Privacy Policy
Last updated: 30.08.2026
1. Introduction
This Privacy Policy explains how Clean Culture Aleksandra Kubicka, ul. Góralska 67/2, 80-292 Gdańsk, Poland, NIP: 5842677326 ("Company", "we", "our", "us") processes personal data in connection with:
- the Slack application FeedBecky (the "App"),
- the web platform available at https://feedbecky.io (the "Platform"), and
- the website https://feedbecky.io (the "Website"),
together referred to as the "Services".
This Privacy Policy should be read together with our Terms of Service (https://feedbecky.io/terms) and, where applicable, the Data Processing Agreement (https://feedbecky.io/dpa).
We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Polish data protection laws.
Contact for all privacy matters: hello@feedbecky.io
2. Our role: controller or processor
Depending on the context, we act in one of two roles:
We act as a data processor when we process personal data contained within a Slack workspace in order to provide the App and the Platform to an organisation (the "Organisation"). This includes feedback activity, user identifiers and workspace data. In this case, the Organisation is the data controller, and our processing is governed by the Data Processing Agreement (https://feedbecky.io/dpa). If you are a user in an Organisation's Slack workspace and have questions about how your data is used, please contact your Organisation's administrator in the first instance.
We act as a data controller when we decide the purposes and means of processing ourselves. This applies to:
- Website visitors (cookies, analytics, contact forms);
- Billing and subscription management (invoicing, payment records);
- Admin accounts on the Platform (authentication, session management);
- Support, complaints and correspondence (including emails sent to hello@feedbecky.io);
- Technical logs kept for security and legal compliance;
- Our own marketing and product communications, where applicable.
3. What data we process
3.1 Data processed to provide the App and Platform
As described in Section 9 of the Terms of Service, the Services are designed to process only the data reasonably necessary for their functionality. The App does not access Slack message history.
- Workspace data: Slack workspace identifier (team ID), workspace name, locale preference, and an encrypted Slack bot token required to operate the integration.
- User data: Slack user identifier, display name, email address (if provided by Slack), and profile avatar URL. These are obtained from Slack at the time of first interaction or sign-in and updated on subsequent interactions.
- Feedback content: free-text feedback messages are not stored in our application database. During delivery, they are held in encrypted form in a task queue and deleted after delivery. Residual copies in the queue storage are deleted within 24 hours. After delivery, the message is stored in the Organisation’s Slack workspace and is subject to that Organisation’s Slack settings and retention policies.
- Feedback metadata: Slack user identifiers of the sender and recipient, feedback category, timestamp, anonymity flag, delivery status, and references to the relevant Slack messages and channels used to create links within the application interface. Where anonymous feedback is selected, the sender’s identity is not disclosed to the recipient. The sender’s Slack user identifier is retained as part of the feedback metadata.
- Feedback request records: Slack user identifiers of the requester and target, category, and request status. The request message content is not stored.
- Session data: Encrypted session identifiers stored temporarily (default: 120 minutes) to authenticate admin users on the Platform.
3.2 Data we process as a controller
- Billing data: Stripe customer identifier, subscription status, and payment method metadata (card type and last four digits). Payments are processed by Stripe; we never store raw payment card data.
- Technical logs: IP address, user agent, and request timestamps.
- Error reports: Technical details of application errors, such as the action that failed, browser and device information, and IP address. Our error monitoring is configured not to send personal data by default.
- Administrative email: The email address of a workspace administrator, received from Slack when that administrator signs in to the admin panel, and used to identify their account. We do not send service notifications or marketing to this address.
- Contact and support data: Your name, email address and the content of your messages when you contact us, submit a complaint, or exercise your rights.
- Website data: Cookie identifiers and usage data as described in Section 9 (Cookies), subject to your consent choices.
4. Data Sources
Personal data is primarily collected directly from the user, although some data may be collected automatically in connection with the use of the Services. We may also collect certain data indirectly from providers of technical, hosting, cloud, and analytics services, or from tools that support the security and operation of the Services, solely to the extent necessary to achieve the purposes described in this Policy.
