Innflyt — Data Processing Agreement
This is the Article 28 Data Processing Agreement between Backroad AS (providing Innflyt) and each customer whose end users submit feedback through the Innflyt widget. It is incorporated into the Terms of Use: accepting those terms accepts this agreement, so no separate signature is required for self-serve customers. A countersigned copy can be requested from [email protected].
Read it alongside the Processor Information page, which describes the same processing in plain language, and the Privacy Policy.
Last updated: 27 July 2026.
Data Processing Agreement
This Data Processing Agreement (this "DPA") forms part of the agreement between:
(1) Backroad AS, a limited company incorporated in Norway (organisation number 934 341 929), registered office in Bergen, Norway, providing the Innflyt service ("Innflyt", the "Processor"); and
(2) the Customer identified in the Order Form or sign-up record that references this DPA (the "Controller"),
each a "party" and together the "parties". This DPA is entered into in connection with the Controller's use of the Innflyt widget and platform (the "Service") and governs the Processing of Personal Data by the Processor on behalf of the Controller. Capitalised terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679).
1. Subject matter, roles, and instructions
1.1 The Controller is the controller and the Processor is the processor of the Personal Data submitted through the Service, within the meaning of Article 4 GDPR. The Processor is not a joint controller and does not determine the purposes of Processing.
1.2 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of data subjects are set out in Annex 1.
1.3 The Processor Processes the Personal Data only on the Controller's documented instructions, including with regard to international transfers, unless required to do otherwise by European Union or Member State law to which the Processor is subject; in such a case the Processor informs the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. The Controller's documented instructions are constituted by this DPA, the configuration choices the Controller makes in the Service (categories, fields, destinations, retention where supported), and any further written instructions. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other data-protection law.
1.4 The Processor does not: use submitted data to train artificial-intelligence or machine-learning models; use submitted data for its own advertising, profiling, or analytics products; sell, rent, or share submitted data with third parties for marketing; or build aggregate data products from Controller data.
2. Confidentiality
2.1 The Processor ensures that persons authorised to Process the Personal Data are bound by an appropriate duty of confidentiality and Process the Personal Data only on the Controller's instructions.
3. Security
3.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing as well as the risk to data subjects, the Processor implements the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
3.2 The Processor may update the measures in Annex 2 from time to time provided the updates do not materially reduce the overall level of security.
4. Sub-processors
4.1 The Controller gives the Processor general written authorisation to engage sub-processors. The sub-processors engaged as at the date of this DPA are listed in Annex 3.
4.2 The Processor informs the Controller of any intended change concerning the addition or replacement of a sub-processor at least thirty (30) days in advance, giving the Controller the opportunity to object. If the Controller reasonably objects on data-protection grounds and the parties cannot resolve the objection, the Controller may suspend or terminate the affected part of the Service.
4.3 The Processor imposes on each sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each sub-processor's obligations.
5. International transfers
5.1 The Processor's primary Processing takes place within the European Economic Area (Stockholm, Sweden). Where a sub-processor is established outside the European Economic Area, the Processor ensures the transfer is covered by an adequacy decision under Article 45 GDPR (for example the European Union – United States Data Privacy Framework for certified entities), the Standard Contractual Clauses approved under Article 46(2)(c) GDPR supplemented by any measures required following a transfer-impact assessment, or another lawful mechanism. The mechanism for each current sub-processor is shown in Annex 3.
6. Assistance to the Controller
6.1 Data subject rights. Taking into account the nature of the Processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data-subject rights under Chapter III GDPR. If a data subject contacts the Processor directly, the Processor promptly forwards the request to the Controller and does not respond substantively unless the Controller authorises a direct response in writing.
6.2 Security, breach, and impact assessments. The Processor assists the Controller in ensuring compliance with the obligations in Articles 32 to 36 GDPR, taking into account the nature of Processing and the information available to the Processor.
