GDPR & Data Processing Agreement
withfeedback.com is operated by APPLIKU DOO NOVI SAD. Last updated 21 August 2026.
This Data Processing Agreement (“DPA”) applies where you use withfeedback.com to process personal data of your own customers, and forms part of the Terms of Service. It takes effect automatically when you create an account — you do not need to ask us to sign a copy, though we will sign one if your procurement process requires it. Write to support@withfeedback.com.
In this DPA, you are the controller and APPLIKU DOO NOVI SAD is the processor. Terms such as personal data, processing, data subject and supervisory authority carry their GDPR meanings.
1. Subject matter and duration
We process personal data only to provide withfeedback.com: collecting feedback and testimonials, moderating them, storing and transcoding media, and displaying the items you approve. Processing lasts for as long as your account is open, plus the retention periods set out in the Privacy Policy.
2. Nature of the data
| Categories of data subject | Categories of personal data |
|---|---|
| Your customers and prospects who submit feedback or a testimonial; recipients of survey invitations; contacts you import | Name, email address, job title, company, the content they submitted, ratings and survey answers, video and images of them, records of consent, truncated IP address and user agent |
| Your team members | Name, email address, role, and audit records of moderation actions |
withfeedback.com is not intended for special-category data under Article 9, nor for children's data. Do not use it to collect either. If a testimonial happens to reveal such data because of what a person chose to write, we process it only as part of that testimonial.
3. Our obligations
- We process personal data only on your documented instructions, which include your use of the application's features and its API. If we believe an instruction breaches data protection law, we will tell you.
- We will not use your customers' personal data for our own purposes, and will never use it to train machine-learning models.
- Our personnel are bound by confidentiality, and access is limited to those who need it to run and support the Service.
- We assist you, so far as is reasonable, with data protection impact assessments and with enquiries from a supervisory authority.
4. Sub-processors
You give general authorisation for the sub-processors listed in the Privacy Policy, which names each one, its location and its purpose. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain responsible for their performance.
We will update that list before a new sub-processor begins processing. If you have a reasonable objection on data protection grounds, tell us at support@withfeedback.com; if we cannot resolve it, you may terminate the affected part of the Service and receive a pro-rata refund of fees paid for the unused remainder of the period.
5. Security measures
Our technical and organisational measures under Article 32 include:
- encryption in transit for all traffic, and encryption at rest for webhook signing secrets;
- passwords and API tokens stored only as hashes, with tokens displayed once at creation;
- tenant isolation on every data path, enforced by automated tests including deliberate cross-tenant attempts;
- role-based access control within a team, with an audit record of every moderation action;
- uploaded video held on private storage and unreachable publicly until the owning testimonial is approved, with public copies deleted and purged from the CDN on rejection or withdrawal of consent;
- rate limiting, per-project caps and abuse blocklists;
- least-privilege credentials for infrastructure, scoped to the specific resource and action they need.
6. Assisting with data subject rights
The application lets you handle most requests yourself, without contacting us: export a contact's data, delete or anonymise it, and withdraw consent so a testimonial stops being displayed. Where a request needs us, we will help, and we will not respond directly to your data subject except to direct them to you — unless the law requires otherwise.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information we hold at the time about what happened, which categories of data are affected, the likely consequences and the steps we are taking. We will follow up as we learn more. Notifying your supervisory authority and data subjects is your decision as controller.
8. International transfers
The application, its database, uploaded files and outbound email run in Germany. Transfers outside the EEA occur only to the sub-processors identified in the Privacy Policy, under an adequacy decision or Standard Contractual Clauses as applicable.
9. Audits
On reasonable written request, and no more than once a year unless a breach or a regulator requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this DPA. We may satisfy this with written responses and documentation rather than granting access to infrastructure shared with other customers.
10. Deletion and return
You may export your data at any time while your account is open. On termination we delete personal data in accordance with the retention periods in the Privacy Policy, except where the law requires us to keep it. Backups age out on their own cycle.
11. Precedence and liability
Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Each party's liability under this DPA is subject to the limitations in the Terms of Service, and this DPA is governed by the law of the Republic of Serbia.
Contact
Questions about this document, or any request relating to your data, go to support@withfeedback.com.
APPLIKU DOO NOVI SAD