diff --git a/docs/legal/README.md b/docs/legal/README.md new file mode 100644 index 000000000..58d983a7b --- /dev/null +++ b/docs/legal/README.md @@ -0,0 +1,47 @@ +# Rybbit transfer documents + +This directory contains a counsel-ready draft of Rybbit's EU transfer package. +It is not legal advice and is not executed merely because it exists in the +repository. + +## Files + +- `rybbit-eu-scc-addendum.md` — prefilled Module Two/Module Three SCC completion + schedule, Annexes I–III, and signature blocks. +- `rybbit-eu-scc-addendum.docx` — Word version generated from the Markdown draft. +- `source/eu-standard-contractual-clauses-2021-official.doc` — unmodified + English Annex containing the European Commission's official SCC text. +- `source/eu-scc-implementing-decision-2021-official.doc` — unmodified English + Commission Implementing Decision downloaded with the SCCs. + +Official source: +https://commission.europa.eu/publications/publications-standard-contractual-clauses-sccs_en + +SHA-256 checksums at download time: + +- SCC Annex: `beb2e873edd0d34edc8c5eca5b688e5d51cb6e6f63d4f7759333a6a26f8bd1de` +- Implementing Decision: `29a194e32353edfba0ad5d74fa1cd595e4ea39a22f7a4664cdafa9fd4f3e3f1c` + +## Required before execution or publication + +1. Have privacy counsel confirm whether Rybbit's relevant processing falls + within GDPR Article 3(2), because the 2021 international SCCs are not designed + for an importer whose relevant processing is already directly subject to the + GDPR. +2. Decide whether Tomato.gg LLC will certify under the EU-U.S. Data Privacy + Framework and, if so, update the transfer-mechanism language. +3. Reconcile the post-termination deletion promise: the current DPA says 30 + days; the current Terms and Security page say 60 days. +4. Confirm that each security statement in Annex II matches production, + especially encryption at rest, backup handling, employee training, and + deletion propagation. +5. Confirm the complete subprocessor inventory, legal names, processing + locations, transfer mechanisms, and contracts. In particular, confirm + OpenRouter/model-provider coverage and Stripe's role. +6. Update the Terms so the DPA and SCC Addendum are expressly part of the + Agreement and establish an order of precedence. +7. Add a binding acceptance mechanism or obtain signatures. Publishing an + unsigned document alone does not execute the SCCs. +8. Complete and retain a transfer impact assessment for any transfer relying on + the SCCs. + diff --git a/docs/legal/rybbit-eu-scc-addendum.docx b/docs/legal/rybbit-eu-scc-addendum.docx new file mode 100644 index 000000000..5d184d2cf Binary files /dev/null and b/docs/legal/rybbit-eu-scc-addendum.docx differ diff --git a/docs/legal/rybbit-eu-scc-addendum.md b/docs/legal/rybbit-eu-scc-addendum.md new file mode 100644 index 000000000..9653e0831 --- /dev/null +++ b/docs/legal/rybbit-eu-scc-addendum.md @@ -0,0 +1,399 @@ +# Rybbit EU Standard Contractual Clauses Addendum + +> **Draft for legal review — not yet executed.** This document completes the +> European Commission Standard Contractual Clauses for the Rybbit hosted +> service using facts currently documented by Rybbit. It becomes binding only +> when it is validly incorporated into the agreement with a Customer or signed +> by both parties. Bracketed review notes must be resolved before publication. + +Effective date: The date on which the Customer accepts or signs the Agreement +that expressly incorporates this Addendum. + +This EU Standard Contractual Clauses Addendum (the **SCC Addendum**) forms part +of the agreement governing the Customer's use of the hosted Rybbit service (the +**Agreement**) between the Customer and **Tomato.gg LLC**, doing business as +Rybbit (**Rybbit**). Capitalized terms not defined here have the meanings given +in the Agreement or the Standard Contractual Clauses. + +## 1. Incorporation of the SCCs + +For a transfer of personal data governed by Regulation (EU) 2016/679 (the +**GDPR**) to Rybbit in the United States that is not covered by an adequacy +decision or another valid transfer mechanism, the parties enter into and agree +to be bound by the standard contractual clauses contained in the Annex to +European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the +**SCCs**). + +The official, unmodified English SCCs downloaded from the European Commission +are stored with this draft at: + +`source/eu-standard-contractual-clauses-2021-official.doc` + +The SCCs are completed by Sections 2 through 6 of this SCC Addendum. If there is +a conflict between the SCCs, this SCC Addendum, the DPA, and the Agreement, the +documents prevail in that order. + +This SCC Addendum does not itself determine whether Rybbit's relevant processing +is directly subject to GDPR Article 3(2). **[LEGAL REVIEW REQUIRED: confirm that +the 2021 SCCs may be used for each covered transfer, or adopt EU-U.S. Data +Privacy Framework certification or another valid mechanism.]