Legal
Data processing agreement
Last updated 8 September 2026
1What this is, and when it binds
This is the agreement under which GasBuggy Media LLC processes personal data on behalf of a customer using facets.team. It gives effect to Article 28 of the UK GDPR and of Regulation (EU) 2016/679, and it carries the standard contractual clauses for moving personal data out of the United Kingdom and the European Economic Area.
You do not need to sign it. Accepting the terms of service has the same effect as signing this document and the clauses annexed to it, and it takes effect from the moment you create an account. We will counter-sign a copy for any customer whose procurement needs one — write to privacy@facets.team — but the protection does not wait for that and never depended on it.
It applies wherever UK or EU data protection law applies to what you are doing, and it does no harm where neither does. We have not made it conditional on your telling us which you are: a customer who discovers halfway through a cycle that they have employees in Ireland should find the agreement already in place rather than discover they needed to ask for it.
2Which of us is responsible for what
You are the controller and we are the processor for everything your people put into the service: the roster, survey invitations, ratings, written comments, nominations, self-assessments, and everything in the manager tools — goals, check-ins, colleague input, performance bands and written assessments. You decide why it is collected and who is included. We process it to run the service and for no other purpose.
We are the controller, and this agreement does not apply, for the account data of the person who signs in — their name, their email address, their sign-in records — and for the ordinary operation of the public website and our billing. The privacy policy governs those, and clause 1 of it says the same thing.
The line matters more here than it usually does, because the two halves of the service sit on different sides of it in the way people expect and the same side in law. Whether a rating is developmental or a performance record changes what may be done with it under terms clauses 2A and 2B; it does not change who is the controller. You are, for both.
3What we may do with it
We process personal data only on your documented instructions. Your instructions are these terms, this agreement, and what you and your people do in the product — opening a cycle, inviting a rater, running a report. There is no other channel by which we take instruction, and a request from someone who is not an account holder is not one.
If we think an instruction breaks data protection law, we will tell you and may pause that processing until it is resolved. If a law we are subject to requires us to process beyond your instructions, we will tell you before we do unless that law forbids it.
We do not use anything your people write to train machine-learning models, and we do not sell it. Terms clause 6 permits us to compute aggregated, de-identified statistics across many organizations to improve the instrument and, in future, to publish research from them. That is the one use beyond running the service, it is described there, and clause 6 also says how to opt out of it.
4Confidentiality
Everyone we permit to touch personal data is bound to keep it confidential, by contract or by a duty that survives their leaving. Administrative access to production is limited to a small number of named operator accounts, each of which must pass a one-time code from an authenticator app before the operator console opens; the roster is revocable and report accesses are logged. Annex II gives the rest.
5Security
We keep the technical and organizational measures set out in Annex II, which describe what is in place today rather than what we intend. Where a measure has a known limit — the backup window, the absence of an off-site copy, the fact that no security audit has been completed — Annex II says so, and /security keeps the longer version. We may change a measure, and will not reduce the overall level of protection by doing so.
6Sub-processors
You give us general authorization to engage the sub-processors listed in Annex III. Each is engaged under a written contract imposing obligations equivalent to these, and we remain fully liable to you for what any of them does.
If we want to add one, we will email every workspace owner at least thirty days before it begins handling any data. Within those thirty days you may object on reasonable data-protection grounds by writing to privacy@facets.team. We will make a good-faith effort to offer you a way to keep using Facets without that provider; if we cannot, you may end the affected part of your subscription without penalty and we will refund what you have paid for time you have not used. If a provider has to be replaced at short notice to keep the service secure or running, we will tell you as soon as we reasonably can rather than thirty days ahead. This is the same commitment clause 5 of the privacy policy makes, in the same words, because it is the same promise.
7Helping you answer the people whose data it is
The product is built so that most of this does not need us. A manager can export any person’s record and any assessment at any time. A participant can be told what was collected from them, because the consent screen says it before they answer. Where a request does need us, we will help you meet it within the time the law gives you, at no charge, and if a request reaches us directly we will pass it to you rather than answer it ourselves.
