Data Processing Agreement

Last updated on

This Data Processing Agreement (the "Agreement") forms part of the agreement governing the Customer's use of the Services (the "Principal Agreement") between the customer that has accepted the Principal Agreement (the "Company") and Craftful Technologies LLP, operating ProductBridge (the "Data Processor"), together the "Parties". It applies automatically to every Company. No signature is required. If you need a countersigned copy, or a version completed with your details for your records, email help@productbridge.io.

Whereas

  • The Company acts as a Data Controller in relation to Company Personal Data or, where applicable, acts as a Processor on behalf of another Data Controller.

  • The Company wishes to engage the Data Processor to provide certain Services that involve the Processing of Personal Data on behalf of the Company.

  • The Parties seek to implement a data processing agreement that complies with applicable Data Protection Laws, including Regulation (EU) 2016/679 (the "GDPR").

  • The Parties wish to lay down their respective rights and obligations in relation to the Processing of Company Personal Data.

1. Definitions and interpretation

1.1 Unless otherwise defined, capitalized terms in this Agreement have the following meanings:

  • "Agreement" means this Data Processing Agreement and all Schedules.

  • "Company Personal Data" means any Personal Data Processed by the Data Processor or a Subprocessor on behalf of the Company pursuant to or in connection with the Principal Agreement.

  • "Data Protection Laws" means the GDPR and, to the extent applicable to the Processing of Company Personal Data, all other binding data protection and privacy laws, regulations and regulatory requirements applicable to either Party, including the UK GDPR, the Swiss Federal Act on Data Protection and applicable US state privacy laws.

  • "EEA" means the European Economic Area.

  • "GDPR" means Regulation (EU) 2016/679, as amended, replaced or superseded from time to time.

  • "Principal Agreement" means the ProductBridge Terms and Conditions governing the Company's use of the Services, together with the Company's subscription or order and any other written agreement expressly applicable to the Company's use of the Services.

  • "Restricted Transfer" means a transfer of Company Personal Data to a country or recipient that requires an appropriate transfer safeguard under applicable Data Protection Laws.

  • "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914, as amended, replaced or superseded from time to time.

  • "Services" means the ProductBridge customer support, messenger, help center, survey, feedback collection, ingestion, management, organization, analysis, prioritization, collaboration, roadmap, changelog, portal, widget, integration, notification and related services provided under the Principal Agreement.

  • "Subprocessor" means any person or entity appointed by or on behalf of the Data Processor to Process Company Personal Data on behalf of the Company in connection with the Services.

1.2 The terms "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Processor" and "Supervisory Authority" have the meanings given to them in the GDPR, and their cognate terms shall be construed accordingly.

2. Processing of Company Personal Data

2.1 The Data Processor shall:

  • comply with the obligations of a Processor under applicable Data Protection Laws in relation to the Processing of Company Personal Data;

  • not Process Company Personal Data other than on the Company's documented instructions, including the Principal Agreement, this Agreement, the Company's use and configuration of the Services, and documented support requests, unless Processing is required by applicable law;

  • where applicable law requires Processing other than on the Company's instructions, inform the Company of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest; and

  • inform the Company if, in the Data Processor's reasonable opinion, an instruction infringes applicable Data Protection Laws, and may suspend the affected Processing until the Parties resolve the issue.

2.2 The Company instructs the Data Processor to Process Company Personal Data as necessary to provide, operate, secure, maintain and support the Services in accordance with the Principal Agreement and the Company's documented use and configuration of the Services.

2.3 The subject matter, duration, nature and purpose of the Processing, the categories of Company Personal Data and the categories of Data Subjects are described in Schedule 1.

2.4 The Company is responsible for the lawfulness of Company Personal Data, its Processing instructions, and the notices, legal bases, consents, permissions and rights necessary for the Company to provide Company Personal Data to the Data Processor and instruct the Processing described in this Agreement.

2.5 For clarity, this Agreement does not govern Personal Data for which the Data Processor determines the purposes and means of Processing as an independent Controller, including account administration, billing, direct business communications, fraud prevention, service security and legal compliance data. That Processing is described in the ProductBridge Privacy Policy.

