Scope and parties
This Data Processing Agreement ("DPA") is part of the Terms of Service between the customer ("you", the controller) and Erdi Izgi, an individual entrepreneur in the Czech Republic, not yet entered in the Trade Register ("we", the processor). It applies whenever we process personal data on your behalf while providing Upvotekit, and it meets the requirements of Article 28 of the GDPR. You accept it by accepting the Terms; no signature is needed. If you need a signed copy, email [email protected].
The processing
- Subject and purpose: hosting and running your feedback boards, roadmap and changelog, embeds, notifications, the API and integrations, as described in the Terms.
- Duration: as long as you use the service, and until the data is deleted as described under "Return and deletion".
- Nature: storage, organisation, display, transmission (email, webhooks and integrations you set up), export and deletion.
- Data subjects: your end users (people who vote, post, comment or follow on your boards, or whom you identify to us), and your workspace members as far as you manage them.
- Personal data: random visitor identifiers; names and email addresses; user ids, company, revenue and other attributes you send through embed tokens or the API; the content people post (text and attachments), votes, follows and comments; email delivery status for notifications.
- Special categories: none are intended. Don't send us special categories of data (for example health data) about your users.
Our obligations
- We process the data only on your documented instructions: the Terms, this DPA, and your settings and actions in the service. If we believe an instruction breaks data protection law, we tell you.
- We don't use the data for our own purposes, don't sell it, and don't use it for advertising.
- Everyone who can access it is bound to confidentiality.
- We keep the security measures below and improve them as the service changes.
- If the law requires us to process data other than on your instructions, we tell you first unless the law forbids it.
Security measures
- Encrypted connections (HTTPS) for the app, portals, API and webhooks; webhooks are signed.
- Tenant isolation: every request is scoped to one workspace and project; private boards need a signed embed token.
- Passwords stored as hashes; integration secrets encrypted; API keys stored as hashes and scoped to one project.
- Role-based access in workspaces (owner, admin, team mate) and an audit log of actions.
- Access to production is limited to the people who run Upvotekit; staff actions in the admin console are logged.
- Rate limits and abuse protection on public endpoints.
- Uploaded images are re-encoded, which strips metadata including location.
- Nightly backups, encrypted before they leave our servers, stored in the EU and kept for up to 3 weeks.
Subprocessors
You authorise the subprocessors on the Subprocessors page. Each is bound by a written agreement with data protection obligations no weaker than this DPA. We tell you by email at least 30 days before we add or replace one. If you object on reasonable data protection grounds and we can't find a solution, you can end your subscription before the change, and we refund any prepaid period you can no longer use. We remain responsible for our subprocessors.
International transfers
Where personal data leaves the EU/EEA, it is protected by an adequacy decision (for example for the UK, or US providers certified under the EU–US Data Privacy Framework) or by the European Commission's standard contractual clauses, which are incorporated here by reference where needed.
Requests and breaches
- Requests from your users: the service lets you find, export, anonymize and delete an end user's data yourself. If a user contacts us directly, we point them to you. We help you further where reasonable.
- We help you with data protection impact assessments and consultations with authorities, as far as they concern our processing.
- Breaches: we notify you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it, and we update you as we learn more.
Return and deletion
- You can export your data at any time, including while a workspace is read-only.
- When you delete end users, content or a workspace, we delete that data. Items in the trash stay until you empty it or delete the workspace.
- When your subscription ends, workspaces stay read-only for 30 days so you can export, then we delete them with their files and audit log.
- Deleted data can remain in backups for up to 3 weeks, after which it is gone, unless the law requires us to keep it.
Information and audits
We give you the information you reasonably need to show compliance with Article 28, for example answers to security questionnaires. If that is not enough, or an authority requires it, you can audit our compliance with reasonable notice, at most once a year, at your cost, without access to other customers' data, and under confidentiality.
Your obligations
- You have a legal basis for the data you send us and for asking your users to vote, post and comment.
- You tell your users about the processing, for example in your privacy policy, including the visitor cookie described in our Cookie Policy when you embed a board in your site or app.
- You only send us the data the service needs.
General
The liability limits of the Terms apply to this DPA. If this DPA and the Terms conflict on data protection, this DPA wins. It stays in force as long as we process personal data for you. The law and courts named in the Terms apply.