All you need to know about data processing at Mend.io
Mend.io takes data protection seriously. Our Services are designed to analyze code and open source components – not personal data. The limited personal data we do process (such as the contact details of our customers’ users) is processed for Mend.io’s own purposes as a data controller, in compliance with applicable data protection laws, and is subject to the security and confidentiality measures described below.
The following applies to our personal data processing with respect to our customers’ data when using a supported version of our application security software service:
1. Processing
- Personal Data: Mend.io only processes personal data in order to be able to conclude and execute contracts with customers (e.g., billing, clarification of questions, support tickets, etc.) and to manage the accounts of users designated by the customer.
- Technical Data: We compile statistical and aggregated information related to the performance, operation, and use of our solution based, inter alia, on customer data, in a form that does not identify any customer or any individual, for our internal business use (e.g., monitor usage to ensure licensing compliance, to create statistical analyses, for research and development purposes and to improve and market the Services).
- Customers’ personal data is not used for any other purpose.
- We do not sell customers’ personal data.
2. PERSONAL DATA WE COLLECT AND DATA SUBJECTS.
- We may collect the name, email address and phone number of the customer’s users.
- The data subjects are the customer’s users (employees).
3. OUR ROLE AS DATA CONTROLLER/ DATA PROCESSOR
- The GDPR delineates the roles of controller and processor based on the influence stakeholders have in determining the means and purposes of data processing.
- Mend.io acts as a data controller – and not as a data processor. Why? Because Mend.io processes the personal data of the customer’s users exclusively for its own purposes: the performance of its contracts with the customers (including the provision of support services), ensuring the functionality and security of the Mend.io systems, and account administration and billing purposes. The determination of the purposes and means of the data processing is therefore carried out by Mend.io.
- Our Services are not intended to process personal data in any form. The customer data examined by the Services consists of code, open source components and related development artifacts, and is not intended to contain personal data. It is the customer’s responsibility to ensure that the data it makes available to the Services does not contain personal data. Accordingly, Mend.io does not process personal data on behalf of its customers.
- For this reason, a data processing agreement (DPA) is not required for the use of our Services – there is no processing of personal data on the customer’s behalf for a DPA to govern. This does not lessen our commitment to data protection: Mend.io complies with applicable data protection laws in its role as a data controller, and applies the security, confidentiality, data minimization and retention measures described on this page to all data it processes.
4. DATA RETENTION.
We keep audit logs for a time period of 90 days and backups for a time period of 30 days. All data is deleted following termination of the customer’s subscription. For additional information – see our Data Retention and Archiving Policy at: https://www.mend.io/data-retention-and-archiving-policy/
5. PROCESSING BY THIRD PARTIES AND DATA TRANSFER.
- As an essential part of our services, we use processors and provide them access to the data collected (e.g., our CRM system, customer management solution, support tickets management system). These processors act on Mend.io’s behalf as our own service providers – not as sub-processors on behalf of our customers.
- We ensure that any data transfer is in full compliance with applicable data protection regulations and we remain liable for any act or omission of such third parties as if made by us directly. We have necessary agreements with such third parties in place to ensure compliance with applicable data protection regulations.
6. PSEUDONYMIZATION AND DATA MINIMIZATION.
We have invested significant resources and implemented technical and organizational measures to minimize the personal data we process and ensure that we only process the data necessary for the specific purpose. We pseudonymize the customer’s contributing developers’ emails. Once pseudonymized, the emails cannot be re-identified by Mend.io.
7. DATA SUBJECT REQUESTS.
- We comply and respond to any Data Subject Requests (DSR) relating to the personal data processed by our solution, such as requests for access and deletion of personal data.
- When the DSR is related to a specific customer, we refer the data subject to such customer and will also notify and cooperate with the customer in parallel.
- We support our customers in their efforts to respond to any DSR.
8. DATA PROTECTION SECURITY MEASURES.
- Mend.io implements a comprehensive approach to data security, encompassing advanced authentication, access control and data confidentiality among other things.
- Mend.io utilizes industry standard, production-grade data storage and security solutions and incorporates common security best practices. Data storage is backed up frequently and on a regular basis, with both main storage and backup encrypted at rest and in transfer
- Mend.io has achieved the ISO 27001 certification and received a SOC 2 Type II attestation report evidencing that appropriate internal controls are in place relating to the security, availability, and confidentiality of customer information within our environment.
9. ABOUT OUR PRIVACY TEAM
As a privacy-first organization, Mend.io takes great pride in its data protection practices. Our privacy team includes experienced and certified privacy experts, as well as external reputable data protection law firms and experts. We are monitoring changes in global data protection regulations as applicable to Mend.io and assessing our compliance, and when necessary, implementing required steps and procedures on an-ongoing basis. For additional information see our Privacy Policy at: https://www.mend.io/privacy-policy/.