1. Definitions
For the purposes of this DPA:
- "Controller" means the customer who determines the purposes and means of processing personal data collected through the WhiskrKit SDK.
- "Processor" means WhiskrKit, which processes personal data on behalf of the Controller.
- "Data Subject" means the end user of the Controller's application whose personal data is processed through the WhiskrKit SDK.
- "Personal Data" has the meaning given in Article 4(1) GDPR.
- "Processing" has the meaning given in Article 4(2) GDPR.
- "Sub-processor" means any third party engaged by WhiskrKit to process personal data in connection with the Service.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed under this DPA.
2. Subject matter and duration
WhiskrKit processes personal data on behalf of the Controller for the purpose of delivering in-app surveys and feedback prompts to the Controller's end users, and providing the Controller with access to aggregated response analytics through the WhiskrKit dashboard.
Processing takes place for the duration of the Controller's active subscription to the Service, and ceases upon termination in accordance with section 9 of this DPA.
3. Nature and purpose of processing
WhiskrKit processes personal data solely to:
- Determine survey eligibility for individual end users based on targeting rules configured by the Controller
- Deliver surveys to eligible end users within the Controller's application
- Record and store survey responses on behalf of the Controller
- Provide the Controller with analytics and filtering of survey responses through the dashboard
- Enforce repeat policies to prevent over-surveying of individual end users
WhiskrKit does not use personal data processed under this DPA for its own purposes, including advertising or profiling. WhiskrKit may use aggregated, de-identified statistics that cannot be linked back to any individual data subject for internal purposes such as service performance monitoring and product improvement.
4. Categories of personal data and data subjects
Data subjects
End users of the Controller's iOS, Android, or web application who are presented with a WhiskrKit survey.
Categories of personal data
The following categories of personal data are processed on behalf of the Controller:
- Per-app, per-install device identifier: on iOS, Apple's IDFV (Identifier for Vendor); on Android and other platforms, an equivalent install-scoped identifier generated by the WhiskrKit SDK
- Device model: the device's hardware model in human-readable form (e.g. "iPhone 15 Pro") and identifier form (e.g. "iPhone15,2")
- Operating system name and version
- Application bundle ID
- Application version and build number
- WhiskrKit SDK version
- Language and region
- Timezone
- Survey responses, including structured responses (e.g. NPS scores, multiple choice selections) and open-text answers
- IP address, processed for rate limiting, security, and request logging purposes. IP addresses are processed in two ways: briefly in the rate-limiting system, with automatic expiry after 15 minutes; and in application logs, which are automatically rotated and capped in size, providing a bounded but variable retention period depending on traffic volume.
The Controller acknowledges that open-text survey responses may contain personal data entered freely by data subjects, including information such as email addresses or other identifying details. The Controller is responsible for ensuring that appropriate disclosures are made to data subjects regarding such data collection.
5. Obligations of the Controller
The Controller represents and warrants that:
- It has a valid lawful basis under the GDPR for collecting feedback from its end users through the WhiskrKit SDK, and where required by applicable law, has obtained valid consent from data subjects for the processing described in section 4.
- It has provided appropriate privacy disclosures to its end users, including disclosure of the use of WhiskrKit as a data processor.
- It will provide WhiskrKit with clear and documented instructions regarding the processing of personal data, and will not instruct WhiskrKit to process personal data in a manner that would violate applicable law.
- It will promptly notify WhiskrKit if it becomes aware of any inaccuracy in the instructions provided.
6. Obligations of the Processor
WhiskrKit agrees to:
6.1 Process only on documented instructions
Process personal data only on the documented instructions of the Controller, unless required to do so by applicable law. Where WhiskrKit is required by law to process personal data without the Controller's instruction, WhiskrKit will inform the Controller of that requirement before processing, unless prohibited by law.
6.2 Confidentiality
Ensure that all personnel authorised to process personal data under this DPA are subject to appropriate confidentiality obligations.
