Data processing agreement
Last updated: Aug 30th, 2025
Effective date: August 6, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service or another written agreement between the customer (“Customer”) and Volcanic Labs SLU, trading as PushFeedback (“PushFeedback”). It applies only when PushFeedback processes Personal Data in Customer Content on Customer’s behalf.
1. Roles and instructions
Customer is the controller and PushFeedback is the processor, except where applicable law assigns a different role. Customer is responsible for ensuring a lawful basis, transparency, and valid instructions for processing. PushFeedback will process Personal Data only on Customer’s documented instructions, including those in the agreement and the Customer’s use of the Services, unless law requires otherwise. In that case, PushFeedback will notify Customer unless prohibited by law. If PushFeedback reasonably believes an instruction infringes applicable data-protection law, it will inform Customer without undue delay and may suspend the affected processing until the parties agree on a lawful instruction.
2. Details of processing
The subject matter is the provision, operation, support, and security of the Services. Processing lasts for the subscription term and the limited period described in Section 9. Its nature and purpose are to collect, store, organise, display, transmit, analyse, and delete feedback at Customer’s direction. The Personal Data may include names, email addresses, IP addresses, session identifiers, page URLs, messages, screenshots, and metadata. Data subjects may include Customer’s end users, visitors, customers, employees, and authorised users.
3. Confidentiality and security
PushFeedback will ensure that persons authorised to process Personal Data are bound by confidentiality obligations. PushFeedback will implement and maintain technical and organisational measures appropriate to the risk, including measures described in our security overview. We may update those measures as technology and the Services evolve, provided the overall level of protection is not materially decreased.
4. Sub-processors
Customer gives PushFeedback general written authorisation to engage sub-processors. A current list is available in our provider documentation. We will provide at least 30 days’ notice of a new sub-processor through that page or another reasonable channel. Customer may object in writing during that period on reasonable data-protection grounds. We will use reasonable efforts to address the objection; if we cannot, Customer may terminate the affected Service before the new sub-processor is engaged and receive a pro-rata refund of prepaid unused fees for that affected Service. PushFeedback will impose written data-protection obligations on each sub-processor that are no less protective than the obligations applicable to PushFeedback under this DPA for the relevant processing, and remains responsible for its sub-processors’ compliance with those obligations.
5. Assistance
Taking account of the nature of processing and information available to us, PushFeedback will reasonably assist Customer with data-subject requests, security obligations, data protection impact assessments, and consultations with supervisory authorities as required by Article 28 of the GDPR. Customer remains responsible for responding to requests and conducting assessments. PushFeedback may charge reasonable fees for assistance requiring material work beyond the standard Services, except to the extent the assistance is required because of PushFeedback’s breach of this DPA.
6. Personal Data Breaches
PushFeedback will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Content and will provide information reasonably available to us to help Customer meet its obligations. Customer is responsible for determining whether a notification to an authority or affected individuals is required.
7. Audits and information
On written request, PushFeedback will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may audit once every 12 months, or more often if required by a supervisory authority, on at least 30 days’ written notice, during normal business hours, without unreasonable disruption, and subject to confidentiality. Customer must first use information, security documentation, and remote review reasonably made available by PushFeedback. Audits may not be performed by a competitor and may not access other customers’ information. Customer is responsible for its auditor’s fees and expenses.
8. International transfers
PushFeedback may transfer Personal Data outside the European Economic Area where permitted by applicable data-protection law. Where a transfer mechanism is required, PushFeedback will use an adequacy decision, Standard Contractual Clauses, or another valid mechanism. On request, we will make relevant transfer documentation available subject to reasonable confidentiality protections.
9. Return and deletion
At the end of the Services, Customer may choose for PushFeedback to return or delete Customer Personal Data. Customer may export Customer Content using available functionality before termination. Unless applicable law requires retention, PushFeedback will carry out Customer’s choice and delete existing copies within 60 days after termination. Data in backups will be isolated and deleted through normal backup rotation, and may not be actively processed except for restoration, security, or legal purposes. On reasonable written request, PushFeedback will confirm deletion.
10. Aggregated data and liability
PushFeedback may generate and use aggregated or de-identified service data that does not identify Customer, its users, or Customer Content. The parties’ liability under this DPA is subject to the limitations and exclusions in the agreement, except to the extent applicable law requires otherwise.
11. Contact
Volcanic Labs SLU
Plaza de Galicia, Local 7, 38612, Santa Cruz de Tenerife, Spain