2.6 The Data Processor shall not use Company Personal Data to train its own general-purpose or foundation AI models and shall use third-party AI services under configurations and contractual terms that do not permit Company Personal Data submitted through the Services to be used to train the providers' general-purpose models.

3. Processor personnel

3.1 The Data Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor who may have access to Company Personal Data, ensuring that access is strictly limited to individuals who need such access for the purposes of the Principal Agreement, support, security, maintenance or compliance with applicable law, and that all such individuals are subject to confidentiality obligations.

3.2 The Data Processor shall apply appropriate access controls and shall revoke or adjust access when it is no longer required for the relevant individual's duties.

3.3 Routine direct production access to Company Personal Data is restricted to the Data Processor's designated founder. Access involving the viewing of Company Personal Data for debugging or support shall occur only with the Company's prior written or electronic consent. This does not prevent access strictly necessary to contain or investigate a security incident, protect the integrity of the Services, or comply with applicable law; in such cases the Data Processor shall provide notice where legally and operationally feasible.

4. Security

4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Data Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.

4.2 In assessing the appropriate level of security, the Data Processor shall take account in particular of the risks presented by Processing, including accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Company Personal Data.

4.3 The technical and organizational measures applicable to the Services are described in Schedule 2 and, in more operational detail, at productbridge.io/security. The Data Processor may update those measures from time to time, provided that such updates do not materially decrease the overall level of protection for Company Personal Data during the applicable subscription term.

4.4 The Company is responsible for using available security and access-control features appropriately, managing its authorized users and credentials, configuring integrations, and securing systems and endpoints under the Company's control.

5. Subprocessing

5.1 The Company grants the Data Processor general written authorization to appoint Subprocessors for the Processing of Company Personal Data in accordance with this section 5.

5.2 The Data Processor maintains a current list of Subprocessors at productbridge.io/legal/subprocessors. The Subprocessors authorized as of the date of this Agreement are set out in Schedule 3.

5.3 The Data Processor shall provide at least fifteen (15) days' prior written notice of an intended addition or replacement of a Subprocessor that will Process Company Personal Data, unless a shorter period is reasonably necessary because of an emergency, security need or legal requirement. To receive these notices by email, write to help@productbridge.io with "subprocessor notices" in the subject line.

5.4 The Company may object to a new Subprocessor on reasonable and documented data protection grounds by notifying the Data Processor within the notice period. The Parties shall work in good faith to resolve the objection. If the objection cannot reasonably be resolved, the Parties shall consider a commercially reasonable alternative, which may include disabling the affected feature or terminating the affected Services in accordance with the Principal Agreement.

5.5 The Data Processor shall enter into a written agreement with each Subprocessor imposing data protection obligations that provide a level of protection for Company Personal Data no less protective in substance than the obligations applicable to the Data Processor under this Agreement, as required by applicable Data Protection Laws.

5.6 The Data Processor shall remain responsible to the Company for the performance of its Subprocessors' data protection obligations to the extent required by applicable Data Protection Laws.

5.7 Integrations that the Company connects itself, such as Intercom, Zendesk, Slack, Jira, Linear, ClickUp, GitHub, Salesforce or Discord, are not Subprocessors. Data is sent to those providers only on the Company's instruction when the integration is connected, and stops when it is disconnected.

6. Data Subject rights

6.1 Taking into account the nature of the Processing, the Data Processor shall assist the Company by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Company's obligations to respond to requests to exercise Data Subject rights under applicable Data Protection Laws. The Services include self-serve tools to export, correct and delete an individual's data.

6.2 The Data Processor shall promptly notify the Company if it receives a request from a Data Subject in respect of Company Personal Data, where the request can reasonably be identified as relating to the Company, and shall not respond to that request except on the documented instructions of the Company or as required by applicable law, in which case the Data Processor shall, to the extent legally permitted, inform the Company of that legal requirement before responding.

7. Personal Data Breach

7.1 The Data Processor shall notify the Company without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Company Personal Data and shall provide the Company with information reasonably available to the Data Processor to assist the Company in meeting any applicable obligations to notify a Supervisory Authority or affected Data Subjects.

