# Data Processing Agreement

Canonical: https://argos-ci.com/dpa

# Data Processing Agreement

Last updated: August 13, 2026.

This DPA takes effect immediately for new customers. For customers with an active paid subscription on August 13, 2026, it takes effect on September 15, 2026, together with the [Terms of Service](/terms).

This Data Processing Agreement (“DPA”) forms part of the [Argos Terms of Service](/terms), or of any other written agreement between Smooth Code SAS (“Argos”, “we”, “us”, or “our”) and the customer (“Customer”, “you”, or “your”) governing access to the Argos platform (together, the “Agreement”).

Smooth Code SAS is a company incorporated under the laws of France, registered with the Paris Trade and Companies Register under number 830 511 788, with its registered office at 30 Boulevard de Sébastopol, 75004 Paris, France.

This DPA applies automatically, without signature, wherever Argos processes personal data on Customer's behalf. Customers whose procurement process requires an executed copy can request one at [contact@argos-ci.com](mailto:contact@argos-ci.com), and we will sign the same document.

Where Customer and Argos have executed a separate data processing agreement, that agreement prevails over this one to the extent of any conflict.

## 1. Roles of the parties

In providing the Service, Argos processes two distinct categories of personal data, and its role differs between them.

Where Argos processes personal data contained in Customer Data, meaning the screenshots, builds, repository metadata, review activity, logs, and user profiles that Customer submits to or generates through the Service, Customer acts as controller and Argos acts as processor. That processing is governed by this DPA.

Where Argos processes personal data for its own purposes, such as administering and securing the Argos accounts of Customer's personnel, billing, and communicating with them, Argos acts as controller. That processing is governed by the [Argos privacy policy](/privacy) and falls outside this DPA.

Where Customer is itself a processor acting on behalf of a third-party controller, Customer warrants that it has the authority to instruct Argos as set out in this DPA, and references to “controller” apply to that third party as the context requires.

## 2. Definitions

**Data Protection Laws** means all laws applicable to the processing of personal data under this DPA, including Regulation (EU) 2016/679 (“GDPR”), the French Data Protection Act (Loi Informatique et Libertés), and the US state privacy laws referred to in Section 15.

**Personal Data** means any information relating to an identified or identifiable natural person that Argos processes on Customer's behalf under the Agreement.

**Personal Data Breach** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

**Processing** means any operation performed on Personal Data, whether or not by automated means.

**Subprocessor** means a third party engaged by Argos to process Personal Data on Customer's behalf.

Terms not defined here have the meaning given to them in the Agreement or, failing that, in the GDPR.

## 3. Scope and duration of the processing

The subject matter, nature, purpose, and duration of the processing, together with the categories of Personal Data and of data subjects, are described in Annex 1, Annex 2, and Annex 3.

This DPA takes effect when Customer begins using the Service and remains in force for as long as Argos processes Personal Data on Customer's behalf. The obligations in Sections 4, 5, 6, 9, 11, and 13 survive its termination for as long as Argos retains any Personal Data.

## 4. Processing instructions

Argos processes Personal Data only on Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by European Union or Member State law. Where such a requirement applies, Argos will inform Customer of it before processing, unless that law prohibits the disclosure on important grounds of public interest.

The Agreement, this DPA, Customer's configuration of the Service, and Customer's use of the Service's documented functionality constitute Customer's complete instructions. Additional instructions require the parties' written agreement and may be subject to a charge where they exceed what the Service ordinarily provides.

Argos will not sell Personal Data, process it for its own purposes, or disclose it except as necessary to provide the Service or as required by law.

Argos will not use Customer Data to train, fine-tune, or develop artificial intelligence or machine learning models without Customer's prior consent, as set out in the Terms of Service. Optional functionality that Customer expressly initiates or enables is not covered by this restriction. Where such functionality relies on a third-party model provider, Argos contracts for the Customer Data submitted to that provider not to be used to train its models.

**Argos will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws.** Argos may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.

