Skarn data processing agreement

One agreement covers the license portal. The data processing agreement below governs the personal data of a Team or Enterprise customer's members that Skarn Software OÜ holds in the customer portal on the customer's behalf. It takes effect with the Team or Enterprise order under its clause 15.1 and needs no separate signature. An order is under the version published on the day the order takes effect; the version and date at the top identify that text.

Last updated 2026-09-30.

Data Processing Agreement

Version 1.0, 2026-09-30

between Skarn Software OÜ and the Customer

Parties

(1) Skarn Software OÜ, a private limited company registered in Estonia under registry code 17585335, with its registered address at Narva mnt 5, 10117 Tallinn, Estonia ("Skarn" or the "Processor").

(2) The legal entity named as the customer in a Team or Enterprise order for the Skarn software (the "Customer" or the "Controller").

Background

A. The Customer holds a Team or Enterprise subscription for the Skarn software under the Skarn End User License Agreement and the applicable order (together the "Order"). The Customer's administrators use the customer portal at account.getskarn.com (the "Portal") to add members of the Customer's staff to the Customer's organization, assign them license seats, verify the Customer's email domains so that colleagues can join through them, and read and export the audit log of those actions.

B. The Customer decides which persons it adds to its organization and why. For the personal data of those persons that the Customer and the persons themselves enter into the Portal, and for the records the Portal creates from those entries, the Customer is the controller and Skarn processes the data on the Customer's behalf.

C. This Agreement sets out the parties' obligations under Article 28 of Regulation (EU) 2016/679 (the "GDPR") for that processing. It does not cover the data for which Skarn is itself the controller; clause 2.3 says which data that is, and the privacy policy at getskarn.com/privacy/ describes it.

1. Definitions

1.1 "Applicable Data Protection Law" means the GDPR, the Estonian Personal Data Protection Act, and any other data protection law of a member state of the European Economic Area ("EEA") that applies to the Customer's processing of Customer Personal Data.

1.2 "Customer Personal Data" means the personal data described in Annex 1 that Skarn processes on behalf of the Customer in connection with the Services.

1.3 "Team Member" means a natural person whom the Customer adds to its organization in the Portal, invites to it, or admits to it through a verified domain, and any person who requests to join it through a verified domain.

1.4 "Services" means the hosting and operation of the Portal and its supporting license service for the Customer's organization, the issuance and renewal of license tokens for the Customer's seats, and the related support, as described in the Order.

1.5 "Sub-processor" means a third party engaged by Skarn to process Customer Personal Data on Skarn's behalf.

1.6 "Security Incident" means a personal data breach within the meaning of Article 4(12) GDPR that affects Customer Personal Data.

1.7 Terms defined in the GDPR have the same meaning in this Agreement.

2. Scope and roles

2.1 Skarn processes Customer Personal Data as a processor on the Customer's behalf and on its documented instructions.

2.2 The Customer is the controller of Customer Personal Data. The Customer decides who is added to its organization, which seats are assigned, which domains are verified, which join mode applies, whether the listing of personal accounts described in Annex 1 is used, and when records are corrected or removed.

2.3 Skarn is an independent controller, and this Agreement does not apply, for: (a) the account and contact data of the person who opens the Customer's account, accepts the terms and places the Order, to the extent Skarn uses it for billing, license issuance, customer communication and its legal obligations; (b) order, invoice, payment and transaction records, including the records Skarn receives from its merchant of record; (c) free license registrations made by individuals before they join the Customer's organization; (d) correspondence and calls from the Customer's representative to Skarn's support addresses and number; and (e) Skarn's own security and anti-abuse processing to the extent stated in Annex 1.

2.4 Where a person is a Team Member of the Customer and also holds a free license registration or a purchase in their own name, clause 2.3 applies to the registration or purchase and this Agreement applies to their record in the Customer's organization.

2.5 Skarn does not process, and the Services have no means to receive, the content of anything the Customer's personnel scan with the Skarn software, the findings the software produces, or any credential it detects. The software runs on the Customer's machines, makes no network call during a scan, and the Portal has no field for that content. The scope of this Agreement is the account, license, seat and audit data described in Annex 1 and nothing else.