7.2 To the extent reasonably available, the information shall include the nature of the Personal Data Breach, the categories and approximate number of affected Data Subjects and records, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information.

7.3 Where complete information is not available at the time of the initial notification, the Data Processor may provide the information in phases without undue further delay.

7.4 The Data Processor shall cooperate with the Company and take reasonable commercial steps to assist in the investigation, mitigation and remediation of a Personal Data Breach affecting Company Personal Data.

8. Data protection impact assessment and prior consultation

8.1 Taking into account the nature of the Processing and the information available to the Data Processor, the Data Processor shall provide reasonable assistance to the Company with data protection impact assessments and prior consultations with Supervisory Authorities or other competent data protection authorities that the Company reasonably considers necessary under Articles 35 or 36 of the GDPR, or equivalent provisions of other applicable Data Protection Laws, solely in relation to the Processing of Company Personal Data by the Data Processor and its Subprocessors.

8.2 Where assistance under this section requires material effort beyond functionality or support included in the Company's subscription and is not caused by the Data Processor's breach of this Agreement, the Parties may agree reasonable fees in advance.

9. Deletion or return of Company Personal Data

9.1 Upon cessation of Services involving the Processing of Company Personal Data, the Data Processor shall, at the choice of the Company, return Company Personal Data made available for export or delete Company Personal Data from active systems within fifteen (15) calendar days, unless applicable law requires continued storage.

9.2 Residual Company Personal Data in backups shall remain protected under this Agreement and shall be deleted or overwritten in accordance with the Data Processor's backup rotation process within fifteen (15) calendar days following deletion from active systems, unless applicable law requires longer storage.

9.3 Upon reasonable written request, the Data Processor shall provide written confirmation that the deletion or return required by this section has been completed, subject to any applicable legal retention requirement.

10. Audit rights

10.1 The Data Processor shall make available to the Company, on reasonable request, information necessary to demonstrate compliance with the Processor obligations applicable under this Agreement and applicable Data Protection Laws, including relevant summaries of policies, assessments, certifications or independent audit materials that are available and appropriate to share. The Data Processor will also complete the Company's security questionnaire on request.

10.2 Where the information provided under section 10.1 is insufficient to satisfy a legal audit requirement, the Company may conduct, or appoint an independent qualified auditor bound by confidentiality to conduct, a reasonable audit of the Data Processor's relevant Processing controls no more than once in any twelve-month period, unless a Personal Data Breach, a material compliance concern or a Supervisory Authority requires additional review.

10.3 Audits shall be conducted during normal business hours, with at least thirty (30) days' advance notice, in a manner that avoids unnecessary disruption and does not compromise confidentiality, security or the rights of other customers. The Company shall bear its audit costs unless the audit identifies a material breach of this Agreement by the Data Processor.

10.4 Audit materials and findings shall be treated as Confidential Information, except to the extent disclosure is required by applicable law or a Supervisory Authority.

11. Data transfers

11.1 The Data Processor shall not transfer or authorize a transfer of Company Personal Data in violation of applicable Data Protection Laws.

11.2 Where Company Personal Data is subject to a Restricted Transfer from the EEA, the United Kingdom or Switzerland, the Parties shall rely on a valid transfer mechanism under Chapter V of the GDPR or the equivalent provisions of the applicable law. Where the SCCs are applicable, the selections and annex information in Schedule 4 shall apply.

11.3 For Restricted Transfers from the Company as Controller to the Data Processor as Processor, Module Two (Controller to Processor) of the SCCs shall apply. If the Company acts as a Processor for particular Company Personal Data, the Parties shall use the SCC module appropriate to the actual roles, including Module Three where applicable. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum.

11.4 The Data Processor shall apply the transfer safeguards and supplementary measures described in this Agreement and Schedule 2 and shall reasonably cooperate with the Company, taking into account the information available to it, in connection with transfer impact assessments required by applicable Data Protection Laws.

11.5 Production systems are hosted in the EEA and backup copies are stored in the EEA. Any authorized remote access from outside the EEA is subject to the restrictions in section 3.3 and the transfer safeguards described in Schedule 4.