5. Purposes and legal bases
Where we act as a controller, we process personal data for the following purposes:
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing and administering accounts, subscriptions and billing | Billing data, admin account data | Art. 6(1)(b) - performance of a contract |
| Issuing invoices and meeting accounting and tax obligations | Billing data | Art. 6(1)(c) - legal obligation |
| Security, fraud prevention, troubleshooting and abuse detection | Technical logs, error reports, session data | Art. 6(1)(f) - legitimate interest (keeping the Services secure) |
| Sending account and service notifications to administrators | Administrative email | Art. 6(1)(b) - performance of a contract |
| Handling support requests, complaints and rights requests | Contact and support data | Art. 6(1)(b) and 6(1)(f) - contract and legitimate interest |
| Establishing, exercising or defending legal claims | Any of the above, as necessary | Art. 6(1)(f) - legitimate interest |
| Website analytics and marketing cookies (if enabled) | Cookie and usage data | Art. 6(1)(a) - your consent, collected via our consent banner |
| Product updates and communications to customers | Email address | Art. 6(1)(f) - legitimate interest, or Art. 6(1)(a) where consent is required |
Where we act as a processor on behalf of an Organisation, the Organisation is responsible for the legal basis of processing, as set out in the Terms of Service and the DPA.
Where we act as a controller, providing data is voluntary, however, it is necessary to achieve the purposes described above. In accordance with the principle of data minimization, we process only data that is necessary to achieve the purposes referred to above.
6. Recipients of data
Personal data may be disclosed to providers necessary to run the Services and handle communications. Categories of data recipients may include, in particular, IT service providers, email service providers, analytics tool providers, consent management tool providers, entities providing legal, accounting, or consulting services, as well as entities authorized to obtain the data pursuant to applicable law.
Data recipients may include entities that process data on behalf of the controller as well as entities that, to a certain extent, may act as separate data controllers when they process data for their own purposes as specified in their own terms of service or privacy policies
Entities processing data on behalf of us acting as a controller include, but are not limited to::
- OVH Sp. z o.o. (ul. Powstańców Śląskich 9, 53-332 Wrocław, Poland, KRS 0000220286, NIP 8992520556), part of the OVHcloud group - hosting and infrastructure provider. Our primary application infrastructure and database are hosted in OVHcloud's Strasbourg (SBG) data centre region in France.
- Functional Software, Inc. dba Sentry (45 Fremont St, 8th Floor, San Francisco, CA 94105, United States) - application error and performance monitoring. We use Sentry's European data region, hosted in Frankfurt, Germany, and we have configured Sentry not to send personal data by default. Sentry states that limited data may nonetheless be processed in the United States. See Section 7.
- Sendinblue SAS, trading as Brevo (17 rue Salneuve, 75017 Paris, France, RCS Paris 498 019 298) - delivery of our own internal operational alert emails, such as a notification to us that a workspace has installed the App or changed its subscription. These are sent to our own mailbox, not to you or your Organisation, and contain the workspace name, its Slack team identifier and the Slack user identifier of the person who installed or changed the subscription. They never contain feedback content. Brevo stores customer data on servers within the European Union. Brevo's own privacy policy states that personal data may in some circumstances be transferred to countries outside the European Economic Area, including the United States and India, subject to appropriate safeguards. See Section 7.
- Stripe - payment processing. Stripe acts as an independent provider for payment transactions; its processing is governed by its own terms and privacy policy.
- Usercentrics (Cookiebot) - consent management for cookies on the Website.
- Slack - the App operates within Slack. Slack is an independent service chosen and contracted by you or your Organisation; we do not control Slack's processing of your data. See Slack's own privacy policy.
- Professional advisors (accounting, legal) and public authorities, where required by law.
A current list of sub-processors used to provide the App and Platform is set out in the DPA.
7. International transfers
Feedback data stays in the European Union. All workspace data, user records, feedback records and feedback request records processed to provide the App and the Platform are stored in the European Union.
Two supporting services process limited personal data outside the European Economic Area:
- Brevo, which delivers our internal operational alert emails to our own mailbox, is a French company and stores data on servers in the European Union. Its own privacy policy states that personal data may in some circumstances be transferred outside the European Economic Area, including to the United States and India.
- Sentry, which monitors application errors, stores that data in its European region in Frankfurt, Germany, but states that limited data may be processed in the United States.
Stripe may also transfer limited personal data outside the European Economic Area as part of its own payment operations.
