Legal
Data Processing Addendum
Last updated July 24, 2026
This addendum forms part of the agreement between iterateTo and a customer who uses the service to process personal data on behalf of their end users.
Template. This document is a starting point, not legal advice. Review it with legal counsel and tailor it to your business before relying on it in production.
1. Roles of the parties
For personal data processed through iterateTo on behalf of the customer (“Customer Data”), the Customer is the data controller and iterateTo is the data processor. iterateTo processes Customer Data only on the Customer’s documented instructions, including those given through the dashboard and API, except where law requires otherwise.
2. Scope and nature of processing
Subject matter: provision of the iterateTo feedback service. Duration: for the term of the agreement plus the deletion period below. Nature and purpose: collecting, storing, organizing, displaying, and making available user feedback so the Customer can triage and act on it. Types of data: feedback text, optional contact emails, host-page context (origin and pathname, with query strings stripped), device/browser environment, optional client-masked screenshots, selected-element metadata, Customer-supplied identify metadata, and hashed IP addresses. Categories of data subjects:the Customer’s end users and site visitors who submit feedback.
3. Processor obligations
- process Customer Data only on documented instructions from the Customer;
- ensure personnel authorized to process Customer Data are bound by confidentiality;
- implement the technical and organizational measures described in Section 5;
- assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting their security, breach-notification, and impact-assessment obligations;
- make available the information reasonably necessary to demonstrate compliance with this addendum.
4. Sub-processing
The Customer authorizes iterateTo to engage the subprocessors listed on our Subprocessors page. iterateTo imposes data-protection obligations on each subprocessor no less protective than those in this addendum and remains responsible for their performance. We will give notice of intended changes to subprocessors so the Customer has the opportunity to object.
5. Security measures
iterateTo maintains technical and organizational measures appropriate to the risk, including encryption of data in transit, access controls scoped to each Customer’s organization, hashed (never raw) IP storage, and a client-side screenshot-masking model in which redactions are applied in the reporter’s browser before any pixels are transmitted. Full detail is on our Security page, which is incorporated here by reference.
6. International transfers
Where processing involves transferring personal data across borders, the parties will rely on an appropriate transfer mechanism. Where the Standard Contractual Clauses (SCCs) approved by the European Commission apply, they are incorporated into this addendum by reference and completed with the details in Sections 1, 2, and 4, with iterateTo acting as data importer.
7. Data-subject requests
iterateTo provides self-service tools so the Customer can fulfil data-subject requests directly: feedback export (CSV/JSON) and erasure-by-subject from project settings and the REST API (see the Privacy Policy). If iterateTo receives a request directly from a data subject, it will, where permitted, refer that person to the relevant Customer.
8. Deletion and return
On the Customer’s instruction — including configuring a retention window, erasing a subject, deleting a feedback item, or deleting a project — iterateTo deletes the corresponding Customer Data and its screenshots. On termination of the agreement, iterateTo will delete or return remaining Customer Data within a reasonable period, except where retention is required by law.
9. Audit
iterateTo will make available information reasonably necessary to demonstrate compliance with this addendum and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, during business hours, and subject to confidentiality.
10. Personal data breach
iterateTo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Customer meet its own notification obligations.
11. Contact
To sign a countersigned copy of this addendum or to reach our data protection contact, email dpo@iterateto.example.