Subido PlatformRoadmapAIDevelopersPricingSign inStart free

Privacy Policy

Last updated: 9 June 2026

This policy explains how Subido handles personal data—both the data of the people who run feedback portals on Subido ("admins"), and the data of the people who use those portals ("voters").

Plain-language summary, not a substitute for the full text. Subido is a platform that other companies use to collect feedback from their own users. For most voter data, the company running the portal is the controller and Subido is the processor acting on their instructions. See section 3 for what that means for you.

Contents

  1. Who we are
  2. Scope of this policy
  3. Controller vs. processor
  4. Data we collect
  5. How we use data
  6. Legal bases
  7. Email & consent
  8. Sharing & sub-processors
  9. International transfers
  10. Retention
  11. Your rights
  12. Security
  13. Cookies
  14. Changes
  15. Contact

1. Who we are

Subido is operated by [SUBIDO LEGAL ENTITY NAME], a company registered in [JURISDICTION] under company number [NUMBER], with its registered office at [REGISTERED ADDRESS] ("Subido", "we", "us"). For privacy questions and data-protection requests, contact privacy@subido.io.

Where this policy refers to our role under the UK GDPR and EU GDPR, references to "GDPR" mean both as applicable.

2. Scope of this policy

This policy covers personal data processed through the Subido marketing site (subido.io), the Subido application (dash.subido.io), the hosted feedback portals we serve on behalf of admins, and our API, MCP server, and embeddable widget.

It does not cover third-party websites we link to, or how an admin uses voter data outside Subido once they export it.

3. Controller vs. processor — the important part

Subido plays two different roles depending on whose data is involved:

  • We are the controller for data about our own customers—the admins and team members who hold Subido accounts. We decide why and how that data is processed (billing, authentication, support, product analytics).
  • We are the processor for the voter data inside a workspace—the posts, votes, comments, and email addresses collected through a portal. The admin's organisation is the controller: they decide what to collect, why to email their voters, and on what legal basis. We process that data on their documented instructions under our Data Processing Addendum.

This allocation follows from who decides the purpose of the processing, not from whose branding or email-sending credentials are used. It is the same whether a portal is white-labelled on a custom domain or served on a subido.io subdomain.

If you are a voter and want to exercise your rights over your data, your request is usually best directed to the organisation running the portal (the controller). We will assist them, and we will help you reach them — see section 11.

4. Data we collect

CategoryExamplesOur role
Account dataAdmin name, email, workspace name, role, brand settingsController
AuthenticationMagic-link tokens, sign-in timestamps, IP at sign-in, optional Turnstile signalsController
BillingPlan, billing contact; card data is handled by our payment provider, not stored by usController
Voter contentPosts, comments, votes, attachments submitted to a portalProcessor
Voter identityVoter email, display name, vote/comment history, email preferences and consent stateProcessor
Usage & logsPages viewed, feature events, error logs, request metadataController (for our analytics) / Processor (within a workspace)

5. How we use data

As controller, we use account, authentication, billing, and usage data to provide and secure the service, authenticate sign-ins, take payment, provide support, understand product usage in aggregate, and meet legal obligations.

As processor, we use voter data only to operate the portal as instructed by the admin: storing and displaying posts and votes, sending the notifications the admin configures, and exposing the data back to the admin through the dashboard, API, and exports. We do not use voter data for our own marketing, and we do not sell personal data.

6. Legal bases (GDPR)

Where we act as controller, we rely on: contract (to provide the service you signed up for), legitimate interests (securing the service, preventing abuse, basic product analytics), consent (where required, e.g. certain cookies or marketing email), and legal obligation (tax, accounting).

Where we act as processor, the legal basis for processing voter data is determined by the admin as controller. Our processing is carried out on their behalf under the DPA.

7. Email & consent

Subido sends two kinds of email: transactional messages required to operate an account (magic-link sign-in, team invites), and portal-activity notifications that an admin chooses to send to their voters (status changes, new comments, changelog announcements).

For voter notifications, Subido provides consent controls that the admin selects. The default behaviour is opt-in: voters are not sent activity email unless they have opted in. Admins may, where lawful for their recipients, choose an opt-out mode instead. The legality of opt-out email depends on where the recipients are located — opt-out is generally permitted for US recipients under CAN-SPAM, while the EU, UK, Canada, and other jurisdictions generally require explicit opt-in. The admin, as controller, is responsible for ensuring the mode they choose is lawful for their recipients.

Where an admin sends through Subido's shared email infrastructure, only the opt-in mode is available. Every activity email includes a one-click unsubscribe link, and voters can opt out of all activity email at any time.

8. Sharing & sub-processors

We do not sell personal data or share it for others' marketing. We share data with vendors who process it on our behalf ("sub-processors"), each under contractual data-protection terms:

Sub-processorPurposeData
PostmarkTransactional & notification email (shared-email path)Recipient email, message content
[HOSTING PROVIDER]Application & database hostingAll stored data
[CDN / FILE STORAGE]Attachment & media hostingUploaded files
[PAYMENT PROVIDER]Subscription billingBilling contact, payment method
[ANALYTICS / ERROR MONITORING]Product analytics, error logsUsage events, request metadata

Admins who connect their own Postmark or SMTP account send notification email through their own provider; in that case that provider is the admin's vendor, not ours. A current sub-processor list is available on request, and our DPA describes how we notify customers of changes.

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition (with notice where required).

9. International transfers

We may process data in countries other than where you are located, including the United States. Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with supplementary measures where needed. Details are available at privacy@subido.io.

10. Retention

As controller, we keep account data for as long as your account is active and for a reasonable period afterward to meet legal and accounting obligations, then delete or anonymise it.

As processor, we retain voter data for as long as the admin's workspace exists. When an admin deletes a post, voter, or workspace, the data is removed in line with our deletion routines; deleting a workspace removes its voter data. Backups are retained on a rolling basis and overwritten in the ordinary course.

11. Your rights

Subject to your jurisdiction, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. Residents of the EEA/UK have these under GDPR; residents of certain US states (e.g. California) have analogous rights.

If you hold a Subido account, contact us at privacy@subido.io and we will handle your request as controller. If you are a voter on a portal, the organisation running that portal is the controller of your data; direct your request to them, and we will support them in responding. If you are unsure who that is, contact us and we will help route your request.

You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in the EEA, your local authority.

12. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, rate-limited passwordless authentication, scoped API keys, HMAC-signed webhooks, and network-hardened infrastructure. No system is perfectly secure, but we work to protect data and to notify affected parties of breaches as required by law.

13. Cookies

We use a small number of cookies and similar technologies. See our Cookie Notice for details and choices.

14. Changes

We may update this policy from time to time. We will post the new version here with a revised "last updated" date and, for material changes, provide additional notice where required.

15. Contact

Questions or requests: privacy@subido.io, or write to [SUBIDO LEGAL ENTITY NAME], [REGISTERED ADDRESS].

This page is a plain-English draft to describe how the product is designed. It is not legal advice, and the precise wording — especially around processor liability, international transfers, and consent — should be reviewed by a privacy lawyer before you rely on it.

Subido

Overview · Platform · Developers · Pricing · Sign in
Privacy · Terms · DPA · Cookies ·

© 2026 Subido · Public roadmaps & customer feedback

We use a few cookies. Essential cookies keep Subido working. We'd also like to set optional analytics cookies to improve the product—only with your consent. See our Cookie Notice.