Privacy Policy

At Responsio ("we", "us", or "our"), accessible via https://responsio.app and https://*.responsio.app ("Service" or "Platform" or "Responsio"), we respect your privacy and are committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Platform or interact with our embedded feedback widgets.

This Privacy Policy should be read alongside our Terms of Service. For specific details regarding the cookies we use on our Platform, please refer to our dedicated Cookie Policy.

1. Roles in Data Protection (GDPR Compliance)

To ensure full transparency under data protection laws (such as GDPR):

2. Information We Collect

  1. Information Collected from Clients (Account Holders):
    • Account Information: Name, email address, password hash, and company details provided during registration.
    • Usage Data: IP address, browser type, operating system, and log data regarding how you navigate our Platform.
  2. Information Collected from End-Users (Via the Widget):
    • User Profile Data: When installed on a Client's platform, the Widget receives End-User metadata passed by the Client, including id, name, email, and profile picture.
    • Feedback Content: Text, images, category tags, votes, and comments submitted by End-Users within the Widget.
    • Technical Metadata: Device information, browser type, and timestamps associated with submission.

3. How We Use Your Information

We use the collected information for the following purposes:

4. Data Visibility and Privacy Rules

  1. Public End-User Data: Content submitted by End-Users (ideas, bug reports, votes, comments) along with their display name and profile picture may be publicly visible to other visitors on the Client's feedback board/Widget.
  2. Private End-User Data: Sensitive End-User data—specifically email addresses and internal User IDs—are strictly hidden from the public and are accessible only by the Client who owns the Project.
  3. No Commercial Exploitation: Responsio does not sell, rent, trade, or monetize End-User or Client personal data to third parties.

5. Data Sharing and Sub-processors

We only share personal data with trusted third-party service providers (Sub-processors) necessary to run our infrastructure, such as:

  1. Hetzner Online: a professional web hosting provider and experienced data center operator. We use their servers to store our application data securely.
  2. Amazon Web Services: offers reliable, scalable cloud computing services. We use AWS to increase our availability and performance. We use AWS to store encrypted backups of databases.

6. Data Security and Retention

  1. Security Measures: We employ industry-standard technical and organizational security measures, including HTTPS encryption in transit, to prevent unauthorized access, loss, or disclosure.
  2. Data Retention: We retain Client account data for as long as the account remains active. When a Client deletes their account or project, all associated End-User data, boards, and posts are permanently deleted from our active databases within a reasonable timeframe.

7. Your Rights (GDPR & Global Privacy Rights)

Depending on your location, you may have the following rights regarding your personal data:

8. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify Clients of any material changes by updating the "Last updated" date at the bottom of this page and, where appropriate, sending an email notification or displaying a notice within the Platform.

Last revision date: