Notice to developers
If your organization uses WePerform, GDPR requires it to tell you what is being processed and why. This is that notice, written to be handed to a team as-is. Copy it, adapt the employer name, and share it — transparency is a requirement of the law and a condition of this product working at all.
What is measured
- Your commits and pull requests in repositories your employer has connected: timestamps, size, complexity, and which files changed.
- Code survival — whether code you wrote is still there 30 days later.
- Security signals — findings introduced or resolved, risky dependencies, and accidental credential commits.
- Review discipline — whether a change was reviewed before it reached the main branch. This is read from the facts, not judged.
- Sampled AI assessments — a model reviews a few of your significant changes each week against a published rubric and writes a short rationale.
What is never measured
Lines of code as a productivity number, commit counts, hours worked, time of day, keystrokes, screen activity, messages, or anything from repositories your employer has not connected. Your source code is analyzed in memory and never stored.
Who can see it
You see all of your own data — every score and every word of every rationale, the same figures your manager sees. Managers see team-level aggregates and a per-person trend direction (improving, stable, declining). There are no leaderboards and no individual rankings.
How it may and may not be used
These numbers are decision support. Nothing about your employment is decided automatically — no score triggers any action. If your employer discusses this data with you, it should be a conversation informed by the rationale, not a verdict handed down by a tool. If you disagree with an assessment, you can flag it: disputed scores are reviewed by a human and removed from your trend.
Your rights
Under the GDPR you may ask your employer for a copy of your data, ask for corrections, object to processing, or request erasure. Your employer is the data controller and decides these requests; Nextarp B.V. acts only as processor on their instructions. Requests can be raised with your employer directly, or via our privacy policy, which we will forward to them.
