Trust

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Michal Kurowski, trading as BugBundler ("BugBundler", "Processor"), and the customer entering into a subscription agreement with BugBundler ("Customer", "Controller"), and reflects the parties' agreement with respect to the processing of personal data under Article 28 of the EU General Data Protection Regulation (GDPR). Registered business (organisation) number is available on request and will be included in the signed copy.

1. Scope and roles

The Customer is the Controller of personal data submitted to BugBundler as part of account administration (workspace members' names, email addresses, and roles) and billing. BugBundler acts as Processor with respect to that data. Bug report content (screenshots, DOM snapshots, console and network logs) is captured and stored on the Customer's own devices. BugBundler does not host, store or retain report content.

Where the Customer has enabled the Jira integration and a reporter chooses to send an individual report to Jira, that report is transmitted over TLS through BugBundler's infrastructure in the EU (Finland) solely in order to deliver it to the Customer's own Jira site. BugBundler processes that content only for the duration of the request: it is held in memory, is not written to any database, file store or log, and is not retained after the request completes. BugBundler acts as Processor in respect of that transmission, and this DPA applies to it.

The Customer's Jira provider is the Customer's own processor under the Customer's separate agreement with that provider, and is not a sub-processor of BugBundler.

Any other sharing of an exported report is done directly by the Customer through its own channels (e.g. email, chat, or an issue tracker), and BugBundler is not involved in it.

2. Processing details

  • Subject matter: provision of the BugBundler service, including account authentication, workspace administration, and subscription billing.
  • Duration: for the term of the Customer's subscription, plus any period required by applicable law (e.g. tax and accounting retention).
  • Nature and purpose: storage and processing of account, workspace, and billing metadata to operate the Service.
  • Categories of data: name, business email address, company name, role/permissions, and subscription or invoice records. Payment card numbers are processed directly by Stripe and are not received or stored by BugBundler.
  • Categories of data subjects: Customer's employees, contractors, and other authorized workspace users.

3. Sub-processors

The Customer provides general authorization for BugBundler to engage the following sub-processors, each bound by written agreements imposing data protection obligations consistent with this DPA:

  • Google Cloud / Firebase (Google Ireland Ltd.) — hosting, authentication, and database infrastructure, located in Finland and Sweden (EU). Where the Jira integration is used, report content also transits this sub-processor's infrastructure in Finland for the duration of the request. It is not stored there.
  • Stripe, Inc. — payment processing and billing.
  • Resend — transactional email delivery.

BugBundler will provide at least 30 days' notice before adding or replacing a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds. An up-to-date list is maintained on the Privacy page.

4. International transfers

BugBundler's primary infrastructure (Cloud Functions and Firestore) is located in the EU (Finland and Sweden). Where a sub-processor is located outside the EEA or processes data outside the EEA (currently: Stripe and Resend), such transfers are governed by the European Commission's Standard Contractual Clauses or another valid transfer mechanism recognized under GDPR Chapter V.

5. Security measures

BugBundler implements encryption in transit (TLS) and at rest (via Google Cloud's platform-level encryption), access controls limiting employee access to production data on a need-to-know basis, and does not embed analytics or session-replay SDKs that collect personal data within the extension. See Security for further detail.

6. Data subject requests and breach notification

BugBundler will assist the Customer in responding to data subject access, rectification, erasure, and portability requests, and will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data.

7. Execution

To countersign this DPA for your organization, or to request a version with your entity details completed, contact legal@bugbundler.com.

Execution

Request a signed copy

Tell us the legal entity name and the signatory, and we will send a copy for signature. The text above is the agreement as it stands.