Legal

Data Processing Agreement

Template effective: July 1, 2026

How to use this agreement

This Data Processing Agreement ("DPA") is required under Article 28 of the GDPR whenever Feedforward processes personal data on your institution's behalf. Fill in the fields marked in [brackets], sign two copies (one for each party), and email the signed copy to hello@feedforward.guru. This DPA forms part of, and is governed by, the Feedforward Terms of Service.

Parties

Data Controller

[Institution full legal name]

Address: [Address]

Country: [Country]

Contact: [DPO or privacy contact email]

Data Processor

Feedforward

Operated from: Spain, European Union

Contact: hello@feedforward.guru

Effective date of this DPA: [DD/MM/YYYY]

1. Definitions

"Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR (Regulation (EU) 2016/679). "PDPA" means Thailand's Personal Data Protection Act B.E. 2562 (2019). "Services" means the Feedforward platform as described in the Terms of Service.

2. Subject matter and details of processing

  • Nature and purpose: Processing of personal data to deliver the Feedforward anonymous feedback platform: authentication, submission storage, upvote recording, AI digest generation, and administrator tooling.
  • Duration: For the term of the Controller's subscription, plus the deletion window specified in Clause 9.
  • Categories of data subjects: Students, parents/guardians, administrators, and teaching staff of the Controller's institution.
  • Types of personal data: Email addresses; pseudonymous submission content; one-way HMAC vote hashes (non-reversible); server log metadata (IP address, timestamps).

3. Processor obligations (GDPR Art. 28(3))

Feedforward shall:

  • (a) Process Personal Data only on documented instructions from the Controller, including with regard to transfers outside the EEA, unless required by Union or Member State law; in such cases Feedforward will inform the Controller unless prohibited by law.
  • (b) Ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • (c) Implement the technical and organisational security measures described in Clause 6.
  • (d) Respect the conditions for engaging sub-processors set out in Clause 5.
  • (e) Assist the Controller in responding to Data Subject rights requests, taking into account the nature of the processing and the anonymisation design of the platform.
  • (f) Assist the Controller in fulfilling its obligations under Articles 32–36 GDPR (security, breach notification, DPIA, prior consultation).
  • (g) At the choice of the Controller, delete or return all Personal Data upon termination and delete existing copies, subject to Clause 9 and any legal retention obligation.
  • (h) Make available all information necessary to demonstrate compliance with this Clause and allow for and contribute to audits as described in Clause 7.

4. Controller obligations

The Controller warrants that it:

  • Has a valid legal basis for processing Personal Data under the GDPR and, where applicable, the PDPA.
  • Has obtained any required parental or guardian consents for minors below the applicable age of digital consent (14 in Spain; as required under applicable law in the Controller's jurisdiction).
  • Has provided Data Subjects with a privacy notice meeting applicable legal requirements before granting them access to the platform.
  • Will inform Feedforward promptly if it believes any instruction given to Feedforward infringes the GDPR or other applicable data protection law.

5. Sub-processors

The Controller grants general authorisation for Feedforward to engage the sub-processors listed below. Feedforward will notify the Controller at least 14 days before adding or replacing a sub-processor. If the Controller objects on reasonable data protection grounds, it may terminate the Services with 30 days' written notice.

Sub-processorPurposeLocation
Supabase Inc.Database hosting and storageEuropean Union (EU West)
Vercel Inc.Application hosting and CDNGlobal (primary: United States)
Resend Inc.Transactional email deliveryUnited States
Anthropic PBCAI-generated digest summariesUnited States

Feedforward imposes data protection obligations on all sub-processors equivalent to those in this DPA. Feedforward remains liable to the Controller for the acts and omissions of its sub-processors.

6. Security measures

Feedforward implements the following measures appropriate to the risk:

  • TLS encryption for all data in transit.
  • Encrypted storage at rest via the hosting provider.
  • Deny-all Row Level Security on all database tables; no direct browser database access.
  • HMAC-based one-way anonymisation of voter identities.
  • HttpOnly, signed session cookies; no client-side credential storage.
  • Access to production systems limited to authorised personnel on a need-to-know basis.
  • Regular dependency and security updates.

7. Audit rights

Feedforward will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA upon written request, with reasonable notice and no more than once per calendar year. The Controller may conduct an audit (or appoint an independent auditor bound by confidentiality) at its own cost, subject to at least 30 days' prior written notice and agreement on scope to avoid disruption to the service.

8. International data transfers

Where Personal Data is transferred outside the EEA or Thailand to sub-processors located in third countries (see Clause 5), Feedforward relies on Standard Contractual Clauses (EU Commission Decision 2021/914) or equivalent mechanisms. For transfers subject to Thai PDPA Chapter 7, Feedforward will implement adequate protection standards as required and agreed with the Controller.

9. Return and deletion

Upon expiry or termination of the Services, Feedforward will, at the Controller's election (communicated within 30 days of termination): (a) securely delete all Personal Data within 90 days, or (b) return a data export in a machine-readable format within 30 days and then delete. Feedforward may retain Personal Data for longer only where required by applicable law, and will notify the Controller of any such obligation.

10. Personal data breaches

Feedforward will notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any Personal Data breach affecting data processed under this DPA, providing sufficient information for the Controller to meet its own notification obligations under the GDPR (Art. 33–34) and/or Thai PDPA (Section 37).

11. Liability and indemnity

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability for a breach that results in a regulatory fine imposed on the other party, or for any liability that cannot be excluded by law.

12. Governing law

This DPA is governed by the laws of Spain. For Controllers based in Thailand, mandatory provisions of Thai law (including the PDPA) apply concurrently to the extent required. Disputes shall be resolved as set out in the Terms of Service.

Signatures

On behalf of the Controller

Authorised signatory name

Title

Signature

Date

On behalf of Feedforward (Processor)

Authorised signatory name

Title

Signature

Date

Ready to sign?

Print this page, complete the bracketed fields, sign, and email both copies to hello@feedforward.guru. We'll countersign and return a copy within 5 business days.