Draft, not yet in force. Some details on this page are still being finalised.
Data Processing Addendum
Version 1.0 · Effective TBD — launch date
This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Terms") between TBD — fill before launch (legal name as registered) ("we", "Processor") and the customer that accepted the Terms ("you", "Controller"). It applies when we process personal data on your behalf while providing TidyKB. You accept it by accepting the Terms. If you need a signed copy, email privacy@tidykb.net.
Contents
- Definitions
- Roles and scope
- Your instructions
- Confidentiality
- Security
- Subprocessors
- International transfers
- Helping you with requests and obligations
- Personal data breaches
- Deletion and return
- Audits and information
- US state privacy laws
- Liability, term and precedence
- Annex I: details of processing
- Annex II: security measures
- Annex III: subprocessors
1. Definitions
"Data Protection Law" means all laws on personal data that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Law of Ukraine "On Personal Data Protection", and US state privacy laws such as the California Consumer Privacy Act ("CCPA"). "Customer Personal Data" means personal data in Customer Data (as defined in the Terms) that we process on your behalf. "Controller", "processor", "data subject", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR. "Service provider" and "business" have the meanings given in the CCPA.
2. Roles and scope
2.1 You are the controller (or a processor acting for your own controller) and we are your processor (or sub-processor) for Customer Personal Data.
2.2 We are an independent controller for account, billing, support and usage data about you and your users, as described in our Privacy Policy; this DPA does not apply to that data.
2.3 Annex I describes the subject matter, duration, nature and purpose of the processing and the types of personal data and data subjects.
2.4 You are responsible for the lawfulness of the Customer Personal Data you give us or instruct us to collect, including having a legal basis, giving privacy notices and obtaining any consents required from data subjects.
3. Your instructions
3.1 We process Customer Personal Data only on your documented instructions. The Terms, this DPA, and your configuration and use of the product are your complete instructions. Other instructions must be agreed in writing (email is fine).
3.2 We will tell you if we believe an instruction breaks Data Protection Law, unless the law prohibits it.
3.3 If the law requires us to process Customer Personal Data other than on your instructions, we will tell you first, unless the law prohibits that.
3.4 We don't sell Customer Personal Data, don't use it for our own purposes (including advertising or training AI models), and don't combine it with data from other sources, except as needed to provide the service or as Data Protection Law permits a processor to do.
4. Confidentiality
Only the founder, and any staff or contractors we may add who need access to provide the service, can access Customer Personal Data. Everyone with access is bound by a duty of confidentiality.
5. Security
We implement the technical and organisational measures in Annex II, appropriate to the risk. We may update them as long as the overall level of protection does not decrease.
6. Subprocessors
6.1 You give general authorisation for us to use the subprocessors listed in Annex III.
6.2 We will notify you of any new or replacement subprocessor at least 14 days before it starts processing Customer Personal Data, by email to account owners and by updating the Subprocessors page (you can subscribe to updates there).
6.3 You may object on reasonable data-protection grounds within that period. We will then try to find a solution. If we can't, you may terminate the affected service and we will refund prepaid fees for the unused period.
6.4 We impose data-protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible to you for their performance.
7. International transfers
7.1 We host Customer Personal Data in the EU (Germany). Some subprocessors process data outside the EU, UK or Switzerland, as shown in Annex III.
7.2 Where Customer Personal Data subject to the GDPR, UK GDPR or Swiss law is transferred to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply: Module 2 (controller to processor) where you are a controller, and Module 3 (processor to processor) where you are a processor. For the SCCs: clause 7 (docking) applies; in clause 9 option 2 (general authorisation, 14 days' notice) applies; the optional wording in clause 11 does not apply; in clauses 17 and 18 the law and courts of Ireland apply; Annexes I–III of this DPA complete the SCC annexes; and the competent supervisory authority is determined under clause 13.
7.3 For UK transfers, the UK International Data Transfer Addendum (version B1.0) issued by the ICO applies alongside the SCCs, with the tables completed by the information in this DPA and "neither party" selected in table 4. For Swiss transfers, the SCCs apply with the adaptations required by the Swiss FDPIC.
7.4 The founder accesses Customer Personal Data remotely from Ukraine to operate and support the service. The mechanisms in 7.2 and 7.3 cover this access.
8. Helping you with requests and obligations
8.1 If we receive a request from a data subject about Customer Personal Data, we will pass it to you within 5 business days and not respond ourselves except to redirect them to you, unless you ask us to.
8.2 Taking into account the nature of the processing, we will help you respond to data subject requests (mainly through the product's export and delete features), and with data protection impact assessments, prior consultations and security obligations, as far as that concerns our processing.
8.3 We may charge reasonable costs for help that goes beyond what the product's features and ordinary support provide.
9. Personal data breaches
9.1 We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
9.2 The notice will describe, as far as we know at the time: what happened, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and what we have done or propose to do. We will send more information as it becomes available.
9.3 Notifying you is not an admission of fault.
10. Deletion and return
10.1 You can export Customer Personal Data through the product at any time while your account is active and for 30 days after it ends.
10.2 After that, we delete Customer Personal Data within 30 days, and from backups as they expire (within 14 days), unless the law requires us to keep it. Product-specific retention is described in Annex I.
10.3 On request we will confirm deletion in writing.
11. Audits and information
11.1 We will make available the information reasonably needed to show compliance with this DPA, mainly this DPA, our Security page and written answers to your reasonable security questionnaires (once a year).
