FeedBecky

Data Processing Agreement

Last updated: 30 August 2026

1. Parties and purpose

This Data Processing Agreement ("DPA") forms part of the Terms of Service (https://feedbecky.io/terms) (the "Terms") between:

  • Clean Culture Aleksandra Kubicka, ul. Góralska 67/2, 80-292 Gdańsk, Poland, NIP: 5842677326 (the "Processor", "we", "us"), and
  • the organisation that has installed or uses the FeedBecky Slack application and the related web platform (the "Controller", "you").

This DPA is incorporated into the Terms by reference and applies whenever we process personal data contained within your Slack workspace on your behalf in connection with the Services. It is intended to satisfy the requirements of Article 28(3) of Regulation (EU) 2016/679 (the "GDPR").

By accepting the Terms or using the Services, you also accept this DPA. In the event of a conflict between this DPA and the Terms with respect to the processing of personal data, this DPA prevails.

Capitalised terms not defined here have the meaning given in the Terms. "Personal data", "processing", "data subject", "supervisory authority", "personal data breach" and related terms have the meanings given in the GDPR.

Our contact point for all data protection matters is hello@feedbecky.io.

2. Roles

For personal data contained within your Slack workspace and processed through the Services (the "Customer Personal Data"), you are the controller and we are the processor. You are responsible for the lawfulness of the processing, including having a valid legal basis and providing any required notices to data subjects, as set out in the Terms.

For clarity, this DPA does not apply where we act as an independent controller (for example, billing, technical logs kept for our own security and legal compliance, and website analytics), as described in our Privacy Policy (https://feedbecky.io/privacy).

Slack is an independent service chosen and contracted by you. Slack is not our sub-processor, and your relationship with Slack is governed by your agreement with Slack.

3. Details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

4. Processor obligations

We shall:

  1. process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by EU or Member State law to which we are subject; in such a case, we will inform you of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Your instructions are set out in the Terms, this DPA and your configuration and use of the Services;
  2. inform you immediately if, in our opinion, an instruction infringes the GDPR or other applicable data protection provisions;
  3. ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  4. implement the technical and organisational measures set out in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to data subjects (Article 32 GDPR);
  5. respect the conditions for engaging sub-processors set out in Section 5;
  6. taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR;
  7. assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to us;
  8. at your choice, delete or return all Customer Personal Data after the end of the provision of the Services, and delete existing copies, unless EU or Member State law requires storage, as set out in Section 8;
  9. make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits as set out in Section 7.

5. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex 3 for the processing of Customer Personal Data.

We will inform you of any intended addition or replacement of a sub-processor at least 14 days before the change takes effect, by email or through the Platform, giving you the opportunity to object. If you object on reasonable data protection grounds and we cannot offer a reasonable alternative, you may cancel your subscription in accordance with the Terms; the cancellation will take effect at the end of the then-current billing period.

Where we engage a sub-processor, we will impose on it, by contract, data protection obligations no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. We remain fully liable to you for the performance of the sub-processor's obligations.

6. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will, to the extent the information is available to us, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. We will provide further information as it becomes available and cooperate with you in your obligations under Articles 33 and 34 of the GDPR.

You are responsible for notifying the competent supervisory authority and data subjects, where required.

7. Audits

We will make available to you, on request, information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security documentation.

Where this information is insufficient to reasonably demonstrate compliance, you may conduct an audit, including an inspection, yourself or through an independent auditor bound by confidentiality, subject to the following: (a) at least 30 days' prior written notice; (b) no more than once per 12-month period, unless a personal data breach has occurred or an audit is required by a supervisory authority; (c) during normal business hours and without unreasonable disruption to our operations; (d) each party bears its own costs. The results of the audit are confidential, and each party will use them solely to assess compliance with this DPA and will not disclose them to third parties except to its professional advisers or where required by law.

8. Deletion and return of data

Upon termination or expiry of the Services, or upon uninstallation of the App from your Slack workspace, Customer Personal Data is deleted from the active application database after a three-day grace period that allows reinstallation, unless you request its return before termination or uninstallation, or EU or Member State law requires further storage. Any feedback content awaiting delivery is deleted from the active task queue, and residual copies in the queue storage are deleted within 24 hours.