** + +## 2. Modules and clause selections + +The following selections apply: + +1. **Module Two (controller to processor)** applies where the Customer is a + controller and Rybbit processes Customer Personal Data as its processor. +2. **Module Three (processor to processor)** applies where the Customer is a + processor acting on behalf of another controller and Rybbit processes + Customer Personal Data as its subprocessor. +3. The optional docking clause in Clause 7 does not apply. +4. In Clause 9, **Option 2 (general written authorization)** applies. Rybbit + will give at least **30 days' prior written notice** of the addition or + replacement of a subprocessor. Notice may be provided by email, through the + service, or through an update to a public subprocessor list where the + Customer can subscribe to updates. The Customer may object on reasonable + data-protection grounds by contacting `hello@rybbit.com` during that period. + Where Module Three applies, the Customer confirms that its controller has + granted the required general authorization and the Customer will promptly + pass Rybbit's subprocessor notices to that controller. +5. The optional independent-dispute-resolution language in Clause 11(a) does + not apply. +6. For Clause 13, the paragraph applicable to the relevant Data Exporter's + establishment or GDPR Article 3(2) status applies. +7. In Clause 17, **Option 1** applies and the SCCs are governed by the law of + **Ireland**. +8. Under Clause 18(b), disputes will be resolved by the courts of **Ireland**. +9. Annex I is completed by Sections 3 and 4 below, Annex II by Section 5, and + Annex III by Section 6. +10. Entering into the Agreement that expressly incorporates this SCC Addendum, + or signing this SCC Addendum, constitutes execution of the SCCs and their + completed Appendix on the Effective Date. + +## 3. Annex I.A — List of parties + +### Data exporter + +Name: The Customer identified in the Agreement, order form, or Rybbit account. + +Address: The Customer address identified in the Agreement, order form, or +Rybbit account. + +Contact person's name, position, and contact details: The Customer account owner +or other privacy contact identified in the Agreement, order form, or Rybbit +account. Any applicable data protection officer or EU representative is the +person identified by the Customer in those records. + +Activities relevant to the data transferred under these Clauses: Configuring +and using the hosted Rybbit web and product analytics service, including +transmitting or making Customer Personal Data available to Rybbit for the +processing described in Annex I.B. + +Signature and date: The parties agree that the Customer's valid acceptance or +signature of the Agreement that expressly incorporates this SCC Addendum +constitutes its signature of the SCCs on the Effective Date. + +Role: + +- Controller when Module Two applies. +- Processor when Module Three applies. + +### Data importer + +Name: **Tomato.gg LLC**, doing business as Rybbit. + +Address: **1276 Rothwell Dr, Troy, Michigan 48084, United States**. + +Contact person with responsibility for data protection: **Rybbit Privacy Team, +hello@rybbit.com**. + +Activities relevant to the data transferred under these Clauses: Providing, +securing, supporting, and maintaining the hosted Rybbit web and product +analytics service as described in Annex I.B and the Agreement. + +Signature and date: The parties agree that Rybbit's valid acceptance or +signature of the Agreement that expressly incorporates this SCC Addendum +constitutes its signature of the SCCs on the Effective Date. + +Role: **Processor**. + +## 4. Annex I.B — Description of the transfer + +### Categories of data subjects + +Customer determines the data subjects whose personal data is submitted to the +service. They may include: + +- visitors to and users of the Customer's websites, applications, products, + and other digital properties; +- the Customer's customers, prospective customers, end users, employees, + contractors, and other individuals whose activity the Customer measures; +- individuals the Customer identifies through Rybbit's optional identify and + user-profile functionality; and +- Customer personnel and authorized users, but only to the extent their data is + processed by Rybbit on the Customer's behalf rather than by Rybbit as an + independent controller for account administration, billing, security, or its + own legal obligations. + +### Categories of personal data transferred + +Depending on the features enabled and the Customer's configuration, Customer +Personal Data may include: + +- page and navigation data, including URLs, URL paths, query parameters, page + titles, referrers, entry and exit pages, timestamps, session duration, and + user journeys; +- event and interaction data, including page views, clicks, copied text, + outbound links, form-submission metadata, event names, event properties, + goals, funnel activity, feature-flag exposure, and Customer-defined custom + events; +- device and technical