Data Processing Agreement (DPA)

Effective Date: January 1, 2024 | Last Updated: January 1, 2024

Introduction

GDPR Compliant Data Processing

This Data Processing Agreement (DPA) forms part of the Terms of Service between FeedbackPro (the "Processor") and the customer (the "Controller") to ensure GDPR compliance in the processing of personal data.

This DPA applies when FeedbackPro processes personal data on behalf of customers in the course of providing feedback collection services. It establishes the rights and obligations of both parties regarding data protection.

Definitions

Term Definition
Controller The customer who determines the purposes and means of processing personal data
Processor FeedbackPro, which processes personal data on behalf of the Controller
Data Subject The individual whose personal data is processed
Personal Data Any information relating to an identified or identifiable natural person
Processing Any operation performed on personal data, including collection, storage, use, disclosure
GDPR General Data Protection Regulation (EU) 2016/679
Supervisory Authority The data protection authority in the relevant EU Member State

Scope and Duration

Scope of Processing

This DPA applies to all processing of personal data by FeedbackPro on behalf of the Controller in connection with:

  • Feedback collection and management services
  • Survey distribution and response collection
  • Analytics and reporting services
  • Customer support activities
  • Technical maintenance and support

Duration

This DPA remains in effect for the duration of the Terms of Service and any period during which FeedbackPro processes personal data on behalf of the Controller.

Details of Processing

Purpose of Processing
  • Feedback collection and analysis
  • Survey management and distribution
  • Customer satisfaction measurement
  • Report generation and analytics
  • Service delivery and support
Categories of Data Subjects
  • Customer's end users
  • Survey respondents
  • Website visitors
  • Service recipients
  • Customer contacts

Categories of Personal Data

Category Data Types Sensitivity
Identity Data Name, email address, phone number Standard
Feedback Data Survey responses, ratings, comments Standard
Technical Data IP address, browser type, device information Standard
Usage Data Interaction patterns, timestamps, session data Standard
Location Data Country, city, timezone (if provided) Standard

Controller Obligations

The Controller warrants and undertakes to:

  • Lawful Basis: Ensure a lawful basis exists for all processing activities
  • Data Subject Rights: Inform data subjects of their rights and how to exercise them
  • Consent: Obtain necessary consents for processing where required
  • Instructions: Provide clear, lawful instructions for data processing
  • Data Accuracy: Ensure personal data provided is accurate and up-to-date
  • Retention: Specify data retention periods and deletion requirements
  • Security: Implement appropriate security measures for data transmission

Processing Instructions

The Controller instructs the Processor to process personal data:

  1. In accordance with this DPA and the Terms of Service
  2. As necessary to provide the feedback collection services
  3. To comply with applicable laws and regulations
  4. As otherwise documented in written instructions from the Controller

Processor Obligations

FeedbackPro (Processor) undertakes to:

Security & Confidentiality
  • Implement technical and organizational security measures
  • Ensure confidentiality of processing staff
  • Provide regular security training
  • Maintain access controls and monitoring
Processing Compliance
  • Process data only on documented instructions
  • Not transfer data to third countries without safeguards
  • Assist with data subject rights requests
  • Maintain records of processing activities
Incident Management
  • Notify Controller of data breaches within 72 hours
  • Provide assistance with breach assessments
  • Implement remediation measures
  • Document all security incidents
Data Return/Deletion
  • Return or delete data at end of service provision
  • Provide data export functionality
  • Securely delete data when instructed
  • Provide deletion certificates when requested

Technical and Organizational Measures

Technical Security Measures

Category Measures Implemented
Encryption AES-256 encryption at rest, TLS 1.3 in transit
Access Control Role-based access, multi-factor authentication, least privilege
Network Security Firewalls, intrusion detection, network segmentation
Monitoring 24/7 security monitoring, log analysis, anomaly detection
Backup & Recovery Encrypted backups, tested recovery procedures, data integrity checks
Vulnerability Management Regular security assessments, patch management, penetration testing

