bugscreen
Pricing
Docs
Documentation
Integrations
AndroidiOSReact Native
How integrations workGitHubJiraClickUpSlack
Sign inGet started
Last updated · 21 July 2026

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service between BugScreen Limited ("we", "us", the processor) and the customer accepting those Terms ("you", the controller). It applies where we process personal data on your behalf in providing BugScreen (the "Service").

No signature is required. This DPA is incorporated into the Terms by reference and takes effect when you accept them. The version date shown at the top of this page identifies the version that applies. Where this DPA conflicts with the Terms, this DPA prevails in respect of the processing of personal data.

Terms defined in the Terms of Service — including Authorised Tester, Customer Data, and Integration — carry the same meaning here. "Personal data", "processing", "controller", "processor", "sub-processor", and "data subject" carry the meanings given in the UK GDPR and, where applicable, the EU GDPR (together, "Data Protection Law").

1. Roles of the parties

For personal data contained in bug reports submitted through your BugScreen integration, you are the controller and we are the processor. You are responsible for the lawfulness of that data, for the basis on which you collect it from your Authorised Testers, and for giving them notice about what the SDKs collect.

For your own account data — the records identifying your organisation, its members, and its subscription — we act as an independent controller, as described in our Privacy Policy. That processing is outside the scope of this DPA.

2. Subject matter, duration, nature and purpose

  • Subject matter. Our provision of the Service to you under the Terms.
  • Duration. For as long as your account remains active, plus the retention windows described in section 9 below.
  • Nature and purpose. Receiving bug reports submitted by your Authorised Testers, storing their screenshot and log attachments for a fixed period, and forwarding the report to the Integrations you have configured, so that an issue, task, or message is created in your own systems.

3. Categories of data subjects and personal data

  • Data subjects: your Authorised Testers — the people you permit to exercise a build of your application and submit reports.
  • Categories of personal data: the free-text description a tester writes; screenshots they attach, which may incidentally show personal data that was on screen; the log file the SDK attaches automatically, containing whatever your own code passed to the SDK's logging API; device, app, and display characteristics collected automatically; and any account identity or custom key/value data your app chooses to attach through the SDK's setUser and setCustomData APIs, which may include an email address if you supply one.
  • Special category data. The Service is not designed for it, and the Terms prohibit uploading it without our written agreement.

The full, current account of what is collected is in our Privacy Policy, which is kept in step with the Service rather than duplicated here.

4. Processing on documented instructions

We will process personal data only on your documented instructions, which comprise the Terms, this DPA, and your configuration of the Service (the Integrations you connect and the SDK settings you choose). We will inform you if, in our opinion, an instruction infringes Data Protection Law. If we are required by law to process personal data other than on your instructions, we will tell you before doing so unless that law prohibits it.

We do not sell personal data and do not use Customer Data to train machine-learning models.

5. Confidentiality

We ensure that personnel authorised to process personal data are bound by an appropriate duty of confidentiality, and we limit access to those who need it to provide or support the Service.

6. Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking account of the state of the art and the risks of the processing. Those measures are described in the security section of our Privacy Policy; they are maintained there rather than restated here so that this DPA cannot drift from what we actually do.

7. Sub-processors

You give us general authorisation to engage sub-processors. The current sub-processors, the service each performs, and the location of processing are published at bugscreen.app/subprocessors. That page is the definitive list and is updated as our supplier mix changes.

We will update that page before engaging a new sub-processor that will process personal data on your behalf, so you can review the change. If you have a reasonable objection on data-protection grounds, tell us at [email protected] and we will work with you in good faith to address it; if we cannot, you may terminate the affected part of the Service. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to you for their performance.

8. Assisting you

  • Data-subject requests. Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights. If we receive such a request directly from one of your Authorised Testers, we will not respond to it ourselves — we will refer them to you and tell you about it.
  • Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, taking account of the information available to us.

Note that we do not retain bug report content, so the durable record of any report sits in the Integration you connected. In practice you can action most data-subject requests directly, and we could not action them there on your behalf.

9. Deletion and return

Screenshot and log attachments are deleted automatically 30 days after upload. That happens unconditionally, and there is no earlier deletion control. Bug report content itself is never stored: it is forwarded to your Integrations at the moment of submission.

It follows that on termination there is no report archive for us to return or delete — what we hold is your account and configuration record. On request before termination takes effect, we will use reasonable efforts to provide a copy of that record, handled manually by our support team, and we will delete it on request afterwards. Deletion is carried out manually rather than by an automated timer, so we do not commit to a fixed window. We may retain personal data where required by law, in which case we continue to protect it under this DPA.

10. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and will provide the information reasonably available to us to help you meet your own notification obligations. Our initial notice may be incomplete; we will supplement it as the investigation progresses.

11. Audits and information

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once in any 12-month period unless required by a supervisory authority or following a personal data breach, must be on reasonable prior notice and during business hours, must not unreasonably disrupt the Service or compromise the confidentiality of other customers' data, and are at your cost. We may satisfy an audit request by providing documentation or responding to a security questionnaire where that reasonably addresses your request.

12. International transfers

Customer Data is processed in the AWS eu-west-2 (London) region. Some of the sub-processors listed at bugscreen.app/subprocessors may process personal data outside the UK and EEA, including in the United States.

Where a transfer is made to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum to those clauses, plus any supplementary measures required to keep the level of protection consistent with UK and EU law. Where you are the data exporter and we are the data importer, those clauses are incorporated into this DPA, with module two (controller to processor) applying and the details in sections 2, 3, and 7 above completing their annexes.

13. Liability, term, and changes

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA takes effect when you accept the Terms and continues while we process personal data on your behalf. We may update this DPA; where a change is material we will give reasonable notice in the same way as for the Terms, and the version date at the top of this page shows when it was last revised.

14. Contact

Questions about this DPA, or requests for a countersigned copy where your procurement process requires one, can be sent to [email protected].

BugScreen Limited is a private limited company registered in England and Wales, company number 17247095, with its registered office at Friarsfield, Glaisdale, Whitby, England, YO21 2PS.

bugscreen© 2026 BugScreen
AboutSolutionsCompareToolsDocsBlogChangelogTermsPrivacyContact