v1.4.0Triage that admits when there's nothing to find

Data Processing Addendum

Last updated

This Data Processing Addendum (“DPA”) forms part of the agreement between Rebase and the Customer and governs Rebase's processing of personal data on the Customer's behalf.

This DPA applies where Rebase (Rebase Technologies Ltd, a company registered in England and Wales (Company No. 17380046), “Processor”) processes personal data on behalf of the Customer (“Controller”) in providing the service, and where such processing is subject to data-protection laws including the EU/UK GDPR. Capitalized terms not defined here have the meaning in our Terms of Service.

1. Roles & scope

The Customer is the controller and Rebase is the processor of personal data contained in Customer Data (the feedback, tickets, comments, and associated diagnostic context captured through the widget). Rebase processes that data only to provide the service and per the Customer’s documented instructions (including these Terms and configuration choices). As controller, the Customer is responsible for establishing a lawful basis for capturing end-user data, obtaining any required consent, and providing notice to its end-users before the widget runs; see the Privacy & Compliance Guide for how to configure masking and gate the widget behind consent.

2. Nature & purpose of processing

Capturing on-page feedback; generating and storing structured tickets; syncing tickets to connected issue trackers; enabling collaboration and notifications; and providing support, security, and billing.

3. Categories of data subjects & personal data

4. Processor obligations

5. Subprocessors

The Customer authorizes Rebase to engage the subprocessors listed on our Subprocessors page. Rebase imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Rebase will give at least 14 days’ notice of intended additions or replacements (via the subprocessor-change notification list) before they take effect, and the Customer may object on reasonable data-protection grounds. If an objection cannot be resolved, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period.

6. International transfers

Rebase’s own infrastructure is hosted in the United Kingdom, and email is delivered from the EEA (Ireland); certain subprocessors listed on the Subprocessors page process data in the United States. Where processing involves transferring personal data outside the EEA/UK to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference.

7. Security measures (Annex II)

8. Data-subject requests

Taking into account the nature of processing, Rebase will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests. If a data subject contacts Rebase directly, we will refer them to the relevant Customer.

9. Personal data breaches

Rebase will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to assist the Controller’s own obligations.

10. Deletion & return

On termination, Rebase will delete or return Customer Data within a reasonable period, except where retention is required by law. Screenshots are deleted on the Customer’s configured schedule (90 days by default). Backups are purged on their normal rotation.

11. Audits

Rebase will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits subject to reasonable confidentiality, scope, and frequency limits.

12. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and the aggregate cap in §10 of the Terms of Service, and liability under this DPA and the Terms counts toward a single combined cap — except where data-protection laws do not permit liability to data subjects or supervisory authorities to be limited in this way.

13. Contact

To request a countersigned copy of this DPA or to raise a data-protection matter, email [email protected].