This Data Processing Addendum forms part of the ReplyOS Terms of Service between Reply Intelligence Group Ltd (Company No. 17040048), registered office Flat 14, 2, Stewart Court, Colnhurst Road, Watford, United Kingdom, WD17 4BW (“the Company”) and the Customer. ReplyOS is the Company’s product. The Company is registered with the Information Commissioner’s Office under registration number ZC192287.
1. Definitions
In this Addendum:
- Controller, Processor, Personal Data, Data Subject, and Process have the meanings given in applicable data protection law.
- Customer is the controller, or where applicable the processor acting on behalf of another controller, that uses ReplyOS.
- The Company is the processor in respect of Customer Personal Data processed on behalf of Customer through the service.
2. Scope
This Addendum applies where the Company processes Customer Personal Data on behalf of Customer in connection with the provision of the service.
3. Subject Matter and Duration
The subject matter of processing is the provision of ReplyOS and associated support, maintenance, analytics, messaging, automation, and integration services.
Processing will continue for the duration of the Customer’s use of the service and any limited post-termination period reasonably required for secure deletion, return, backup rotation, dispute handling, or legal compliance.
4. Nature and Purpose of Processing
The Company may process Customer Personal Data to:
- receive, store, organise, and display enquiries and messages;
- route, send, and log communications;
- provide automation, AI-assisted workflow, and analytics features;
- provide support, troubleshooting, security, maintenance, and service improvement;
- facilitate customer-authorised integrations.
5. Categories of Data Subjects
Depending on the Customer’s use of the service, data subjects may include:
- Customer personnel and authorised users;
- Customer’s current, former, or prospective customers, patients, clients, or contacts;
- other individuals whose data is included in enquiries, messages, or connected systems by Customer.
6. Categories of Personal Data
Depending on configuration and use, personal data may include:
- names;
- phone numbers;
- email addresses;
- message contents;
- booking and enquiry metadata;
- communication timestamps;
- channel and delivery data;
- account and user identifiers;
- technical usage and log data.
7. Customer Instructions
The Company will process Customer Personal Data only on documented instructions from Customer, including as set out in the Terms, this Addendum, the service configuration selected by Customer, and Customer’s lawful use of the service.
8. Confidentiality
The Company will ensure that persons authorised to process Customer Personal Data are subject to appropriate obligations of confidentiality.
9. Security
The Company will implement appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature of the processing and the risks involved.
10. Subprocessors
Customer authorises the Company to use subprocessors reasonably required to provide the service, including hosting, infrastructure, communications, analytics, support, payment, and (where enabled) AI providers.
The Company will impose data protection obligations on subprocessors as required by applicable law and remain responsible for their processing to the extent required by law.
Current subprocessors, and the locations in which they process Customer Personal Data, include:
- Supabase: database, authentication, and serverless infrastructure. Database hosted in Ireland (AWS eu-west-1); serverless functions and support access may operate from the United States.
- Vercel: application hosting and edge delivery. United States, with edge locations in the United Kingdom and Ireland.
- Twilio: SMS and telephony messaging. United States.
- Stripe: subscription billing and payments. United States and Ireland.
- Resend: transactional email delivery, including staff notification emails. United States.
- Meta Platforms: WhatsApp, Facebook Messenger, and Instagram messaging (when connected by Customer). United States and Ireland.
- OpenAI: AI-drafted reply suggestions and workflow features (where enabled by Customer). United States. Customer Personal Data is used for inference only and is not used to train models.
- Retell: AI voice channel, including its named subprocessors for speech and language models (where voice is enabled). United States.
The Company will give Customer notice of any intended addition or replacement of a subprocessor by updating this list and the trust page at www.replyos.co.uk/security. Customer may object on reasonable data protection grounds within 30 days of notice.
11. Assistance
Taking into account the nature of processing and the information available to the Company, the Company will provide reasonable assistance to Customer with:
- data subject rights requests;
- security and breach obligations;
- data protection impact assessment support where reasonably required;
- regulator enquiries relating to processing carried out by the Company on Customer’s behalf.
12. Personal Data Breach
The Company will notify affected customers within 72 hours of becoming aware of a personal data breach affecting their data, and will provide incident detail reasonably required to support Customer’s regulatory obligations.
13. Deletion or Return
Upon termination of the service and subject to legal, security, dispute, and backup retention requirements, the Company will delete or return Customer Personal Data in accordance with its standard retention and deletion processes, unless applicable law requires continued retention.
14. Information and Audit
The Company will make available information reasonably necessary to demonstrate compliance with this Addendum and applicable processor obligations, and may satisfy audit obligations through documentation, certifications, summaries, questionnaires, or other proportionate means.
15. International Transfers
Where Customer Personal Data is transferred outside the UK, the Company will implement appropriate safeguards where required under applicable data protection law. International transfers, where they occur, are governed by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
16. Priority
If there is any conflict between this Addendum and the Terms in relation to data protection matters, this Addendum will prevail to the extent of that conflict.