Zuletzt aktualisiert:
Dieses Dokument wird ausschließlich auf Englisch bereitgestellt. Es bindet die EU-Standardvertragsklauseln ein, deren amtliche Übersetzungen nicht umformuliert werden dürfen; maßgeblich ist daher die englische Fassung.
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Rabin Apps, LLC ("SupDesk," "we," "us") and the customer that accepted them ("Customer," "you"). It applies automatically, without signature, where you use the Service to process personal data that is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or the Swiss Federal Act on Data Protection. It records the terms required by Article 28(3) GDPR.
"Controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data that we process on your behalf under the Terms and Conditions. "End-User" means an individual who contacts you, submits feedback, or otherwise interacts with you through a SupDesk portal, feedback board, help center, or chat widget. "Data Protection Law" means the GDPR, the UK GDPR, the Swiss FADP, and any other privacy law applicable to a party's processing under this DPA.
The Service places us on both sides of this line depending on the data, so this DPA states which applies when.
We process Customer Personal Data only on your documented instructions, including on transfers to a third country, unless required otherwise by law to which we are subject — in which case we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest. The Terms and Conditions, this DPA, and your use of the Service's features constitute your complete documented instructions. If we consider an instruction to infringe Data Protection Law, we will inform you.
We ensure that the people authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to provide or support the Service. Access to production systems is role-restricted and requires authentication as described in Annex II.
We implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as required by Article 32 GDPR. We may update those measures over time provided the level of protection is not reduced. Annex II describes the measures in force as of the date of this DPA.
You give us general written authorisation to engage the sub-processors listed in Annex III. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance of those obligations.
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights under Chapter III GDPR. Much of this is self-service, so you can usually respond without involving us.
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event in time to allow you to meet your own notification obligations under Articles 33 and 34 GDPR. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We also provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the information available to us. Our incident response process and timelines are published at supdesk.app/security.
At your choice, we delete or return all Customer Personal Data at the end of the provision of the Service, and delete existing copies, unless law requires us to retain it. Deleting your account from account settings cancels any paid subscription and permanently deletes the workspaces you own and the content in them. Export your data before you delete, because deletion is not reversible. Data held in routine backups is deleted on the ordinary backup rotation of our infrastructure providers.
We make available to you the information necessary to demonstrate compliance with Article 28, and we allow for and contribute to audits conducted by you or an auditor you mandate. Because we are a small team, that obligation is discharged through documentation first — which is faster for you and does not take the Service offline.
We are established in the United States and our sub-processors operate there, so Customer Personal Data is transferred outside the EEA, the UK, and Switzerland.
Where you are a "business" and we are a "service provider" as those terms are defined in the California Consumer Privacy Act as amended by the CPRA, we process personal information only to perform the Service and for the business purposes set out in the Terms and Conditions. We do not sell or share personal information as those terms are defined in the CCPA, we do not retain, use, or disclose it for any purpose other than performing the Service, and we do not combine it with personal information received from other sources except as the CCPA permits a service provider to do. We certify that we understand and will comply with these restrictions.
This annex completes Annex I to the Standard Contractual Clauses. The data exporter is the Customer, acting as controller; the data importer is Rabin Apps, LLC, acting as processor. Contact details for both are the ones held in the Customer's account and support@rabinapps.com respectively.
| Item | Description |
|---|---|
| Subject matter | Provision of the SupDesk customer support and product feedback platform. |
| Duration | For as long as the Customer's account is active. Content the Customer creates is retained for the life of the account; other categories are deleted automatically on the published schedule (audit records 365 days, consent records 730 days, rate limiting records 90 days, payment provider event records 365 days, short-lived tokens 1 day). |
| Nature and purpose | Collecting, storing, organising, retrieving, transmitting, and deleting personal data in order to operate feedback boards, changelogs, customer portals, email messaging, live chat, a help center, satisfaction surveys and analytics, AI-assisted triage and reply suggestions, integrations, a public REST API, an MCP server, and mobile applications. |
| Categories of data subjects | The Customer's End-Users — people who submit feedback, vote, comment, start a chat, contact support, subscribe to a changelog, join a beta programme, or register on a waitlist. Also the Customer's own team members who hold console access. |
| Types of personal data | Email address; name; the Customer's own identifier for an End-User; the content of feedback posts, votes, comments, private messages, live chat conversations, help center articles, changelog entries, and canned responses; satisfaction survey ratings and free-text comments; beta programme feedback; waitlist registrations and referral relationships; file attachments; and, for team members, authentication and profile data received from the identity provider used to sign in. |
| Special categories | None. The Service is not designed to process special categories of personal data and the Customer must not submit them. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Competent supervisory authority | The supervisory authority of the Customer's place of establishment in the EEA, or of its EU representative where it is not established in the EEA. |
The measures below are in force as of the date of this DPA and complete Annex II to the Standard Contractual Clauses. Certifications held by our infrastructure providers are theirs, not ours; SupDesk does not currently hold SOC 2 Type II or ISO 27001, which remain on our roadmap.
The sub-processors we engage to provide the Service, as authorised under section 7. The current list is published at supdesk.app/subprocessors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage. | United States |
| Cloudflare | Hosting, CDN, attachment storage, bot protection, live chat infrastructure, and AI inference. | United States and global edge network |
| Stripe | Payment processing and subscription billing. | United States |
| Resend | Transactional and changelog email delivery, including the subscriber lists used for changelog broadcasts. | United States |
| Website analytics through Google Tag Manager, loaded only with the visitor's consent. | United States | |
| OneSignal | Push notification delivery for the mobile apps. | United States |
| Sentry | Crash and error diagnostics for the mobile apps. | United States |
| Expo | Mobile app builds and over-the-air updates. | United States |
These receive Customer Personal Data only when you switch on the corresponding integration or issue an API key. They act on your instruction rather than as our sub-processors, and what they do with the data is governed by your agreement with them, not by this DPA.
| Destination | What is sent | Location |
|---|---|---|
| Slack | Notifications to a connected workspace, including the end-user's email address and an excerpt of their message. | United States |
| GitHub | Copying the title and body of a feedback post into a GitHub issue. | United States |
| Outbound webhooks | Event payloads delivered to a URL the project specifies; a copy of each delivery is retained so it can be inspected and retried. | Determined by the customer |
| OpenAI, Anthropic, or Google | AI processing when a project supplies its own provider API key, under that project's own agreement with the provider. | United States |