Trust
Data Processing Addendum
When your users submit feedback through your widget, you are the controller and we are your processor. This sets out what we may do with that data, what we must do to protect it, and what we owe you when something goes wrong.
Effective date: 26 July 2026
This addendum forms part of the terms of service and applies automatically to every customer processing personal data through Fidibeki. No signature is required, though we will sign a copy on request.
Scope and the role of each party
This addendum governs personal data that we process on your behalf. In practice that means feedback submitted through a widget you operate, together with anything a reporter chose to attach to it, and the derived records the service produces from that submission.
You are the controller. You decide which product to put the widget on, which rules run, what is collected, and why. Establishing a lawful basis for that collection, and telling your users about it, is yours.
We are the processor. We hold and process the data to run the service for you, on your instructions, and for nothing else.
Some data is outside this split. Your own account, workspace configuration, and billing records are data for which we are the controller, described in the privacy notice rather than here. Where you are yourself a processor for someone else, you confirm you have the authority to appoint us as a sub-processor.
Processing on your documented instructions
We process customer personal data only on your documented instructions, including for international transfers, unless a law we are subject to requires otherwise. Where such a law applies, we will tell you before processing unless that law forbids it.
Your instructions are, together:
- The terms of service and this addendum;
- Your configuration of the service — projects, widget rules, consent modes, retention window, integrations, and whether AI analysis is enabled for a project;
- Use of the product's documented features and API by your authorised members.
If we believe an instruction infringes data-protection law, we will tell you and may pause the affected processing rather than carry it out.
Subject matter and duration
The subject matter, nature, purpose, data categories, and categories of data subjects are set out in Annex I. Processing lasts as long as your subscription, plus the deletion periods described under return and deletion.
Confidentiality
Access to customer personal data is limited to people who need it to run or support the service, and everyone with such access is bound by a duty of confidentiality that survives the end of their engagement.
Support access to sensitive material — attachments, replays, exports — is logged with actor, timestamp, and purpose. That audit trail is a capability we are still completing; see what is not yet settled.
Security of processing
We implement appropriate technical and organisational measures under Article 32, described concretely in Annex II. Those measures are the commitment, not the marketing summary: if we change them, they must remain at least equivalent in protection.
We hold no SOC 2, ISO 27001, or comparable certification, and we do not imply otherwise anywhere in this document.
Sub-processors
You give general authorisation for us to engage sub-processors. Those engaged today, and what each one does, are listed in Annex III.
Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than these, and we remain fully liable to you for their performance.
Changes. We will give you at least 30 days' notice before a new sub-processor starts processing customer personal data. If you have a reasonable data-protection objection, tell us within that period and we will work to offer a change; if we cannot, you may terminate the affected part of the service and receive a pro-rata refund for the unused period. Silence for 30 days is acceptance.
International transfers
Where a sub-processor processes customer personal data outside the country you are in, including outside the European Economic Area, that transfer requires a valid mechanism — an adequacy decision, Standard Contractual Clauses, or another lawful route — together with a transfer impact assessment.
We do not claim EU data residency for flows that do not support it, and we do not claim transfer mechanisms we have not confirmed. The per-provider position is recorded in Annex III, and where it is still unverified the annex says so rather than filling the gap.
Assisting you with data-subject requests
Reporters usually contact the company whose product they used, which is you. If a reporter contacts us directly about data we hold for you, we will not answer on your behalf; we will route the request to you and tell the reporter we have done so.
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in meeting requests for access, rectification, erasure, restriction, portability, and objection. The service provides self-serve export and deletion for feedback, attachments, and replays, which is normally enough to answer a request without our involvement. Where it is not, ask us.
Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting customer personal data, so that you can meet your own Article 33 deadline. Notification goes to the contact your workspace holds.
The notification describes, as far as we know it at the time:
- The nature of the breach and the categories and approximate volume affected;
- The likely consequences;
- Measures taken or proposed, including to mitigate adverse effects;
- A contact point for further information.
We keep an internal breach register recording incident facts, assessments, chronology, containment, and post-incident actions, held behind an administrative boundary separate from the tenant runtime. Notifications sent to you are preserved as frozen snapshots, so what you were told and when is reconstructable rather than a matter of memory.
