personal Data, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. The measures in place are described on the Security page. Six Colors may change those measures provided the replacement offers an equivalent or higher level of protection, and will not reduce the overall level of security during the term of this DPA.

You are responsible for the security of your organization's credentials and API keys, for managing your members' access, and for what you choose to include in the packages you publish. Disclosure resulting from a failure to keep those credentials secure is not a breach of Six Colors' security.

6. Subprocessors

You give Six Colors general authorization to engage Subprocessors. The Subprocessors engaged as at the date of this DPA are listed on the Subprocessors page.

Six Colors will impose on each Subprocessor data protection obligations no less protective than those in this DPA, by written contract, and remains fully liable to you for the performance of each Subprocessor's obligations.

Six Colors will notify the Notification Address with reasonable advance notice before a new Subprocessor begins processing Customer Personal Data. If you object on reasonable data protection grounds and the objection cannot be resolved, you may terminate your subscription and receive the refund set out in the Terms of Service, which together are your sole remedy.

7. Data subject rights

Taking into account the nature of the processing, Six Colors will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR.

If Six Colors receives such a request directly from a Data Subject in respect of Customer Personal Data, it will not respond to the substance of the request and will forward it to you without undue delay. This does not apply to requests about a Data Subject's own hex.pm account, for which Six Colors is the Controller under section 2.

8. Personal data breaches

Six Colors will notify the Notification Address without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe the nature of the breach, its likely consequences, the measures taken or proposed, and a contact point, to the extent that information is available at the time.

Six Colors will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to Six Colors.

9. Deletion and return

At your choice, Six Colors will delete Customer Personal Data or return it to you. To request a copy, contact support@hex.pm.

After termination or expiry of your subscription, Six Colors retains Customer Personal Data for 90 days so that you can make that choice. That applies however the subscription ended. After those 90 days Six Colors may delete the data at any time, and deletes it on your request, unless retention is required by Union or Member State law.

Copies held by Subprocessors and in backups are deleted on those systems' own cycles. Until they are, they remain subject to this DPA and are not restored or used for any other purpose.

10. Audits and information

Six Colors will make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

You agree to exercise this right first by requesting that information, together with any third party audit reports Six Colors holds and any certifications the Subprocessors listed on the Subprocessors page publish. Where that information is not sufficient, an inspection of Six Colors' own systems and records may be carried out at your expense on reasonable notice, no more than once a year except where required by a Supervisory Authority or following a Personal Data Breach, and subject to confidentiality obligations.

11. International transfers

Six Colors is established in Sweden and processes Customer Personal Data on infrastructure located in the United States, as described on the Subprocessors page.

If you are established in the EEA, your disclosure of Customer Personal Data to Six Colors does not leave the EEA and is not a restricted transfer. If you are established in the United Kingdom or Switzerland it is a transfer to an adequate country. Six Colors is the exporter for the onward transfer to its Subprocessors and is responsible for the mechanism. Those Subprocessors are in countries the European Commission has found to provide an adequate level of protection, or are covered by Standard Contractual Clauses approved by the European Commission, with the UK and Swiss equivalents where those apply.

If Six Colors or a Subprocessor receives a legally binding demand from a public authority for Customer Personal Data, Six Colors will notify you unless the law prohibits it, and will challenge the demand where there are reasonable grounds to do so.

If a mechanism Six Colors relies on ceases to be valid, Six Colors will implement an alternative without undue delay. If it cannot, you may terminate your subscription.

12. Liability and term

Liability arising under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.

This DPA takes effect when you agree to the Terms of Service and remains in force for as long as Six Colors processes Customer Personal Data on your behalf.

13. Changes

Six Colors may update this DPA where required to reflect a change in the Services, in Data Protection Law, or in guidance from a Supervisory Authority. Material changes that reduce your rights will be notified to the Notification Address with reasonable notice before they take effect. The change history is available in the git repository.

Annex 1: Details of the processing

Subject matter. Provision of the Services to your organization, being a private package repository and private documentation hosting on hexorgs.pm.

Duration. The term of your subscription, plus the retention and deletion periods in section 9.

Nature and purpose. Hosting, storage, transmission and backup of your organization's private packages and documentation; authenticating your members and enforcing their access to that private content.

Categories of Data Subject. Members of your organization, people you have invited to join it, and any individual whose Personal Data you choose to include in the content you publish to it.

Types of Personal Data. The organization name; the identity of each member and their role and permissions within the organization; the email address and intended role of anyone you invite; where your organization uses single sign-on, the identifiers your identity provider returns, including issuer, subject and email address; entries in your organization's audit log, which record the acting member, their IP address and user agent; and any Personal Data contained in the packages and documentation you choose to publish.

Special categories of Personal Data. None is requested or required. The Services are not designed to process special category data, and you should not publish it.