data, including IP address processed transiently for + routing, security, geolocation, and identifier generation; IP address stored + when the Customer expressly enables IP storage; user-agent, browser and + version, operating system, device type, language, screen or viewport + dimensions, timezone, and related client signals; +- approximate location derived from IP address, which may include country, + region, city, latitude, and longitude; +- pseudonymous identifiers, including session identifiers, user or device + identifiers derived from IP address and user-agent, and related aliases; +- identifiers and profile data supplied through optional identification + features, including Customer-assigned user IDs and Customer-defined user + traits such as name, email address, account, plan, role, company, or other + attributes selected by the Customer; +- session-replay data, including DOM content, displayed text, clicks, pointer + movement, scrolling, viewport changes, and form interactions, subject to + default and Customer-configurable masking controls; +- diagnostic and performance data, including JavaScript error messages and + stack traces, network or page-performance measurements, and web-vitals data; +- imported analytics records and other data the Customer submits through the + service, API, SDKs, MCP tools, support channels, or integrations; +- natural-language analytics prompts, current queries, and prompt history sent + when the Customer uses optional AI query-generation functionality; and +- any other personal data the Customer elects to include in custom events, + properties, traits, URLs, page content, replays, imports, prompts, or support + requests, subject to the Agreement. + +### Sensitive data and safeguards + +The service is not designed for special-category data under GDPR Article 9, +criminal-conviction data under GDPR Article 10, payment-card data, government +identifiers, passwords, authentication secrets, or similarly sensitive data. +The Customer must not submit such data unless the parties expressly agree and +the Customer has established a lawful basis and appropriate safeguards. + +If sensitive data is nevertheless included in Customer-controlled fields or +content, the safeguards in Annex II apply, including purpose limitation, +role-based access, confidentiality obligations, encryption, logging, +pseudonymization where supported, and Customer-configurable URL, text, and input +masking. The Customer is responsible for configuring collection and masking to +avoid unnecessary sensitive data. + +### Frequency of the transfer + +Continuous or recurring for tracking and service operation, and occasional for +imports, support, configuration, deletion, export, and other Customer-initiated +operations, for the duration of the Agreement. + +### Nature of the processing + +Receiving, transmitting, collecting, recording, organizing, structuring, +pseudonymizing, deriving approximate geolocation, storing, retrieving, +consulting, analyzing, aggregating, displaying, exporting, securing, supporting, +restricting, deleting, and otherwise processing Customer Personal Data on the +Customer's documented instructions to provide the service. + +### Purposes of the transfer and further processing + +- provide web and product analytics, reports, dashboards, funnels, goals, + journeys, retention analysis, user profiles, session replay, error tracking, + web-vitals reporting, feature flags, experiments, APIs, exports, and related + features selected by the Customer; +- authenticate and authorize Customer-directed access to Customer Personal + Data; +- maintain, secure, monitor, troubleshoot, and support the service; +- respond to Customer instructions and data-subject requests; and +- delete or return Customer Personal Data as required by the Agreement. + +Rybbit will not process Customer Personal Data for advertising or sell it. + +### Retention + +Subject to Customer configuration and any written order form: + +- hosted analytics data is retained for **3 years on Standard plans, 5 years on + Pro plans, and for the configured or agreed period on Enterprise plans**; +- session-replay events are ordinarily retained for **30 days**; +- data is retained for the term of the Agreement and the applicable plan or + feature retention period; and +- following termination, Rybbit will delete or return Customer Personal Data at + the Customer's choice and delete remaining copies within **30 days**, except + where applicable law requires retention. + +**[OPERATIONAL REVIEW REQUIRED: Rybbit's current DPA promises deletion within +30 days, while the current Terms and Security page say 60 days. Confirm that the +30-day commitment is operationally achievable or change all documents to one +accurate period before execution.]