Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Controller") and akanoodles holdings limited, a company registered in England & Wales (number 16289830) ("Processor", "akanoodles"). It applies whenever akanoodles processes Personal Data on the Controller's behalf in the course of providing Drop. This DPA is offered as standard to all Pro, Team, and Enterprise customers; it does not require negotiation for the standard terms below.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Sub-processor" have the meanings given in the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

"Customer Personal Data" means Personal Data that the Controller (or its end users) submits to Drop or which Drop processes on the Controller's behalf in providing the service.

2. Roles and scope

For Customer Personal Data, the Controller is the data controller and akanoodles is the data processor. akanoodles will only process Customer Personal Data:

3. Subject-matter, duration, nature, purpose, and categories

Subject-matterProvision of the Drop design-to-code service
DurationThe term of the Controller's pilot or annual licence, plus the retention periods set out in our Privacy Policy
Nature of processingStorage, transmission, retrieval, hashing, anonymised analytics
PurposeAuthenticating plugin licence checks; managing pilot and licence engagements; generating code from design tokens; diagnosing faults; issuing and reconciling invoices; delivering email notifications
Categories of Data SubjectThe Controller's authorised users (typically the Controller's employees, contractors, or design-system collaborators)
Categories of Personal DataEmail addresses; account identifiers (one-way hashed for telemetry); pilot and licence billing metadata; IP addresses incidental to HTTP requests; feedback submissions where users include personal data

Drop does not process special-category Personal Data (Article 9 UK GDPR) or criminal-conviction data (Article 10) in the ordinary course of providing the service.

4. Sub-processors

The Controller authorises akanoodles to engage the sub-processors listed below. The authoritative, maintained version of this list is the Drop Subprocessor Register (docs/legal/subprocessors.md), available on request; where this table and that register differ, the register governs and this page will be corrected to match.

Sub-processorServiceRegion of processing
Cloudflare, Inc.Edge compute (Workers), DNS, CDN, network securityUK / EU edge nodes; processed in transit
Supabase, Inc.Authentication, Postgres database (licence state, audit log, subscription records), edge function runtimeeu-west-2 (London)
Stripe (contracting entity to be confirmed)Payment processing for hosted invoicesEU / UK Stripe infrastructure; contracting entity and transfer basis to be confirmed
Resend, Inc.Transactional email deliveryUS (SCCs, UK Addendum)
HubSpot, Inc.CRM — sales pipeline and marketing communicationsUS (SCCs, UK Addendum)
Oracle Corporation (Oracle Cloud)Self-hosted observability VM for the telemetry endpoint (Loki, Tempo, Mimir, Grafana)uk-london-1 (United Kingdom)
GitHub, Inc.GitHub App that opens pull requests into the Controller's own repositoryUS-hosted; we send GitHub no personal data, so no processing agreement is required — see note below
Docker, Inc. (Docker Hub)Distribution of the per-customer ship-mcp container imageUS (Docker DPA in force; SCCs with UK Addendum)

We maintain a written contract with Cloudflare, Supabase, Resend, HubSpot, Oracle and Docker, requiring data-protection terms substantially equivalent to those in this DPA. Two items are stated as open rather than covered — one in the table above, and one described immediately below. For Stripe the payment relationship is plainly operating, but our own records name more than one Stripe legal entity and those entities carry different transfer positions, so we do not assert a specific one until it is confirmed. We state these gaps rather than imply cover that is not yet in place. Both are targeted for closure by 31 October 2026.

GitHub, and why it is not listed as a processing gap. This page previously said GitHub's paperwork was “being completed”. It is not being completed, because it is no longer needed. GitHub's build automation used to receive the account email address and first name so it could send the welcome email; on 10 August 2026 we removed both from that hand-off, and the build now looks the details up from our own database instead. GitHub therefore holds no personal data on our behalf. What remains is information about the Controller's own GitHub account — the handle and installation target created when the Controller installs our App — for which GitHub is an independent controller under its own privacy statement, exactly as GitHub's own data protection agreement describes at its clause 3.C.

Under verification. Personal data the Controller sends us by hand — for example an email raising a data-subject request — reaches an akanoodles mailbox, and may incidentally reach our internal messaging tool. The providers of those two services are being confirmed and will be added to this table by 31 October 2026. They are disclosed here as open items rather than omitted.

