跳转到主要内容
功能
价格博客文档
登录

为独立开发者和小团队打造的反馈与应用控制台。

© 2026 Rabin Apps LLC

产品

  • 功能
  • 价格
  • 反馈看板
  • 更新日志
  • 私信
  • 在线客服
  • 帮助中心
  • AI 功能
  • Beta 测试
  • 候补名单

法律信息

  • 条款
  • 隐私
  • Cookies
  • 不出售我的数据
  • 安全
  • 数据处理协议
  • 次级处理方

资源

  • 博客
  • 平台支持
  • 文档
  • 最新动态
  • llms.txt
  • 系统状态

公司

  • 关于我们
  • 联系我们

数据处理协议

最后更新: 2026年8月6日

本文件仅提供英文版本。本文件纳入了欧盟标准合同条款,其官方译文不应被改写,因此以英文版本为准。

1. About this Agreement

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Rabin Apps, LLC ("SupDesk," "we," "us") and the customer that accepted them ("Customer," "you"). It applies automatically, without signature, where you use the Service to process personal data that is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or the Swiss Federal Act on Data Protection. It records the terms required by Article 28(3) GDPR.

  • •No signature is required. Accepting the Terms and Conditions accepts this DPA, and we record which version you accepted and when.
  • •If you need a copy for your records, print this page — it is formatted for that purpose.
  • •Where this DPA conflicts with the Terms and Conditions, this DPA prevails, but only in respect of personal data we process on your behalf.

2. Definitions

"Controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data that we process on your behalf under the Terms and Conditions. "End-User" means an individual who contacts you, submits feedback, or otherwise interacts with you through a SupDesk portal, feedback board, help center, or chat widget. "Data Protection Law" means the GDPR, the UK GDPR, the Swiss FADP, and any other privacy law applicable to a party's processing under this DPA.

3. Roles of the Parties

The Service places us on both sides of this line depending on the data, so this DPA states which applies when.

  • •You are the controller of Customer Personal Data. You decide what End-User data your projects collect and for what purpose, and you are responsible for having a lawful basis to collect it and for providing the notices your End-Users are entitled to.
  • •We are the processor of Customer Personal Data and process it only to provide and support the Service.
  • •We are an independent controller of a limited set of data we hold in our own right: your account records, billing records, and the security and operational logs we keep to run the Service. Our Privacy Policy, not this DPA, governs that processing.
  • •You must not use the Service to process special categories of personal data under Article 9 GDPR, or data relating to criminal convictions under Article 10. The Service is not designed for them and this DPA does not contemplate them.

4. Processing on Documented Instructions

We process Customer Personal Data only on your documented instructions, including on transfers to a third country, unless required otherwise by law to which we are subject — in which case we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest. The Terms and Conditions, this DPA, and your use of the Service's features constitute your complete documented instructions. If we consider an instruction to infringe Data Protection Law, we will inform you.

5. Confidentiality

We ensure that the people authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to provide or support the Service. Access to production systems is role-restricted and requires authentication as described in Annex II.

6. Security

We implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as required by Article 32 GDPR. We may update those measures over time provided the level of protection is not reduced. Annex II describes the measures in force as of the date of this DPA.

7. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex III. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance of those obligations.

  • •We maintain the current list at supdesk.app/subprocessors. That page is the authoritative list.
  • •We will give you at least 30 days' notice before adding or replacing a sub-processor, by publishing the change and announcing it through our changelog. You can subscribe there to be notified. A provider that has been announced but has not yet reached its effective date is listed separately, both there and in Annex III below, and receives no data until that date.
  • •You may object to a new sub-processor on reasonable data protection grounds within that notice period by contacting us. If we cannot offer a reasonable alternative, you may terminate the affected part of the Service and receive a prorated refund of prepaid fees for the unused remainder of your term.
  • •Annex III(b) lists destinations that receive data only because you switch on an optional integration. Those are your instruction, not our sub-processors, and data sent to them is governed by your agreement with that service.

8. Assisting with Data Subject Rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights under Chapter III GDPR. Much of this is self-service, so you can usually respond without involving us.

  • •Access and portability: you can export your data, including End-User records and content, from your account settings. End-Users can export their own data from the portal settings of the project they contacted.
  • •Erasure: you can delete individual End-Users, projects, or your entire account from the console. End-Users can delete their own record from the portal settings.
  • •Rectification and restriction: End-User records and the content attached to them can be edited or removed from the console.
  • •If an End-User contacts us directly about data we process on your behalf, we will not respond substantively other than to direct them to you, and we will inform you without undue delay.

