Data Processing Addendum

Last updated: 5 August 2026

This Addendum (“DPA”) governs how Everrun processes personal data on your behalf. It forms part of the Terms of Service and applies automatically to every account from signup — no signature needed.

Roles and subject matter

For the data you enter about your own clients and the workflow metadata we collect for you, you are the controller (or a processor acting for your own clients) and Everrun is your processor. The subject matter is the monitoring of your automation workflows and the alerting built on it. For your own account data, Everrun is an independent controller under the Privacy Policy. Where you act as a processor for your own clients, Everrun is your sub-processor; you warrant that your instructions to us are consistent with your agreement with the relevant controller, and you remain our sole point of contact and instruction.

Duration

This DPA applies for as long as you have an account, plus the deletion period below.

Nature and purpose of processing

Storage and display of client records you create; collection and storage of workflow run metadata (statuses, timestamps, durations, sanitised error messages) from the platforms you connect; evaluation of alert rules; delivery of alert and digest emails to recipients you configure. For n8n and Make, Everrun reads from your connected systems with read-only credentials and never writes to them; for Zapier, your workflows send heartbeat pings to Everrun and we never connect to your Zapier account at all. Execution payloads are never fetched or stored.

Personal data and data subjects

Categories of dataData subjects
Client names, contact names, contact email addresses, free-text notes you authorYour clients' personnel
Workflow, connection and automation names; instance URLs; sanitised error messages (which may incidentally contain personal data your workflows put into error text)Your personnel; your clients' personnel (incidentally)
Alert recipient email addresses you configureYour personnel; anyone you choose as a recipient

No special categories of data are intended to be processed.

Documented instructions

We process this data only on your documented instructions — which are the Terms, this DPA, and the configuration you make in the product (the connections you add, the thresholds you set, the recipients you enter) — unless EU or member-state law requires otherwise, in which case we will inform you before processing unless that law forbids it. We will tell you if we believe an instruction infringes data-protection law.

Confidentiality

Persons authorised to process the data are bound by confidentiality obligations.

Security measures (Art. 32)

The measures actually in place: application-layer AES-256-GCM encryption of the platform credentials you connect, with the key held in the hosting environment, separate from the database, and decryption only at polling time; row-level security isolating every tenant on every table; credential-stripping sanitisation of error messages before storage; no storage of execution payloads; no routine application logging (error reports go to Sentry’s EU region with cookies and authentication headers stripped before sending); encryption in transit; backups encrypted on our own equipment before storage, so no storage provider holds a readable copy; EU (Frankfurt) hosting for database and application functions.

Sub-processors

You give general authorisation for the sub-processors listed in the Privacy Policy’s sub-processor table. We will update that table and notify account email addresses at least 30 days before a new sub-processor processes personal data; if you object on reasonable data-protection grounds, you may terminate and request deletion. We remain responsible to you for our sub-processors’ performance and engage them only where they offer commitments consistent with this DPA.

Assistance

Taking into account the nature of the processing, we will assist you with data-subject requests concerning data we process for you, and with your security, breach-notification and impact-assessment obligations, to the extent the information is available to us. If a data subject contacts us directly about data we process for you, we will pass the request to you rather than respond on your behalf, unless the law requires us to respond.

Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, with the information we have at the time and updates as we learn more.

Deletion or return on termination

On termination or on your request, we delete the personal data we process for you from live systems within one month; residual copies persist in encrypted backups for up to 90 days before they age out. Before deletion you may export what you need — today by asking us, as no self-serve export exists yet — and we will provide a copy in a commonly used format within the same one-month window.

Audit

We satisfy audit rights first by making available the information reasonably necessary to demonstrate compliance with this DPA — this policy set, our sub-processor list, and written answers to reasonable questions. Where that is genuinely insufficient, or where data-protection law requires it, we will additionally allow an audit by you or an auditor you mandate: remotely, at most once per year, on at least 30 days’ notice, during business hours, under confidentiality, at your cost, and without access to other customers’ data. We will always cooperate with a supervisory authority.

International transfers

Data is stored in the EU (Frankfurt).

Where a sub-processor processes personal data outside the EEA, the transfer relies on an approved safeguard: the EU–US Data Privacy Framework where the provider is certified, or the European Commission’s Standard Contractual Clauses incorporated into the provider’s data-processing terms. A copy of the applicable safeguard is available in each provider’s published legal terms, or from us on request.

Each provider’s location is listed in the Privacy Policy’s sub-processor table.

Liability and contact

Liability under this DPA is subject to the limitations in the Terms. Questions and requests: privacy@everrun.dev.