Customer is responsible for the lawfulness of the Personal Data it submits to the Service and of the instructions it gives, including for having an appropriate legal basis and for providing any notice required of it.

## 5. Confidentiality

Argos ensures that persons authorised to process Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that the obligation survives the end of their engagement.

Argos limits access to Personal Data to those personnel who need it to provide, secure, or support the Service, and provides them with appropriate data protection and security training.

## 6. Security

Argos implements and maintains the technical and organisational measures described in Annex 5, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, and the risks to data subjects.

Argos's current security certifications and attestations, including its SOC 2 Type II attestation, are published in the [Argos trust center](https://app.eu.vanta.com/argos/trust/8z3w834xz9a4snga4obms).

Argos may update the measures in Annex 5 over time, provided the level of protection is not materially reduced.

## 7. Subprocessors

Customer grants Argos general written authorisation to engage Subprocessors to process Personal Data, subject to this Section.

The current list of Subprocessors is published in the [Argos trust center](https://app.eu.vanta.com/argos/trust/8z3w834xz9a4snga4obms/subprocessors) and summarised in the [Argos privacy policy](/privacy).

Argos informs Customer of any intended addition or replacement of a Subprocessor before that Subprocessor begins processing Personal Data, by updating the published list and notifying customers who have subscribed to changes at [contact@argos-ci.com](mailto:contact@argos-ci.com). Where a change is required urgently to preserve the security or the continuity of the Service, Argos informs Customer as soon as reasonably possible.

Customer may object to a new Subprocessor on reasonable data protection grounds, and the parties will discuss the objection in good faith. If Argos cannot make the Service available without that Subprocessor and the parties cannot agree on an alternative, a Customer holding a paid subscription may terminate it on written notice, and Argos will refund any prepaid fees covering the period after termination. This is Customer's exclusive remedy for an objection.

Argos imposes on each Subprocessor, by written contract, data protection obligations that are substantially equivalent to those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor's obligations.

## 8. Data subject rights

Taking into account the nature of the processing, Argos assists Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests to exercise data subject rights, including access, rectification, erasure, restriction, portability, and objection.

The Service provides functionality allowing Customer to access, export, correct, and delete Customer Data directly. Where that functionality is sufficient to answer a request, it constitutes Argos's assistance.

If Argos receives a request directly from a data subject relating to Personal Data, it will not respond to the substance of the request but will inform Customer without undue delay and direct the data subject to Customer.

## 9. Personal Data Breach

Argos notifies Customer of a Personal Data Breach without undue delay after becoming aware of it, and in any event within forty-eight (48) hours.

The notification describes, to the extent known at the time and supplemented as further information becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact.

Argos takes reasonable steps to contain and remediate the breach, and assists Customer in meeting Customer's own notification obligations to supervisory authorities and to data subjects under Articles 33 and 34 GDPR.

Argos's notification of a breach is not an acknowledgement of fault or liability.

## 10. Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to it, Argos provides Customer with reasonable assistance in carrying out data protection impact assessments and in any prior consultation of a supervisory authority required under Articles 35 and 36 GDPR.

## 11. International transfers

Argos is established in France. Because Argos is established in the European Union, Customer's transmission of Personal Data to Argos is not itself a transfer to a third country within the meaning of Chapter V of the GDPR.

Argos hosts the Service on infrastructure operated by Amazon Web Services. Screenshots and other Customer Data are stored in the United States and replicated to the European Union. Other Subprocessors listed in the trust center may process Personal Data in the countries indicated there.

Where Argos, acting as data exporter, transfers Personal Data to a Subprocessor established outside the European Economic Area in a country that is not the subject of an adequacy decision, the transfer relies on a mechanism recognised under Chapter V of the GDPR. Argos relies on the standard contractual clauses adopted by the European Commission on 4 June 2021, under the module appropriate to the role of the Subprocessor, and Annexes 1, 2, 3, and 5 of this DPA describe the processing to which those transfers relate. Where a Subprocessor established in the United States is certified under the EU-U.S. Data Privacy Framework, Argos may rely on that certification instead.

