Data Processing Addendum

Last updated

This Data Processing Addendum (“DPA”) forms part of the agreement between Rebase and the Customer and governs Rebase's processing of personal data on the Customer's behalf.

This DPA applies where Rebase (Collectables Ltd, “Processor”) processes personal data on behalf of the Customer (“Controller”) in providing the service, and where such processing is subject to data-protection laws including the EU/UK GDPR. Capitalized terms not defined here have the meaning in our Terms of Service.

1. Roles & scope

The Customer is the controller and Rebase is the processor of personal data contained in Customer Data (the feedback, tickets, comments, and associated diagnostic context captured through the widget). Rebase processes that data only to provide the service and per the Customer’s documented instructions (including these Terms and configuration choices). As controller, the Customer is responsible for establishing a lawful basis for capturing end-user data, obtaining any required consent, and providing notice to its end-users before the widget runs; see the Privacy & Compliance Guide for how to configure masking and gate the widget behind consent.

2. Nature & purpose of processing

Capturing on-page feedback; generating and storing structured tickets; syncing tickets to connected issue trackers; enabling collaboration and notifications; and providing support, security, and billing.

3. Categories of data subjects & personal data

4. Processor obligations

5. Subprocessors

The Customer authorizes Rebase to engage the subprocessors listed on our Subprocessors page. Rebase imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Rebase will give notice of intended additions or replacements (via the subprocessor-change notification list), and the Customer may object on reasonable data-protection grounds.

6. International transfers

Where processing involves transferring personal data outside the EEA/UK to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference.

7. Security measures (Annex II)

8. Data-subject requests

Taking into account the nature of processing, Rebase will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests. If a data subject contacts Rebase directly, we will refer them to the relevant Customer.

9. Personal data breaches

Rebase will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to assist the Controller’s own obligations.

10. Deletion & return

On termination, Rebase will delete or return Customer Data within a reasonable period, except where retention is required by law. Screenshots are deleted on the Customer’s configured schedule (90 days by default). Backups are purged on their normal rotation.

11. Audits

Rebase will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits subject to reasonable confidentiality, scope, and frequency limits.

12. Contact

To request a countersigned copy of this DPA or to raise a data-protection matter, email [email protected].