1. Roles of the parties
With respect to contact-plane data, the Customer is the controller and we act as processor, following the Customer’s documented instructions.
Signal-plane data is anonymous by construction and does not constitute personal data, since it cannot be attributed to an identified or identifiable person by any means reasonably available, including means available to the Customer.
2. Subject matter and duration
- Subject matter: delivering to the Customer’s designated recipient the requests for contact that people voluntarily submit.
- Duration: the term of the agreement, plus the configured retention period.
- Categories of data subject: people who choose to request contact through the Service.
- Categories of data: name, chosen contact method, language, whether the request is for themselves or someone else, and any message the person writes.
3. Instructions and limits
We will process data only to provide the Service and in accordance with documented instructions. We will not sell personal data, will not share it for advertising, and will not use it to train models.
If a Customer instruction conflicts with applicable law or with the Service’s privacy commitments, we will say so and will not carry it out.
4. Architectural commitments
In addition to the usual organisational measures, we commit to system properties that a change of staff does not alter:
- Separate database instances, with separate credentials, for anonymous and identifying data.
- No service holding credentials to both planes, and no code module importing both — verified on every build.
- Field-level encryption at rest for contact data, with per-plane keys, including backup keys.
- Scheduled purge on expiry of retention, with restore verification that also checks purge state.
- An audit record of all operational access to the contact plane.
5. Subprocessors
We use subprocessors for hosting, message delivery, and storage. They are listed on the subprocessors page. We impose obligations equivalent to those in this addendum and remain responsible for their performance.
We will give notice before adding a new subprocessor that processes contact-plane data, with reasonable time to object.
6. Incidents
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any security breach affecting personal data processed on your behalf, with the information available so you can meet your own notification obligations.
7. Assistance and data subject requests
We will reasonably assist you in responding to access, correction, or deletion requests concerning contact-plane data.
We cannot satisfy such a request against anonymous use. There is no identifier to search on, and creating one so that we could would destroy the very property that makes the data anonymous.
8. Return and deletion
On termination, at the Customer’s election, we will return or delete contact-plane data within thirty days, unless law requires retention. Backups are overwritten on their normal cycle, which does not exceed ninety days.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with this addendum and will allow audits on reasonable notice, no more than once a year except following an incident.