Customers whose procurement process requires standard contractual clauses executed between Customer and Argos can request them at [contact@argos-ci.com](mailto:contact@argos-ci.com).

Argos provides information about the transfer mechanism applicable to a given Subprocessor, and about the safeguards accompanying it, on request at [contact@argos-ci.com](mailto:contact@argos-ci.com).

## 12. Information and audit

Argos makes available to Customer the information necessary to demonstrate compliance with its obligations under Article 28 GDPR.

Argos satisfies that obligation by making available the security documentation published in its [trust center](https://app.eu.vanta.com/argos/trust/8z3w834xz9a4snga4obms) and, where one is available, its most recent SOC 2 Type II report.

Where that documentation does not reasonably answer a question Customer is required to resolve, Customer may audit Argos's compliance with this DPA. Argos operates without customer-facing premises, and the infrastructure processing Personal Data is operated by the Subprocessors listed in the trust center, so an audit is conducted remotely on the basis of documentation and interviews.

An audit may take place no more than once in any twelve (12) month period, on at least thirty (30) days' written notice, during normal business hours, without unreasonably disrupting the Service or Argos's operations, and subject to confidentiality obligations at least as protective as those in the Agreement. An auditor mandated by Customer must not be a competitor of Argos, and Customer bears its own costs and Argos's reasonable costs of assisting.

The once-yearly limit does not apply where an audit is required by a supervisory authority or follows a Personal Data Breach affecting Customer's Personal Data.

## 13. Return and deletion

Following termination or expiry of the Agreement, and at Customer's choice, Argos will return Personal Data to Customer or delete it.

Customer exercises the choice to have its Personal Data returned by exporting it through the functionality the Service provides, which is available throughout the term and for thirty (30) days after termination of the account or subscription. Customer may also delete its projects, builds, and team directly in the Service at any time. Where Customer has not exported or deleted its Personal Data by the end of that period, Argos deletes it.

Argos deletes existing copies unless European Union or Member State law requires it to retain them, or where retention is reasonably necessary for legitimate legal, security, backup, or compliance purposes. Copies held in backups are removed as those backups expire in accordance with Argos's standard retention processes, and remain subject to this DPA until they are.

Argos provides written certification of deletion on Customer's request.

## 14. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement.

Nothing in this DPA limits either party's liability to a data subject under Article 82 GDPR, or any other liability that cannot be limited under applicable law.

## 15. US state privacy laws

This Section applies where Customer is subject to a US state privacy law, including the California Consumer Privacy Act as amended, the Colorado Privacy Act, and comparable laws in other states.

Argos acts as a “service provider” or “processor” as those terms are defined in the applicable law, and processes personal information solely on Customer's behalf for the purposes described in Annex 1.

Argos will not sell or share personal information, will not retain, use, or disclose it for any purpose other than performing the Service, and will not retain, use, or disclose it outside the direct business relationship between the parties or combine it with personal information received from other sources, except as permitted by the applicable law.

Argos will notify Customer if it determines that it can no longer meet its obligations under the applicable law, and Customer may take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.

Argos engages subcontractors only under a written contract imposing equivalent obligations, as set out in Section 7.

Where the applicable law requires the processor to permit assessments of its policies and technical and organisational measures, Argos satisfies that requirement by making available its most recent SOC 2 Type II report, where one is available, which is conducted by a qualified and independent assessor at Argos's expense. Where no such report is available, Section 12 governs the assessment.

For the avoidance of doubt, Section 13 gives Customer the right to direct the return or the deletion of personal information at the end of the provision of the Service, and Section 4 records that Argos processes personal information only for the purposes Customer specifies.

## 16. General

This DPA is governed by the law that governs the Agreement, and the courts designated in the Agreement have jurisdiction over disputes arising from it. Where standard contractual clauses are executed between the parties, their own governing law and jurisdiction provisions prevail for disputes arising under them.

