1. Parties and Scope
This Data Processing Agreement forms part of the agreement between the customer, acting as data controller, and sarvaFeed, Inc., acting as data processor. It applies whenever sarvaFeed processes personal data on the customer's behalf in the course of providing the Service. Where the customer processes personal data of individuals in the EU/EEA or the UK, this DPA governs that processing.
2. Nature and Purpose of Processing
sarvaFeed processes personal data only to provide and support the Service: hosting feedback boards, storing votes and comments, sending notifications, and generating analytics for the customer. Processing continues for the duration of the agreement and any wind-down period. We process personal data solely on documented instructions from the customer, including with regard to international transfers, unless required otherwise by law.
3. Categories of Data and Data Subjects
The personal data processed typically includes names, email addresses, account identifiers, IP addresses, and the content users submit to feedback boards. Data subjects include the customer's end users, community members, and the customer's own team members who administer the workspace. sarvaFeed does not intentionally process special categories of personal data and asks customers not to submit them through the Service.
4. Subprocessors
The customer authorizes sarvaFeed to engage subprocessors to deliver the Service. Current subprocessors provide cloud hosting infrastructure, transactional email delivery, and product analytics. Each subprocessor is bound by written terms offering data protection no less protective than this DPA. We maintain a current list of subprocessors and will give reasonable notice before adding or replacing one, so the customer may object.
5. International Transfers
Where personal data is transferred out of the EU/EEA or the UK to a country without an adequacy decision, sarvaFeed relies on the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where applicable. We apply supplementary technical and organizational measures where a transfer risk assessment indicates they are needed.
6. Security Measures
sarvaFeed implements appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, network isolation, logging, and regular security reviews. Access to production data is limited to personnel who need it to operate the Service and is subject to authentication and audit.
7. Deletion and Return
On termination of the agreement, sarvaFeed will delete or return the customer's personal data at the customer's choice, and delete existing copies unless retention is required by law. Customers may also export or delete personal data at any time through the Service. Absent a specific instruction, personal data is deleted or anonymized within 30 days of account closure.
8. Audits and Assistance
sarvaFeed makes available the information necessary to demonstrate compliance with this DPA and allows for audits, including inspections, conducted by the customer or an appointed auditor, on reasonable notice and subject to confidentiality. We also assist the customer, taking into account the nature of processing, with data subject requests and with data protection impact assessments and breach notifications.
9. Contact
Questions about this DPA or requests to execute a signed copy can be sent to privacy@sarvafeed.com, or in writing to sarvaFeed, Inc., 548 Market St, Suite 36879, San Francisco, CA 94104.
