Data Processing Agreement
Effective August 4, 2026
This page summarizes the terms under which ResponsiveMe (“Processor”) processes personal data on behalf of a business customer (“Controller”) using the Service, for customers who need GDPR-, UK GDPR-, or Saudi PDPL-aligned processing terms. A signed, customer-specific DPA document is available on request through the contact page for customers who need one executed as a standalone contract; this page reflects the same terms.
1. Subject matter and duration
ResponsiveMe processes personal data submitted to the Service by the Controller and its authorized users for the duration of the Controller’s subscription, and afterward only as needed to comply with the retention and deletion terms below.
2. Nature and purpose of processing
Storage, retrieval, generation, transmission, and deletion of account, workspace, and content data as necessary to provide the Service described in our Terms of Service — including AI-assisted generation, spreadsheet/report storage, and automation execution.
3. Categories of data subjects
The Controller’s employees, contractors, and workspace members who use the Service, and any third parties named in content the Controller submits (e.g. a recipient’s name in a drafted message).
4. Categories of personal data
Contact details (name, email), authentication credentials, and any personal data the Controller chooses to include in submitted content, workbooks, datasets, or automation configurations. The Controller is responsible for ensuring it has a lawful basis to submit any personal data about third parties into the Service.
5. Subprocessors
ResponsiveMe uses the following subprocessors to provide the Service. We’ll provide reasonable advance notice through the contact page before adding a new subprocessor that will materially change how Controller data is processed.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU/US (per project region) |
| Vercel | Application hosting | Global edge network, US-based company |
| OpenAI | AI generation | US |
| Anthropic | AI generation (optional secondary provider) | US |
| Paddle | Billing, tax, invoicing (Merchant of Record) | UK/EU |
| Resend | Transactional email delivery | US |
| Microsoft | Power BI integration (only if the Controller’s users connect it) | US/EU |
6. Security measures
Row-level database access control scoped per workspace, encryption in transit (TLS) for all traffic, AES-256-GCM encryption at rest for stored third-party OAuth tokens, hashed (never plaintext) passwords and IP addresses, rate limiting and abuse detection, and audit logging of security-relevant account and administrative actions.
7. Data retention and deletion
Personal data is retained for the duration of the Controller’s subscription and deleted or anonymized on a schedule after account/workspace deletion, consistent with our Privacy Policy. The Controller (workspace owner) can delete a workspace, and any member can delete their own account, directly in the product at any time.
8. Data subject requests
Where the Controller receives a data subject request (access, deletion, correction) concerning data processed through the Service, ResponsiveMe will provide reasonable assistance to fulfill it, including through the self-service export/delete tools in the dashboard’s Privacy section.
9. International transfers
Where personal data is transferred outside the European Economic Area, UK, or Saudi Arabia, ResponsiveMe relies on appropriate safeguards such as Standard Contractual Clauses with the relevant subprocessor.
10. Breach notification
ResponsiveMe will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, providing the information reasonably available at the time and updating it as the investigation progresses.
11. Contact
For a countersigned copy of this agreement or any data-processing questions, use the contact page.