Data Processing Agreement (DPA)
Table of Contents
Introduction
GDPR Compliant Data Processing
This Data Processing Agreement (DPA) forms part of the Terms of Service between FeedbackPro (the "Processor") and the customer (the "Controller") to ensure GDPR compliance in the processing of personal data.
This DPA applies when FeedbackPro processes personal data on behalf of customers in the course of providing feedback collection services. It establishes the rights and obligations of both parties regarding data protection.
Definitions
| Term | Definition |
|---|---|
| Controller | The customer who determines the purposes and means of processing personal data |
| Processor | FeedbackPro, which processes personal data on behalf of the Controller |
| Data Subject | The individual whose personal data is processed |
| Personal Data | Any information relating to an identified or identifiable natural person |
| Processing | Any operation performed on personal data, including collection, storage, use, disclosure |
| GDPR | General Data Protection Regulation (EU) 2016/679 |
| Supervisory Authority | The data protection authority in the relevant EU Member State |
Scope and Duration
Scope of Processing
This DPA applies to all processing of personal data by FeedbackPro on behalf of the Controller in connection with:
- Feedback collection and management services
- Survey distribution and response collection
- Analytics and reporting services
- Customer support activities
- Technical maintenance and support
Duration
This DPA remains in effect for the duration of the Terms of Service and any period during which FeedbackPro processes personal data on behalf of the Controller.
Details of Processing
Purpose of Processing
- Feedback collection and analysis
- Survey management and distribution
- Customer satisfaction measurement
- Report generation and analytics
- Service delivery and support
Categories of Data Subjects
- Customer's end users
- Survey respondents
- Website visitors
- Service recipients
- Customer contacts
Categories of Personal Data
| Category | Data Types | Sensitivity |
|---|---|---|
| Identity Data | Name, email address, phone number | Standard |
| Feedback Data | Survey responses, ratings, comments | Standard |
| Technical Data | IP address, browser type, device information | Standard |
| Usage Data | Interaction patterns, timestamps, session data | Standard |
| Location Data | Country, city, timezone (if provided) | Standard |
Controller Obligations
The Controller warrants and undertakes to:
- Lawful Basis: Ensure a lawful basis exists for all processing activities
- Data Subject Rights: Inform data subjects of their rights and how to exercise them
- Consent: Obtain necessary consents for processing where required
- Instructions: Provide clear, lawful instructions for data processing
- Data Accuracy: Ensure personal data provided is accurate and up-to-date
- Retention: Specify data retention periods and deletion requirements
- Security: Implement appropriate security measures for data transmission
Processing Instructions
The Controller instructs the Processor to process personal data:
- In accordance with this DPA and the Terms of Service
- As necessary to provide the feedback collection services
- To comply with applicable laws and regulations
- As otherwise documented in written instructions from the Controller
Processor Obligations
FeedbackPro (Processor) undertakes to:
Security & Confidentiality
- Implement technical and organizational security measures
- Ensure confidentiality of processing staff
- Provide regular security training
- Maintain access controls and monitoring
Processing Compliance
- Process data only on documented instructions
- Not transfer data to third countries without safeguards
- Assist with data subject rights requests
- Maintain records of processing activities
Incident Management
- Notify Controller of data breaches within 72 hours
- Provide assistance with breach assessments
- Implement remediation measures
- Document all security incidents
Data Return/Deletion
- Return or delete data at end of service provision
- Provide data export functionality
- Securely delete data when instructed
- Provide deletion certificates when requested
Technical and Organizational Measures
Technical Security Measures
| Category | Measures Implemented |
|---|---|
| Encryption | AES-256 encryption at rest, TLS 1.3 in transit |
| Access Control | Role-based access, multi-factor authentication, least privilege |
| Network Security | Firewalls, intrusion detection, network segmentation |
| Monitoring | 24/7 security monitoring, log analysis, anomaly detection |
| Backup & Recovery | Encrypted backups, tested recovery procedures, data integrity checks |
| Vulnerability Management | Regular security assessments, patch management, penetration testing |