Where this DPA conflicts with the Agreement, this DPA prevails on matters of data protection. Where this DPA conflicts with standard contractual clauses executed between the parties, those clauses prevail.

If a provision of this DPA is held invalid or unenforceable, the remainder continues in effect.

Argos may update this DPA to reflect changes in the Service, in its Subprocessors, or in Data Protection Laws. Where an update materially reduces Customer's rights, Argos will give at least thirty (30) days' notice before it takes effect, through the Service or by email.

## 17. Contact

Questions about this DPA, requests for an executed copy, requests for the SOC 2 Type II report, and Subprocessor change notifications: [contact@argos-ci.com](mailto:contact@argos-ci.com).

Smooth Code SAS, 30 Boulevard de Sébastopol, 75004 Paris, France.

## Annex 1. Description of the processing

**Subject matter.** Provision of the Argos visual testing platform.

**Nature and purpose.** Storing and serving screenshots and other media uploaded by Customer; comparing them against baselines; recording builds, tests, and review decisions; ingesting repository and pull request metadata from connected integrations; sending notifications; providing authentication and access control; maintaining logs for security, debugging, and abuse prevention; and providing support to Customer.

**Duration.** For the term of the Agreement, followed by the retention and deletion periods described in Section 13.

**Frequency.** Continuous, for as long as Customer uses the Service.

## Annex 2. Categories of Personal Data

- Names, email addresses, usernames, avatars, and account identifiers of Customer's personnel and of users Customer authorises
- Authentication and authorisation data, including single sign-on identifiers and access tokens
- IP addresses, device and browser information, and other technical metadata
- Repository, branch, commit, pull request, and CI metadata, including the identity of authors and reviewers
- Review activity, comments, and approval decisions
- Personal data appearing within screenshots, recordings, and other media that Customer uploads
- Personal data appearing within logs and error reports generated by Customer's use of the Service
- Contact details and message content exchanged with Argos support

Customer determines what appears in the media it uploads. Argos recommends running visual tests against environments seeded with synthetic data, so that no special categories of personal data within the meaning of Article 9 GDPR enter the Service. Argos does not intentionally process special categories of personal data, and the Service is not designed for them.

## Annex 3. Categories of data subjects

- Customer's employees, contractors, and other authorised users
- Customer's personnel appearing in repository, CI, and review metadata
- End users, customers, or other individuals whose personal data appears in the screenshots, recordings, or logs that Customer submits

## Annex 4. Subprocessors

The authoritative and always-current list is published in the [Argos trust center](https://app.eu.vanta.com/argos/trust/8z3w834xz9a4snga4obms/subprocessors) and prevails over any copy of it. A summary, with the role and location of each Subprocessor, is maintained in the [Argos privacy policy](/privacy).

## Annex 5. Technical and organisational measures

The measures Argos maintains include the following. The controls in force at any time, and the evidence supporting them, are published in the [Argos trust center](https://app.eu.vanta.com/argos/trust/8z3w834xz9a4snga4obms).

**Encryption.** Personal Data is encrypted in transit using TLS and at rest. Third-party access tokens are encrypted at the application level and are never stored in plain text.

**Access control.** Role-based access control, enforced least privilege, and restricted administrative access, logged and monitored.

**Infrastructure.** Managed infrastructure with vendor security patching, and separation of development and production environments.

**Vulnerability management.** Dependency scanning, a remediation process, and a public responsible disclosure policy.

**Secure development.** Code review before merge and automated testing in continuous integration. The Argos platform and SDKs are open source, so these practices are publicly verifiable.

**Resilience.** Managed database backups and redundant object storage.

**Incident response.** An incident response procedure covering detection, containment, remediation, and notification.

**Personnel.** Confidentiality obligations, security and data protection training, and prompt access revocation on departure.

**Data minimisation.** Collection limited to what the Service requires, an optional GitHub integration mode that requires no repository content permission, and retention periods aligned with Section 13.