There is one thing we will not do, and you should know it before you rely on this clause rather than after. We will not tell you, or anyone with an account, how a particular person rated somebody or what they wrote. Individual peer ratings have no read access for any signed-in account, results are suppressed below three raters, and written comments are never quoted verbatim. That is not a limitation on our assistance to you; it is the architecture the product is sold on, and terms clause 4 makes it an obligation on you as well.
The consequence is worth stating plainly: a subject access request cannot be used as a route to rater identity, by you, by an employee, or by us on anyone’s behalf. Where a regulator or a court orders otherwise we will comply and will tell you unless we are forbidden to.
What a requester does get, so that you can answer them. Their results as the product shows them, which they can already reach. The substance of what was written about them, in paraphrase, which is the only form it exists in for reporting. Not individual ratings tied to a rater, and not rater identity. Where paraphrase would still identify the writer — on a small team, content does that by itself — a description of the theme rather than the text, disclosed as such rather than passed off as the whole. Clause 7 of the privacy policy says the same thing to the person making the request, in the same order, and the two are meant to be read together.
We will not approach a rater for consent, and you should not either. It is the orthodox mechanism and it defeats the purpose: asking tells the rater they have been identified as one, and a declined request is itself information about them. Terms clause 4 already makes pressuring a rater a breach on your side; this is the same rule applied to us.
On who is striking this balance. You are the controller, so the Article 15(4) assessment is formally yours. We are not making it for you case by case. The constraint is a property of the system you bought — individual ratings have no read access for any account, and the floors cannot be lowered by you, by a manager, or by anyone signed in, with the single exception Annex II records: a lower floor set on one engagement cycle at your written request, never as a default, and shown on that cycle’s own page to everyone who can read its results — and it applies to every request identically, including ones you would rather answer in full. If that is not a constraint you can work within, it is better found before a cycle opens than during a request.
Rectification and erasure need the same care. An opinion is not made accurate by being corrected; what can be corrected is the record that it was expressed, and a data subject may have a statement of their own recorded beside it. Erasure of individual answers about a person removes part of an aggregate other people’s results were built from. We will help you work out which is possible in a given case.
8Breaches, assessments, and consultation
If personal data is breached we will tell you without undue delay and in any case within seventy-two hours of becoming aware — first with whatever we know at the time, which may be very little, and then in writing with the full account once we have it. We will not wait for a complete picture to make the first call. We will give you what you need for your own notifications, and we will not notify your regulator or your people on your behalf unless you ask us to or the law requires us to directly.
For a product built on people answering candidly, a breach is not only a data loss. It is an unmasking, and we treat it that way.
We will help with a data protection impact assessment or a prior consultation, and we will give you whatever description of the system a works council or equivalent consultation needs. Terms clause 4 names that obligation as yours and this is the half of it that is ours; asking us costs nothing and finding out late is expensive.
9Deleting it, and giving it back
Raw answers are deleted within 90 days of the team or organization leaving the service. That covers per-person ratings, free text, nominations, self-assessments and engagement responses — eleven tables. It is the commitment made to every participant on the consent screen before they answer.
Backups add up to seven days to that. Our database provider takes automatic daily backups and keeps them on a rolling seven-day window in the same region, so a backup taken before a deletion holds the deleted rows until it ages out. End to end that is ninety-seven days, and we would rather publish the second number than let the first imply something cleaner than the truth. There is no off-site copy and point-in-time recovery is not enabled.
Two things deliberately survive. Derived reports — evidence packs, coaching packs, briefs, engagement scorecards — are kept, because they are your record of a debrief that happened and they identify nobody once the reporting floors have been applied. And the audit log keeps its entries, including entries recording that something existed which has since been deleted; a log that could be erased by the same action it exists to record would not be a log. It holds what happened and when, not the answers.
