Draft pending legal review. This addendum has not been reviewed by counsel and the placeholders
[TRADER LEGAL NAME]and[US BUSINESS ADDRESS]are unfilled. If you need an executed DPA before sending personal data, write to support@seethebug.com.
1. Scope and role of the parties
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the Customer and [TRADER LEGAL NAME], trading as SeeTheBug, and applies where SeeTheBug processes personal data on the Customer’s behalf.
The Customer is the controller of the personal data contained in Capture Packages, and SeeTheBug is the processor. The Customer determines what its Deployment Profiles collect, from whom, and for what purpose; SeeTheBug stores and transmits the result on the Customer’s instructions.
Where SeeTheBug processes data as a controller in its own right — Account data, website data and server logs — that processing is governed by the Privacy Policy and not by this DPA.
This DPA applies wherever the Customer is established. Accounts are not currently available to Customers in the EEA or the UK (see section 9 of the Terms), but that restriction concerns who may hold an Account — it does not limit where a Customer’s End Users may be. A Customer anywhere in the world may run a reproduction on the machine of an End User located in the EEA or the UK, and this DPA governs the personal data in the resulting Capture Package when it does.
Terms defined in the Terms of Service have the same meaning here. “Data Protection Law” means the EU GDPR, the UK GDPR and the Data Protection Act 2018, and any other data protection law applicable to the processing.
2. Processing on documented instructions
SeeTheBug will process personal data only:
- to provide the Service in accordance with the Terms of Service;
- in accordance with the Customer’s further documented instructions, where those are consistent with the Service’s functionality; and
- as required by law, in which case SeeTheBug will inform the Customer beforehand unless legally prohibited.
SeeTheBug will not use Capture Package contents for its own purposes, will not disclose them except as permitted by this DPA, and will not use them to train machine-learning models.
If SeeTheBug considers an instruction to breach Data Protection Law, it will inform the Customer without undue delay.
3. Details of the processing
The subject-matter, duration, nature and purpose of the processing, the categories of personal data and of data subjects, are set out in Annex 1.
Processing continues for as long as the Customer’s Account is open, and ends in accordance with section 10.
4. Confidentiality
SeeTheBug will ensure that any person authorized to process personal data under this DPA is bound by an obligation of confidentiality and is granted access only to the extent needed to perform their role. Access to Capture Package contents is limited to what is necessary to operate the Service or to respond to a Customer support request.
5. Security
SeeTheBug will implement and maintain the technical and organizational measures set out in Annex 2, appropriate to the risk, in accordance with Article 32 of the GDPR.
The Customer acknowledges that end-to-end encryption of Capture Package payloads is available and is enabled by configuring an encryption key for the Account. Where the Customer chooses not to configure one, payloads are stored without that additional layer of protection. The Customer is responsible for that choice and for the safekeeping of its private key; SeeTheBug holds no copy and cannot recover a payload if the key is lost.
6. Sub-processors
The Customer gives SeeTheBug general authorization to engage sub-processors. The current list is published at Sub-processors.
SeeTheBug will:
- impose data protection obligations on each sub-processor no less protective than those in this DPA, and remain liable for its sub-processors’ performance;
- give the Customer notice, by email to Account administrators and by updating the published list, before a new sub-processor begins processing; and
- consider in good faith any reasonable objection the Customer raises on data protection grounds within 30 days of that notice. If the objection cannot be resolved, the Customer may terminate the affected part of the Service without penalty.
7. Data subject requests
Where SeeTheBug receives a request from a data subject relating to personal data processed on the Customer’s behalf, it will not respond to the substance of the request itself but will refer the individual to the Customer and inform the Customer without undue delay.
SeeTheBug will provide reasonable assistance, at the Customer’s cost where the effort is more than incidental, in enabling the Customer to respond to requests for access, rectification, erasure, restriction, portability and objection — including by making Capture Packages available to the Customer through the Portal and by deleting a Capture Package on the Customer’s instruction.
Because Capture Package payloads may be encrypted with a key SeeTheBug does not hold, and because SeeTheBug holds no direct relationship with End Users, the Customer is the only party able to locate the data relating to a given individual within a payload.
8. Personal data breach
SeeTheBug will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer’s behalf, and will provide the information reasonably available to it — the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
SeeTheBug will cooperate with the Customer and take the reasonable steps the Customer directs to assist in investigating and remedying the breach. Notification is not an acknowledgment of fault.
9. Data protection impact assessments
On request, SeeTheBug will provide the Customer with information reasonably necessary to carry out a data protection impact assessment or a prior consultation with a supervisory authority, to the extent the Customer cannot obtain it from the Privacy Policy, this DPA or the published sub-processor list.
10. Deletion and return on termination
The Customer may delete any Capture Package at any time through the Portal, which removes both the payload and its diagnostic-log archive from storage.