Notifying a supervisory authority or affected individuals is the controller's decision and remains yours. We will not make it for you.
Data protection impact assessments
We provide reasonable assistance with data protection impact assessments and prior consultation under Articles 35 and 36, limited to information about our processing that you cannot reasonably obtain yourself. The security page, this addendum, and its annexes are written to answer most of what an assessment asks.
Session replay and AI analysis are the two capabilities most likely to require an assessment on your side. Both are off by default and become active only through a decision you make.
Return and deletion
During your subscription you can export and delete customer personal data yourself at any time. Replays and attachments are removed automatically once they pass your plan's retention window by a daily cleanup, and that deletion is permanent.
On termination, deleting a workspace starts a seven-day grace period, after which the data is removed. For 30 days after termination we will help you export data on request. We delete existing copies unless a law we are subject to requires storage, in which case we tell you what is retained and why.
Audits and information
We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice: written questionnaires and this documentation come first, and we will answer them properly. An on-site or hands-on audit is available where a supervisory authority requires it or after a breach affecting your data, on reasonable notice, no more than once a year unless the law demands otherwise, and subject to confidentiality and to not compromising other customers' data.
AI sub-processing
AI analysis is disabled by default and is enabled per project by you. When it is on, free-text messages and the media a reporter chose to submit may be sent to Google Gemini for cleaning, transcription, sentiment scoring, and moderation flags.
- Session replays are never sent to any AI provider.
- Only the input categories explicitly enabled for the matching rule are sent, and authorisation is carried by the rule rather than assumed from the plan;
- Files placed with the provider target immediate deletion, tracked by a retry ledger;
- Our stored evidence of AI processing records the provider, model, purpose, category, and status — never the prompt, the source content, or raw provider output;
- Derived output follows the same retention, export, and deletion rules as its source.
AI output is advisory. It can be wrong, and it should not be the sole basis for a decision producing legal or similarly significant effects for a person.
The downstream contractual position with the AI provider is among the items under what is not yet settled, and you should read that before enabling AI on a project carrying personal data.
Liability and order of precedence
The liability limits in the terms of service apply to this addendum, except where data-protection law does not permit them to. Nothing here limits a data subject's rights or a supervisory authority's powers.
If this addendum conflicts with the terms of service on the processing of customer personal data, this addendum wins. A separately signed data processing agreement wins over both.
Annex I — Description of the processing
Subject matter and nature
Collecting product feedback through a widget you install, storing it, making it available to your authorised members for triage, and — where you enable them — analysing it, recording sessions, sending updates to reporters, and forwarding notifications to systems you connect.
Purpose
Providing the Fidibeki service to you, and supporting you in using it.
Categories of data subjects
- Reporters — the users of your product who submit feedback;
- Your workspace members, in their capacity as users of the service;
- Any individual a reporter refers to in free text or captures in media.
Categories of personal data
- Free-text feedback, ratings, and reactions;
- Attachments a reporter chose to add: screenshots, audio, video, element captures;
- Session replay, where you enabled it and the reporter consented — inputs masked, identity-bearing attributes stripped, canvas pixels suppressed;
- Reporter email address, only where the reporter opted in to updates about their feedback;
- Technical context: page origin, browser and device characteristics, and locally computed interaction signals;
- Workspace member identifiers, roles, and activity records.
Special categories. Free text and media can contain health, political, religious, biometric, sexual, employment, or child-related information, because a reporter can type or capture anything. This is not data the service solicits, and configuring rules so that it is not solicited is your obligation under the terms.
Frequency and duration
Continuous for the duration of the subscription. Retention follows your plan's window for replays and attachments — 30, 90, or 365 days — with raw widget analytics events kept for 90 days and daily aggregates for two years.
Annex II — Technical and organisational measures
These are implemented today. Where something is still being built, it is marked as such here rather than listed as if it were finished.