On termination you have sixty days to export before anything is deleted, matching the notice in terms clause 7. Ask at privacy@facets.team for deletion of a team, a review, or a whole account at any other time and we will do it.
Export is on request rather than self-serve. The manager-tools export is built; coaching packs, leadership briefs and engagement scorecards are produced by hand. Ask at the same address and we will send them within thirty days. Terms clause 7 says the same thing, and neither sentence depends on a feature shipping.
10Showing you that this is true
We will give you the information you need to show that we are meeting these obligations. /security is the standing version and is written to be read by somebody evaluating us rather than somebody being reassured; our sub-processors’ own certifications are named there.
No independent security audit of Facets has been completed. There is no SOC 2 report and we do not imply one. If your procurement requires it before signing, say so early: it is a real piece of work with a real cost and a real calendar, and it belongs in an agreement as a scoped commitment rather than as a box we tick optimistically.
You may audit us once in any twelve months on reasonable written notice, or more often if a regulator requires it or after a breach affecting your data. You pay your own costs, we pay ours, and anything you learn is confidential.
11Sending it out of the UK and the EEA
We are in the United States and so is the service, so personal data coming from the UK or the EEA is transferred out of it. Two mechanisms are incorporated into this agreement and take effect without either of us signing anything further.
For the EEA: the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor). You are the data exporter, GasBuggy Media LLC is the data importer. The optional docking clause applies; the Clause 17 governing law and the Clause 18 forum are those of Ireland, unless you are established in another member state, in which case they are that state’s. Annex I, II and III below are the Annexes to those clauses.
For the UK: the same clauses as modified by the Information Commissioner’s International Data Transfer Addendum (version B1.0), which is incorporated with the tables completed by Annexes I to III below and with no additional protections selected. The importer may end the addendum where a change in UK law makes it no longer possible to comply.
We rely on the clauses rather than on adequacy, deliberately. Some of our sub-processors are certified under the EU–US Data Privacy Framework and could carry a transfer on that basis, but the framework is under appeal to the Court of Justice, the US oversight board it depends on has lacked a quorum since January 2025, and two earlier frameworks were struck down. A transfer resting on a mechanism that may not exist next year is not a protection we want to be relying on when it stops existing. Where a sub-processor is DPF-certified that is a second basis and not the first one.
Onward transfers by a sub-processor are made under its own equivalent clauses, verified against each provider’s published terms. Where those clauses conflict with these, these prevail as between you and us.
12If two documents disagree
The standard contractual clauses win over this agreement, and this agreement wins over the terms of service, in each case only on the point of conflict and only where the winning document gives more protection. A signed agreement under terms clause 1A can replace this one for the customer who signed it, and cannot reduce what a participant was told on the consent screen.
A1Annex I — the parties and the processing
Data exporter. The customer — the organization or individual that created the workspace — acting as controller. Its name, address and contact are those on its account; its activities relevant to the transfer are running team feedback surveys, leadership 360s, engagement cycles and manager tools for its own workforce.
Data importer. GasBuggy Media LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110-7825, United States, acting as processor. Contact: privacy@facets.team. Its activities relevant to the transfer are operating facets.team.
Categories of data subject. The customer’s employees, workers and contractors, in whichever of these roles they occupy: people rated by their team, people who give ratings, leaders receiving a 360, raters in a 360, respondents to an engagement cycle, managers, people managed, and colleagues asked for written input on an assessment.
Categories of personal data. Name, work email address, job role, team membership and reporting relationship; ratings on the instrument’s items; free-text answers and comments; nominations; self-assessments; engagement responses and comments; and, in the manager tools, goals, check-in notes, colleague input, performance bands and written assessments.
Special categories. None. Terms clause 2B forbids using the manager tools to record health data, beliefs, or any other special category, and the surveys have no field that asks for one. If special category data is entered anyway it is entered against instructions, and clause 3 above applies.
Frequency. Continuous for as long as the account exists.
