Data processing addendum
This page summarises the data-processing addendum that applies whenever your workspace stores personal data in Dubinga. It is written to be checked against Article 28 GDPR line by line; email the privacy address below for a countersigned copy.
Roles
For workspace content and the data retrieved from your connected platforms, your organization is the controller and Dubinga is the processor. For your own account, billing and support records, Dubinga is the controller — the privacy policy covers that side.
Documented instructions only
We process workspace and platform data only on your documented instructions — the ones you give by using the product, connecting platforms and approving proposals — and never for our own purposes. Everyone with access to that data is bound by confidentiality.
Security measures
Encryption in transit and encryption at rest for stored secrets, tenant isolation enforced by forced PostgreSQL row-level security inside the database itself, least-privilege database roles, and an approval audit trail that cannot be edited afterwards.
Subprocessors
We engage only the subprocessors on the published list, each bound by a contract carrying equivalent data-protection obligations. Workspace owners are notified before we add or replace one, with time to object.
Assistance with data-subject requests
Taking into account the nature of the processing, we assist you in answering data-subject requests — access, export, correction, deletion and restriction — within the timelines the law gives you.
Breach notification
We notify you of a personal-data breach affecting your workspace without undue delay after becoming aware of it, with what we know at that point: the scope, the likely consequences, and the measures taken.
Deletion and return at termination
When the agreement ends, we delete or return workspace content and platform data at your choice, and delete the remaining copies — backups rotate out within at most 30 days. Statutory retention duties survive where the law requires.
Audit information
On request we provide the information reasonably necessary to demonstrate these commitments, including summaries of the security measures and of subprocessor contracts.
International transfers
Where processing moves personal data outside your region, it relies on the European Commission's standard contractual clauses or an equivalent lawful mechanism, as the privacy policy describes.
Getting a signed copy
This page is a faithful summary, not a substitute for the signature. Email the privacy address below for a countersigned copy of the full addendum for your records.
Contact
- Privacy and data-subject requests:
- privacy@dubinga.com
- Everything else:
- hello@dubinga.com
We answer data-subject requests within one month.
This page is written to be read, not to be survived. If anything here is ambiguous, ask us and we will fix the wording.