Draft, not yet reviewed. This document still contains unfilled placeholders and has not been reviewed by a lawyer. Do not rely on it, and do not accept paying customers against it.
Data Processing Agreement
Last updated 6 October 2026
This Agreement forms part of the Terms of Service between the Customer and [LEGAL ENTITY NAME] ("BugShot", "Processor"). It applies where BugShot processes personal data on the Customer's behalf, and it takes precedence over the Terms in the event of conflict on data protection matters.
1. Roles
The Customer is the controller and BugShot is the processor in respect of Reporter Data, as those terms are used in the UK GDPR and EU GDPR. Where the CCPA applies, BugShot is a service provider and does not sell or share personal information, nor retain, use or disclose it for any purpose other than performing the service.
BugShot is a separate controller for Account Data, meaning the account holder's own contact and billing details, which are covered by the privacy policy rather than this Agreement.
2. Subject matter and duration
Subject matter: receiving, storing, deduplicating, displaying and forwarding bug reports submitted through the BugShot widget on the Customer's websites.
Duration: for as long as the Customer holds an account, plus the retention period of the Customer's plan.
Nature and purpose: hosted software as a service, provided so the Customer can diagnose and fix defects reported by their own users.
3. Customer instructions
BugShot processes Reporter Data only on the Customer's documented instructions, which consist of this Agreement, the Terms, and the Customer's configuration of their projects. BugShot will tell the Customer if it believes an instruction infringes data protection law, and will not be obliged to follow it.
BugShot will not process Reporter Data for its own purposes, will not use it to train machine learning models, and will not sell or share it.
4. Categories of data
Data subjects: end users of the Customer's websites who choose to submit a bug report.
Personal data:
- A screenshot of the page as it appeared, subject to the masking described in Annex II.
- The free text description the reporter wrote.
- An email address, where the reporter chooses to provide one.
- Page address, title and referrer.
- Browser, operating system, viewport, language, timezone and connection type.
- Console error messages and the addresses of failed requests, with query strings removed.
- A record of recent clicks and navigation, excluding values typed into fields.
- The submitting IP address, retained for 30 days.
- Any data the Customer chooses to attach through the widget API.
Special category data is not expected. Screenshots capture whatever is on screen, so the Customer is responsible for configuring masking before deployment. The Terms prohibit using the service for special category data, protected health information or full payment card data without prior written agreement.
5. Confidentiality
BugShot ensures that anyone authorised to process Reporter Data is bound by confidentiality obligations and accesses it only as necessary to provide or support the service.
6. Security
BugShot implements the technical and organisational measures set out in Annex II, appropriate to the risk, in accordance with Article 32.
7. Sub-processors
The Customer gives general authorisation for the sub-processors listed on the sub-processors page. BugShot will give at least 30 days notice by email before adding or replacing one. The Customer may object on reasonable data protection grounds within that period, and if the objection cannot be resolved the Customer may terminate without penalty and receive a pro rata refund.
BugShot imposes equivalent data protection obligations on each sub-processor and remains fully liable for their performance.
8. Data subject requests
The Customer can fulfil access, erasure and portability requests directly from the Data page in the dashboard, without contacting BugShot. Erasure by reporter email deletes the matching reports and their screenshots from object storage, and removes any issue left with no reports.
If a data subject contacts BugShot directly, BugShot will not respond substantively but will forward the request to the Customer without undue delay. Where the Customer cannot fulfil a request through the dashboard, BugShot will provide reasonable assistance.
9. Personal data breach
BugShot will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Reporter Data. The notification will describe the nature of the breach, the categories and approximate numbers affected, the likely consequences and the measures taken.
10. Assistance
Taking into account the nature of the processing and the information available to it, BugShot will assist the Customer with data protection impact assessments, prior consultation with supervisory authorities, and Articles 32 to 36 generally.
11. Deletion and return
Reports and screenshots are deleted automatically once they exceed the Customer's plan retention period. On termination the Customer may export all data for 30 days, after which BugShot deletes it, including from object storage. Closing an account from the dashboard deletes everything immediately.
12. Audits
BugShot will make available the information necessary to demonstrate compliance with Article 28 and will contribute to audits conducted by the Customer or an auditor it mandates, no more than once per year unless required by a supervisory authority, on 30 days notice, during business hours, and without unreasonable disruption. The parties will treat audit findings as confidential.
13. International transfers
Where Reporter Data is transferred out of the UK or EEA, the transfer is made under the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, controller to processor, incorporated into this Agreement by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. Annex I and Annex II below serve as the annexes to those Clauses. Docking clause: optional. Clause 9(a): Option 2, general authorisation, 30 days notice. Clause 17: the law of [GOVERNING JURISDICTION]. Clause 18(b): the courts of [GOVERNING JURISDICTION].
Data location: BugShot's database and object storage are currently hosted in North America. An EU hosted option is not yet available. Customers requiring EU data residency should contact [CONTACT EMAIL] before deploying the widget.
14. Liability
Liability under this Agreement is subject to the limitations in the Terms of Service, to the extent permitted by applicable law.
Annex I: Details of processing
Data exporter: the Customer, acting as controller.
Data importer: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], acting as processor.
Categories of data subjects, personal data, and duration: as set out in sections 2 and 4 above.
Frequency: continuous, on submission by a data subject.
Competent supervisory authority: that of the Customer's establishment.
Annex II: Technical and organisational measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS on every connection. The widget submits with credentials omitted. |
| Encryption at rest | Provider level encryption on database and object storage. Destination credentials additionally encrypted with AES-GCM under a key held only in the runtime environment. |
| Pseudonymisation and minimisation | Form field contents blurred before capture. Query strings stripped from recorded addresses. Request and response bodies and headers never recorded. Typed values excluded from interaction history. |
| Access control | Passwordless sign in by single use, time limited, hash stored token. Signed HTTP only session cookies. Every query scoped to the owning account at the data layer. |
| Tenant isolation | Enforced structurally: data access functions require an account identifier and join through project ownership. Covered by automated tests that attempt cross tenant access. |
| Endpoint protection | Per project origin allowlist, per address rate limiting, request size and image type limits, and full server side revalidation of every submitted field. |
| Screenshot access control | Served only under expiring HMAC signed URLs; object storage is not publicly readable. |
| Availability | Managed, replicated infrastructure with provider level redundancy. |
| Retention and deletion | Automated nightly deletion at plan retention limits. IP addresses purged after 30 days. Deletion is explicit at every level rather than relying on database cascade behaviour. |
| Logging and accountability | Audit records of every action that destroys data, exports it in bulk, or changes access, retained with actor and subject. |
| Change management | Type checked codebase with automated unit and end to end tests covering isolation, authorisation, erasure and abuse controls, run before deployment. |
Signature
This Agreement is accepted by the Customer on acceptance of the Terms of Service and requires no separate signature. Customers requiring a countersigned copy may request one at [CONTACT EMAIL].