Privacy Policy
At Responsio ("we", "us", or "our"), accessible via https://responsio.app and https://*.responsio.app ("Service" or "Platform" or "Responsio"), we respect your privacy and are committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Platform or interact with our embedded feedback widgets.
This Privacy Policy should be read alongside our Terms of Service. For specific details regarding the cookies we use on our Platform, please refer to our dedicated Cookie Policy.
1. Roles in Data Protection (GDPR Compliance)
To ensure full transparency under data protection laws (such as GDPR):
- Responsio as a Data Controller: We act as the Data Controller for personal data belonging to our Clients (account holders who sign up to use Responsio).
- Responsio as a Data Processor: We act as a Data Processor for personal data belonging to End-Users submitting feedback via our Widget installed on Clients' websites. The Client is the Data Controller of their End-Users' data.
2. Information We Collect
- Information Collected from Clients (Account Holders):
- Account Information: Name, email address, password hash, and company details provided during registration.
- Usage Data: IP address, browser type, operating system, and log data regarding how you navigate our Platform.
- Information Collected from End-Users (Via the Widget):
- User Profile Data: When installed on a Client's platform, the Widget
receives
End-User metadata passed by the Client, including
id,name,email, andprofile picture. - Feedback Content: Text, images, category tags, votes, and comments submitted by End-Users within the Widget.
- Technical Metadata: Device information, browser type, and timestamps associated with submission.
- User Profile Data: When installed on a Client's platform, the Widget
receives
End-User metadata passed by the Client, including
3. How We Use Your Information
We use the collected information for the following purposes:
- To provide, operate, and maintain the Responsio Platform and Widget functionality.
- To authenticate End-Users without requiring them to register separate accounts with Responsio.
- To send administrative notifications, technical updates, and security alerts to Clients.
- To monitor system health, prevent abuse, and enforce our Terms of Service.
4. Data Visibility and Privacy Rules
- Public End-User Data: Content submitted by End-Users (ideas, bug reports, votes, comments) along with their display name and profile picture may be publicly visible to other visitors on the Client's feedback board/Widget.
- Private End-User Data: Sensitive End-User data—specifically email addresses and internal User IDs—are strictly hidden from the public and are accessible only by the Client who owns the Project.
- No Commercial Exploitation: Responsio does not sell, rent, trade, or monetize End-User or Client personal data to third parties.
5. Data Sharing and Sub-processors
We only share personal data with trusted third-party service providers (Sub-processors) necessary to run our infrastructure, such as:
- Hetzner Online: a professional web hosting provider and experienced data center operator. We use their servers to store our application data securely.
- Amazon Web Services: offers reliable, scalable cloud computing services. We use AWS to increase our availability and performance. We use AWS to store encrypted backups of databases.
6. Data Security and Retention
- Security Measures: We employ industry-standard technical and organizational security measures, including HTTPS encryption in transit, to prevent unauthorized access, loss, or disclosure.
- Data Retention: We retain Client account data for as long as the account remains active. When a Client deletes their account or project, all associated End-User data, boards, and posts are permanently deleted from our active databases within a reasonable timeframe.
7. Your Rights (GDPR & Global Privacy Rights)
Depending on your location, you may have the following rights regarding your personal data:
- Access & Rectification: Request a copy of your personal data or request corrections to inaccurate data.
- Erasure ("Right to be Forgotten"): Request the deletion of your personal data. (End-Users should direct deletion requests to the respective Client platform holding their data).
- Data Portability: Request a transfer of your personal data in a structured, machine-readable format.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
8. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify Clients of any material changes by updating the "Last updated" date at the bottom of this page and, where appropriate, sending an email notification or displaying a notice within the Platform.
Last revision date: