telltab
Features Pricing Docs Blog FR Sign in Free trial

Data Processing Agreement (DPA)

Annex to the Telltab contract, entered into pursuant to article 28 of the GDPR · Date: 23 September 2026

1. Purpose

This Data Processing Agreement ("DPA") supplements Telltab's Terms of Service entered into between the customer operating the site integrating the Telltab widget (the "Controller") and Reverdin Studio, operator of the Telltab service (the "Processor"). It sets out the respective obligations of the parties regarding the processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of the Telltab service, in accordance with article 28 of Regulation (EU) 2016/679 ("GDPR").

2. Nature and purpose of the processing

The Processor processes personal data on behalf of the Controller solely to provide the Telltab service: collection, storage, analysis and display of end-user feedback submitted via the widget embedded on the Controller's site.

3. Duration of the processing

Processing is carried out for the entire duration of the contract between the parties. Upon termination, the provisions of Section 12 ("Fate of data at the end of the contract") apply.

4. Categories of data subjects

End users of the Controller's site who have submitted feedback via the Telltab widget.

5. Categories of data processed

  • Text messages submitted by end users
  • End user's email address, when voluntarily provided in order to be contacted back or notified of a reply
  • URL of the page from which the feedback was submitted
  • Screenshots attached by the end user to their feedback ("Bug report" mode)
  • Voice recordings and their text transcription, when the end user uses voice feedback
  • Technical metadata (browser, viewport)

6. Documented instructions

The Processor only processes data on documented instructions from the Controller, as set out in the Terms of Service, this DPA, and the service configuration made by the Controller from its dashboard. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or any other data protection provision.

7. Confidentiality

The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8. Sub-processors

The Controller authorises the Processor to engage the following sub-processors, necessary for the provision of the service:

  • Hetzner Online GmbH (Germany) — hosting of the infrastructure and database.
  • Anthropic PBC (United States), called through the internal LiteLLM gateway — automatic sentiment analysis of text feedback.
  • Stripe Payments Europe Ltd (Ireland) — processing of the Controller's payments and billing.
  • Internal transcription service (self-hosted at Hetzner, EU) — transcription of voice recordings into text.

The Processor informs the Controller of any intended changes concerning the addition or replacement of a sub-processor, thereby giving the Controller the opportunity to object. The Processor imposes on each sub-processor data protection obligations equivalent to those set out in this DPA.

9. Security

The Processor implements the following technical and organisational measures:

  • Encryption of data in transit (TLS) and at rest
  • Isolation of data per customer (site) within the database
  • Regular encrypted backups
  • Access control restricted to authorised personnel and strong authentication for infrastructure access
  • Logging of access and sensitive operations
  • Regular updates of software components and vulnerability monitoring

10. Personal data breach notification

In the event of a personal data breach affecting data processed on behalf of the Controller, the Processor notifies the Controller within a maximum of 72 hours after becoming aware of it. This notification describes the nature of the breach, the categories and approximate number of data subjects and data records concerned, the likely consequences, and the measures taken or proposed to address it.

11. Assistance to the Controller

The Processor assists the Controller, insofar as possible, in fulfilling its obligations under the GDPR, in particular with regard to responding to requests to exercise data subject rights, data protection impact assessments (DPIA), and prior consultation of the competent supervisory authority.

12. Fate of data at the end of the contract

At the end of the contract, at the Controller's choice, the Processor deletes or returns all personal data processed on its behalf, and destroys existing copies, unless a legal obligation requires otherwise. The Controller has 30 days after termination to export its data from the dashboard before it is permanently deleted.

13. Audit

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and in article 28 of the GDPR, and allows for audits, including inspections, conducted by the Controller or an auditor mandated by it, subject to reasonable notice and on terms agreed between the parties so as not to disrupt the operation of the service.

14. Record of processing activities

The Processor maintains a record of the categories of processing activities carried out on behalf of the Controller, in accordance with article 30(2) of the GDPR.

15. Transfers outside the European Union

Data is hosted within the European Union. The use of Anthropic PBC (United States) as a sub-processor involves a transfer of data outside the EU, governed by standard contractual clauses adopted by the European Commission. The Controller may request a copy of the applicable safeguards by writing to hello@telltab.com.

16. Governing law

This DPA is governed by French law. Any dispute relating to its interpretation or performance shall be submitted to the competent courts of Paris.

DPA contact: hello@telltab.com

© 2026 Telltab · Terms · Privacy · DPA · Legal · Accessibility · Contact