** + +### Transfers to subprocessors + +The subject matter, nature, and duration of processing by each subprocessor are +described in Annex III. Each subprocessor processes data only for the duration +necessary to provide its services to Rybbit, subject to its agreement with +Rybbit and applicable deletion or return requirements. + +## Annex I.C — Competent supervisory authority + +The competent supervisory authority is determined under Clause 13(a) for the +relevant Data Exporter: + +- if the Data Exporter is established in an EU Member State, the supervisory + authority responsible for the Data Exporter's compliance with the GDPR; +- if the Data Exporter is subject to GDPR Article 3(2) and has appointed an EU + representative, the authority of the Member State in which that + representative is established; or +- if the Data Exporter is subject to GDPR Article 3(2) but is exempt from + appointing a representative, a supervisory authority in a Member State where + affected data subjects are located. + +## 5. Annex II — Technical and organizational measures + +Rybbit maintains the following measures for the hosted service. Measures apply +as appropriate to the relevant processing and may evolve to maintain or improve +security without materially reducing the overall level of protection. + +### Governance, confidentiality, and access + +- Access to Customer Personal Data is limited to authorized personnel with a + service, support, security, or operational need. +- Authorized personnel are subject to confidentiality obligations and receive + security training. +- Customer access is controlled through authenticated accounts, organization + and site membership, assigned roles, and scoped API credentials. +- Passwords are salted and hashed rather than stored in plaintext. User sessions + expire after 14 days of inactivity. +- Administrative and database access is restricted and separated from public + application access. + +### Infrastructure and network protection + +- Primary hosted-service application and database infrastructure is operated on + Hetzner servers located in Germany. +- Database servers are not exposed to the public internet and are protected by + private networks and firewall rules that restrict access to authorized + application and administrative systems. +- The service uses Cloudflare for edge security and object storage for hosted + session-replay payloads. +- Rybbit applies security updates, dependency monitoring, automated testing, + infrastructure monitoring, and a vulnerability-disclosure process. + +### Encryption and transmission controls + +- Data is encrypted in transit using HTTPS/TLS. +- Customer Personal Data is encrypted at rest. +- Hosted session-replay payloads stored in Cloudflare R2 are encrypted before + storage. +- Credentials and secrets are not intentionally included in source code or + Customer-facing responses and are restricted to authorized systems and + personnel. + +### Minimization, pseudonymization, and privacy controls + +- By default, raw visitor IP addresses are used transiently for routing, + security, approximate geolocation, and pseudonymous identifier generation + and are not stored as raw IP addresses. Raw IP storage occurs only when the + Customer expressly enables that setting. +- Visitor identifiers are generated from IP address and user-agent information + using hashing; Customers can enable daily-rotating salts to reduce linkage + across days. +- Rybbit does not require cookies or browser local storage for its default + analytics tracking. +- Session replay masks all input values by default. Customers can configure + additional text-selector, input-type, URL-path, and content masking and can + disable replay entirely. +- Customers control optional identification, IP storage, session replay, error + tracking, web-vitals, autocapture, custom-event, trait, and import features. + +### Logging, monitoring, testing, and incident response + +- Rybbit monitors infrastructure and account activity and maintains incident + response procedures. +- Security events and service errors are logged to the extent necessary for + investigation, reliability, and security. +- Rybbit acknowledges vulnerability reports and coordinates remediation through + its published security contact. +- If Rybbit becomes aware of a personal data breach affecting Customer Personal + Data, it will investigate, mitigate, document, and notify the Customer without + undue delay with the information available to it, and provide further + information as it becomes available. + +### Availability, backup, deletion, and recovery + +- Hosted infrastructure is monitored continuously and Customer data is backed + up daily. +- Rybbit maintains mechanisms to delete individual users, sessions/replays, + sites, and accounts and to delete or return Customer Personal Data after + termination. +- Deletion requests cover relevant primary analytics records, profile and alias + records, and hosted replay payloads, subject to propagation time and lawful + retention requirements. +- Rybbit regularly patches and updates the hosted service and uses automated + testing before deployment. + +### Subprocessor management + +- Subprocessors are subject