During normal delivery, feedback message content is not stored in our application database. It is held in encrypted form in a task queue and deleted after delivery. Residual copies in the queue storage are deleted within 24 hours. After delivery, the message is stored within the Controller’s Slack workspace and is subject to the Controller’s Slack settings and retention policies.

Customer Personal Data contained in backups is permanently deleted or overwritten within 10 days after deletion from the active application database.

Before uninstallation or termination, you may request a copy of the Customer Personal Data we hold, as described in Annex 1, by contacting hello@feedbecky.io.

Short-lived technical records are deleted on their own schedule regardless of termination: admin session records expire after 120 minutes, and application logs are retained for 14 days and then deleted. Message content and delivery logs held by our email provider for administrator notifications are retained for 30 days and then deleted.

9. International transfers

Except for the limited processing by Sentry and Brevo described below, Customer Personal Data is stored and processed within the European Union (see Annex 3). We will not transfer Customer Personal Data outside the European Economic Area without ensuring appropriate safeguards under Chapter V of the GDPR (such as an adequacy decision or the EU Standard Contractual Clauses) and, where required, informing you in accordance with Section 5.

Two exceptions apply, both limited to supporting functions rather than feedback content:

  • Error monitoring. Application errors are reported to Sentry's European data region, hosted in Frankfurt, Germany. Sentry is established in the United States and states that limited data may be processed there.
  • Operational alerts. Our own internal alert emails about workspace activity, such as a new installation or a subscription change, are delivered to our own mailbox through Brevo, a French provider storing data on servers in the European Union. These are not sent to the Controller and contain no feedback content. Brevo states that personal data may in some circumstances be transferred outside the EEA, including to the United States and India, subject to appropriate safeguards

Both transfers are covered by the EU Standard Contractual Clauses in our data processing agreements with those providers and, where applicable, the EU-U.S. Data Privacy Framework. No feedback content is transferred outside the European Economic Area. The encrypted task queue is hosted within the European Union, and feedback content is not sent to Sentry or Brevo.

10. Data subject requests

If we receive a request from a data subject relating to Customer Personal Data (for example, a request for access or erasure from a user in your workspace), we will, to the extent legally permitted, promptly redirect the data subject to you and notify you of the request. We will not respond to such a request ourselves except on your documented instructions or where required by law.

11. Liability and term

Each party's liability under or in connection with this DPA is subject to the limitations of liability set out in the Terms, except where such limitation is prohibited by applicable law.

This DPA takes effect when you accept the Terms or first use the Services (whichever is earlier) and remains in force for as long as we process Customer Personal Data on your behalf.

12. Governing law

This DPA is governed by the laws of Poland, in line with the Terms, without prejudice to mandatory provisions of the GDPR.


Annex 1 - Details of processing

Subject matter of processing: provision of the FeedBecky Slack application and web platform, enabling users within the Controller's Slack workspace to request, give and receive feedback.

Duration of processing: the term of the Controller's use of the Services, until deletion in accordance with Section 8.

Nature and purpose of processing: collection, storage, structuring, transmission and deletion of data necessary to operate the feedback functionality, authenticate admin users, and configure the workspace; sending the Processor's own internal operational alert emails about workspace activity to the Processor's mailbox; troubleshooting, security and support.

Categories of data subjects: users of the Controller's Slack workspace (employees, contractors and other members granted access), including workspace administrators.

Types of personal data:

  • Workspace data: Slack workspace identifier (team ID), workspace name, locale preference, encrypted Slack bot token;

  • User data: Slack user identifier, display name, email address (if provided by Slack), profile avatar URL;

  • Feedback content: free-text feedback messages processed in encrypted form through a task queue for the purpose of delivery. The content is not stored in the application database. It is deleted from the active queue after delivery, and any residual copies in the queue storage are deleted within 24 hours;

  • Feedback metadata: Slack user identifiers of the sender and recipient, feedback category, timestamp, anonymity flag, delivery status, and references to the relevant Slack messages and channels used to create links within the application interface. This metadata is retained for the duration of the Controller’s use of the Services;

  • Feedback request records: Slack user identifiers of requester and target, category, request status. Request message content is not stored;

  • Session data: encrypted session identifiers for admin authentication (lifetime: 120 minutes);

  • Application logs: IP address, user agent and request timestamps generated while the Services are used, retained for 14 days for security and troubleshooting.

