1. Purpose and incorporation
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (“Customer,” “Controller”) and Gatherly (“Processor,” “we,” “us”). It applies when Gatherly processes personal data on your behalf in connection with the Service.
By creating a Gatherly account or using the Service, you agree to this DPA. If you need a signed copy, email support@gatherly.sh.
This DPA implements Article 28 of the GDPR and equivalent rules under UK GDPR. It does not apply to Gatherly’s processing of your own account, billing, and website data as a controller, which is described in our Privacy Policy.
2. Definitions
“Customer Data” means personal data submitted to the Service by or for you, including end-user feedback, messages, attachments, identity claims (for example from a customer-signed identity JWT), and related metadata.
“GDPR” means Regulation (EU) 2016/679 and, where applicable, the UK GDPR. Terms such as “controller,” “processor,” “personal data,” “processing,” and “personal data breach” have the meanings given in the GDPR.
“Subprocessor” means a third party engaged by Gatherly to process Customer Data in order to provide the Service.
3. Roles
You are the controller of Customer Data. Gatherly is the processor. You determine the purposes and essential means of processing Customer Data (including what you collect through the widget and which identity claims you send). Gatherly processes Customer Data only to provide, secure, and support the Service, and as otherwise described in this DPA and the Terms.
You warrant that you have a lawful basis to collect and instruct us to process Customer Data, including providing required notices to end users.
4. Customer instructions
You instruct Gatherly to process Customer Data as needed to provide the Service, including hosting the widget and APIs, storing and displaying feedback in your inbox, applying the settings you configure (such as attachment retention), supporting your team members, and providing customer support when you ask us to look at your workspace.
Gatherly will not process Customer Data except on your documented instructions (including this DPA, the Terms, and actions you take in the dashboard) unless required to do so by EU or member-state law, in which case we will inform you unless the law prohibits that notice.
We will notify you if, in our opinion, an instruction infringes the GDPR.
5. Details of processing
- Subject matter: hosting and processing Customer Data so you can collect and manage end-user feedback through Gatherly.
- Duration: for the term of your account, plus the limited backup period described in the Privacy Policy after deletion.
- Nature and purpose: collection, storage, retrieval, display, organization, transmission, and deletion of Customer Data to operate the widget, inbox, chats, and related features.
- Types of personal data: as submitted by you or your end users, which may include names, email addresses, user identifiers, messages, screenshots or other attachments, page URLs, device or browser information, IP addresses, and any other data you choose to include in identity JWTs or free-text fields.
- Categories of data subjects: your end users, visitors, and other people who interact with the widget on properties you control, and your team members who access the inbox.
You must not instruct Gatherly to process special-category data under GDPR Article 9, payment card numbers, or health records unless we have agreed in writing.
6. Processor obligations
Gatherly will:
- Ensure persons authorized to process Customer Data are bound by confidentiality
- Implement appropriate technical and organizational measures as described in Section 9
- Engage subprocessors only as described in Section 7
- Assist you with data-subject requests, security, breach notification, and data-protection impact assessments, taking into account the nature of processing and information available to us
- Delete or return Customer Data at the end of the Service as described in Section 12
- Make available information reasonably necessary to demonstrate compliance with this DPA
7. Subprocessors
You authorize Gatherly to use the following subprocessors to process Customer Data as needed to provide the Service:
- Supabase — authentication, database, and file storage on servers in the EU (Ireland)
- Vercel — application hosting and edge delivery
- Resend — transactional email, if a message includes Customer Data
- Sentry — application error monitoring; error reports may include request metadata or snippets of Customer Data
Stripe, Google, and GitHub may process your account or sign-in data as described in the Privacy Policy. They are not subprocessors of Customer Data under this DPA unless they receive it as part of a feature you enable.
We will impose data-protection terms on subprocessors that are no less protective than this DPA. We remain responsible for their processing of Customer Data. If we add or replace a subprocessor that processes Customer Data, we will update this page. You may object on reasonable data-protection grounds by emailing support@gatherly.sh within 14 days. If we cannot reasonably accommodate the objection, you may stop using the affected Service or close your account.
8. International transfers
Gatherly is operated from Denmark. Customer Data in Supabase (database, files, and auth) is stored on servers in Ireland (EU). Other subprocessors may process Customer Data in the EU, the United Kingdom, the United States, or other countries where they operate.
Where a transfer of Customer Data outside the EEA, UK, or Switzerland requires a safeguard, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), or another lawful transfer mechanism.
9. Security
Taking into account the state of the art, costs, and the nature of Customer Data, Gatherly implements measures designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These include:
- Encryption in transit (HTTPS)
- Access controls and authentication for the dashboard
- Secret management for project keys
- Isolation of customer workspaces in the application data model
- Operational backups
You are responsible for protecting account credentials, project secret keys, and the integrity of identity JWTs you mint.
10. Personal data breaches
If Gatherly becomes aware of a personal data breach affecting Customer Data, we will notify you without undue delay and provide information reasonably available to us to help you meet your own notification duties. We will take reasonable steps to contain and remediate the breach.
11. Assistance
Taking into account the nature of processing, Gatherly will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling requests from data subjects to exercise their rights. End users should generally contact you; we will assist you where a request is made to us or you cannot fulfill it from the dashboard.
We will also assist you, on request and considering the information available to us, with data-protection impact assessments and consultations with supervisory authorities that relate to the Service.
12. Return and deletion
You can view and delete Customer Data from the dashboard while your account is active (including by deleting individual items or a project). There is no bulk export button yet; email support@gatherly.sh if you need a copy. When you delete a project or your account, we delete associated Customer Data from production systems, except that residual copies may remain in backups for a limited period, and we may retain data where EU or Danish law requires it. The Transparency page describes the deletion steps in the product.
Bug-report attachments follow the retention period you set on the project (30 days by default).
13. Audits
Upon written request, Gatherly will provide information reasonably necessary to demonstrate compliance with this DPA, such as this document, the Privacy Policy, and a description of our security measures.
If that information is not sufficient, you may request an audit, no more than once per 12 months except after a personal data breach or where a supervisory authority requires it. Audits are at your cost, limited to processing of your Customer Data, subject to confidentiality, and scheduled on reasonable notice so they do not unreasonably disrupt our operations. We may require the audit to be performed by an independent auditor bound by confidentiality.
14. Liability
Each party’s liability under this DPA is subject to the limitations in the Terms, except that those limitations do not exclude liability that cannot be limited under applicable data-protection law.
15. Term and changes
This DPA lasts for as long as Gatherly processes Customer Data for you. We may update this DPA as described in the Terms. Material changes will be posted on this page with an updated effective date.
16. Contact
Questions about this DPA: support@gatherly.sh
If you are in Denmark, the supervisory authority is Datatilsynet. You and your end users may also contact the authority in the country where you or they live or work.