12. General terms

  • Confidentiality. Each Party shall keep confidential this Agreement and any non-public information it receives about the other Party and its business in connection with this Agreement ("Confidential Information") and shall not use or disclose that Confidential Information without the prior written consent of the other Party, except where disclosure is required by law or the information is lawfully in the public domain.

  • Notices. Notices under this Agreement shall be in writing. Notices to the Company may be sent to the email address of its account owner or to another contact notified in writing. Notices to the Data Processor may be sent to help@productbridge.io.

  • Order of precedence. In the event of a conflict concerning the Processing of Company Personal Data, the following order of precedence shall apply: (a) the SCCs or another mandatory transfer instrument, for the affected Restricted Transfer; (b) this Agreement; and (c) the Principal Agreement. The remainder of the Principal Agreement remains in effect.

  • Liability. Subject to mandatory Data Protection Laws and the SCCs where applicable, the liability of each Party arising from or related to this Agreement is subject to the exclusions and limitations of liability set out in the Principal Agreement. Nothing in this Agreement limits rights of Data Subjects or liability that cannot lawfully be limited.

  • Term and effective date. This Agreement becomes effective when the Company accepts the Principal Agreement, or on the date of the last signature where the Parties execute a signed copy, and continues for as long as the Data Processor Processes Company Personal Data on behalf of the Company.

  • Changes. The Data Processor may update this Agreement to reflect changes in Data Protection Laws or the Services. Material changes will be notified to the Company at least thirty (30) days before they take effect.

  • Electronic execution. Where the Parties execute a signed copy, this Agreement may be executed electronically and in counterparts, each of which is deemed an original and all of which together constitute one instrument.

Schedule 1: Details of processing

This Schedule describes the Processing covered by the Agreement. The Company's specific configuration, integrations, connected sources and documented instructions determine the actual scope of Processing within the categories below.

1. Subject matter

Provision of ProductBridge customer support, messenger, help center, survey, feedback collection, ingestion, management, organization, AI-assisted analysis, prioritization, collaboration, roadmap, changelog, portal, widget, integration, notification and related services.

2. Duration

For the duration of the Principal Agreement and thereafter only as necessary to complete return or deletion under section 9, maintain residual backup copies for the fifteen (15) day backup retention period, comply with law, or resolve security incidents or disputes.

3. Nature and purpose of Processing

3.1 The nature of Processing may include collection, receipt, transmission, ingestion, import, storage, hosting, organization, normalization, classification, tagging, linking, deduplication, AI-assisted analysis, summarization, theme and observation generation, search, retrieval, display, collaboration, prioritization, notification, export and deletion.

3.2 The purpose of Processing is to provide and operate the Services requested and configured by the Company, including resolving support conversations, centralizing feedback from Company-selected sources, identifying patterns and themes, producing feedback insights, managing feedback workflows, supporting prioritization, linking feedback to roadmap and changelog activity, and communicating product updates.

3.3 Where the Company enables AI-assisted features, relevant feedback text, conversation text, workspace content and limited related context necessary to provide the requested feature may be submitted to authorized AI service providers listed in Schedule 3. Company Personal Data is not used to train ProductBridge models or the providers' general-purpose models as described in section 2.6.

4. Categories of Data Subjects

  • Company employees, contractors, workspace members and authorized users;

  • the Company's end users and customers, including visitors who use the messenger, help center, surveys, feedback portal or in-app widget;

  • prospective customers or leads whose communications are imported by the Company;

  • feedback submitters, support requesters, review authors, survey respondents, portal contributors, commenters, voters and subscribers; and

  • other individuals whose Personal Data is included in Company-provided or integration-imported content.