9. Personal Data Breaches and Impact Assessments

We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event in time to allow you to meet your own notification obligations under Articles 33 and 34 GDPR. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We also provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the information available to us. Our incident response process and timelines are published at supdesk.app/security.

10. Return and Deletion

At your choice, we delete or return all Customer Personal Data at the end of the provision of the Service, and delete existing copies, unless law requires us to retain it. Deleting your account from account settings cancels any paid subscription and permanently deletes the workspaces you own and the content in them. Export your data before you delete, because deletion is not reversible. Data held in routine backups is deleted on the ordinary backup rotation of our infrastructure providers.

11. Audits and Information

We make available to you the information necessary to demonstrate compliance with Article 28, and we allow for and contribute to audits conducted by you or an auditor you mandate. Because we are a small team, that obligation is discharged through documentation first — which is faster for you and does not take the Service offline.

  • •On written request, we will answer reasonable questions about our processing and provide the documentation we maintain, including the technical and organisational measures in Annex II and our published security documentation. We will respond within 30 days.
  • •If that documentation does not resolve your question, an on-site inspection may be requested where a supervisory authority requires one, or following a confirmed personal data breach affecting your data.
  • •An on-site inspection is limited to once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonable disruption to the Service.
  • •Any auditor must be independent, must not be a competitor of ours, and must be bound by confidentiality obligations at least as protective as those in this DPA before any access is granted.
  • •No audit may extend to the personal data, systems, or configuration of our other customers, or to information whose disclosure would compromise the security of the Service.
  • •You bear your own costs, and our reasonable costs where an audit requires effort beyond providing existing documentation.

12. International Transfers

We are established in the United States and our sub-processors operate there, so Customer Personal Data is transferred outside the EEA, the UK, and Switzerland.

  • •Where personal data subject to the GDPR is transferred to us, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA and apply, completed by the information in Annexes I, II, and III.
  • •For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 applies to those Clauses.
  • •For transfers subject to the Swiss FADP, references in those Clauses to the GDPR are read as references to the FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
  • •Onward transfers to sub-processors are made under transfer mechanisms with equivalent effect.

13. California

Where you are a "business" and we are a "service provider" as those terms are defined in the California Consumer Privacy Act as amended by the CPRA, we process personal information only to perform the Service and for the business purposes set out in the Terms and Conditions. We do not sell or share personal information as those terms are defined in the CCPA, we do not retain, use, or disclose it for any purpose other than performing the Service, and we do not combine it with personal information received from other sources except as the CCPA permits a service provider to do. We certify that we understand and will comply with these restrictions.

14. Term, Precedence, and Governing Language

  • •This DPA takes effect when you accept the Terms and Conditions and continues for as long as we process Customer Personal Data on your behalf.
  • •Where the Standard Contractual Clauses conflict with this DPA, the Clauses prevail. Where this DPA conflicts with the Terms and Conditions, this DPA prevails in respect of Customer Personal Data.
  • •Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms and Conditions, except where Data Protection Law does not permit that.
  • •We may update this DPA to reflect changes in Data Protection Law or in the Service. We will post the updated DPA with a revised "Last updated" date and, where the change is material, record your acceptance of the new version.
  • •This DPA is provided in English. If it is translated, the English version governs.

Annex I — Description of the Processing

This annex completes Annex I to the Standard Contractual Clauses. The data exporter is the Customer, acting as controller; the data importer is Rabin Apps, LLC, acting as processor. Contact details for both are the ones held in the Customer's account and support@rabinapps.com respectively.