Nature and purpose. Collecting, storing, aggregating, scoring and reporting structured feedback for the customer’s development purposes, and hosting the customer’s own performance records.
Duration. For the life of the account. Raw answers are deleted within 90 days of a team or organization leaving, plus up to seven days in backups. Derived reports and audit entries persist as clause 9 describes.
Competent supervisory authority. The supervisory authority of the EU member state in which you, as the data exporter, are established. Where you are not established in the EU but are caught by Article 3(2) and have appointed an Article 27 representative, it is the authority of that representative’s member state; where neither applies, it is the authority of a member state in which the data subjects are located. For a transfer under the UK Addendum it is the Information Commissioner’s Office. This is stated as the rule rather than as a name because the answer depends on facts about you, and naming one authority would be wrong for most customers.
A2Annex II — technical and organizational measures
Encryption. Data is encrypted at rest with AES-256 and in transit with TLS by our infrastructure providers.
Access control. Administrative access to production is limited to named operator accounts, controlled by an allowlist in the deployment configuration together with a revocable roster, and each must additionally pass a one-time code from an authenticator app before the operator console will open. Customer accounts may enable two-step verification; it is offered and not required. Report accesses are logged.
Access links. Participant links are random tokens of which only a one-way hash is stored, so an existing link cannot be looked up or read back by anyone, including us.
Segregation and least privilege. Row-level security separates one workspace from another. Individual peer ratings have no read access for any signed-in account, including the customer’s own administrators.
Data minimization in reporting. Results are suppressed below three raters and item-level results below five; unit and manager suppression apply jointly; free-text answers are paraphrased rather than quoted. These floors cannot be lowered by a customer, a manager, or anyone with an account. One exception exists and is named rather than hidden: a lower floor can be set on a single cycle at the customer’s written request, never as a default, and the cycle’s own page says so in plain sight to everyone who can read the results.
Model provider constraints. Where narrative output is enabled, the model provider receives aggregates, or comments with the writer’s identity removed, and never the confidential note to a facilitator. Its commercial terms state it may not train models on customer content. A workspace can turn model-written output off entirely, in which case every report comes from deterministic templates.
Bot protection. Cloudflare Turnstile on the sign-in form only. It is not present on any page where somebody answers a question.
Backups and recovery. Automatic daily backups on a rolling seven-day window, held in the same region as the database. No off-site copy. Point-in-time recovery is not enabled, so up to 24 hours of writes could be lost in a restore. No recovery time is published, because none has been measured.
Deletion. An automated sweep deletes raw answers across eleven tables within 90 days of a team or organization being marked as having left.
Certifications. Ours: none. Our providers’, as they state them, are listed on /security. We do not present a provider’s certification as ours.
A3Annex III — sub-processors
These four process personal data for which you are the controller:
Supabase — database, authentication and file storage. Managed PostgreSQL in AWS us-east-1, United States. Holds everything.
Vercel — application hosting, United States. Processes data in the course of serving the application.
Resend — transactional email, United States. Receives recipient addresses and message contents, including invitation links.
Anthropic — narrative report text, where a workspace has it enabled, United States. Receives what Annex II describes and never individual ratings attributable to a person.
Three companies appear in the privacy policy and deliberately not here. The lists differ for a reason and it is easier to say it than to be asked. Stripe acts as merchant of record for a purchase and decides on its own account what that requires, which makes it a separate controller rather than anyone’s sub-processor here. Cloudflare sees the IP and browser characteristics of someone opening the sign-in form, which is account data we control, and it is absent from every page where a participant answers. Google measures the public marketing site only and is never present in the application. None of the three touches personal data you control, so none is a sub-processor under this agreement, and all three are named in the privacy policy because that document answers a different question.
Each of the four uses sub-processors of its own and publishes its own list. Changes to this annex follow clause 6.
13Contact
Anything about this agreement, a data subject request, an audit, or a sub-processor objection — privacy@facets.team.