Rearview

Data Processing Addendum

Last updated: June 26, 2026

This Addendum forms part of the Terms of Service between the customer (“Controller”) and Rearview (“Processor”) and applies where Rearview processes personal data on the customer’s behalf. A countersigned copy for enterprise agreements is available on request at legal@joinrearview.com.

1. Roles

The customer is the Controller and Rearview is the Processor of Customer Data. Each party complies with applicable data protection laws (including GDPR/UK GDPR and US state privacy laws where relevant).

2. Scope & purpose

Rearview processes Customer Data only to provide the Service and on the Controller’s documented instructions (including via product configuration), and not for any other purpose.

3. Nature of the data

Subject matter: aggregation of production-change events. Data subjects: the Controller’s personnel and collaborators identified in connected tools. Data categories: names/usernames, emails, and change descriptions present in connected events. Special-category data is not intended to be processed.

4. Confidentiality & security

Rearview ensures personnel are bound by confidentiality and implements technical and organizational measures appropriate to the risk (encryption in transit, signed webhooks, hashed credentials, access controls, rate limiting).

5. Sub-processors

The Controller authorizes the sub-processors listed in our Privacy Policy. We’ll give notice of new sub-processors and a chance to object; we remain responsible for their performance.

6. Data subject requests & assistance

Rearview will, taking into account the nature of processing, assist the Controller in responding to data-subject requests and in meeting security, breach-notification, and impact-assessment obligations.

7. Breach notification

Rearview will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, with information reasonably available.

8. Return & deletion

On termination, Rearview will delete or return Customer Data per the Terms (export window then deletion), except where retention is required by law.

9. International transfers

Where Customer Data is transferred across borders, the parties rely on Standard Contractual Clauses or another valid transfer mechanism, incorporated by reference.

10. Audit

Rearview will make available information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality and security constraints.