Article 28(3) description of the processing
ItemDescription
Subject matterProvision of the SupDesk customer support and product feedback platform.
DurationFor as long as the Customer's account is active. Content the Customer creates is retained for the life of the account; other categories are deleted automatically on the published schedule (audit records 365 days, consent records 730 days, rate limiting records 90 days, payment provider event records 365 days, short-lived tokens 1 day).
Nature and purposeCollecting, storing, organising, retrieving, transmitting, and deleting personal data in order to operate feedback boards, changelogs, customer portals, email messaging, live chat, a help center, satisfaction surveys and analytics, AI-assisted triage and reply suggestions, integrations, a public REST API, an MCP server, and mobile applications.
Categories of data subjectsThe Customer's End-Users — people who submit feedback, vote, comment, start a chat, contact support, subscribe to a changelog, join a beta programme, or register on a waitlist. Also the Customer's own team members who hold console access.
Types of personal dataEmail address; name; the Customer's own identifier for an End-User; the content of feedback posts, votes, comments, private messages, live chat conversations, help center articles, changelog entries, and canned responses; satisfaction survey ratings and free-text comments; beta programme feedback; waitlist registrations and referral relationships; file attachments; and, for team members, authentication and profile data received from the identity provider used to sign in.
Special categoriesNone. The Service is not designed to process special categories of personal data and the Customer must not submit them.
Frequency of transferContinuous, for the duration of the Agreement.
Competent supervisory authorityThe supervisory authority of the Customer's place of establishment in the EEA, or of its EU representative where it is not established in the EEA.

Annex II — Technical and Organisational Measures

The measures below are in force as of the date of this DPA and complete Annex II to the Standard Contractual Clauses. Certifications held by our infrastructure providers are theirs, not ours; SupDesk does not currently hold SOC 2 Type II or ISO 27001, which remain on our roadmap.

  • •Encryption in transit: all data is transmitted over TLS 1.2 or higher, and HTTP traffic is redirected to HTTPS.
  • •Encryption at rest: database storage and file attachments are encrypted at rest by our infrastructure providers, which use AES-256.
  • •Application-level encryption: credentials entrusted to us — customer-supplied AI provider keys, Slack tokens, and webhook secrets — are encrypted with AES-GCM before storage, using keys held in a managed secrets store.
  • •Tenant isolation: each project's data is isolated at the database level by row-level security. The REST API and MCP server run with elevated database access and enforce the same project scoping in the application layer.
  • •Access control: role-based access control (Owner, Admin, Member) across all projects and workspaces; API keys are project-scoped, stored only as a hash, and revocable at any time.
  • •Authentication: managed by our identity provider, with two-factor authentication (TOTP) available on every account and re-verification required for sensitive actions. We never store or have access to user passwords.
  • •Pseudonymisation: IP addresses used for rate limiting and abuse prevention are stored only as a truncated, irreversible hash; raw IP addresses are not retained.
  • •Network and application protection: DDoS protection, a web application firewall, bot detection, a Content Security Policy with a per-request nonce, server-side request forgery protection on customer-supplied URLs, and signature verification on inbound webhooks.
  • •Resilience: automated database backups with point-in-time recovery, provided by our database infrastructure provider.
  • •Deletion: a scheduled nightly process enforces the published retention periods; account deletion removes the workspaces owned by the account and their contents.
  • •Incident response: a documented process aligned to Article 33, with containment targeted within 24 hours, internal assessment within 48 hours, and regulatory notification within 72 hours.
  • •Vulnerability management: a published responsible disclosure process at security@rabinapps.com, with acknowledgement within 48 hours, initial assessment within 7 days, and a 30-day target for patching confirmed vulnerabilities.

Annex III — Sub-processors

The sub-processors we engage to provide the Service, as authorised under section 7. The current list is published at supdesk.app/subprocessors.

Authorised sub-processors
Sub-processorPurposeLocation
SupabaseDatabase, authentication, and file storage.United States
CloudflareHosting, CDN, attachment storage, bot protection, live chat infrastructure, and AI inference.United States and global edge network
StripePayment processing and subscription billing.United States
ResendTransactional and changelog email delivery, including the subscriber lists used for changelog broadcasts.United States
GoogleWebsite analytics through Google Tag Manager, loaded only with the visitor's consent.United States
OneSignalPush notification delivery for the mobile apps.United States
SentryCrash and error diagnostics for the mobile apps.United States
ExpoMobile app builds and over-the-air updates.United States

Annex III(b) — Destinations You Enable

These receive Customer Personal Data only when you switch on the corresponding integration or issue an API key. They act on your instruction rather than as our sub-processors, and what they do with the data is governed by your agreement with them, not by this DPA.

Optional destinations enabled by the Customer
DestinationWhat is sentLocation
SlackNotifications to a connected workspace, including the end-user's email address and an excerpt of their message.United States
GitHubCopying the title and body of a feedback post into a GitHub issue.United States
Outbound webhooksEvent payloads delivered to a URL the project specifies; a copy of each delivery is retained so it can be inspected and retried.Determined by the customer
OpenAI, Anthropic, or GoogleAI processing when a project supplies its own provider API key, under that project's own agreement with the provider.United States