This Data Processing Agreement (“DPA”) forms part of the agreement between a business customer (“Customer,” “Controller”) and Activity Racoon(“Activity Racoon,” “Processor”) for use of the Activity Racoon platform. It applies when Activity Racoon processes personal data on behalf of the Customer, including hosted deployments at https://app.aracoon.com or equivalent.
Self-hosted deployments: If the Customer runs the full Activity Racoon stack on infrastructure it controls and Activity Racoon does not access personal data except for optional support, the Customer is typically the sole operator of that data. This DPA still describes recommended roles and subprocessors (such as AI providers) that may apply when those features are enabled.
By using the Service to process personal data, the Customer agrees to this DPA. In case of conflict between this DPA and the Terms & Conditions regarding personal data processing, this DPA prevails.
1. Definitions
- Personal Data — any information relating to an identified or identifiable individual processed through the Service.
- Customer Data— Personal Data submitted to or collected through the Service on the Customer's instructions.
- Subprocessor — a third party engaged by Activity Racoon to process Customer Data.
Capitalized terms not defined here have the meanings in the Terms or applicable data-protection law (including the EU GDPR and UK GDPR where relevant).
2. Roles of the parties
The Customer is the Controller (or acts on behalf of a Controller) for workplace and employee data collected through agents, integrations, and dashboards. The Customer alone determines the purposes and means of monitoring and of using collected data, including for HR, discipline, or termination. Activity Racoon is the Processor, processing Customer Data only on documented instructions from the Customer (including organization policy settings), except where law requires otherwise.
The Customer is solely responsible for establishing lawful bases, providing workforce notice, configuring the Service, and responding to data-subject requests. Activity Racoon does not audit or approve the Customer's monitoring program.
3. Subject matter, duration, and nature of processing
Subject matter: provision of engineering intelligence, activity analytics, delivery metrics, task attribution, and related features.
Duration:for the term of the Customer's subscription or contract, plus any retention period described in the Privacy Policy or Customer agreement, and until deletion is completed.
Nature of processing: collection, storage, organization, aggregation, analysis, display, synchronization with third-party tools, and optional AI-assisted interpretation of activity data.
4. Categories of data subjects and personal data
Data subjects
- Customer employees and contractors using monitored workstations
- Developers using the IDE extension
- Customer administrators and dashboard users
Types of personal data
- Identifiers — name, email, Windows username, hostname, machine ID, organization membership
- Workplace activity — application names, window titles, browser URLs, session and AFK timing, process metadata, activity categories
- Optional screenshots — desktop images when enabled by Customer policy
- Development context — file paths, branches, edit summaries, task attribution metadata from the IDE extension
- Integration data — issue, repository, and collaboration metadata from connected tools
- Account and audit data — logins, policy changes, invitations
See the Privacy Policy for a full description. The Customer configures which features are enabled.
5. Processor obligations
Activity Racoon will:
- process Customer Data only on documented instructions from the Customer, including through organization policy settings and use of the Service;
- ensure personnel authorized to process Customer Data are bound by confidentiality;
- implement appropriate technical and organizational measures as described in our Security page;
- assist the Customer, where reasonable, with data-subject requests and security assessments;
- delete or return Customer Data at the end of the agreement, subject to legal retention requirements and backup cycles;
- make available information necessary to demonstrate compliance with this DPA.
6. Subprocessors
The Customer authorizes Activity Racoon to engage Subprocessors. Current categories include:
| Subprocessor | Purpose | When used |
|---|---|---|
| Google (Gemini API) | AI summaries, Q&A, task matching, optional screenshot analysis | When AI features are enabled and configured |
| Infrastructure / hosting providers | Compute, networking, and storage for hosted deployments | Hosted Service |
| Sentry | Error and performance monitoring for the Service | When enabled (PII sending disabled by default) |
| Grafana Labs (Grafana Cloud) | Operational metrics and tracing | When observability stack is enabled |
| Google Cloud Storage | Cached application process icons | When icon caching is configured |
Connected integrations (Atlassian/Jira, GitHub, GitLab, Linear, Slack, and similar) are accessed using credentials the Customer provides. Those vendors process data under their own terms when the Customer connects them.
We will notify Customers of new Subprocessors that materially affect Customer Data processing and allow objection on reasonable grounds related to data protection.
7. Security measures
Activity Racoon maintains measures including TLS for API traffic, Argon2 password hashing, encrypted agent credentials, optional AES-256-GCM screenshot encryption, optional encrypted agent ingest, organization-scoped access control, and integrity chaining for selected events. Details are in the Security document.
8. Data subject requests
The Customer is responsible for responding to requests from data subjects (access, correction, deletion, restriction, portability, objection). Activity Racoon will assist by providing tools and reasonable support to export or delete data in hosted deployments, or by guiding self-hosted administrators, within the scope of the Service.
9. Personal data breaches
Activity Racoon will notify the Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Data in a hosted deployment. Notification will include available details about the nature of the breach, likely consequences, and measures taken or proposed. Where GDPR applies, we will aim to notify within 72 hours of awareness when feasible.
10. International transfers
Customer Data may be processed in the United States and other countries where Activity Racoon or its Subprocessors operate. Where required by law, Activity Racoon will use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms for transfers from the EEA, UK, or Switzerland.
11. Audits
Upon reasonable written request, Activity Racoon will provide information about its security practices and, for enterprise customers under a separate written agreement, may allow audits or questionnaires subject to confidentiality and frequency limits.
12. Liability
Liability arising from this DPA is subject to the limitations and indemnification provisions in the Terms & Conditions and EULA, except where prohibited by mandatory data-protection law. The Customer acknowledges that claims by employees or other individuals relating to monitoring or use of Customer Data are primarily between those individuals and the Customer.
13. Governing law
This DPA is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles, except that data-subject rights and Processor obligations under mandatory data-protection law apply as required in the data subject's jurisdiction.
14. Contact and execution
To request a countersigned copy, ask questions about this DPA, or notify us of a subprocessors objection, contact [email protected].
Related documents: Privacy Policy · Terms & Conditions · End User License Agreement · Security