6.3 Security
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encrypted transmission of personal data between the SDK and WhiskrKit servers (TLS)
- Encryption of personal data at rest, using full-disk encryption (LUKS) on the volume storing all database and application data
- Hashed storage of API keys
- Access controls limiting access to personal data to authorised personnel only
- Automatic rotation and size-capping of application logs to limit retention of incidental data such as IP addresses
- Automated daily backups of the underlying infrastructure
- Regular review of security measures
6.4 Sub-processors
Not engage any new sub-processor without informing the Controller in advance and providing the Controller with the opportunity to object. Current sub-processors are listed in section 7 of this DPA. WhiskrKit will impose data protection obligations on sub-processors equivalent to those set out in this DPA, and remains liable to the Controller for the performance of sub-processors.
6.5 Assistance with data subject rights
Assist the Controller, by appropriate technical and organisational measures, in fulfilling its obligations to respond to requests from data subjects exercising their rights under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Given that the only end-user identifier held by WhiskrKit is the per-install device identifier, WhiskrKit can fulfil such requests to the extent that the Controller is able to supply the relevant device identifier. Upon receipt of a valid request accompanied by the relevant device identifier, WhiskrKit will make available or delete the associated data as appropriate.
6.6 Assistance with security and compliance obligations
Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including obligations relating to security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with supervisory authorities.
6.7 Security incident notification
Notify the Controller without undue delay, and where feasible within 48 hours, upon becoming aware of a Security Incident affecting personal data processed under this DPA. This timeline is intended to allow the Controller sufficient time to fulfil its own notification obligations to supervisory authorities under Article 33 GDPR. The notification will include, to the extent available:
- A description of the nature of the Security Incident
- The categories and approximate number of data subjects and records affected
- The likely consequences of the Security Incident
- Measures taken or proposed to address the Security Incident
6.8 Deletion or return of data
Upon termination of the Service, delete or return all personal data processed under this DPA at the choice of the Controller, and delete existing copies unless retention is required by applicable law. Data will be retained for no longer than 30 days following termination, after which it will be permanently deleted. The Controller may request an export of their data prior to deletion by contacting ue.tikrksihw@ycavirp .
6.9 Audit rights
Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA, and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, provided that:
- The Controller gives reasonable prior written notice of at least 30 days
- Audits are conducted during normal business hours and in a manner that minimises disruption
- Costs associated with audits are borne by the Controller
- No more than one audit is conducted per 12-month period, unless required by a supervisory authority
WhiskrKit may satisfy audit obligations by providing recent third-party audit reports or certifications (such as SOC 2 or ISO 27001) where available, in lieu of an on-site audit.
7. Sub-processors
WhiskrKit currently engages the following sub-processors in connection with the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting and data storage | Germany |
| Lettermint | Transactional email delivery | Netherlands |
| Soverin | Email hosting (inbound) | Netherlands |
| [Payment provider] | Billing and payment processing | [Location] |
WhiskrKit will inform the Controller of any intended changes to this sub-processor list by updating this DPA and notifying customers by email at least 14 days in advance. The Controller may object to the engagement of a new sub-processor by notifying WhiskrKit in writing within 14 days of receiving notice. If the Controller objects and WhiskrKit cannot accommodate the objection, either party may terminate the Service upon written notice.
WhiskrKit will notify Controllers of material changes to this DPA at least 30 days in advance by email.
8. International data transfers
All personal data processed under this DPA is stored on servers hosted by Hetzner in Germany. Where sub-processors outside the European Economic Area are engaged, WhiskrKit will ensure that appropriate safeguards are in place, including Standard Contractual Clauses as adopted by the European Commission.
9. Termination and deletion
Data retention and deletion upon termination is governed by section 6.8 of this DPA.
10. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service, except that nothing in the Terms of Service or this DPA limits either party's liability for damages arising from a breach of this DPA that results in harm to data subjects under Article 82 GDPR, or for damages arising from intent (opzet) or gross negligence (grove nalatigheid), or for any liability that cannot be excluded under mandatory Dutch law.
11. Governing law
This DPA is governed by Dutch law. Any disputes arising from or related to this DPA will be submitted to the competent court in the Netherlands.
12. Order of precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA takes precedence with respect to the processing of personal data.
Contact
For questions about this DPA or to exercise any rights under it, contact us at ue.tikrksihw@ycavirp .
WhiskrKitue.tikrksihw@ycavirp