Feedmind
Legal

Data processing addendum

This addendum forms part of the terms of service and governs any personal data Feedmind processes on your behalf. It applies automatically. You do not need to request or sign a separate copy, though we will countersign one if your procurement process needs it.

1. Roles

For personal data contained in your store data, you are the controller and Feedmind is the processor. For account, billing and support data about your own staff, Feedmind is the controller and the privacy policy applies.

2. Subject matter, duration, nature and purpose

Subject matter: the provision of catalog scoring and content improvement services. Duration: for as long as your account exists, plus the deletion periods below. Nature and purpose: reading product content, deriving scores, generating proposed changes, and publishing changes you approve.

Categories of data subject: your staff who use the service, and any individuals identifiable from your product content, which in ordinary catalogs is rare. Categories of personal data: names and contact details of your users, and any personal data you have placed in product fields. Feedmind does not receive your customers' order or contact data.

3. Instructions

We process personal data only on your documented instructions, which are given by your use of the service and by this addendum. We will tell you if an instruction appears to infringe applicable data protection law. If we are required by EU or member state law to process for another purpose, we will inform you before doing so unless that law forbids it.

4. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations and are granted access only where their role requires it.

5. Security measures

We maintain technical and organisational measures appropriate to the risk, including: TLS 1.2 or higher in transit and AES-256 at rest; multi factor authentication on production access; least privilege access control with an audit log of administrative actions on customer accounts; segregation of customer data at the application layer; managed secret storage; encrypted backups held in the EU with restoration testing; and a documented incident response procedure.

6. Subprocessors

You give general authorisation for the subprocessors below. Each is bound by data protection terms no less protective than this addendum. We remain liable for their performance.

SubprocessorRoleDataRegion
SupabaseApplication database and authenticationAccount, catalog and score dataEU (Frankfurt)
Google CloudCompute and object storageCatalog content, scan artefactsEU (Belgium)
ScalewayBackground processing and queuesScan and fix job payloadsEU (Paris)
StripePayments and invoicingBilling contact, VAT ID, payment methodEU and US
AnthropicLanguage model for drafted contentProduct content sent for draftingEU and US
OpenAILanguage model for drafted contentProduct content sent for draftingEU and US
Google (Vertex AI)Language model for drafted contentProduct content sent for draftingEU and US

We will announce any intended addition or replacement at least thirty days before it takes effect, by email and on the subprocessor page. If you object on reasonable data protection grounds within that period, you may terminate the affected service with a pro rata refund of the unused period.

7. International transfers

Processing takes place in the European Union by default. Where a subprocessor may process outside the EEA, as noted in the table, the transfer relies on the European Commission's Standard Contractual Clauses, module two or three as applicable, together with a transfer impact assessment and the supplementary measures of encryption in transit and at rest and data minimisation.

8. Assistance

We assist you, taking into account the nature of the processing, with data subject requests, with security obligations under Article 32, with breach notification under Articles 33 and 34, and with data protection impact assessments and prior consultation under Articles 35 and 36. The self service export and deletion functions in the product are the primary mechanism for data subject requests.

9. Personal data breach

We notify you without undue delay and in any case within seventy two hours of becoming aware of a personal data breach affecting your data, with the information available at the time, and we update you as the investigation proceeds.

10. Deletion and return

On termination, or on disconnection or uninstall, we delete personal data processed on your behalf within thirty days, except where EU or member state law requires retention. Backups are purged on their ordinary rotation, which completes within thirty five days. An export can be requested at any time before deletion.

11. Audit

We make available the information necessary to demonstrate compliance with this addendum, and will answer a reasonable security questionnaire once per year. Where you require an on site audit, it takes place at your cost, with thirty days notice, during business hours, and must not compromise the confidentiality of other customers.

12. Order of precedence

In case of conflict, this addendum prevails over the terms of service in respect of the processing of personal data on your behalf.