Retroboard
FeaturesAboutBlog
Sign inGet started

Data Processing Agreement

Last updated August 20, 2026
Scope
This DPA applies where Retroboard processes personal data on behalf of a customer subject to the GDPR, UK GDPR, or similar data protection legislation. It supplements our Terms of Service.
Roles
The customer is the data controller of board content and member information; Retroboard is the data processor, processing personal data only on documented instructions from the controller.
Subprocessors
  • Google Firebase (authentication) — Google LLC, USA/EU
  • Neon (managed PostgreSQL hosting) — Neon Inc., USA/EU
We will notify customers of subprocessor changes with reasonable advance notice.
Security measures
Encryption in transit and at rest, role-based access to production systems, isolated per-environment credentials, and audit logging. See our Security page for details.
Data subject requests
We assist controllers in responding to data subject requests (access, rectification, erasure, portability) within the timelines required by applicable law.
Breach notification
We notify affected customers without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting their data.
Requesting a signed copy
Enterprise customers may request a countersigned DPA at legal@retroboard.org.

Retroboard
FeaturesAboutBlogSecurityPrivacyTermsDPA

© 2026 Retroboard · retroboard.org