Data Processing Addendum
This addendum forms part of the Terms and Conditions between you and Theruka Holding SpA. It applies where you put personal data about other people into Decision Memory - in which case you are the controller of that data and we process it for you.
Version 2026-08-31 · in effect from 2026-08-31 · Terms and Conditions · Privacy Policy · Trust and data handling
1. When this applies, and who is who
This addendum is part of the Terms and Conditions. Accepting those accepts this. Where the two disagree about the processing of personal data, this addendum wins.
It applies when you put personal data about other people into Decision Memory: a colleague named as a milestone owner, a stakeholder on a project roster, somebody you invite, somebody you send a share link to. For that data you are the controller and Theruka Holding SpA is your processor.
It does not apply to your own account data - your sign-in address and your billing records. We are the controller of those, and the privacy policy governs them.
If you are an individual using the product for yourself and hold no personal data about anybody else in it, nothing here engages.
2. What we process, and for how long
Subject matter: the operation of the product for you. Duration: for as long as your account exists, and no longer - see clause 9.
Nature and purpose: storing, displaying, organising and exporting the programme content you enter, sharing it with people you nominate, generating reports and AI drafts when a person on your account asks for one, and keeping backups.
Types of personal data: names, email addresses, roles and job titles, and anything else you choose to type into a project, milestone, risk, decision, comment or uploaded file. We do not require any of it and we have no field that asks for it.
Categories of data subject: your team members, and any third party you name in your programme content - stakeholders, suppliers, customers of yours.
3. We act only on your instructions
We process this personal data only on your documented instructions, which are: these terms, this addendum, and your use of the product's features.
We do not use it for our own purposes. We do not sell it, we do not use it to train or fine-tune AI models, we do not build profiles from it, and we do not combine it with another customer's personal data.
The pattern library described in the privacy policy is not an exception to that sentence, because nothing in it is personal data: it holds four values per judged mitigation - two classifications, a verdict and a month - all drawn from fixed lists, with no free text, no identifier and no field describing the programme. If that ever ceased to be true, this clause would have to change, and it has not.
If we are ever required by law to process it otherwise, we will tell you before we do, unless the law forbids us from telling you.
4. Confidentiality
Everyone who can access your data is bound by confidentiality obligations, and access is limited to those who need it to run or support the service.
Access is enforced on the server for every request, not in the browser, and it is scoped to the account that owns the record.
5. Security
Every record is owned by an account and read and written by that account's identifier, scoped on the server on every request. One account's data is never merged with another's, never pooled to produce a shared result, and never used to answer another account's request.
Data is encrypted in transit. Credentials we hold on your behalf - a Jira API token, for instance - are encrypted at rest with AES-256-GCM and are never returned to a browser; only the last four characters of such a token can be displayed.
There are no passwords to steal: sign-in is by Google or by a single-use emailed link, and a session is a signed cookie rather than a server-side record.
See clause 11 for what we do not offer.
6. Sub-processors
You authorise the sub-processors listed in the privacy policy, which names each one, what it handles and where it is. That list is public and is kept current.
We will give you at least 60 days' notice before adding or replacing a sub-processor that handles personal data on your behalf. If you object on reasonable data protection grounds within that period, we will work with you to find a resolution; if none is found, you may terminate the affected part of the service and receive a pro-rata refund of any period paid for and not used.
Each sub-processor is bound by terms no less protective than these, and we remain liable to you for their performance.
7. Personal data breach - 72 hours
If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay and in any case within 72 hours of becoming aware of it.
The notification will describe what we know: the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and what we are doing about it. Where we do not yet have all of that, we will send what we have rather than wait, and follow up.
The 72 hours is measured from OUR awareness, and it is deliberately the same window the regulation gives you for your own notification - so you are not left discovering a breach with your clock already spent.
We will not notify your regulator or your data subjects on your behalf. That is your decision to make, and we will give you what you need to make it.
8. Helping you answer people
Most of this you can do yourself, immediately, without asking us: the product lets you find, correct, export and delete any record in your workspace.
Where somebody exercises a right and the product cannot answer it, we will assist you, at no charge for a reasonable volume of requests.
If a data subject contacts us directly about data we hold for you, we will not respond to the substance - we will tell them to contact you, and tell you that they asked.
We will also give you the information you reasonably need for a data protection impact assessment or a prior consultation with a regulator, so far as it concerns our processing.
9. Deletion at the end
You can delete everything yourself, at any time, from inside the product. An account owner deleting the account permanently erases the workspace and everything in it - projects, portfolios, milestones, risks, mitigations, decisions, reports, integrations and share links. It is immediate and it cannot be undone by you or by us.
There is no retention window and no archive. We do not keep a shadow copy.
What survives is your billing record and the record that you accepted these documents, because we are required to keep the first and because the second is the evidence of this agreement. Neither contains your programme content.
Backups are overwritten on their ordinary cycle.
10. International transfers
All processing takes place in the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, the transfer is covered by the European Commission's Standard Contractual Clauses, with the UK Addendum and the Swiss amendments as applicable.
The privacy policy sets this out in full, including how to obtain a copy of the safeguards.
11. What we do not offer, stated plainly
We hold no SOC 2 report, no ISO 27001 certificate and no equivalent third-party audit. If your procurement process requires one, we do not currently meet it, and we would rather you knew that now than after a questionnaire.
We do not offer on-site or third-party physical audits. We will answer a written security questionnaire, and we will provide the information reasonably needed to demonstrate compliance with this addendum, once in any twelve-month period and more often if a regulator requires it.
We do not offer a guaranteed uptime figure or a service level commitment, consistent with the terms.
We will not sign a Business Associate Agreement, and the product is not suitable for data covered by HIPAA. We never store cardholder data, so no part of the product is in PCI DSS scope.
These are limits, not aspirations. If any of them changes, this addendum changes with it and gets a new version.
12. Liability, changes, and precedence
The liability provisions of the Terms and Conditions apply to this addendum, and the two are one agreement for that purpose.
We may update this addendum. Each version has a date, and the version in force when you accepted the terms is recorded against your account. Where a change reduces your protection, we will ask you to accept it before it applies to you.
Questions, or a countersigned copy for your records: support@theruka.com.
Theruka Holding SpA · support@theruka.com
Back to the site