3. Subject matter, nature, purpose and duration of the processing

3.1 Subject matter. The subject matter is the Customer's organization records in the Portal: the organization itself, its Team Members, their email addresses, invitations, seat assignments, license tokens, verified domains, join requests, sessions and the audit log, as detailed in Annex 1.

3.2 Nature. The processing consists of collection through the Portal forms and the registration form, storage in the license service database and its backups, organization and structuring of the records, retrieval and display to the Customer's administrators and to the Team Member concerned, disclosure by transmission in the transactional emails the service sends to Team Members, inclusion of a Team Member's name and email address in the license token issued to them, export to the Customer on its request, erasure on the Customer's action or instruction, and the technical administration and support of the systems that hold the data.

3.3 Purpose. Skarn processes Customer Personal Data only for the following purposes:

(a) creating and maintaining the Customer's organization record and the records of its Team Members;

(b) sending Team Members the invitation, sign-in, email verification, seat, join and migration messages that the Portal produces;

(c) issuing, renewing, reissuing and revoking the license tokens that name a Team Member as holder;

(d) verifying the Customer's domains and routing registrations and join requests from addresses on a verified domain to the Customer, as described in Annex 1;

(e) for an Enterprise Customer, listing to its administrators the personal accounts registered on a verified domain and sending a migration notice to such an account at an administrator's request;

(f) keeping the audit log of the above actions, for the Customer's own compliance evidence and for the security of the service;

(g) supporting the Customer's administrators and Team Members in their use of the Portal;

(h) backing up the Portal database and restoring it after a failure.

3.4 Duration. Skarn processes Customer Personal Data for the term of the Order, for the deletion period in clause 12.2, and, for the backup copies that Annex 1 describes as locked or scheduled, until each copy expires.

4. Instructions and Customer responsibilities

4.1 The Customer's documented instructions consist of this Agreement, the Order, and the actions the Customer's administrators take in the Portal. Each such action (an invitation, a seat assignment, a role change, a domain verification, a join decision, a listing request, a migration notice, a rename or a removal) is an instruction to process accordingly.

4.2 Skarn processes Customer Personal Data on no other instruction unless Union or member state law requires it; in that case Skarn informs the Customer of the legal requirement before processing, unless the law prohibits that information on important grounds of public interest.

4.3 Skarn immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other Union or member state data protection provisions. Skarn is not obliged to review the Customer's instructions for lawfulness.

4.4 The Customer is responsible for: (a) the lawful basis of its processing of Customer Personal Data; (b) informing its Team Members, in its own privacy notice, that their name and work email address are held in the Portal, that a license token naming them is issued, that their sign-ins, invitation claims and license downloads are recorded in the audit log with the IP address and browser identifier, that the Customer's administrators can read and export that log, and that the systems are administered and supported by Skarn's management board from the Republic of Serbia; (c) the accuracy of the data its administrators enter; (d) not instructing Skarn to process special categories of personal data, criminal offence data or the data of children; and (e) the acts and omissions of its administrators in the Portal.

4.5 For a Customer using the account listing described in Annex 1 (Enterprise only), the Customer is responsible for the lawfulness of its own use of the listing and of any contact it makes with the persons listed.

5. Processor obligations

Skarn shall:

(a) process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, as set out in clauses 4 and 8;

(b) ensure that every person authorised to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality (clause 6);

(c) take all measures required pursuant to Article 32 GDPR, including, as a minimum, the technical and organisational measures in Annex 2 (clause 7);

(d) engage Sub-processors only under the conditions in clause 9;

(e) taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III GDPR (clause 10);

(f) assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Skarn (clause 11);

(g) at the Customer's choice, delete or return Customer Personal Data after the end of the Services, and delete existing copies, unless Union or member state law requires storage (clause 12);

(h) make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer (clause 13).

6. Confidentiality

6.1 Skarn restricts access to Customer Personal Data to the persons who need it to perform the Services, the administration of the systems and the support of the Customer. Those persons are bound by written confidentiality obligations that survive the end of their engagement.

6.2 Skarn's staff console records every action a staff member takes on the Customer's records in the audit log with the acting person's verified email address as actor.

7. Security

7.1 Skarn takes all measures required pursuant to Article 32 GDPR. As a minimum, Skarn implements and maintains the technical and organisational measures in Annex 2. Skarn may update those measures from time to time, provided the updates do not reduce the overall level of protection.

