Privacy Policy
withfeedback.com is operated by APPLIKU DOO NOVI SAD. Last updated 21 August 2026.
This policy explains what APPLIKU DOO NOVI SAD does with personal data in withfeedback.com. It names every third party that data reaches, and gives real retention periods rather than “as long as necessary”.
1. Two kinds of people, two different roles
This distinction decides who is responsible for what, so it comes first.
- Our customers — the people who hold an account. For their account data we are the controller.
- Our customers' customers — the people who leave a testimonial or feedback. For that data our customer is the controller and we are their processor: we hold it and act on their instructions. If you left a testimonial and want it removed, the fastest route is the business you left it for, though you may also write to us at support@withfeedback.com and we will pass it on or act where we can.
2. What we collect
From account holders
- Email address, name, and password (stored only as a salted hash).
- Team, project and configuration data you create.
- Billing identifiers from Paddle — enough to match a subscription to an account. We never receive or store card numbers.
- Usage counters for plan limits, and audit records of moderation actions (who approved or rejected what, and when).
From people leaving feedback
- What they chose to submit: their text, rating or survey answers, and optionally a name, job title, company, email address, and a video or image.
- A record of consent to public display, if given — including the wording shown, the version of it, the time, a truncated IP address and the browser user agent. This exists so that consent can be evidenced and withdrawn.
- Anti-abuse signals: a truncated IP address and timing data, used to block automated submissions.
Automatically
- Server logs, retained for operations and security.
- Counts of widget impressions. These are aggregate counts; we do not build a profile of visitors to your site, and the widget sets no advertising or tracking cookies.
3. Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing the Service to an account holder | Performance of a contract |
| Handling feedback and testimonials on a customer's behalf | Our customer's basis, on their instructions, as their processor |
| Publicly displaying a testimonial | The consent of the person who gave it |
| Billing, accounting and tax records | Legal obligation |
| Security, abuse prevention and rate limiting | Legitimate interests — keeping shared infrastructure usable |
| Service email such as confirmations and password resets | Performance of a contract |
4. Who else sees it
We do not sell personal data and we do not share it for advertising. Data reaches the following processors, and no others:
| Processor | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Server infrastructure and DNS for the application and its database. |
| DigitalOcean, LLC | Frankfurt, Germany (EU) — region fra1 | Object storage and CDN for uploaded images, video and the widget script. |
| Amazon Web Services, Inc. | Frankfurt, Germany (EU) — region eu-central-1 | Transactional email delivery (Amazon SES). |
| Paddle.com Market Limited | United Kingdom | Merchant of record: subscription checkout, invoicing and tax handling. Card details are entered on Paddle's systems and never reach ours. |
| Google Ireland Limited | Ireland (EU), with transfers to the United States | reCAPTCHA bot protection on account forms, and Google sign-in where a user chooses it. |
| OpenRouter, Inc. | United States | Optional AI-assisted moderation of submitted testimonials, per project. Routed with zero-retention providers only, and submitted text is redacted of email addresses and URLs before it is sent. |
| Functional Software, Inc. (Sentry) | United States | Application error monitoring. Enabled only when a DSN is configured. |
We may also disclose data where the law compels it. Where we can lawfully tell you first, we will.
5. Where it is stored
The application, its database, uploaded files and outbound email all run in Germany. Three processors involve transfers outside the EEA — Paddle (United Kingdom, covered by an adequacy decision), and OpenRouter and Sentry (United States, under Standard Contractual Clauses). Google's reCAPTCHA and sign-in may also transfer data to the United States.
AI-assisted moderation is off unless a customer turns it on for a project. When it is on, the submitted text is stripped of email addresses and URLs before it is sent, and it is routed only to providers that do not retain it for training.
6. How long we keep it
| Data | Retention |
|---|---|
| IP addresses and user agents attached to a submission or a consent record | Truncated on capture (IPv4 to /24, IPv6 to /48) and purged after 90 days. |
| Original uploaded video files, after the testimonial is published | 30 days. The published, transcoded version is kept while the testimonial is displayed. |
| Uploads that were started but never completed | Reserved uploads expire after 30 minutes; uploads not attached to a submitted testimonial are deleted after 24 hours. |
| Video files whose processing failed | 7 days, then deleted with the original. |
| Testimonials, feedback and contact records | For as long as the customer's account holds them. Deleting a testimonial erases its text and answers, anonymises the contact if no other record refers to it, and deletes the associated video, its derivatives and its CDN copies. |
| Consent records | Retained for as long as the testimonial they authorise is displayed, and after withdrawal as evidence that consent was given and then withdrawn. |
Backups, billing records and security logs may persist beyond these periods where the law requires it or a dispute is live.
7. Your rights
Under the GDPR and comparable laws you may request access to your data, its correction, its deletion, a portable export, restriction of processing, or object to processing based on legitimate interests. You may also withdraw consent at any time — for a published testimonial, the withdrawal link in the email you received removes it from public display immediately.
Write to support@withfeedback.com. We respond within one month. Account holders can also export and delete data directly in the application without asking us. If you are unhappy with our response you may complain to your local data protection authority.
8. Security
- Everything travels over HTTPS.
- Passwords are stored only as salted hashes. API tokens are stored only as hashes and shown once at creation.
- Webhook signing secrets are encrypted at rest.
- Uploaded video stays on private storage and is unreachable publicly until the owning testimonial is approved. Rejection or consent withdrawal removes the public copy and purges it from the CDN.
- Every project's data is isolated by tenant, and that isolation is covered by automated tests rather than convention.
No system is perfectly secure. If you find a vulnerability, please tell us at support@withfeedback.com before disclosing it publicly.
9. Cookies
We set cookies to keep you signed in and to protect forms against cross-site request forgery. We set no advertising cookies. The embeddable widget sets no cookies on your visitors at all.
10. Children
The Service is not directed at children and accounts are not knowingly created for anyone under 16. If you believe a child's data reached us, write to support@withfeedback.com and we will delete it.
11. Changes
We will update this page when our processing changes, including when the processor list above changes. For material changes we notify account holders before they take effect. The date at the top shows when it last changed.
Contact
Questions about this document, or any request relating to your data, go to support@withfeedback.com.
APPLIKU DOO NOVI SAD