Special categories of data: none intended. The Controller must not use the Services to deliberately process special categories of personal data (Article 9 GDPR).

Annex 2 - Technical and organisational measures (Article 32 GDPR)

  • Data minimisation by design: feedback message content is not stored in the application database. It is processed in encrypted form through a task queue solely for delivery and deleted after delivery, with residual queue copies deleted within 24 hours. Only the metadata necessary for delivery, status tracking and links to the relevant Slack messages is retained.
  • Encryption: Slack bot tokens and session identifiers are stored encrypted; data in transit is protected by TLS.
  • Hosting: the primary application infrastructure, application database and encrypted task queue are hosted with OVH Sp. z o.o. (OVHcloud) in the Strasbourg (SBG) data centre region in France, within the European Union. Limited personal data may also be processed by Sentry and Brevo as described in this DPA.
  • Access control: access to production systems and Customer Personal Data is restricted to authorised persons on a need-to-know basis and protected by authentication; admin sessions expire automatically after 120 minutes.
  • Logging and monitoring: application logs (IP address, user agent, request timestamps) are retained for 14 days for security and troubleshooting, then deleted. Application errors are reported to Sentry's European data region (Frankfurt, Germany), configured so that personal data is not sent by default.
  • Resilience and recovery: automated backups are performed by the hosting provider and stored within the European Union. Customer Personal Data deleted from active systems may remain in encrypted backups for up to 10 days after deletion, after which it is permanently deleted or overwritten. Backups are accessed only where necessary for disaster recovery and are not used for any other purpose. If a backup is restored during this period, the applicable deletion requests will be reapplied.
  • Operational alerts: our own internal alert emails about workspace activity are sent to our own mailbox through a specialist email provider. They carry the workspace name, its Slack team identifier and the Slack user identifier of the person who acted; no feedback content is included in these emails.
  • Deletion: uninstallation starts a three-day grace period, after which Customer Personal Data is deleted from the active application database. Feedback content already awaiting delivery is deleted from the active task queue, and any residual copies in the queue storage are deleted within 24 hours. Messages previously delivered to Slack remain within the Controller’s Slack workspace and are subject to the Controller’s Slack retention policies.
  • Confidentiality: persons authorised to process data are bound by confidentiality obligations.
  • Sub-processor management: sub-processors are bound by written data protection obligations no less protective than this DPA.

Annex 3 - Approved sub-processors

Sub-processor Entity and location Role Location of processing
OVHcloud OVH Sp. z o.o., ul. Powstańców Śląskich 9, 53-332 Wrocław, Poland (KRS 0000220286, NIP 8992520556) Hosting and infrastructure (application, database, queue, backups) European Union - Strasbourg (SBG), France
Sentry Functional Software, Inc. dba Sentry, 45 Fremont St, 8th Floor, San Francisco, CA 94105, United States Application error and performance monitoring. Configured with send_default_pii disabled, so personal data is not sent by default; error reports may still incidentally contain technical identifiers. Sentry EU data region - Frankfurt, Germany. Sentry states that limited data may be processed in the United States (see Section 9).
Brevo Sendinblue SAS, trading as Brevo, 17 rue Salneuve, 75017 Paris, France (RCS Paris 498 019 298) Delivery of the Processor's own internal operational alert emails to the Processor's mailbox, for example a new installation or a subscription change. These carry the workspace name, its Slack team identifier and the Slack user identifier of the person who acted. No feedback content is included, and nothing is sent to the Controller. European Union. Brevo states that personal data may in some circumstances be transferred outside the EEA, including to the United States and India (see Section 9).

For clarity: Stripe processes billing data for which the Processor acts in its own right, not as the Controller's sub-processor for Customer Personal Data; Slack is an independent service contracted by the Controller; Usercentrics (Cookiebot) relates to website cookie consent only. None of these process Customer Personal Data from your Slack workspace on our behalf.


Contact: Clean Culture Aleksandra Kubicka ul. Góralska 67/2, 80-292 Gdańsk, Poland NIP: 5842677326 Email: hello@feedbecky.io

FeedBecky

Slack-native feedback app.

Add to Slack Privacy Policy Terms of Service DPA Contact

© 2026 FeedBecky. All rights reserved.