to written data-protection obligations appropriate + to the services they provide. +- Rybbit evaluates the service and transfer mechanism used for subprocessors + and remains responsible for their processing to the extent required by the + SCCs and applicable law. +- Rybbit provides prior notice of additions or replacements as described in + Section 2. + +### Assistance to the Data Exporter + +Taking into account the nature of processing and the information available to +it, Rybbit provides reasonable assistance with data-subject requests, security +obligations, breach notifications, data-protection impact assessments, and +consultation with supervisory authorities as required by the SCCs and the DPA. + +## 6. Annex III — List of subprocessors + +The Customer generally authorizes the following subprocessors, subject to the +notice and objection procedure in Section 2. + +| Subprocessor | Location | Processing | Duration | Transfer safeguard | +| --- | --- | --- | --- | --- | +| **Hetzner Online GmbH** | Germany | Primary hosted application, database, server, storage, networking, and backup infrastructure | Service term plus deletion/return period | Processing in the EEA; no Chapter V transfer for EEA processing | +| **Cloudflare, Inc.** | United States and global infrastructure | Edge network and security services; Cloudflare R2 object storage for hosted session-replay payloads | Service term plus deletion/return period | EU-U.S. Data Privacy Framework for covered US transfers; Cloudflare DPA and SCCs as fallback or for other restricted transfers | +| **Plus Five Five, Inc. (Resend)** | United States | Transactional email delivery, authentication messages, service notifications, and Customer-directed email reports | Duration of relevant email and service processing | EU-U.S. Data Privacy Framework for covered US transfers; Resend DPA and SCCs as fallback | +| **OpenRouter, Inc.** | United States; model-provider location varies | Optional AI query generation. Processes Customer prompts, current queries, prompt history, and related technical context; model providers may process prompts according to the selected routing and provider terms | Only while the optional feature is used, plus provider deletion/retention period | OpenRouter DPA incorporating Module Two SCCs and applicable agreements with model providers **[COMMERCIAL REVIEW REQUIRED: confirm Rybbit's account is covered by the cited DPA and document enabled model providers and retention settings.]** | + +Stripe processes Rybbit subscription and billing information. Stripe ordinarily +acts as an independent controller or as Rybbit's processor for Rybbit account +administration rather than as a subprocessor of Customer Analytics Data, so it +is not listed in Annex III. **[LEGAL REVIEW REQUIRED: confirm this role +classification against Rybbit's Stripe configuration and customer checkout +flow.]** + +## 7. Signatures + +This signature block may be used where the SCC Addendum is not incorporated by +a valid electronic acceptance mechanism. + +### Customer / Data Exporter + +Legal name: ______________________________________________ + +By: ______________________________________________________ + +Name and title: __________________________________________ + +Date: ____________________________________________________ + +### Tomato.gg LLC d/b/a Rybbit / Data Importer + +By: ______________________________________________________ + +Name and title: __________________________________________ + +Date: ____________________________________________________ diff --git a/docs/legal/source/eu-scc-implementing-decision-2021-official.doc b/docs/legal/source/eu-scc-implementing-decision-2021-official.doc new file mode 100644 index 000000000..db750c7cb Binary files /dev/null and b/docs/legal/source/eu-scc-implementing-decision-2021-official.doc differ diff --git a/docs/legal/source/eu-standard-contractual-clauses-2021-official.doc b/docs/legal/source/eu-standard-contractual-clauses-2021-official.doc new file mode 100644 index 000000000..23303a5fe Binary files /dev/null and b/docs/legal/source/eu-standard-contractual-clauses-2021-official.doc differ diff --git a/docs/src/app/[locale]/(home)/dpa/page.tsx b/docs/src/app/[locale]/(home)/dpa/page.tsx index d6c6f52bc..af1b0027a 100644 --- a/docs/src/app/[locale]/(home)/dpa/page.tsx +++ b/docs/src/app/[locale]/(home)/dpa/page.tsx @@ -101,9 +101,6 @@ export default function DataProcessingAgreement() {
When processing visitor data, IP addresses are only used temporarily to determine geographic location (country - and region) using{" "} - - Maxmind - - . The actual IP addresses are never stored in our database, preserving visitor anonymity while still providing - geographic insights to website owners. + and region) using a locally hosted MaxMind GeoLite2 database. IP addresses are not sent to MaxMind. The actual + IP addresses are never stored in our database, preserving visitor anonymity while still providing geographic + insights to website owners.