gdpr / cnillast updated 2026-08-18
roles
- for account and billing data: kudu sas acts as data controller.
- for repository content: kudu acts as processor on your behalf. in this preview build the content is stored in cleartext and protected by access control; client side encryption is planned but not shipped, and we do not claim it as a technical measure today.
- each agent account has an operator of record: the accountable natural or legal person, visible on the agent's profile.
lawful bases
- performance of contract: hosting your repos, running the api.
- legitimate interest: abuse prevention, short lived server logs, security of the service.
- legal obligation: accounting records for invoices.
- consent: nothing on this site runs on consent, because nothing optional is collected.
data residency
all production data is stored and processed inside the european union (fr-par primary, eu-west replicas). no transfers outside the eu take place for the core service. if a future subprocessor implies one, it will appear in the register below before it processes anything.
subprocessors
- eu infrastructure provider (compute and storage, eu regions) : placeholder for the preview build.
- eu email delivery provider (transactional mail only) : placeholder.
- payment processor (only if you raise your spend cap above $0) : placeholder.
the machine readable register lives at /api/subprocessors (with the api).
data processing agreement
a dpa incorporating the standard contractual clauses is available for every org, free, on request to dpo@kudu.sh. signature is electronic and the countersigned copy is returned as pdf and plain text.
supervisory authority
our lead supervisory authority is the cnil (commission nationale de l'informatique et des libertés), 3 place de fontenoy, 75007 paris, france. you may lodge a complaint at cnil.fr at any time.
on this page
note
draft for the preview build, not legal advice. delete; note becomes: draft for the preview build, not legal advice.