Where personal data is transferred outside the European Economic Area, the transfer is protected by appropriate safeguards under Chapter V of the GDPR, in particular the EU Standard Contractual Clauses included in our agreements with these providers, and, where applicable, the EU-U.S. Data Privacy Framework.
8. Retention
We keep personal data only as long as needed:
- Workspace, user, feedback and request records: for the duration of the Organisation's use of the Services. Uninstalling the App from a Slack workspace starts a three-day grace period, after which the associated records are automatically deleted from the active application database. Reinstalling within those three days restores the workspace.
- Feedback content: not stored in the application database. It is deleted from the active task queue after delivery, and residual copies in the queue storage are deleted within 24 hours. Messages delivered to Slack remain subject to the Organisation’s Slack retention policies.
- Session data: deleted automatically after expiry (120 minutes).
- Technical logs: application logs are retained for 14 days and then deleted.
- Error reports: retained by our error monitoring provider for its standard retention period and then deleted.
- Administrative email records: message content and delivery logs are retained by our email provider for 30 days and then deleted.
- Billing and invoicing data: for the period required by accounting and tax law (in Poland, generally 5 years from the end of the relevant tax year).
- Support correspondence and complaints: for the time needed to handle the matter and for the applicable limitation periods for legal claims.
After the applicable retention periods have expired, the applicable data is deleted, anonymized, or restricted by the controller to the extent that this obligation arises from generally applicable laws.
9. Cookies
The Website uses cookies and similar technologies. We manage cookie consent through Cookiebot, a consent management platform. When you first visit the Website, a banner lets you accept, reject or customise non-essential cookies. You can change your choices at any time via the cookie settings link on the Website.
Cookie categories:
- Necessary cookies - required for the Website and Platform to function (e.g. session authentication, security, consent storage). These do not require consent.
- Statistics cookies - help us understand how visitors use the Website. Set only with your consent.
- Marketing cookies - used to deliver relevant content or measure campaigns. Set only with your consent.
The specific cookies in each category, their providers and their lifetimes are listed in the cookie declaration on the Website, which Cookiebot scans and keeps up to date automatically. That declaration is the authoritative list.
A detailed, automatically updated list of cookies used, their providers and lifetimes is available in the cookie declaration on the Website.
10. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten"), where applicable;
- restrict processing;
- data portability, where processing is based on contract or consent;
- object to processing based on legitimate interests;
- withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
To exercise your rights, contact us at hello@feedbecky.io. We will respond within one month, extendable by two further months for complex requests (we will inform you if this is the case).
If we are unable to identify the person making the request, we may ask for additional information necessary to verify that person’s identity.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
If an objection is raised, we will cease processing of the applicable data to the extent covered by the objection, unless there are compelling legitimate grounds for further processing or the data is necessary for the establishment, exercise, or defense of legal claims.
Note for workspace users: where we act as a processor for your Organisation, we may need to redirect your request to your Organisation, which is the controller of that data. We will assist the Organisation in fulfilling your request as required by the DPA.
You also have the right to lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl. You may also complain to the supervisory authority in your country of residence.
11. Data deletion
You or your Organisation may request deletion of data at any time by contacting hello@feedbecky.io. In addition, uninstalling the App starts a three-day grace period, after which the associated records are deleted from the active application database; reinstalling within that period restores them. Any residual feedback content in the task queue is deleted within 24 hours. Messages already delivered to Slack remain subject to the Organisation’s Slack retention policies, except where retention is required by law (e.g. invoicing records).
12. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption of sensitive credentials (such as Slack bot tokens) and session identifiers, hosting within EU data centres, access controls, and the data minimisation design described in Section 3 (in particular, feedback content is not stored in the application database and residual copies in the encrypted task queue are deleted within 24 hours). Details are set out in Annex 2 of the DPA.
13. Automated decision-making
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
14. Children
The Services are intended for business use by individuals aged 18 or over. We do not knowingly process children's data.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be published on the Website with a revised "Last updated" date. Where a change materially affects your rights, we will notify you as described in the Terms of Service.
16. Contact
Clean Culture Aleksandra Kubicka ul. Góralska 67/2 80-292 Gdańsk, Poland NIP: 5842677326 Email: hello@feedbecky.io