7.2 The Customer is responsible for the security of its own administrators' accounts and devices, for the choice of who receives administrator, billing or member roles, and for the storage of license tokens downloaded from the Portal. A license token is not bound to a machine: anyone who holds a token and a build of the software that trusts the issuing key can use the tier it grants until it expires or until a later build carrying the revocation refuses it.

8. Transfers outside the EEA

8.1 Skarn is established in Estonia and its production data stores are configured as Annex 3 describes.

8.2 The members of Skarn's management board administer and support the Portal and its infrastructure from the Republic of Serbia in their capacity as the management of Skarn Software OÜ. As such administration and support are performed directly by the processor's own management, they do not constitute a transfer of personal data to a third country under Chapter V of the GDPR. The Customer acknowledges and authorizes this operational arrangement and the related access and support from Serbia.

8.3 The Sub-processors listed in Annex 3 whose services can involve processing outside the EEA (Cloudflare and GitHub) rely on the standard contractual clauses or the EU-US Data Privacy Framework as stated in that Annex, under their own data processing terms with Skarn.

8.4 Skarn informs the Customer without undue delay if any material change occurs regarding the location or mechanism of processing under this clause.

9. Sub-processors

9.1 The Customer gives Skarn general written authorisation to engage the Sub-processors listed in Annex 3 for the purposes stated there.

9.2 Skarn imposes on each Sub-processor, by written contract, data protection obligations that provide at least the level of protection required by this Agreement, and remains fully liable to the Customer for the performance of the Sub-processor's obligations.

9.3 Before Skarn engages a new Sub-processor or replaces an existing one, Skarn notifies the Customer by email to the email addresses of the Customer's owner and administrators recorded in the Portal, and updates the list published at getskarn.com/trust/subprocessors/, at least thirty (30) days before the new Sub-processor first processes Customer Personal Data.

9.4 The Customer may object to a new or replacement Sub-processor on any reasonable ground by written notice within fourteen (14) days of Skarn's notification. The parties then discuss the objection in good faith. If Skarn cannot address the objection within thirty (30) days, the Customer may terminate the Order for the affected Services by written notice, and Skarn refunds any prepaid fees for the period after termination on a pro rata basis.

9.5 A new or replacement Sub-processor does not process Customer Personal Data before the period in clause 9.3 has ended, except that where a replacement is strictly required to address a security incident or the unexpected failure of a Sub-processor, Skarn may engage the replacement before the period in clause 9.3 ends, notifies the Customer at once with the information in clause 9.3, and, if the Customer objects under clause 9.4, suspends the processing of Customer Personal Data by that replacement immediately; the Customer's right to terminate under clause 9.4 applies.

10. Data subject requests

10.1 The Customer is responsible for responding to requests from Team Members exercising their rights under Applicable Data Protection Law.

10.2 If Skarn receives such a request directly, it forwards the request to the Customer's owner and administrator addresses recorded in the Portal within five (5) business days and does not respond to the data subject itself, except to say that the request has been passed to the Customer and unless Applicable Data Protection Law requires Skarn to respond.

10.3 The Portal lets the Customer's administrators fulfil most requests themselves: they can read a Team Member's record, correct the display name, change the role, revoke a seat, remove a member, and export the audit log. Where a request cannot be fulfilled through the Portal, Skarn acts on the Customer's written instruction within ten (10) business days. Skarn may charge a reasonable fee for assistance that goes beyond the Portal functions and is repeated or manifestly excessive.

11. Security Incidents, impact assessments and consultation

11.1 Skarn notifies the Customer of a Security Incident without undue delay and in any event within forty-eight (48) hours after becoming aware of it.

11.2 The notification describes, to the extent known at the time, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Skarn provides further information in phases as it becomes available.

11.3 Skarn's notification is not an admission of fault or liability.

11.4 Taking into account the nature of the processing and the information available to it, Skarn assists the Customer with the Customer's obligations under Articles 32 to 36 GDPR, including a data protection impact assessment and a prior consultation of a supervisory authority, to the extent the assessment or consultation concerns the Services. The information in Annexes 1 to 3 and the pages under getskarn.com/trust/ are the first source for that assistance.

