Data Processing Agreement
How Shipbell processes your end users' personal data for you under Article 28 of the GDPR: on your instructions, securely, with sub-processors you are told about, and deleted when you are done.
Last updated
In short
- For your end users' data, you are the controller and Shipbell is your processor.
- We process that data only to run Shipbell for you, and only on your instructions.
- We keep it confidential and secure, and we help you answer your end users' requests.
- We tell you without undue delay about a personal data breach.
- We use sub-processors, and we tell you in advance by email before we change them, so that you can object.
- When you leave, you can export your data, and then we delete it.
Parties and scope
This Data Processing Agreement ("DPA") is between you, the customer, as controller, and [legal-entity-name] ("Shipbell", "we"), as processor. It is part of our Terms of Service and applies whenever we process personal data for you as part of the service. It is meant to meet the requirements of Article 28 of the GDPR and of similar data protection laws.
Words such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning they have in the GDPR. If this DPA and the Terms of Service disagree about personal data, this DPA applies.
This DPA does not cover data that we control ourselves, such as your team's account data, billing data and the data we need to keep the service secure. Our Privacy Policy covers that.
Subject matter, duration, nature and purpose
- Subject matter: the personal data of your end users that you collect and manage with Shipbell.
- Duration: as long as you use Shipbell, and afterwards until the data is deleted as described under "Deletion or return at the end".
- Nature: collecting problem reports, ideas, diagnostics and screenshots through the web widget, the iOS package, the REST API and your boards; storing and organising them; scrubbing diagnostics and re-encoding images; showing public content on your boards and developer page; sending the emails and alerts you switch on; moderation; export and erasure; deletion when retention periods end; and backups.
- Purpose: to provide the service to you under the Terms of Service, so that you can collect feedback from your end users, reply to them, show your progress and changelog, and keep them informed.
Categories of data subjects
- End users of your apps who send feedback from your apps or sign in to your boards.
- People you add as end users, or on whose behalf you post, in the admin or through the API.
- People who ask to receive your changelog or other updates by email.
- People who send a notice about content on your board.
Types of personal data
- Identity: the user identifier your app sends, the email address and whether it is verified, first and last name if your app sends them, the public display name, the language, and the extra user details you allow, which are limited in size.
- Content: problem reports and their visibility history, ideas, comments, votes and "me too", follows, and your team's replies.
- Diagnostics: app and device details, settings, the page path, recent errors, references to errors in your error-tracking service, and the context your app adds.
- Screenshots and other images.
- Sessions: hashed session tokens, the browser or app type, the time of last use and hashed IP addresses.
- Email: email addresses, each person's email settings for each list and for all email from the app, records of the emails sent, and consent records for your changelog and new-app announcements.
- Moderation: trust and block status, reports and notices about content, and the email addresses given with notices.
- Requests: records of exports and erasures.
Special categories of personal data, such as health data: Shipbell is not designed for them, so do not ask for them. Free text and screenshots can still contain such data. If that is likely for your app, allow only private reports, turn screenshots off and keep diagnostics minimal.
Your instructions
- We process personal data only on your documented instructions, unless the law requires us to do otherwise. In that case we tell you first, unless the law forbids it.
- Your instructions are the Terms of Service, this DPA, your settings in the admin and your calls to the API. Any other instruction must be agreed in writing.
- We tell you straight away if we think an instruction breaks data protection law.
Confidentiality
Everyone we allow to process your personal data is bound by confidentiality, by contract or by law, and has access only as far as their work requires.
Security measures
We take appropriate technical and organisational measures to protect personal data, taking into account the risks for the people concerned. Annex 2 describes them. We may change them over time, but we will not lower the overall level of protection.
Sub-processors
- You give us a general written authorisation to use sub-processors.
- Annex 3 lists the categories. We give you the current list of sub-processors on request at info@shipbell.app.
- We tell you by email, sent to the workspace owners, about any intended addition or replacement of a sub-processor at least [sub-processor-notice-period] before it takes effect.
- You may object to the change on reasonable data protection grounds within that period. We then discuss it with you in good faith. If we cannot resolve it, you may end the affected part of the service before the change takes effect.
- We give each sub-processor, by written contract, the same data protection obligations as this DPA gives us, and we remain responsible to you for their work.
Helping with data subject requests
- Shipbell gives you tools to answer your end users' requests: in the admin or through the API, you can export or erase an end user's data, change their email settings, edit content, and make their reports private or redact them.
- If an end user sends a request about your data to us, we pass it to you without undue delay, and we do not answer it ourselves unless you ask us to or the law requires it.
- Where the tools are not enough, we help you as far as is reasonable.
Helping with security, impact assessments and consultations
Taking into account the nature of the processing and the information we have, we help you meet your duties on security, on reporting personal data breaches, on data protection impact assessments and on prior consultation with a supervisory authority, for example by telling you how Shipbell works.
Personal data breaches
- We tell you without undue delay after we become aware of a personal data breach affecting your data, by email to the workspace owners.