4.1 Vendors the Controller contracts directly — not akanoodles sub-processors

Two categories of third party are involved in using Drop but are not engaged by akanoodles, are not covered by this DPA, and belong in the Controller's own record of processing:

VendorRoleWhy it is not our sub-processor
Figma, Inc.The design tool the Drop plugin runs insideThe plugin executes within the Controller's own Figma session under the Controller's own pre-existing Figma contract. akanoodles transmits no Personal Data to Figma and holds no Figma account on the Controller's behalf
The Controller's chosen LLM provider, where cloud “bring your own key” is enabled — Anthropic, OpenAI, Google, OpenRouter, or any OpenAI-compatible endpoint the Controller namesModel inferenceThe Controller supplies their own API key and endpoint. akanoodles never holds, sees, proxies or stores that key, has no account or contract with the provider, and the request goes directly from the Controller's own container to the endpoint without transiting akanoodles infrastructure

Drop's default is local inference — the model runs on the Controller's own machine via Docker Model Runner, Ollama or Apple MLX, and no prompt leaves the Controller's infrastructure. Enabling cloud “bring your own key” is a deliberate configuration choice by the Controller and is the only setting that sends design-derived content to a third party. Where it is enabled, the Controller should add their chosen provider to their own sub-processor register and execute a DPA with that provider directly. akanoodles makes no representation about any such provider's residency, retention, or training-on-inputs policy, because akanoodles is not party to that contract.

akanoodles will give the Controller at least 30 days' notice before adding or replacing a sub-processor (e.g. via email to the account contact and an update to drop.akanoodles.com/dpa). The Controller may object on reasonable data-protection grounds; if a workaround cannot be agreed, the Controller may terminate the affected portion of the service and receive a pro-rata refund for unused prepaid fees. This notice commitment does not extend to a vendor the Controller elects themselves under section 4.1.

5. Confidentiality and personnel

akanoodles ensures that any person authorised to process Customer Personal Data is bound by confidentiality (contractual or statutory) and has been trained on data-protection responsibilities proportionate to their role.

6. Security measures

akanoodles implements appropriate technical and organisational measures to protect Customer Personal Data, taking account of the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing. Current measures include, without limitation:

7. Personal Data Breach

akanoodles will notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of a Personal Data Breach affecting Customer Personal Data. The notice will include the nature of the breach, the categories and approximate volumes affected, the likely consequences, and the measures taken or proposed to address it.

8. Data Subject rights

Where a Data Subject submits a request directly to akanoodles to exercise rights under UK GDPR (access, rectification, erasure, portability, restriction, objection), akanoodles will forward the request to the Controller without undue delay and will assist the Controller in responding using appropriate technical and organisational measures, insofar as possible.

If you close your akanoodles engagement, an automated erasure runs against telemetry, identity, and engagement stores, typically within 5 minutes of the deletion. Stripe and our accounting records retain financial data for 7 years after the engagement ends, as required by HMRC.

9. Audits

akanoodles will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Once per year, on at least 30 days' notice, the Controller may audit akanoodles' compliance through written information requests; on-site audits are available to annual licence customers under the Master Services Agreement. SOC 2 / ISO 27001 attestations, where obtained, will be made available to the Controller in lieu of audit on request.

10. International transfers

akanoodles is established in the United Kingdom. Customer Personal Data is stored in the United Kingdom or the European Union. For sub-processors outside those regions, akanoodles relies on the standard contractual clauses incorporated in their data-processing agreements; the Controller authorises akanoodles to enter into those clauses on the Controller's behalf where required for the provision of Drop.

11. Deletion or return on termination

Upon termination of the Controller's pilot or annual licence, akanoodles will, at the Controller's choice, delete or return Customer Personal Data within 30 days, except to the extent that retention is required by applicable law (notably HMRC accounting record-keeping for 7 years).

12. Liability

The liability of each party under this DPA is subject to the limitation of liability provisions in the Terms of Service.

13. Order of precedence

If there is a conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict for any matter relating to the processing of Personal Data. For annual licence customers, the Master Services Agreement may amend this DPA in writing.

14. Contact

Data Protection contact: [email protected]
Legal notices: [email protected]

15. Acceptance

By using Drop on a paid plan (Pro, Team, or Enterprise) and processing Personal Data through Drop, the Controller is deemed to accept this DPA on behalf of itself and any affiliate end users it permits to access the service. Enterprise customers receive a counter-signed copy of this DPA as part of their Master Services Agreement.