Trust

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Michal Kurowski, trading as BugBundler ("BugBundler", "Processor"), and the customer entering into a subscription agreement with BugBundler ("Customer", "Controller"), and reflects the parties' agreement with respect to the processing of personal data under Article 28 of the EU General Data Protection Regulation (GDPR). Registered business (organisation) number is available on request and will be included in the signed copy.

1. Scope and roles

The Customer is the Controller of personal data submitted to BugBundler as part of account administration (workspace members' names, email addresses, and roles) and billing. BugBundler acts as Processor with respect to that data. Bug report content (screenshots, DOM snapshots, console and network logs) is captured and stored only on the Customer's own devices — BugBundler has no feature that transmits this content to BugBundler's infrastructure, so it falls outside the scope of this DPA entirely. Any sharing of an exported report is done directly by the Customer through its own channels (e.g. email, chat, or an issue tracker).

2. Processing details

  • Subject matter: provision of the BugBundler service, including account authentication, workspace administration, and subscription billing.
  • Duration: for the term of the Customer's subscription, plus any period required by applicable law (e.g. tax and accounting retention).
  • Nature and purpose: storage and processing of account, workspace, and billing metadata to operate the Service.
  • Categories of data: name, business email address, company name, role/permissions, and subscription or invoice records. Payment card numbers are processed directly by Stripe and are not received or stored by BugBundler.
  • Categories of data subjects: Customer's employees, contractors, and other authorized workspace users.

3. Sub-processors

The Customer provides general authorization for BugBundler to engage the following sub-processors, each bound by written agreements imposing data protection obligations consistent with this DPA:

  • Google Cloud / Firebase (Google Ireland Ltd.) — hosting, authentication, and database infrastructure, located in Finland and Sweden (EU).
  • Stripe, Inc. — payment processing and billing.
  • Resend — transactional email delivery.

BugBundler will provide at least 30 days' notice before adding or replacing a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds. An up-to-date list is maintained on the Privacy page.

4. International transfers

BugBundler's primary infrastructure (Cloud Functions and Firestore) is located in the EU (Finland and Sweden). Where a sub-processor is located outside the EEA or processes data outside the EEA (currently: Stripe and Resend), such transfers are governed by the European Commission's Standard Contractual Clauses or another valid transfer mechanism recognized under GDPR Chapter V.

5. Security measures

BugBundler implements encryption in transit (TLS) and at rest (via Google Cloud's platform-level encryption), access controls limiting employee access to production data on a need-to-know basis, and does not embed analytics or session-replay SDKs that collect personal data within the extension. See Security for further detail.

6. Data subject requests and breach notification

BugBundler will assist the Customer in responding to data subject access, rectification, erasure, and portability requests, and will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data.

7. Execution

To countersign this DPA for your organization, or to request a version with your entity details completed, contact legal@bugbundler.com.