WePerform Privacy Policy
Based on the privacy policy of Nextarp B.V., adapted for the WePerform service. Last updated: 17 July 2026.
Who we are
WePerform is operated by Nextarp B.V., Wilhelminaplein 1, 3072 DE Rotterdam, The Netherlands, reachable at info@nextarp.com or +31 10 257 99 99. We handle personal data confidentially and in accordance with the General Data Protection Regulation (GDPR). This policy covers visitors of weperform.co and users of the WePerform application.
Personal data we process
- Account data: your name, work email address and directory identifiers received from your organization's Microsoft 365 or Google Workspace sign-in. We store no passwords.
- Repository metadata: commit author names and email addresses, reviewer usernames, timestamps and activity metadata from the repositories your organization connects. We process source code transiently in memory to compute metrics and never store source code.
- Assessment output: computed metrics, scores and written rationales relating to contributions attributed to mapped developers.
- Billing data: company name, billing address and subscription state. Card details are processed by Stripe and never touch our systems.
- Website analytics: aggregate, cookieless statistics (Plausible). We do not use tracking cookies on this website and do not process special categories of personal data.
Purposes and legal bases
We process personal data to provide the Service (performance of the contract with your organization), to bill subscriptions (contract and legal obligation), to secure and improve the Service (legitimate interest), and to respond when you contact us (legitimate interest or consent). For repository and assessment data processed on behalf of your organization, we act as processor and your organization is the controller — questions about why your organization uses WePerform belong with your employer, and our terms require them to use assessment output lawfully and transparently.
Retention
We keep personal data no longer than strictly necessary: workspace data is deleted on termination of the agreement (unless retention is legally required); billing records are kept for the statutory period; transient code analysis leaves no stored copy by design.
Sub-processors
We do not sell personal data. We use only the sub-processors needed to deliver the Service, each under a data-processing agreement providing equivalent protection:
- Google Cloud (EU, europe-west1) — hosting, database, and job execution.
- Google Cloud Vertex AI (EU) — the model that produces sampled code assessments. Code diffs are sent for analysis and are not retained by us or used to train models; only the resulting score and written rationale are stored.
- Stripe — subscription billing. Card details never reach our systems.
- Plausible — cookieless website analytics on this marketing site only (no personal data, no tracking cookies).
We notify workspace owners before adding or replacing a sub-processor. Beyond these, we disclose personal data only where legally required.
Automated decision-making (Article 22)
WePerform produces scores and trends about individual developers. These are decision support, not decisions. The Service takes no automated action about any person: it does not rank, rate for employment purposes, trigger consequences, or feed any automated process. Every score is accompanied by a written rationale, is visible in full to the person it describes, and can be disputed — sustained disputes are removed from trend calculations. Any employment decision remains a human judgement made by the customer, who as controller is responsible for using the output lawfully and transparently.
Your rights
You may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent where processing is based on it. Send requests to info@nextarp.com; we respond within four weeks. For data processed on behalf of your organization we will refer the request to your organization as controller. You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
We take appropriate technical and organizational measures against misuse, loss, unauthorized access, unwanted disclosure and unauthorized modification — including tenant isolation, encrypted transport, secrets held in a dedicated secret store, EU-region infrastructure defined as reviewable code, and the architectural guarantee that source code is never persisted. Details: see our security page.
Cookies
weperform.co uses no tracking or advertising cookies. Website analytics are cookieless and aggregate. The WePerform application uses strictly necessary session cookies for sign-in only.