12. Deletion and return

12.1 During the term, the Customer's administrators delete Customer Personal Data themselves through the Portal: removing a member deletes the member record and its email addresses; revoking a seat ends the assignment; removing a domain ends the routing through it. The audit log keeps the entry that records each of those actions. A license token that a Team Member has already downloaded stays on that person's machine; Skarn adds a revoked token's identifier to the deny list that later builds of the software carry, and cannot recall the token from a build already installed.

12.2 After the end of the Services, Skarn deletes Customer Personal Data from the live database within thirty (30) days of the Customer's written request, or returns it first if the Customer so requests. The deletion covers the organization record, the member records and their email addresses, invitations, seat assignments, verified domains, join requests, the listing notices of Annex 1, and the license records of the organization, except as stated in clause 12.4.

12.3 Return. At any time before deletion the Customer can export its audit log from the Portal in CSV and NDJSON form and read its member list there. On request Skarn provides the Customer Personal Data in a machine-readable form within the period in clause 12.2.

12.4 Data retained after deletion. Notwithstanding clause 12.2, the following data and copies shall be retained after the end of the Services:

(a) the audit log, which is an append-only, hash-chained record necessary to ensure the integrity and evidentiary reliability of licensing actions under the Estonian Accounting Act and to establish, exercise or defend legal claims, where any data subject erasure request reaching the audit log shall be fulfilled by permanently blocking the relevant entries generated up to the date of the blocking action and putting them beyond use in accordance with Article 17(3)(b) and (e) of the GDPR, as physical deletion or modification would break the underlying cryptographic hash chain. Entries that mention a data subject solely in free text (such as notes or display names) and records whose association with the data subject cannot be automatically determined by the system (including historical entries from a period when a personal account was later converted into an organization account, where the account number alone identifies the organization) shall be blocked following manual review and confirmation by Skarn's management board rather than automatically;

(b) the backup copies described in Annex 1, which are stored in compliance mode storage where immutable locks prevent early removal, with erasure requests handled via permanent blocking where locks apply;

(c) order, invoice, and payment records, for which Skarn is the controller, for the period the Estonian Accounting Act and the Taxation Act require; and

(d) the deny list entries for revoked license identifiers, which carry no personal data.

12.5 Skarn confirms the deletion in writing on request.

13. Information and audits

13.1 Skarn makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR: this Agreement and its Annexes, the pages under getskarn.com/trust/, and written answers to the Customer's reasonable questions within twenty (20) business days. Skarn has no third-party audit report or certification to offer at the date of this Agreement.

13.2 Skarn allows for and contributes to audits, including inspections, of its processing of Customer Personal Data, conducted by the Customer or by an independent auditor bound by confidentiality and mandated by the Customer, at reasonable intervals or where there are indications of non-compliance, during business hours and without disrupting the Services. The audit covers Skarn's own systems and records and the documentation Skarn holds about its Sub-processors; for each Sub-processor, Skarn facilitates the audit in accordance with that Sub-processor's data processing terms. The Customer gives thirty (30) days' written notice of an audit, except where there are indications of non-compliance or after a Security Incident affecting the Customer. Each party bears its own costs of an audit, except that the Customer bears Skarn's reasonable costs of a second audit within the same twelve (12) months that finds no non-compliance.

13.3 Skarn may refuse an auditor that is a competitor of Skarn, and may require the auditor to sign a confidentiality undertaking before access.

14. Liability

14.1 Each party is liable for the damage it causes by processing that infringes Applicable Data Protection Law, as Article 82 GDPR provides. Subject to the limitations set forth in the End User License Agreement, each party's total aggregate liability arising under or in connection with this Agreement is limited to the fees paid or payable under the Order in the twelve (12) months before the event giving rise to the claim, except where Applicable Data Protection Law does not permit such a limitation.

15. Term and termination

15.1 This Agreement takes effect on the date the Order takes effect and remains in force for as long as Skarn processes Customer Personal Data.

15.2 Clauses 6, 12, 13, 14 and 16 survive the end of this Agreement.

16. General

16.1 Precedence. For the processing of Customer Personal Data this Agreement prevails over the Order and the End User License Agreement in case of conflict.