6.3 Personal data breach. The Processor notifies the Controller of any Personal Data breach without undue delay after becoming aware of it, and in any event within forty-eight (48) hours where reasonably possible. The notification contains the information required under Article 33(3) GDPR to the extent available, supplemented in phases as further information becomes available. The Controller is responsible for notifying supervisory authorities and data subjects under Articles 33 and 34 GDPR; the Processor supports the Controller with the information available.
7. Retention, return and deletion
7.1 Retention (storage limitation). The Processor retains Personal Data only for as long as necessary for the purpose set out in Annex 1, in accordance with Article 5(1)(e) GDPR. By default Innflyt retains feedback submissions for 365 days and optional screenshot attachments for 90 days, after which the data is permanently deleted by an automated daily process. The Controller may agree a different retention period within the supported limits (a minimum of 30 days and a maximum of 3650 days for each), or may instead elect to retain the data until the Controller deletes it. Deletion under this clause is a hard deletion of the underlying records and of the corresponding stored objects; the Processor keeps a deletion log recording the project, the scope, the record and attachment counts, and the timestamp of each deletion, and that log contains no end-user Personal Data.
7.2 Return and deletion on termination. On termination of the Service, or at the Controller's earlier written request, the Processor, at the Controller's choice, deletes or returns all Personal Data Processed on the Controller's behalf and deletes existing copies within thirty (30) calendar days, unless European Union or Member State law requires storage of the Personal Data. The Processor confirms deletion in writing. Backup copies are overwritten on the ordinary backup-retention cycle.
8. Audit
8.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable prior notice (at least thirty (30) days save in the case of a substantiated security incident), no more than once per twelve-month period absent cause, and appropriate confidentiality protections. The Processor may satisfy an audit request by providing recent security assessments, penetration-test results, or third-party attestations where available.
9. Controller obligations
9.1 The Controller warrants that it has a lawful basis for the Processing, that its instructions are lawful, and that it has provided any notices and obtained any consents required of a controller. The Controller is responsible for the configuration choices it makes in the Service. The Controller will surface guidance in its own user interface inviting end users not to include sensitive personal data that the feedback does not require.
10. Term, liability, and governing law
10.1 This DPA takes effect on the date the Controller accepts it (including by signing the referencing Order Form or completing sign-up) and remains in force for as long as the Processor Processes Personal Data on the Controller's behalf.
10.2 Each party's liability arising out of or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the Innflyt Terms of Service (or other written agreement) accepted by the Controller, which the parties agree is the "underlying agreement" for this purpose. Where no such agreement is in force, the limitations in the Innflyt Terms of Service apply by reference. Nothing in this DPA or that agreement limits or excludes liability that cannot lawfully be limited or excluded under applicable mandatory law.
10.3 This DPA is governed by the laws of Norway — including the Personal Data Act (personopplysningsloven, LOV-2018-06-15-38), which implements the GDPR in Norway through the European Economic Area Agreement — and the parties submit to the courts of Bergen, Norway, without prejudice to mandatory data-subject rights to bring proceedings elsewhere. The competent supervisory authority for the Processor is the Norwegian Data Protection Authority (Datatilsynet).
Annex 1 — Details of the Processing
- Subject matter: Capture, storage, routing, and display of end-user feedback submitted through the Innflyt widget embedded on the Controller's site or application.
- Duration / retention: Feedback submissions are retained for a default of 365 days and optional screenshot attachments for a default of 90 days (each configurable within a 30-to-3650-day range, or retained until the Controller deletes the data), after which they are permanently deleted by an automated daily process (clause 7.1). On termination of the Service or earlier Controller request, all data is deleted or returned within 30 days (clause 7.2).
- Nature and purpose: Receiving feedback submissions; storing them; routing them to the Controller's configured destinations (webhook, email, Slack, or third-party tools the Controller integrates); displaying them in the Controller's dashboard.
- Categories of data subjects: End users of the Controller's site or application who submit feedback.
- Categories of Personal Data: Feedback message (free text); feature tag selected by the end user; urgency flag; page Uniform Resource Locator; browser user-agent string and derived browser / operating-system / device / viewport fields; pseudonymised (hashed, peppered) Internet Protocol address used solely for rate limiting (the raw address is never stored); submission timestamp; optional follow-up email and optional end-user identifier — either entered by the end user in the widget, or supplied by the Controller's own application for a signed-in end user; optional user-initiated screenshot attachments.