- As far as we have it, we give you the information you need to meet your own duties: what happened, the categories and approximate number of people and records concerned, the likely consequences, and what we have done or propose to do. If we do not have all of it at once, we send it in stages.
- We take reasonable steps to contain the breach and to reduce its effects.
- Telling you about a breach is not an admission of fault.
Deletion or return at the end
- While you use Shipbell, data is deleted when the retention periods for your project end (Annex 1).
- You can export your data at any time while you use Shipbell, and for [post-termination-export-period] after the service ends.
- After that, we delete your personal data from our live systems within [account-deletion-period], unless the law requires us to keep it.
- Backups are deleted after 30 days, plus the period during which they are locked against deletion ([backup-lock-period]). Until then they stay protected. If a backup is ever restored, the erasures of end-user data made after it was taken are applied again first.
Information and audits
- We make available to you the information needed to show that we meet this DPA, for example answers to reasonable security questionnaires and descriptions of our measures.
- You, or an independent auditor you appoint who is bound by confidentiality, may audit our compliance with this DPA. Tell us at least [audit-notice-period] in advance. An audit must be reasonable in scope, take place during business hours, avoid disrupting the service and give no access to other customers' data.
International transfers
Shipbell's servers are in the European Union. Some sub-processors may process personal data outside the European Economic Area (EEA). When they do, we make sure appropriate safeguards are in place: [transfer-mechanism]. We transfer personal data outside the EEA only as data protection law allows.
Your obligations as controller
- You have a legal basis for the personal data you send through Shipbell, and you give your end users the information the law requires, including a privacy notice linked from your board.
- You choose your project settings, such as whether reports can be public and which choice is selected at first, whether screenshots are allowed, which diagnostics are sent, how long data is kept and which emails are sent. These are your decisions as controller.
- You are responsible for the legal basis of the emails you switch on. Announcements of your new apps rely on the rules for emailing existing customers about similar products, which need a clear and free chance to opt out. Shipbell shows the notice and the opt-out; whether those rules cover your apps and your end users is your responsibility.
- You keep your signing keys and API keys secure.
Liability and term
The limits of liability in the Terms of Service apply to this DPA, except where the law does not allow it. This DPA lasts as long as we process personal data for you.
Annex 1: Default retention periods
Shipbell deletes end-user data automatically every day when these default periods end. You can set different periods for each project.
- Screenshots: 90 days after the report is closed.
- Diagnostics: 180 days after the report is closed.
- Report text and its thread: 24 months after the report is closed, or earlier erasure. This also applies to public reports, with their public comments and "me too" votes.
- Ideas and the public comments on them: until erasure or deletion of the project.
- Sessions, sign-in links and sign-in codes: until they expire, plus 7 days.
- Records that stop a request from being processed twice: 24 hours.
- Hashed IP addresses: 30 days.
- Records of the emails sent: 90 days. The address and the content are cleared as soon as delivery has finished.
- Email addresses given with notices about content: 1 year.
- Audit log: 1 year.
- Export files: 7 days.
- Backups: 30 days, plus the period during which they are locked against deletion ([backup-lock-period]).
Annex 2: Security measures
- Encryption in transit: all connections to Shipbell use HTTPS.
- Separation: each customer's data is kept apart, with access rules enforced in the database itself as well as in our code, and tested automatically.
- Access control: team roles with different rights, strong sign-in for team accounts, and a new sign-in for sensitive actions such as exports, erasures, key changes and member changes.
- Credentials: passwords, session tokens and secret API keys are stored only as hashes. Secret API keys expire. End-user identity is checked with public keys only, so Shipbell holds nothing that could forge an end user's identity.
- Data minimisation: diagnostics are limited to known fields, scrubbed in the app and on our servers, and never public. IP addresses are stored only as keyed hashes. No profile pictures are collected.
- Images: uploads are checked, re-encoded without their metadata, and shown only through short-lived links after an access check.
- Logging: important actions are recorded in an audit log that cannot be changed and holds no secrets.
- Network: our servers are not directly reachable from the internet.
- Backups: regular database backups in separate storage that is locked against deletion, with regular restore tests.
- Retention and erasure: automatic daily deletion when retention periods end, and a record of erasures that is applied again after any restore.
- Maintenance: security updates for our systems and dependencies.
Annex 3: Categories of sub-processors
- Cloud hosting: the servers and databases that run Shipbell and store the service data.
- Object storage: screenshots, other images and export files.
- Backup storage: database backups, kept apart from the servers.
- Network, DNS and security: delivering traffic to Shipbell and protecting it from attacks and bots. This includes processing IP addresses.
- Email delivery: sending the emails you switch on, including recipients' email addresses and the email content.
- Error monitoring: technical details of errors in Shipbell itself, limited to internal identifiers.
- Team chat alerts, only if you turn them on: the type, visibility, platform and app version of a new item, its title (at most 80 characters, or none if you choose minimal alerts), and links to the admin and to the matching issue in your error-tracking service.
Services of your own that you connect, such as your error-tracking account or your webhook endpoints, are not our sub-processors. Data goes to them on your instructions.