5. Categories of Company Personal Data

  • identity and contact data, such as name, email address, username, profile image, role, company and other contact details;

  • customer and account identifiers, such as internal user IDs, account IDs, organization IDs, plan or segment information, custom attributes and identity claims supplied through secure identity mode, and integration identifiers;

  • feedback and communication content, such as requests, comments, messages, support conversations, issue descriptions, reviews, survey responses, votes, product requests, attachments or files where supported, and related text supplied by the Company;

  • product and workflow metadata, such as source, channel, timestamps, status, tags, categories, priority, sentiment or classification outputs, linked product areas, roadmap links and changelog subscriptions;

  • technical and integration metadata associated with Company workspace content, such as IP address, browser and device information, locale, event identifiers, message identifiers and source-system references; and

  • other Personal Data included by the Company or Data Subjects in free-text or connected-source content.

6. Special categories of Personal Data

6.1 The Services do not require the Company to submit special categories of Personal Data under Article 9 of the GDPR, criminal conviction data under Article 10 of the GDPR, or equivalent highly sensitive data. The Company shall avoid intentionally submitting such data unless necessary for a lawful use case and appropriate safeguards and instructions have been established.

6.2 Because feedback, support conversations, reviews, surveys and other free-text content may be unstructured, Company Personal Data may incidentally contain sensitive information not predictable by the Data Processor. Such data remains subject to the protections of this Agreement.

7. Frequency of Processing

Continuous or on-demand during the Company's use of the Services, depending on the Company's configuration and connected integrations.

8. Processing locations and access

8.1 Production infrastructure is hosted on Amazon Web Services (AWS) in the EEA. The PostgreSQL database and ProductBridge file storage operate on AWS infrastructure in Paris, and vector search operates in Frankfurt.

8.2 Backup copies are stored in the EEA and are retained for fifteen (15) calendar days in accordance with section 9.2.

8.3 Routine direct production access is limited to the designated founder, and any access involving the viewing of Company Personal Data for debugging or support is subject to section 3.3.

Schedule 2: Technical and organizational measures

The measures below describe the safeguards the Data Processor maintains for Company Personal Data. Specific implementation details may evolve with the Services, provided the overall level of protection is not materially decreased. The current operational detail is published at productbridge.io/security.

1. Governance and confidentiality

  • Access to Company Personal Data is restricted to authorized personnel with a need to know for service delivery, support, security, maintenance or legal obligations.

  • Authorized personnel are subject to confidentiality obligations or equivalent duties.

  • ProductBridge maintains internal responsibility for security and privacy operations appropriate to the size and nature of the Services.

2. Identity and access management

  • Logical access controls are used to restrict access to systems Processing Company Personal Data, and every administrative access to production is logged.

  • Routine direct production access is limited to the designated founder and is revoked or adjusted when no longer required.

  • Access involving the viewing of Company Personal Data for debugging or support requires the Company's prior written or electronic consent, subject to the limited exceptions in section 3.3.

  • Credentials and secrets are managed using controls designed to prevent unauthorized disclosure or use. Credentials for connected tools are encrypted inside the application.

  • The Company is provided account and workspace controls appropriate to the Services, including roles and, on request, SSO/SAML, and remains responsible for managing its authorized users.

3. Data transmission and storage security

  • Encryption in transit for public web and API communications involving Company Personal Data, using HTTPS with TLS 1.2 or higher.

  • Encryption at rest using AES-256.

  • Connections to third-party integrations use secure transport and authentication mechanisms supported by those services.

4. Infrastructure and environment security

  • Production infrastructure is operated in the EEA on AWS.

  • The PostgreSQL database and ProductBridge file storage operate on AWS infrastructure in Paris.

  • Backup copies are stored in the EEA and retained for fifteen (15) calendar days.

  • Network, host and cloud configuration controls are used to reduce unauthorized access to production systems.

  • Production and non-production environments are logically separated as appropriate to the architecture.

  • Security updates and patches are applied on a risk-based basis.

5. Application and tenant security

  • Application authorization controls are designed to restrict Company workspace data to authorized users and services.

  • Logical tenant or workspace separation controls are used for the multi-tenant SaaS architecture, and custom domains are isolated per Company.

  • Passwords are hashed and sessions use signed, HTTP-only, Secure cookies. Secure identity mode verifies end users with signed JWTs.

  • Development and deployment practices are designed to reduce the introduction of security vulnerabilities, with remediation handled on a risk-based basis. Vulnerability reports are acknowledged within three business days under a published safe-harbour policy.

