1. Roles
Controller
The party that determines the purposes and means of processing personal data. In this DPA, you are the Controller.
Processor
The party that processes personal data on behalf of the Controller. Radius is the Processor.
2. Subject matter & duration
Radius processes personal data only:
- On documented instructions from the Controller
- For the duration of the primary service agreement
- For the purposes of providing the service
3. Categories of data
- User identifiers (name, email, role)
- Codebase metadata and files (repository structures, source code snippets)
- Collaboration data (Slack channel messages, integration logs)
- AI prompt history and context (chat messages, context variables)
4. Security measures
Radius maintains SOC 2 Type II controls, encryption in transit (TLS 1.2+) and at rest (AES-256), and role-based access control with least-privilege principles.
5. Subprocessors
Current subprocessors are listed on the Subprocessors page. We give 30 days' notice before adding a new one.
6. International transfers
Where personal data is transferred outside the UK/EEA, we rely on the UK International Data Transfer Addendum and EU Standard Contractual Clauses.
7. Assistance
Radius will assist Controllers with:
- Data subject requests
- Data protection impact assessments
- Breach notification (within 72 hours of awareness)
8. Deletion
Upon termination, personal data is deleted within 30 days unless retention is required by law.