16.2 Amendments to this Agreement require the written form. Skarn may update Annex 3 through the notification procedure in clause 9, and Annex 2 as clause 7.1 provides.

16.3 If a provision is invalid, the remaining provisions stay in force and the parties replace the invalid provision with a valid one that comes closest to its purpose.

16.4 Governing law and forum. This Agreement is governed by the law of the Republic of Estonia, and the Harju County Court in Tallinn has exclusive jurisdiction, with the mandatory rules of Applicable Data Protection Law and the competence of supervisory authorities unaffected.

Annex 1: Description of the processing

1. Data subjects

(a) The Customer's administrators, holding the owner, admin or billing role in the organization, in their capacity as the Customer's personnel. The owner who opened the account is also a data subject of Skarn's own controller processing under clause 2.3(a).

(b) Team Members holding the member role, with or without a seat.

(c) Persons invited by an administrator who have not yet accepted.

(d) Persons who register for a free license, or request to join, with an email address on a domain the Customer has verified.

(e) For an Enterprise Customer only: holders of personal Skarn accounts whose email address is on a domain the Customer has verified and who appear in the listing described in section 3 of this Annex.

2. Categories of personal data, their source and their retention in the live database

Category Content Who enters it Retention
Organization record Organization name, slug (embedded in every license), join mode, seat reclaim settings, review flag The administrator; the slug is set by Skarn staff when a customer is created by hand Until deletion under clause 12
Member record Display name (first and last name, printed on the license), role (owner, admin, billing, member), status (active, suspended), creation time The name by the Team Member when accepting an invitation, editable later by the member and by an administrator; the role by an administrator; the status by an administrator or by the service Until removal by an administrator or deletion under clause 12
Email addresses Work email address, verification time or provisioning time An administrator (invitation), the Team Member (own additional addresses), Skarn staff (an address provisioned on the Customer's behalf) Until removal or deletion
Invitations Email address, role, inviting person, creation and expiry times, status, claim time An administrator, or the service for a join through a verified domain Pending for 14 days, then marked expired; the row stays until deletion
Seat assignments Seat pool, member, invited email, status, invitation, activation and revocation times, reclaim flag Administrator decisions and the service's seat rules (expiry, idle reclaim, cooldown) Until deletion; a revoked assignment stays as history
Verified domains Domain name, verification token, status, creating person, verification and check times An administrator Until the administrator removes the domain or deletion
Join requests Email address, domain, status, reason, decision time and deciding person The person who registers or requests to join with an address on the verified domain; the decision by an administrator or by the configured join mode Until deletion
License records License identifier, holder account (the Team Member's name and email address), organization slug, tier, seat count, issue and expiry dates, issuance history; the license token itself, stored encrypted Derived by the service from the member, organization and order records Until deletion; a revoked license identifier stays on the deny list, without personal data
Sessions Hashed session identifier, member, creation and expiry times, IP address, browser identifier The service, from the Team Member's browser at sign-in Until expiry, 7 days after sign-in; expired rows are deleted by the nightly job
Sign-in and verification links Hashed token, email address, purpose, expiry The service 15 minutes; rows deleted one day after expiry
Audit log Sequence, time, actor (an email address, or "system", "cron", "paddle", "admin", "reconcile"), action, subject kind and identifier, details including the customer identifier and, for sign-ins and invitation claims, the IP address, and for license downloads and token reveals, the IP address and the browser identifier; a hash chain The service, on every member, administrator, staff or automated action Append-only; never deleted (clause 12.4)
Account listing (Enterprise) For each personal account whose address is on a verified domain: email address, display name, account state (eligible, paid, unverified, ineligible) and contact state (invited, requested, notified, none); the notice record: address, time sent, sending administrator Computed by the service from personal accounts on the Customer's request; the notice record is written when an administrator sends a migration notice The listing is computed at each request; the notice records stay until deletion
Support correspondence Email a Team Member sends to a Skarn support address, and Skarn's replies; a voicemail left on the support number with the caller's number The Team Member Skarn's company mailbox; no automatic deletion; deleted by hand under the written procedure of 2026-09-22, 24 months after the license ends

The Customer's administrators can read, in the Portal, their organization's audit log entries, including the IP address and browser identifier they carry, and can export them in CSV and NDJSON form.

