This Data Processing Addendum (“DPA”) forms part of the Terms of Service between 1801 Labs (“Processor”) and the organisation using Peel (“Customer”, the controller). It applies when Peel processes personal data on the Customer's behalf under the GDPR, the UK GDPR or KVKK. Company-plan customers can request a countersigned copy at [email protected].
1. Subject matter, nature and purpose
Providing the Peel retro board service: storing and relaying end-to-end encrypted board content, keeping facilitator accounts and team spaces, and posting links and status to Slack or Microsoft Teams when the Customer installs those apps. Board content is encrypted on the Customer's devices with keys the Processor never receives; the Processor's processing of that content is limited to storage and transmission of ciphertext.
2. Duration
For the term of the Customer's use of Peel, plus the deletion periods in §9.
3. Data subjects and categories of data
- Data subjects: the Customer's facilitators and participants.
- Encrypted (unreadable to the Processor): card content, display names and avatars, board names, votes, reactions, stickers, actions, team-space logs, key bundles.
- Readable: facilitator account identifiers, names and emails from the identity provider; plan and subscription status; board metadata (operation types, sizes, timestamps, phase, counts, catalogue template id); Slack/Teams workspace, channel and message identifiers; IP addresses transiently at the network edge.
- Special categories: none intended. The Customer should not ask teams to post special-category data.
4. Processor obligations
- Process personal data only on the Customer's documented instructions — these terms, the product settings and the Customer's actions in Peel — unless the law requires otherwise (we'll tell you unless prohibited).
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement the security measures in Annex 1.
- Assist the Customer, taking into account the nature of processing, with data-subject requests, security, breach notifications, impact assessments and consultations with authorities.
- Make available the information needed to demonstrate compliance (see §8).
5. Sub-processors
The Customer authorises the sub-processors in Annex 2. We will announce new or replacement sub-processors at least 30 days in advance on this page and by email to Company-plan contacts. The Customer may object on reasonable data-protection grounds; if we cannot resolve the objection, the Customer may terminate the affected service and receive a pro-rata refund. We impose data-protection obligations on sub-processors that are no less protective than this DPA and remain responsible for them.
6. International transfers
Where personal data is transferred outside the EEA, the UK or Türkiye to a country without an adequacy decision, the parties rely on the Standard Contractual Clauses (Commission Decision 2021/914, Module 2 or 3 as applicable), the UK Addendum, and the standard contracts under KVKK Article 9, which are incorporated by reference.
7. Personal data breaches
We notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer data, with the information reasonably available, and keep the Customer updated. Because board content is end-to-end encrypted, a breach of our storage does not by itself expose card text.
8. Audits
We make available our security documentation (the public security page and, for Company-plan customers, the security review pack). Further audits, at most once a year, with 30 days' notice, during business hours and under confidentiality, at the Customer's cost unless they reveal a material breach.
9. Deletion and return
Encrypted content can be exported by the Customer at any time from the app. On termination we delete Customer personal data within 60 days, except where law requires retention. Board storage is deleted by expiry alarms; account data on account deletion.
10. Precedence
If this DPA conflicts with the Terms of Service, this DPA prevails for personal-data processing. The Standard Contractual Clauses prevail over both.
Annex 1 — Technical and organisational measures
- End-to-end encryption of board content (AES-256-GCM; Ed25519 signatures; X25519 sealed boxes) — keys stay on Customer devices.
- TLS for all traffic; encryption at rest by Cloudflare; integration tokens encrypted with AES-GCM under a separate secret.
- Strict Content Security Policy; no third-party scripts except Paddle.js on the checkout page; no analytics SDKs.
- Least-privilege access to production; secrets in Cloudflare-managed storage; multi-factor authentication for administrative accounts.
- Rate limiting and abuse controls; automated deletion of unclaimed boards after 60 days.
- Responsible-disclosure programme ([email protected]).
Annex 2 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, Workers, Durable Objects, D1, R2, KV, network | Global network; USA |
| Cloudflare, Inc. (Email Routing) | Support email | US / global |
Paddle (merchant of record), identity providers chosen by users (Google, Apple, Microsoft) and the Customer's own Slack or Microsoft workspace act as independent controllers or as the Customer's own providers, not as our sub-processors. GIPHY receives search terms only, through our proxy.