Organizational Security Measures

  • Staff Training: Regular data protection and security awareness training
  • Confidentiality Agreements: All staff sign confidentiality and data protection agreements
  • Access Management: Regular review of access rights and permissions
  • Incident Response: Documented procedures for security incident management
  • Vendor Management: Due diligence and contracts with all sub-processors
  • Compliance Monitoring: Regular audits and compliance assessments

Sub-processing

Authorized Sub-processors

The Controller provides general authorization for the Processor to engage sub-processors, subject to the conditions set out below:

Sub-processor Service Location Safeguards
Amazon Web Services Cloud Infrastructure EU/US Standard Contractual Clauses
Google Cloud Platform Analytics & Storage EU/US Standard Contractual Clauses
Stripe Payment Processing EU/US Standard Contractual Clauses
SendGrid Email Services EU/US Standard Contractual Clauses

Sub-processor Obligations

The Processor ensures that:

  • Sub-processors are bound by equivalent data protection obligations
  • Appropriate technical and organizational measures are implemented
  • The Processor remains fully liable for sub-processor performance
  • Changes to sub-processors are communicated with 30 days notice

Data Subject Rights

FeedbackPro will assist the Controller in fulfilling data subject rights requests:

Access Requests

Provide data export functionality and processing information

Rectification

Update or correct personal data upon instruction

Erasure

Delete personal data and provide confirmation

Response Timeframes

  • Initial Response: Within 72 hours of receiving Controller's instruction
  • Data Export: Within 7 business days for standard requests
  • Data Deletion: Within 30 days unless longer retention required by law
  • Complex Requests: May require up to 60 days with regular status updates

Data Breach Notification

Notification Procedures

  1. Immediate Assessment (0-4 hours)
    • Detect and contain the breach
    • Assess scope and impact
    • Document initial findings
  2. Controller Notification (Within 72 hours)
    • Nature and categories of data affected
    • Number of data subjects impacted
    • Containment and remediation measures
    • Assessment of risk to data subjects
  3. Ongoing Support
    • Assist with supervisory authority notifications
    • Support data subject notifications if required
    • Provide detailed forensic reports
    • Implement additional safeguards

Audits and Inspections

Controller's Rights

The Controller has the right to:

  • Receive annual compliance reports and certifications
  • Conduct audits with reasonable notice (minimum 30 days)
  • Request additional information about processing activities
  • Engage third-party auditors (subject to confidentiality agreements)

Processor's Compliance

FeedbackPro will:

  • Provide reasonable cooperation during audits
  • Make available all information necessary to demonstrate compliance
  • Allow and contribute to audits conducted by the Controller or auditor
  • Implement recommendations from audit findings

Liability and Indemnification

Limitation of Liability

Each party's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.

Indemnification

  • Processor Indemnification: FeedbackPro will indemnify Controller for damages resulting from Processor's breach of this DPA
  • Controller Indemnification: Controller will indemnify Processor for damages resulting from Controller's unlawful instructions or breach of this DPA
  • Regulatory Fines: Each party is responsible for fines imposed due to their own non-compliance

Termination

Termination Events

This DPA terminates:

  • Upon termination of the Terms of Service
  • When no personal data is being processed under the agreement
  • Upon material breach that remains uncured after 30 days written notice

Post-Termination Obligations

Upon termination, FeedbackPro will:

  1. Data Return: Return all personal data to Controller in portable format
  2. Data Deletion: Securely delete all copies of personal data
  3. Certification: Provide written certification of deletion
  4. Sub-processors: Ensure sub-processors also delete data
  5. Timeframe: Complete within 90 days of termination

Exceptions to Deletion

Personal data may be retained only:

  • As required by applicable law
  • For backup systems (subject to deletion within 12 months)
  • In anonymized form that cannot be re-identified
Agreement Acceptance

By using FeedbackPro services, the Controller acknowledges and accepts the terms of this Data Processing Agreement. This DPA is incorporated by reference into the Terms of Service.

Questions and Support

For questions about this DPA or data processing practices, contact our Data Protection Officer at dpo@feedbackpro.com or visit our GDPR Compliance page.

Last updated: October 7, 2025 at 10:08 AM