Data Processing Agreement
Last updated August 25, 2026
This Data Processing Agreement ("DPA") is between the customer using Managed Telebugs ("Customer") and Kyrylo Silin PE, trading as Telebugs ("Telebugs"). It is part of the Managed Terms of Service. It applies when Telebugs handles personal data in Customer's error data and related content.
1. Who does what
Customer is the controller and Telebugs is the processor. Customer decides what data to send and why. Telebugs processes it only to provide, secure, support, maintain, and back up Customer's Managed instance, or to follow Customer's other written instructions.
Each party must follow the data protection laws that apply to it. Customer is responsible for having a lawful reason to collect and send the data. If we believe an instruction breaks the law, we will tell Customer unless the law forbids us from doing so.
2. How we use and protect the data
We will not sell Customer data, use it for targeted advertising, or use it to train general-purpose AI models. Anyone we allow to access it must keep it confidential and may access only what is needed for their work.
We use security measures appropriate to the risk, including those in Annex 2. We may change these measures as technology and risks change, but we will not materially reduce the overall protection of the service.
3. Help with privacy duties
Taking into account the service and the information available to us, we will reasonably help Customer with data subject requests, security and breach duties, data protection impact assessments, regulator questions, and proof of compliance with this DPA.
If someone contacts us about personal data controlled by Customer, we will direct that person to Customer unless the law requires us to act.
4. Data breaches
We will tell Customer without undue delay after we confirm a personal data breach affecting Customer data. We will share the information we reasonably have about what happened, the affected data, likely effects, and what we are doing about it. We will provide updates as we learn more.
5. Subprocessors
Customer allows Telebugs to use subprocessors to provide the service. We require them to protect Customer data and remain responsible for their work under this DPA. Our current infrastructure subprocessor is:
- Hetzner Online GmbH: hosting, storage, network, and backups.
We will give at least 14 days' notice before adding a subprocessor that handles Customer data, unless an urgent security, legal, or service continuity issue makes that impractical. Customer may object for a reasonable privacy reason. If we cannot resolve the concern, Customer may cancel the affected service before the new subprocessor starts.
6. Data location and international transfers
Customer chooses an available hosting region. We will not move the primary instance to another region without permission unless the law requires it. Support or security access may come from outside the chosen region.
When personal data is transferred from the European Economic Area, Switzerland, or the United Kingdom to a country without an approved transfer basis, the legally applicable Standard Contractual Clauses are part of this DPA. For EEA transfers, this is Module Two of the European Commission clauses adopted by Decision 2021/914, with Customer as data exporter and Telebugs as data importer. The annexes below describe the processing and security measures.
7. Deletion
Customer may export its data while the service is active. After access ends, we will return or delete personal data where reasonably possible. We delete remaining data within 90 days, including protected backups as they rotate out, unless the law requires longer storage. Until deletion, this DPA continues to protect the data.
8. Proof and audits
On reasonable written request, we will provide information needed to show that we follow this DPA. Customer may audit us once a year, or after a breach or regulator request. Audits must start with available records, use reasonable notice, protect other customers and confidential data, and avoid unnecessary disruption. Customer pays its audit costs unless the audit finds that we materially broke this DPA.
9. Legal requests and conflicts
If the law requires us to use or disclose Customer data beyond Customer's instructions, we will tell Customer first unless the law forbids notice. Where practical, we will challenge requests that appear unlawful or too broad.
This DPA controls if it conflicts with the Managed Terms about processing personal data. The liability terms in the Managed Terms also apply here, unless the law says otherwise. Questions can be sent to [email protected].
Annex 1: What we process
Purpose and length: We receive, store, organize, search, display, transmit, back up, secure, support, and delete application error data for the trial or subscription, followed by the deletion period in this DPA.
People: Customer's users, staff, contractors, clients, application users, and anyone whose data appears in an error report.
Data: Names, usernames, email addresses, account IDs, IP addresses, device and application data, error messages, stack traces, breadcrumbs, request data, tags, source maps, attachments, comments, project settings, and other data Customer chooses to send.
Telebugs is not intended for card data, government IDs, passwords, private keys, health records, or similarly sensitive data unless the parties agree in writing that the service is suitable for it.
Annex 2: Security measures
- a separate private instance for each Managed customer;
- TLS for public endpoints and administrative access;
- restricted administrative access and account permissions;
- routine software and security updates;
- backups, restoration procedures, and service monitoring;
- confidentiality duties for people with access;
- incident investigation and notification procedures; and
- data export and deletion procedures.