This page tracks material changes to ProductLift's legal documents. Editorial fixes, typos, broken links, and non-substantive rewording are generally not listed. For sub-processor changes, customers with a signed Data Processing Agreement also receive notice in accordance with that agreement.
If you are a ProductLift customer and need a prior version of any document for your records, contact us at [email protected].
September 7, 2026
Subprocessors: no change to the list. Added a section clarifying that integrations you connect with your own credentials (Slack, Jira, Azure DevOps, HubSpot, webhooks, your own Stripe account or email provider) are not sub-processors, and that the fetch service used for admin-triggered import of public web pages receives no personal data.
Privacy Statement: disclosed the use of PostHog (EU-hosted) for onboarding analytics of account holders; corrected a garbled sentence in the "Security of Personal Data" section and linked it to DPA Annex 3 and the Security page.
Security page: rewritten to match the DPA and our current infrastructure. Backup retention corrected from 90 to 60 days (in line with the August 13 privacy and DPA change); removed references to desktop and mobile apps, an on-call team and workstation policies that did not describe our setup; added the current authentication options (two-factor, Entra ID SSO), backup immutability, recovery objectives and our position on certifications.
August 13, 2026
DPA: backup carve-outs added to Article 4.4, Article 5.2, and new Article 11.3 to clarify that erasure obligations apply to the active production environment and that data in encrypted backups is deleted on backup rotation (see Annex 3, section 4).
DPA: Annex 3 §4 now documents that backup storage is append-only; §9 now describes backups as immutable once written. No change to the 60-day retention already in place.
DPA: references to "Dutch Data Protection Authority" in Articles 9.5 and 13.1 replaced with "competent supervisory authority" so the wording works for Controllers established in any EEA member state.
DPA: Article 6.1 EEA-processing list expanded to include Bunny.net (Slovenia) and Mailgun (EU endpoint, Frankfurt). No new data flows; both were already sub-processors.
Privacy Statement: server-log and backup retention aligned from 90 days to 60 days to match DPA Annex 3.
Subprocessors: Boei processing location corrected from Utrecht (registered office) to Nuremberg, Germany (actual hosting). Notes clarified that Boei is operated by Ruby Foundry B.V., the same legal entity as ProductLift, and is listed for transparency.
August 5, 2026
DPA: added Article 9a (assistance with the Controller's obligations under Articles 32-36 GDPR) and Annex 3 (Technical and Organisational Measures). Only increases the Processor's obligations; no existing customer protection is reduced.
DPA: corrected Article 4.1, which previously contained a copy-paste of the applicability clause. Article 4.1 now sets out the term/commencement of the Agreement as intended.
August 3, 2026
Subprocessors: removed DigitalOcean, LLC. Hetzner Online GmbH (already an authorised sub-processor) is now the sole primary hosting provider and also holds encrypted backups; region updated to Falkenstein, Germany. AWS S3 scope reduced to static asset storage only (no backups). Mailgun processing was already in the EU region, corrected on the list to Frankfurt, Germany.
DPA: Article 6 (International Data Transfers) updated to reflect the removal of DigitalOcean and the corrected Mailgun EU region; Mailgun removed from the list of US transfers. Annex 1 snapshot refreshed to match the current Subprocessors page.
May 29, 2026
Subprocessors: added BunnyWay d.o.o. (Bunny.net) (Slovenia, EU) as a sub-processor for CDN delivery of static assets via origin pull.
April 17, 2026
Published a standalone Subprocessors page as the authoritative list and as Annex 1 of the DPA. Hetzner, Anthropic, and Google added.
Privacy Statement: added sections for AI-powered features, international data transfers, and a structured list of retention periods.
Cookie Statement: rewritten to cover both productlift.dev and app.productlift.dev with explicit per-cookie tables. Hotjar and Facebook Pixel references removed.
Terms: added 60-day notice for price changes, 30-day notice for material amendments (with opt-out), and an SLA carve-out.
EULA: renumbered articles to remove the missing-Article-3 gap and fixed the affected cross-references.
Affiliate Terms: replaced the [Date] placeholder in the effective date and refreshed related sections.
April 6, 2026
Rebranded the operating entity across all legal documents to Ruby Foundry B.V. (trading as ProductLift). New KVK (99995662), BTW (NL869219789B01), and registered address (Mulderstraat 35).
March 3, 2026
DPA: restructured to add a purpose-limitation article, an international-data-transfers article with legal bases (DPF / SCCs), formal sub-processor governance, and dedicated Annex 1 (sub-processors) and Annex 2 (processing details).
About this changelog
We only list material changes, things that alter rights, obligations, data flows, liability, or the list of sub-processors. Editorial fixes (typos, broken links, renumbering, reworded sentences with the same meaning) are not listed. The "effective date" at the top of each legal document reflects the latest version; prior versions are available to customers on request.