11.2 If that information is not enough to meet a requirement of Data Protection Law or a supervisory authority, you may audit our compliance, with at least 30 days' notice, no more than once a year, during business hours, at your cost, through an auditor bound by confidentiality who is not our competitor. The audit must not give access to other customers' data or compromise security.
11.3 An audit covers our own systems and practices. We have no physical premises of our own and cannot admit anyone to our hosting provider's data centre; for physical security, that provider's ISO 27001 certification is the evidence we can offer.
12. US state privacy laws
Where the CCPA or a similar US state law applies, we act as your service provider (or processor) and: (a) process Customer Personal Data only for the business purposes in the Terms and Annex I; (b) do not sell or share it, or retain, use or disclose it outside our direct business relationship with you or for any other commercial purpose; (c) do not combine it with personal information we receive from others, except as the law allows; (d) comply with the applicable law and provide the same level of privacy protection it requires; (e) notify you if we can no longer meet our obligations; and (f) allow you to take reasonable steps to stop and remediate unauthorised use. We certify that we understand these restrictions.
13. Liability, term and precedence
13.1 Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law or the SCCs do not allow this.
13.2 This DPA lasts as long as we process Customer Personal Data for you.
13.3 If this DPA conflicts with the Terms, this DPA prevails for personal data. If it conflicts with the SCCs, the SCCs prevail.
13.4 We may update this DPA to reflect changes in law or in our services, with 30 days' notice for changes that reduce your protection; such changes don't apply without your agreement where the law requires it.
Annex I: details of processing
Parties. Data exporter: the customer, as identified in its account (contact: account owner email). Role: controller (or processor). Data importer: TBD — fill before launch (legal name as registered), TBD — fill before launch (registered address), TBD — fill before launch, privacy@tidykb.net. Role: processor. Activities: providing TidyKB under the Terms.
Categories of data subjects
- The customer's Freshdesk agents and authors whose names, IDs or contact details appear in knowledge-base content or metadata.
- Any other people whose personal data the customer has included in its knowledge-base articles (for example staff named in articles, or people visible in screenshots).
- The customer's users of TidyKB, where their data appears in activity logs attached to Customer Data.
Categories of personal data
- Names, agent IDs and business contact details in article metadata or content.
- Any other personal data the customer chooses to include in knowledge-base articles, including images referenced by URL.
- Records of who applied which change and when (activity log).
Special categories of data
None intended. The customer agrees not to include special categories of data in its knowledge base content processed by TidyKB (Terms, section 9).
Frequency of processing
Continuous while a Freshdesk account is connected (scheduled scans weekly, or daily on some plans, and on demand).
Nature and purpose of processing
Fetching knowledge-base content from the customer's Freshdesk account through its API, using a read-only key the customer provides; storing a working copy; analysing it for broken links, stale content, duplicates and translation drift; preparing changes and, on the customer's explicit confirmation and with a second key the customer adds for the purpose, writing them back to Freshdesk; keeping before/after snapshots for undo; generating translation drafts with an AI subprocessor; and emailing reports to the customer's users. Requests to Freshdesk are limited to knowledge-base (Solutions) endpoints by an allowlist enforced in code, which contains no delete operation.
Duration and retention
For the term of the Terms. Working copies of content are deleted 30 days after the customer disconnects Freshdesk, immediately if the customer uses "Delete my data", and in any case within 30 days after the account ends; backups expire within 14 days. Undo snapshots, and the change records they belong to, are kept for 90 days from the last change to that record. Both API keys are deleted immediately on disconnect, in one operation. A daily job enforces every window.
Subprocessor processing
As listed in Annex III: hosting, database and backups (Hetzner), AI translation (Anthropic, article text and glossary only), transactional email (Resend), the bot check on the free audit (Cloudflare Turnstile), and our support mailbox and its forwarding (Google, Porkbun), only for what the customer sends us.
Annex II: security measures
- Encryption: TLS 1.2+ for all traffic; secrets and third-party credentials encrypted inside the database with a key held outside it, using public-key encryption so that the web tier can store a credential but cannot read one back. Backups are written with owner-only permissions; we do not add full-disk encryption on top of the hosting provider's storage.
- Access control: production access limited to the founder; SSH keys only (no passwords); separate deploy key for automated deployments; two-factor authentication on all admin accounts (hosting, DNS, code, email, payments); least-privilege credentials for each service.
- Tenant isolation: every database query is scoped to the customer's organisation; automated tests check this.
- Minimisation: we request the narrowest permissions a connected system offers and fetch only the data a feature needs.
- Logging and monitoring: error reports are kept on our own server for 30 days and server logs for 14 days, scrubbed of request bodies, cookies, query strings and authorisation headers; uptime monitoring and alerts; access to production is logged.
- Resilience: nightly database dumps kept for 14 days, beside the hosting provider's own automatic server backups, in the same data centre; restores tested with a scripted drill.
- Secure development: code review of changes, dependency updates, automated tests in CI, separate staging and production environments with no production personal data in staging.
- Incident response: documented steps to contain, assess and notify (section 9).
- Physical security: provided by Hetzner's ISO 27001-certified data centres in Germany.
- Deletion: automated retention jobs as described in Annex I.
Annex III: subprocessors
The current list is on our Subprocessors page, which forms part of this DPA.