- Tenant isolation. Application data is stored under enforced row-level security in PostgreSQL; media and replay objects use tenant-prefixed keys in private, S3-compatible storage;
- Authentication. Passwordless magic links, brief audience-scoped tokens, and rotating refresh cookies with reuse detection — token reuse outside a narrow window revokes the whole session family. SAML SSO is available, and a workspace can require it and disable local login;
- Authorisation. Explicit per-route permissions across projects, rules, feedback, issues, sessions, members, API keys, integrations, and account operations. Invitations can be restricted to verified company email domains;
- Upload pipeline. Attachments upload through brief presigned URLs, are verified for size and MIME type, and land quarantined until signature verification passes. Storage objects stay private; downloads and playback stream through the authenticated API rather than direct storage links;
- Encryption. Integration secrets and custom headers are encrypted at rest with AES-256-GCM and shown exactly once at creation. Outbound webhooks are signed with HMAC-SHA256. Transport is encrypted in transit;
- Abuse resistance. Public submission endpoints enforce per-IP and per-project rate ceilings, verify browser origin against your allowed domains, and apply daily AI cost budgets. Limiter identities are brief HMAC hashes, and diagnostics never persist raw network or visitor data;
- Capture minimisation. The widget never reads input values, private page text, or network payloads, and builds no visitor fingerprint. Durable widget storage exists only after purpose-specific consent;
- Telemetry scrubbing. Error events are filtered by a deterministic allowlist before leaving the application: request URLs, headers, cookies, bodies, user and IP data, breadcrumbs, and free-text exception messages are removed or replaced with fixed placeholders;
- Breach register. Incident facts, assessments, chronology, containment and post-incident actions are recorded append-only behind a platform-administration boundary excluded from the tenant runtime role;
- Deletion. A daily cleanup enforces plan retention windows for replays and attachments; workspace deletion runs on a seven-day grace period;
- Access logging — in progress. Logging of views and downloads of attachments, replays, and exports with actor, timestamp, and purpose is being completed. Treat it as a roadmap item, not a control you can rely on today.
Annex III — Sub-processors
Roles and purposes below are accurate. The location, legal entity, and transfer mechanism columns a complete annex would carry are not yet verified, and are deliberately left unstated rather than guessed.
- Managed hosting, PostgreSQL, Redis, and S3-compatible object storage. Running the service and storing application data, media, and replay objects;
- Stripe. Billing and subscription processing;
- Resend. Transactional email delivery;
- Sentry. Error telemetry, receiving only allowlist-scrubbed events;
- Cloudflare Turnstile. Signup bot protection, receiving the challenge token and the submitting request's IP address;
- Google Gemini. AI analysis, only for projects where you enable it, and never for session replays;
- Slack, Microsoft Teams, and webhook endpoints you configure. Only where you connect them, and only the fields the destination's allowlist permits. These act on your instruction and are governed by your relationship with them.
Umami analytics runs on the marketing site only, with visitor consent, and processes no customer personal data. It is listed in the privacy notice rather than here.
What is not yet settled
A processor agreement is worth less than nothing if it asserts things nobody has checked. These items are open, and we would rather you knew that before relying on this document:
- Sub-processor locations, legal entities, and contract status. Not yet independently verified across providers. Until they are, Annex III states roles only;
- Transfer mechanisms. Which providers rely on adequacy, which on Standard Contractual Clauses, and the transfer impact assessment for each, are not yet documented per provider;
- The AI provider's downstream terms. The executed agreement, data retention and logging settings, and zero-data-retention status with the AI provider are not yet confirmed. If your feedback carries personal data you consider sensitive, leave AI analysis off for that project until this is closed;
- Maximum retention periods for several internal record types. Plan windows for replays and attachments are enforced in code; some audit, delivery, workflow, and evidence records have a bounded lifecycle that is implemented but no approved maximum period;
- Sensitive-category processing instructions. Project-level controls making AI use an explicit privacy decision rather than a plan default are still being built;
- Certification. No SOC 2, ISO 27001, or equivalent, and none claimed.
We will update this addendum as these close, and tell you about material changes the same way we would any other change to the terms.
Contact
For questions about this addendum, a signed copy, a security questionnaire, or a sub-processor objection, write to [email protected]. Every contact route is on the contact page.
Reviewing us for a purchase?
Bring the questionnaire. We would rather answer the hard questions before you buy than after.