Data Processing Agreement

Last updated: March 24, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between FeedBoards ("Processor") and the customer ("Controller") and applies where FeedBoards processes personal data on behalf of the Controller.

1. Definitions

"Personal Data", "Processing", "Data Subject", "Controller", "Processor" have the meanings given in GDPR (Regulation (EU) 2016/679).

2. Scope and Purpose

FeedBoards processes personal data submitted by the Controller (via spreadsheet uploads and connected data sources) solely to provide the dashboard generation service described in the Terms of Service.

3. Controller Obligations

The Controller warrants that:

  • It has a lawful basis for providing personal data to FeedBoards
  • It has provided required notices to data subjects
  • The data shared is limited to what is necessary for the Service

4. Processor Obligations

FeedBoards agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure authorized personnel are subject to confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in fulfilling data subject rights requests
  • Delete or return all personal data upon termination
  • Provide all information necessary to demonstrate compliance

5. Sub-processors

FeedBoards uses sub-processors listed in the Privacy Policy (Section 4). We will notify Controllers of any new sub-processors with 14 days' notice. Controllers may object within 14 days of notification.

6. Security

FeedBoards implements the security measures described in Section 7 of the Privacy Policy.

7. Data Breach

FeedBoards will notify the Controller without undue delay (and within 72 hours maximum) of becoming aware of a personal data breach affecting Controller's data.

8. Data Subject Rights

FeedBoards will assist the Controller in responding to data subject requests within the timeframes required by applicable law.

9. Deletion

Upon termination of the Service or written request, FeedBoards will delete all Controller personal data within 30 days, except where retention is required by law.

10. Governing Law

This DPA is governed by the laws applicable to the main Terms of Service agreement.

To request a signed DPA, email hello@feedboards.com with subject "DPA Request".