6. AI processing safeguards

  • AI-assisted Processing is limited to the data and context reasonably necessary to provide the Company-requested feature.

  • Company Personal Data is not used by ProductBridge to train general-purpose or foundation models.

  • ProductBridge uses third-party AI services under configurations and contractual terms that do not permit Company Personal Data submitted through the Services to be used to train the providers' general-purpose models.

7. Logging, monitoring and incident response

  • The Data Processor uses application, infrastructure and operational monitoring appropriate to service reliability and security.

  • Monitoring services are configured so that the monitoring provider does not intentionally receive Company Personal Data or other PII from the ProductBridge application.

  • Relevant security events and suspected incidents are investigated and handled through an incident response process.

  • Confirmed Personal Data Breaches affecting Company Personal Data are handled in accordance with section 7 of the Agreement, with notice within 72 hours of awareness.

8. Availability, backup and recovery

  • Infrastructure and data management practices include daily automated backup, point-in-time recovery, resilience and restoration capabilities appropriate to the Services.

  • Backup access is restricted to authorized systems and personnel.

  • Backup copies are retained for fifteen (15) calendar days and are deleted or overwritten through the backup rotation process.

  • Recovery and restoration activities are performed as necessary for service continuity, disaster recovery or incident response.

9. Data minimization and lifecycle management

  • The Data Processor Processes Company Personal Data according to the Company's configuration and instructions and limits Processing to the purposes described in the Agreement and Principal Agreement.

  • Company Personal Data is deleted from active systems within fifteen (15) calendar days following cessation of the relevant Services, subject to the Company's choice of return and any legal retention requirement.

  • Residual backup copies are retained for no longer than the fifteen (15) day backup retention period described in section 9.2.

10. Subprocessor management

  • Subprocessors are evaluated for their role in Processing Company Personal Data and are bound by written data protection obligations as required by applicable Data Protection Laws.

  • The Data Processor remains responsible for Subprocessor performance to the extent required by applicable Data Protection Laws.

  • The current list is maintained at productbridge.io/legal/subprocessors, with fifteen (15) days' notice of additions or replacements.

11. Review and improvement

  • The Data Processor may update technical and organizational measures to respond to evolving technology, risk, service architecture or legal requirements, provided the overall protection of Company Personal Data is not materially decreased.

Schedule 3: Authorized Subprocessors

The following providers are authorized to Process Company Personal Data on behalf of the Data Processor in connection with the Services, as applicable to the Company's configuration. The current list, with change history, is maintained at productbridge.io/legal/subprocessors. Additions and replacements are managed in accordance with section 5 of the Agreement.

Provider

Service / purpose

Company Personal Data

Primary location / safeguards

Amazon Web Services (AWS)

Cloud hosting, compute, PostgreSQL database infrastructure, file and object storage

Customer workspace data and associated metadata as required by the Services

Production in Paris (EU); backups in Germany (EU)

Qdrant Cloud

Vector search used for duplicate detection and semantic search

Embeddings derived from feedback text

Frankfurt (EU)

Anthropic

AI-assisted analysis, classification, summarization and related ProductBridge AI features

Feedback text, workspace content and limited related context required for the requested AI feature

United States; SCCs and provider terms that prohibit training on submitted data

OpenAI

AI-assisted analysis, classification, summarization and the support agent

Feedback and conversation text and limited related context required for the requested AI feature

United States; SCCs and provider terms that prohibit training on submitted data

Voyage AI

Text embeddings for semantic search

Feedback text

United States; SCCs

Resend

Transactional email delivery and ProductBridge notifications

Recipient email address, recipient name where available, and notification content required for delivery

United States; SCCs

Brevo

Marketing contact sync for Customer administrators

Email addresses of Customer administrators

European Union

Cloudflare

DNS, CDN and custom domains

Traffic metadata

Global edge network; SCCs

Inngest

Background job orchestration

Job payloads, which may include references to workspace content

EU region; SCCs where applicable

Intercom

Customer support and support communication for ProductBridge's own helpdesk

Customer administrator contact details and support conversation content voluntarily provided through support interactions

United States; SCCs

Services or software components that do not Process Company Personal Data on behalf of the Data Processor are outside the scope of this Schedule. Self-hosted software components, including Better Auth and PostgreSQL, are not third-party Subprocessors. Monitoring services configured not to receive Company Personal Data or PII are likewise outside the scope of this Schedule.

