Legal
Data Processing Agreement
Effective June 17, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Suggestra (“Processor”, “we”, “us”) and the entity that accepts it (“Customer”, “you”) when Customer uses the Suggestra service to process personal data on Customer’s behalf.
This DPA applies where Customer acts as a controller (or equivalent under applicable law) of personal data and Suggestra processes that data as a processor on Customer’s instructions. It supplements our Terms of Service and Privacy Policy.
By using Suggestra to collect feedback from reviewers or other individuals on Customer’s websites, Customer enters into this DPA. If you need a signed copy for your records, contact privacy@suggestra.dev.
1. Definitions
- Applicable Data Protection Law — GDPR, UK GDPR, Swiss FADP, and other data protection laws that apply to the processing of Personal Data under this DPA.
- Personal Data — any information relating to an identified or identifiable natural person processed by Processor on behalf of Customer through the service.
- Processing — any operation performed on Personal Data, whether or not by automated means, as defined in Applicable Data Protection Law.
- Sub-processor — a third party engaged by Processor to process Personal Data on behalf of Customer.
- Service — the Suggestra website, dashboard, embed widget, APIs, and related support described in the Terms.
Capitalized terms not defined here have the meanings given in the Terms.
2. Roles of the parties
Customer determines the purposes and means of processing Personal Data submitted through Customer’s use of the service (for example, feedback left by invited reviewers on Customer’s sites). Customer is the controller unless Applicable Data Protection Law assigns a different role.
Processor processes Personal Data only on Customer’s documented instructions as described in this DPA, the Terms, and Customer’s configuration of the service (including invited reviewers, websites, and API usage).
3. Details of processing
Subject matter
Provision of the Suggestra feedback and collaboration platform.
Duration
For the term of Customer’s subscription or free use of the service, and as described in Section 12 (Return and deletion).
Nature and purpose
Hosting, storage, organization, retrieval, display, transmission, and deletion of feedback and related account data so Customer can collect and manage website feedback.
Categories of data subjects
- Customer’s employees, contractors, and invited reviewers
- Other individuals whose Personal Data Customer chooses to submit through comments, exports, or API integrations
Types of Personal Data
Depending on Customer’s use, this may include:
- Identity and contact data (name, email address, profile image)
- Account and authentication data
- Feedback content (comments, thread metadata, page URLs, DOM context)
- Optional viewport screenshots on eligible plans
- Technical data (IP address, browser information, session identifiers) generated when accessing the dashboard or widget
Customer is responsible for not submitting special categories of data unless permitted by law and appropriately safeguarded.
4. Customer instructions
Processor shall process Personal Data only:
- to provide and maintain the service;
- as configured by Customer in the dashboard;
- as documented in this DPA and the Terms; and
- as required by Applicable Data Protection Law, in which case Processor will inform Customer before processing unless the law prohibits such notice.
Customer instructs Processor to use Sub-processors as described in Section 7. Customer is responsible for providing any privacy notices and obtaining any consents required for its processing activities.
5. Processor obligations
Processor shall:
- process Personal Data only on documented instructions from Customer, subject to Section 4;
- ensure that persons authorized to process Personal Data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures as described in Section 6;
- assist Customer with data subject requests as described in Section 9;
- notify Customer of Personal Data breaches as described in Section 10;
- delete or return Personal Data as described in Section 12, unless retention is required by law;
- make available information reasonably necessary to demonstrate compliance and allow audits as described in Section 11;
- notify Customer if Processor believes an instruction infringes Applicable Data Protection Law.
6. Security measures
Processor maintains measures designed to protect Personal Data, taking into account the nature of processing and the risks involved. These measures include, as appropriate:
- encryption in transit (HTTPS/TLS);
- access controls and authentication for dashboard and API access;
- hashed storage of passwords;
- logical separation of customer data;
- restrictions on secret API key exposure;
- monitoring and procedures to address security incidents.
Customer is responsible for safeguarding account credentials, API keys, and reviewer access. Details of security practices may be updated from time to time without reducing overall protection in a material way.
7. Sub-processors
Customer authorizes Processor to engage Sub-processors to support the service. Current categories of Sub-processors include:
- Cloud infrastructure and hosting — to run the application and store data
- Payment processing — Stripe, for subscription billing
- Email delivery — for transactional messages such as account verification
Processor will impose data protection obligations on Sub-processors that are substantially similar to those in this DPA. Processor remains responsible for Sub-processors’ performance of their processing obligations.
Processor will notify Customer of new Sub-processors by updating this page or by email. Customer may object on reasonable grounds relating to data protection by contacting privacy@suggestra.dev within thirty (30) days. If the parties cannot resolve the objection, Customer may discontinue use of the affected part of the service or terminate the agreement.
8. International transfers
Personal Data may be processed in countries outside the country where Customer or data subjects are located. Where required by Applicable Data Protection Law, Processor will ensure appropriate safeguards for transfers, such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.
Customer may request further information about transfer safeguards by contacting privacy@suggestra.dev.
9. Data subject requests
Processor will, taking into account the nature of processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer’s obligations to respond to requests from data subjects to exercise their rights under Applicable Data Protection Law.
Customer should direct data subjects to Customer as the controller. If Processor receives a request directly, Processor will promptly notify Customer and will not respond except on Customer’s instructions or as required by law.
10. Personal Data breaches
Processor will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer’s Personal Data. Notification will include, to the extent known, the nature of the breach, likely consequences, and measures taken or proposed to address it.
Processor will cooperate with Customer and provide reasonable assistance so Customer can meet its breach notification obligations under Applicable Data Protection Law.
11. Audits and information
Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request additional assurance no more than once per year, subject to reasonable notice, confidentiality obligations, and minimal disruption to Processor’s operations. Where available, third-party certifications or audit reports may satisfy this requirement.
12. Return and deletion
Upon termination or expiry of the service, Customer may export feedback data using dashboard or API features where available. Processor will delete Customer’s Personal Data within a reasonable period after termination, except where retention is required by law or for legitimate backup, security, or billing purposes, after which it will be deleted or anonymized.
Customer may delete websites, threads, and account data earlier through the dashboard.
13. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions in the Terms, except where prohibited by Applicable Data Protection Law.
14. Order of precedence
If there is a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA prevails. If any provision of this DPA is invalid, the remainder remains in effect.
15. Changes
Processor may update this DPA to reflect changes in the service, Sub-processors, or legal requirements. Material changes will be posted on this page with an updated effective date. Continued use of the service after changes take effect constitutes acceptance.
16. Contact
Data protection and DPA inquiries: privacy@suggestra.dev
Related documents: Privacy Policy · Terms of Service