Data Processing Agreement
Last updated August 20, 2026
Scope
This DPA applies where Retroboard processes personal data on behalf of a customer subject to the GDPR, UK GDPR, or similar data protection legislation. It supplements our Terms of Service.
Roles
The customer is the data controller of board content and member information; Retroboard is the data processor, processing personal data only on documented instructions from the controller.
Subprocessors
- Google Firebase (authentication) — Google LLC, USA/EU
- Neon (managed PostgreSQL hosting) — Neon Inc., USA/EU
Security measures
Encryption in transit and at rest, role-based access to production systems, isolated per-environment credentials, and audit logging. See our Security page for details.
Data subject requests
We assist controllers in responding to data subject requests (access, rectification, erasure, portability) within the timelines required by applicable law.
Breach notification
We notify affected customers without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting their data.
Requesting a signed copy
Enterprise customers may request a countersigned DPA at legal@retroboard.org.