LEGAL
Data Processing Agreement (DPA) — Summary
Last updated: August 2026
This is a draft; legal review is recommended before publication.
This summary describes the key terms of the data-processing relationship between Response360 (processor) and the customer/tenant (controller). A signable full DPA is available on request.
1. Roles
For personal data of a tenant’s end users, the tenant is the “controller” and Response360 is the “processor”. Response360 processes data only per the tenant’s documented instructions and to deliver the Service.
2. Sub-processors
Approved sub-processors: AWS SES (eu-central-1 / Frankfurt), MongoDB Atlas (Frankfurt), a WhatsApp Business Platform provider (BSP), and an OpenAI-compatible AI provider. Reasonable notice is given before adding a new sub-processor.
3. Security and data residency
Data resides in the EU (Frankfurt) region. Transport encryption (TLS), access control and audit logging are applied. [Full list of technical and organizational measures is in the full DPA annex.]
4. Retention and deletion
Message/queue data is retained for a limited period via the RETENTION_DAYS TTL; upon termination, data is returned or destroyed per the tenant’s request.
5. Signable DPA
A signable full Data Processing Agreement is available on request. Please write to [email protected].