3. Routing through verified domains and the account listing

When a person registers for a free license, or asks to join, with an email address on a domain the Customer has verified, the service does not issue an individual license. It tells the person that the domain belongs to the Customer's organization, and, depending on the join mode the Customer chose: sends the person an invitation to the organization at once (automatic mode, the default, when a seat is free); queues a join request and notifies the Customer's administrators (manual mode, or automatic mode with no free seat); or tells the person to ask an administrator for an invitation (invitations only). The person's email address is thereby disclosed to the Customer.

An Enterprise Customer with a verified domain can list, and export as a CSV file, the personal Skarn accounts registered with an address on that domain, with the address, the display name, the account state and the contact state, and can send such an account holder a migration notice by email through the service. The account holder decides whether to join; the account is not changed by the listing.

4. Special categories

None. The Customer instructs no processing of special categories of personal data, criminal offence data or children's data, and the Portal has no field for them.

5. Skarn's own security processing of the same records

The service writes the IP address into the sessions table and the audit log for its own security: detecting account takeover, abuse and disputes about who performed an action. It applies rate limits keyed on the IP address, which are deleted after one day. The registration form's IP address is stored only as a keyed hash on free registrations and cleared after 30 days; that record belongs to clause 2.3(c).

6. Backup copies

Copy What it holds Where Retention
Nightly table export Every table of the license database that is not ephemeral, including the audit log Cloudflare R2, in the same account as the database Deleted 30 days after it is written
Weekly full database dump The whole license database Amazon Web Services S3, region eu-central-1 (Frankfurt), in a bucket with Object Lock Locked against deletion for 365 days from upload; expires 395 days after upload
Weekly audit log export The whole audit log since its genesis, verified before export The same bucket Locked against deletion for 7 years from upload; expires 30 days after the lock ends. Exports written before 22 September 2026 carry a 10-year lock
Database point-in-time history The database's own recent history Cloudflare D1 30 days (D1 Time Travel on the Workers Paid plan)

The weekly exports are produced by a scheduled job on a GitHub-hosted runner, which holds the export for the duration of the job and uploads it through a write-only role. Deleting a record from the live database does not remove it from a copy already written; each copy leaves the system only when its retention ends.

Annex 2: Technical and organisational measures

This Annex summarises the measures in place on 2026-09-21.

1. Hosting and encryption in transit. The Portal and the license service run on Cloudflare Workers with the database on Cloudflare D1. Every connection is over TLS; the zone enforces HTTPS, TLS 1.2 as the minimum, and DNSSEC is enabled for getskarn.com. Company mail is protected by SPF, DKIM, DMARC, MTA-STS and DANE.

2. Encryption at rest. License tokens are stored encrypted under a key held outside the database. The S3 backup bucket applies server-side encryption. Session identifiers and sign-in tokens are stored as hashes.

3. Authentication of Team Members and administrators. The Portal uses single-use sign-in links valid for 15 minutes, sent to the verified email address; there are no passwords. Session cookies are HttpOnly, Secure and SameSite, and sessions expire 7 days after sign-in.

4. Authentication of Skarn staff. The staff console requires a single-use sign-in link to the staff address followed by a WebAuthn passkey or hardware security key assertion; a link alone never issues a session. Staff sessions expire after 8 hours, or after 30 idle minutes. Recovery is a second enrolled authenticator; there is no email-only or SMS fallback.

5. Authorisation. Team Members see only their own organization; administrator functions require the owner or admin role. Staff have two levels; commercial and financial fields are readable only by two named financial readers. Every console route carries an explicit access policy, and a route absent from the policy list is unreachable. The console never displays a license token.

6. Audit. Every action on the Customer's records, by a Team Member, an administrator, Skarn staff or an automated job, is written to an append-only, hash-chained audit log that names the actor. The chain is verified before every weekly backup and on every deployment. The database migration tooling refuses any statement that would update or delete audit log rows.

7. License signing. Licenses are signed with an Ed25519 key held in AWS Key Management Service as a non-exportable key in a single-purpose AWS account; only the license service's signing worker can use it, every signing call is recorded in CloudTrail, and a weekly reconciliation compares signing calls with issued licenses.

