Controller, processor, or both?
Most SaaS products sit in two roles at once. For your own signup, billing and marketing data you are the controller. For the data your customers load into the product you are usually a processor acting on their instructions. Your public privacy policy should cover the first role and point to a data processing agreement for the second — mixing them into one document is the single most common SaaS mistake.
- Account, billing and support data you control
- Customer content you process on their behalf, and your sub-processors
- Product analytics and session-recording tools, named
- Security measures in general terms, without over-promising
- Where a DPA and sub-processor list can be requested