RResponse360
← Back to home

LEGAL

Data Processing Agreement (DPA) — Summary

Last updated: August 2026

This is a draft; legal review is recommended before publication.

This summary describes the key terms of the data-processing relationship between Response360 (processor) and the customer/tenant (controller). A signable full DPA is available on request.

1. Roles

For personal data of a tenant’s end users, the tenant is the “controller” and Response360 is the “processor”. Response360 processes data only per the tenant’s documented instructions and to deliver the Service.

2. Sub-processors

Approved sub-processors: AWS SES (eu-central-1 / Frankfurt), MongoDB Atlas (Frankfurt), a WhatsApp Business Platform provider (BSP), and an OpenAI-compatible AI provider. Reasonable notice is given before adding a new sub-processor.

3. Security and data residency

Data resides in the EU (Frankfurt) region. Transport encryption (TLS), access control and audit logging are applied. [Full list of technical and organizational measures is in the full DPA annex.]

4. Retention and deletion

Message/queue data is retained for a limited period via the RETENTION_DAYS TTL; upon termination, data is returned or destroyed per the tenant’s request.

5. Signable DPA

A signable full Data Processing Agreement is available on request. Please write to [email protected].