Organizational Security Measures
- Staff Training: Regular data protection and security awareness training
- Confidentiality Agreements: All staff sign confidentiality and data protection agreements
- Access Management: Regular review of access rights and permissions
- Incident Response: Documented procedures for security incident management
- Vendor Management: Due diligence and contracts with all sub-processors
- Compliance Monitoring: Regular audits and compliance assessments
Sub-processing
Authorized Sub-processors
The Controller provides general authorization for the Processor to engage sub-processors, subject to the conditions set out below:
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services | Cloud Infrastructure | EU/US | Standard Contractual Clauses |
| Google Cloud Platform | Analytics & Storage | EU/US | Standard Contractual Clauses |
| Stripe | Payment Processing | EU/US | Standard Contractual Clauses |
| SendGrid | Email Services | EU/US | Standard Contractual Clauses |
Sub-processor Obligations
The Processor ensures that:
- Sub-processors are bound by equivalent data protection obligations
- Appropriate technical and organizational measures are implemented
- The Processor remains fully liable for sub-processor performance
- Changes to sub-processors are communicated with 30 days notice
Data Subject Rights
FeedbackPro will assist the Controller in fulfilling data subject rights requests:
Access Requests
Provide data export functionality and processing information
Rectification
Update or correct personal data upon instruction
Erasure
Delete personal data and provide confirmation
Response Timeframes
- Initial Response: Within 72 hours of receiving Controller's instruction
- Data Export: Within 7 business days for standard requests
- Data Deletion: Within 30 days unless longer retention required by law
- Complex Requests: May require up to 60 days with regular status updates
Data Breach Notification
Notification Procedures
- Immediate Assessment (0-4 hours)
- Detect and contain the breach
- Assess scope and impact
- Document initial findings
- Controller Notification (Within 72 hours)
- Nature and categories of data affected
- Number of data subjects impacted
- Containment and remediation measures
- Assessment of risk to data subjects
- Ongoing Support
- Assist with supervisory authority notifications
- Support data subject notifications if required
- Provide detailed forensic reports
- Implement additional safeguards
Audits and Inspections
Controller's Rights
The Controller has the right to:
- Receive annual compliance reports and certifications
- Conduct audits with reasonable notice (minimum 30 days)
- Request additional information about processing activities
- Engage third-party auditors (subject to confidentiality agreements)
Processor's Compliance
FeedbackPro will:
- Provide reasonable cooperation during audits
- Make available all information necessary to demonstrate compliance
- Allow and contribute to audits conducted by the Controller or auditor
- Implement recommendations from audit findings
Liability and Indemnification
Limitation of Liability
Each party's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.
Indemnification
- Processor Indemnification: FeedbackPro will indemnify Controller for damages resulting from Processor's breach of this DPA
- Controller Indemnification: Controller will indemnify Processor for damages resulting from Controller's unlawful instructions or breach of this DPA
- Regulatory Fines: Each party is responsible for fines imposed due to their own non-compliance
Termination
Termination Events
This DPA terminates:
- Upon termination of the Terms of Service
- When no personal data is being processed under the agreement
- Upon material breach that remains uncured after 30 days written notice
Post-Termination Obligations
Upon termination, FeedbackPro will:
- Data Return: Return all personal data to Controller in portable format
- Data Deletion: Securely delete all copies of personal data
- Certification: Provide written certification of deletion
- Sub-processors: Ensure sub-processors also delete data
- Timeframe: Complete within 90 days of termination
Exceptions to Deletion
Personal data may be retained only:
- As required by applicable law
- For backup systems (subject to deletion within 12 months)
- In anonymized form that cannot be re-identified
Agreement Acceptance
By using FeedbackPro services, the Controller acknowledges and accepts the terms of this Data Processing Agreement. This DPA is incorporated by reference into the Terms of Service.
Questions and Support
For questions about this DPA or data processing practices, contact our Data Protection Officer at dpo@feedbackpro.com or visit our GDPR Compliance page.
Last updated: October 7, 2025 at 10:08 AM