On termination of the Account, and on the Customer’s request, SeeTheBug will delete the Account and all personal data processed on the Customer’s behalf — including Capture Packages, their stored files, and the retained records of removed Authorized Users — within 30 days, except where SeeTheBug is required by law to retain something, in which case it will retain only what is required and continue to protect it under this DPA.
The Customer should export anything it wishes to keep before requesting deletion.
11. International transfers
Personal data processed under this DPA is hosted in the United States. Section 11 of the Privacy Policy describes the transfer arrangements.
Where the Customer is established in the EEA or the UK and Data Protection Law requires a transfer mechanism, the European Commission’s Standard Contractual Clauses (Decision 2021/914), and the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference, with SeeTheBug as data importer and the Customer as data exporter, and with Annexes 1 and 2 of this DPA serving as the corresponding annexes.
12. Audits and information rights
SeeTheBug will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including its own description of measures in Annex 2 and the compliance documentation and certifications of its hosting provider.
Where Data Protection Law gives the Customer an audit right that this information does not satisfy, the parties will agree the scope, timing and cost of an audit in advance. Audits will be limited to once in any twelve-month period unless a personal data breach or a regulator’s requirement makes another necessary, will be conducted on reasonable notice during business hours, and must not compromise the confidentiality or security of other customers’ data.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in section 14 of the Terms of Service, except to the extent Data Protection Law does not permit those limits to apply.
If there is a conflict between this DPA and the Terms of Service on the processing of personal data, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
Annex 1 — Details of the processing
Subject-matter. Provision of the SeeTheBug service: capture, transmission, storage and delivery of issue-reproduction packages produced on End Users’ machines at the Customer’s direction.
Duration. For as long as the Customer’s Account is open, and until deletion under section 10.
Nature of the processing. Collection on the End User’s machine by the Client, encryption where configured, upload, storage, and making available to the Customer’s Authorized Users for download; deletion on the Customer’s instruction.
Purpose. Enabling the Customer’s support and engineering teams to diagnose faults reported by their own customers or personnel.
Categories of data subjects.
- End Users who run the Client.
- Individuals whose personal data appears incidentally in a recording or in collected diagnostics — for example a name visible on screen, or a user account named in a log.
Categories of personal data. As set out in section 6 of the Privacy Policy, which is incorporated here by reference and which the Customer should read in full. In summary, and depending entirely on the Customer’s Deployment Profile: screen recordings of the displays the End User selected; microphone audio where the End User enabled it; keystrokes shown by the on-screen keystroke panel during recording; operating-system usernames and group membership; hostnames, domain names and machine identifiers; IP and MAC addresses and network peer addresses; running processes with owning usernames and full command lines; application log files and configuration files matching the Customer’s patterns; the title, notes and attachments the End User supplies; and the output of any custom collectors the Customer configured.
Special categories of personal data. None. The Terms of Service prohibit the Customer from configuring collection of, or knowingly uploading, Sensitive Personal Information.
Frequency. Intermittent — only when an End User runs a reproduction.
Annex 2 — Technical and organizational measures
These are the measures actually in place, not aspirations. They are summarized in section 13 of the Privacy Policy.
Encryption.
- TLS for all traffic between the Client, the Portal, the API and the database.
- Encryption at rest provided by the hosting platform.
- Optional end-to-end encryption of Capture Package payloads: AES-256-GCM with a key generated per package, that key wrapped to the Customer’s public key with RSA-OAEP-SHA256. SeeTheBug holds no private key. Package headers and the diagnostic-log archive are not covered by this encryption — see section 7 of the Privacy Policy.
Access control.
- Role-based authorization in the Portal; Capture Packages are scoped to the owning Account and every request is checked against the caller’s Account.
- Passwords hashed with Argon2id and a per-password salt.
- Short-lived access tokens; refresh tokens are invalidated when a password changes.
- Rate limiting on authentication endpoints and temporary lockout after repeated failed sign-in attempts.
- Administrative access to production limited to the operator and protected by the hosting provider’s own account controls.
Data minimization and confidentiality of logging.
- Values that look like credentials are masked before anything is written to a server log or to the diagnostic-log archive included in a Capture Package.
- Transactional email is logged by recipient and subject only, never by content.
Resilience and integrity.
- Managed database with the hosting provider’s backup and point-in-time restore.
- A SHA-256 checksum of each payload, computed before encryption, is stored with the package so that corruption is detectable.
Organizational measures.
- Confidentiality obligations on anyone with access.
- Least-privilege access, reviewed when roles change.
- Documented, operator-invoked deletion process covering both database records and stored payload files.
Because SeeTheBug is operated by a sole trader, it does not hold ISO 27001, SOC 2 or equivalent certification. The hosting provider’s certifications are available through the provider.