Schedule 4: International transfer provisions

This Schedule applies only where a transfer of Company Personal Data requires an appropriate transfer mechanism under Chapter V of the GDPR or equivalent applicable law.

1. EU Standard Contractual Clauses

  • 1.1 For a Restricted Transfer subject to the GDPR, the unmodified standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (the "SCCs") are incorporated into and form part of this Agreement for the relevant transfer. This Schedule records the Parties' selections and completes the SCC Annex information.

  • 1.2 For transfers from the Company as Controller and data exporter to the Data Processor as Processor and data importer, Module Two (Controller to Processor) applies. Where the Company acts as a Processor, Module Three (Processor to Processor) applies.

  • 1.3 Clause 7 (Docking Clause) applies.

  • 1.4 For Clause 9, Option 2 (general written authorization) applies. The Data Processor shall provide at least fifteen (15) days' prior written notice of intended Subprocessor additions or replacements, subject to the emergency exception in section 5.3.

  • 1.5 The optional language in Clause 11 is not used unless the Parties expressly agree otherwise in writing.

  • 1.6 For Clause 17, Option 1 applies and the SCCs are governed by the law of the EU Member State in which the Company is established, or, where the Company is not established in an EU Member State, the law of an EU Member State agreed in writing between the Parties that allows for third-party beneficiary rights.

  • 1.7 For Clause 18, disputes arising from the SCCs shall be resolved by the competent courts of the Member State whose law governs under 1.6.

  • 1.8 For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner. For transfers subject to Swiss law, the SCCs apply with the adaptations required by the Federal Data Protection and Information Commissioner.

2. Completion of SCC Annexes

Annex I.A is completed by the Party details in the opening section of this Agreement and the Company's account details. Annex I.B is completed by Schedule 1 and section 3 of this Schedule. Annex I.C identifies the Supervisory Authority competent for the Company under Clause 13 of the SCCs. Annex II is completed by Schedule 2. Annex III is completed by Schedule 3.

3. Transfer details

  • Data exporter: the Company. Role: Controller, unless the Company is acting as a Processor for particular Company Personal Data.

  • Data importer: Craftful Technologies LLP, operating ProductBridge. Role: Processor.

  • Contact point for the data importer: help@productbridge.io.

  • Transfer frequency: continuous or on-demand during use of the Services, depending on the Company's configuration and connected sources.

  • Nature and purpose: as described in Schedule 1.

  • Retention: active Company Personal Data is deleted within fifteen (15) calendar days following cessation of the relevant Services, subject to the Company's choice of return and legal retention requirements. Residual backup copies are retained for no longer than the additional fifteen (15) day backup rotation period described in section 9.2.

  • Special category data: not required by the Services. Free-text content may incidentally contain sensitive data; the safeguards in Schedule 2 apply.

  • Onward transfers: to authorized Subprocessors under section 5 and Schedule 3, subject to applicable transfer requirements.

  • Storage and access: production infrastructure and backup copies are hosted in the EEA, and any authorized remote access from outside the EEA is restricted as described in section 3.3 and Schedule 2.

4. Hierarchy

If there is a conflict between this Agreement and the SCCs or another mandatory transfer instrument, the SCCs or mandatory transfer instrument shall control for the affected Restricted Transfer.

Contact

Questions about this Agreement, requests for a countersigned copy, and subprocessor-notice subscriptions: help@productbridge.io.

@ProductBridge - 2026 All rights reserved | Made with 🖤 in 🇺🇸 🇮🇳 🇩🇪

@ProductBridge - 2026 All rights reserved | Made with 🖤 in 🇺🇸 🇮🇳 🇩🇪

@ProductBridge - 2026 All rights reserved | Made with 🖤 in 🇺🇸 🇮🇳 🇩🇪

Shape Image
Shape Image