- Special categories: Not solicited. Because the message field is free text and screenshots are user-initiated, special-category data (Article 9) or criminal-conviction data (Article 10) may be included voluntarily by end users; the Processor Processes any such data only for the storage-and-forwarding purpose.
Annex 2 — Technical and Organisational Measures
- Encryption in transit: Transport Layer Security version 1.2 or higher between the widget, the ingestion endpoint, and Innflyt infrastructure.
- Encryption at rest: Managed PostgreSQL with Advanced Encryption Standard, 256-bit keys.
- Access control on data: Row-Level Security enabled on every table holding Controller data, with explicit policies; anonymous and signed-in end-user roles are denied; data access is restricted to the server-side service role and enforced in application logic. Administrative access protected by multi-factor authentication.
- Pseudonymisation: End-user Internet Protocol addresses are not stored; rate limiting uses a hashed, peppered identifier only.
- Secrets handling: Service-role credentials and secrets are stored only in encrypted continuous-integration secrets and server-side environment variables, never in source control or client-side code. Anonymous and signed-in end-user database roles hold no execution rights on privileged database functions and no permissive access to any table holding Controller data; data access is confined to the server-side service role.
- Integrity of dispatch: Every webhook dispatch carries an HMAC using the Secure Hash Algorithm 256-bit so the Controller can verify authenticity before acting.
- Idempotency: A unique idempotency key per submission prevents duplicate records on client retry.
- Asynchronous dispatch: A durable queue decouples downstream destinations from the end-user submission path.
- Screenshot storage and delivery: Attachments are stored in a private (non-public) bucket with non-enumerable, Universally-Unique-Identifier-based object paths; bucket listing is disabled; uploads use short-lived signed upload Uniform Resource Locators. The bucket is not publicly readable. Screenshots are delivered to the Controller's configured destinations exclusively through signed, time-limited download Uniform Resource Locators.
- Monitoring and remediation: Continuous dependency-vulnerability scanning, source-control security alerts, and managed-platform advisor scans; findings tracked and remediated on a risk-based schedule.
- Review: These measures are reviewed at least annually and updated in response to changes in risk, technology, or law.
Annex 3 — Approved Sub-processors
| Sub-processor | Service | Location | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Managed PostgreSQL database, server-side runtime, storage / content-delivery network | Stockholm, Sweden | Intra-European-Economic-Area; no cross-border mechanism required |
| Cloudflare Inc. | Domain Name System for innflyt.com and innflyt.no; Cloudflare Email Service (currently beta) for outbound transactional email; edge network | Global network with European edge nodes | Standard Contractual Clauses (Article 46(2)(c) GDPR); Cloudflare Data Processing Addendum |
| GitHub Inc. | Source-code hosting and continuous-integration / continuous-deployment | United States, with European edge nodes | European Union – United States Data Privacy Framework; GitHub Data Protection Agreement |
| Clerk, Inc. | Authentication and identity for the customer dashboard (administrator sign-in only). Does not process end-user feedback data — its scope is the Controller's own administrator account identities (name, email). | United States | Standard Contractual Clauses (Article 46(2)(c) GDPR) under Clerk's Data Processing Addendum (and the European Union – United States Data Privacy Framework where Clerk is certified) |
| Functional Software, Inc. ("Sentry") | Application error monitoring for the server-side Edge Functions. Receives technical error metadata only — request identifier, project identifier, function name, processing stage — and never feedback content, free-text, or end-user email. | Application error data in the European Union (Frankfurt, Germany, de.sentry.io); Sentry account metadata in the United States | Application error data is EU-resident (no cross-border transfer of error data); Sentry account metadata under Sentry's Data Processing Addendum / Standard Contractual Clauses |
Signatures
For Backroad AS (Processor): name, title, date, signature.
For the Customer (Controller): name, title, date, signature.