8. Backups. See Annex 1, section 6. The backup job holds a role that can only add objects to the locked bucket and cannot read, delete or unlock them.

9. Abuse controls. Registration and sign-in are rate limited per address and per email; the registration form is protected by Cloudflare Turnstile; the edge runs Cloudflare's managed and OWASP rulesets; disposable and public email domains cannot be verified as organization domains.

10. Change management. Every change to the service is reviewed, passes automated tests and workflow-security checks, and is deployed by a workflow whose secrets are bound to protected environments. Production deployments require an explicit dispatch by a member of Skarn's management board.

11. Personnel. Persons with production access are limited to the two members of Skarn's management board, who are bound by the written confidentiality undertakings of clause 6.1.

12. Data minimisation. The Portal holds no scan content, findings or credentials. Card data is collected by Skarn's merchant of record and never by Skarn. Website analytics are cookieless and store the IP address with its last two bytes removed.

13. Devices and provider accounts. Every device used to administer the Portal has full-disk encryption, an automatic screen lock and a current operating system and browser. Every provider account is protected through a password manager with a second factor, with no shared accounts, and hardware security keys or platform passkeys are enrolled for the staff console, GitHub, Cloudflare, Terraform Cloud, Microsoft 365, HubSpot, Paddle and the AWS root and single sign-on identities.

Annex 3: Sub-processors

The list at getskarn.com/trust/subprocessors/ also names parties that process only the data for which Skarn is the controller (clause 2.3); those parties are not Sub-processors under this Agreement. The Sub-processors of Customer Personal Data on 2026-09-21 are:

Sub-processor Role and purpose Customer Personal Data it processes Location and transfer mechanism
Cloudflare, Inc., San Francisco, United States Hosting of the Portal and the license service (Workers), the database (D1), the nightly backup store (R2), DNS, the Turnstile challenge, the edge firewall All Customer Personal Data in transit and at rest Cloudflare's global network; the database and the backup store are not restricted to Cloudflare's EU jurisdiction. Transfers under Cloudflare's customer data processing addendum: EU standard contractual clauses (Module Three) and the EU-US Data Privacy Framework
Amazon Web Services EMEA SARL, Luxembourg License signing (Key Management Service) and the weekly locked backups (S3) The holder name, email address and organization of each license signed; the weekly database dump and audit log export Region eu-central-1 (Frankfurt, Germany); no transfer outside the EEA in normal operation. AWS data processing addendum with EU standard contractual clauses for support access
GitHub, Inc., San Francisco, United States Runs the weekly backup job on a hosted runner The full database export and audit log export, for the duration of the job Hosted runner location not fixed by GitHub. GitHub data protection agreement: EU standard contractual clauses and the EU-US Data Privacy Framework, which applies to the skarn-security organization under the GitHub Customer Agreement
SMTP2GO (Sand Dune Mail Ltd, Christchurch, New Zealand) Delivery of the transactional emails the Portal sends Recipient address and message content: names, organization name, invitation, sign-in and verification links EU sending infrastructure (Amsterdam); New Zealand is covered by Commission Decision 2013/65/EU
Microsoft Ireland Operations Limited, Dublin, Ireland Company mailboxes (Microsoft 365, Exchange Online) through which support requests from Team Members are received and answered Email address, message content and attachments of Team Members who write to a Skarn support address; voicemail messages from the support number European Union (EU Data Boundary); Microsoft Products and Services Data Protection Addendum with EU standard contractual clauses
Zadarma, contracted through IP Telecom Bulgaria LTD, Burgas, Bulgaria The support telephone number; every call goes to voicemail and the recording with the caller's number is emailed to the company mailbox Caller number and voicemail content of a Team Member who calls the support number Zadarma states that it processes personal data in databases located in the European Union

Not a Sub-processor: Paddle.com Market Limited, Skarn's merchant of record, which is an independent controller for the checkout, billing and transaction data of the Customer's purchasing representative; HubSpot Ireland Ltd, Skarn's customer relationship system, which holds records of the Customer's representative and prospective buyers and receives nothing from the Portal; HubSpot logs only the emails a founder chooses to log with a prospect, and never a Team Member's support correspondence; Hetzner Online GmbH, which hosts the website analytics and receives nothing from the Portal.