Last updated: August 5, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ResponiQ LLC (“ResponiQ,” “Processor”) and the customer agreeing to it (“Customer,” “Controller”). It applies to ResponiQ's processing of Personal Information on Customer's behalf. If this DPA conflicts with the Terms, this DPA controls for data protection matters.
“Personal Information” means information relating to an identified or identifiable individual that ResponiQ processes on Customer's behalf under the Terms. “Processing,” “Controller,” “Processor / Service Provider,” and “Sub-processor” have the meanings given under applicable data protection law (including the CCPA/CPRA and other U.S. state privacy laws).
Customer is the Controller and ResponiQ is the Processor / Service Provider. ResponiQ processes Personal Information only to provide the Service and only on Customer's documented instructions. ResponiQ will not “sell” or “share” Personal Information and will not retain, use, or disclose it for any purpose other than performing the Service, except as permitted by law. Details of processing are in Annex A.
Customer warrants that it has provided all required notices and has a lawful basis to provide the Personal Information to ResponiQ, and that its instructions will not cause ResponiQ to violate any law. Customer is responsible for the accuracy and content of data it submits, and must not submit protected health information (PHI) or special-category data into the Service.
ResponiQ ensures that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations.
ResponiQ implements and maintains reasonable technical and organizational measures appropriate to the risk, including those summarized in Annex B.
Customer provides general authorization for ResponiQ to engage Sub-processors. Current Sub-processors are listed in Annex C. ResponiQ imposes data protection obligations on each Sub-processor substantially similar to this DPA and remains responsible for their performance. ResponiQ will give notice of any intended addition or replacement (by updating this page or via email), and Customer may object on reasonable data protection grounds.
ResponiQ will provide reasonable assistance to enable Customer to respond to requests from individuals to exercise their rights (access, deletion, correction, opt-out). If ResponiQ receives such a request directly, it will refer the individual to Customer where appropriate.
ResponiQ will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to unauthorized disclosure of or access to Personal Information processed for Customer, and will provide information reasonably available to assist Customer's own obligations.
On termination of the Service, ResponiQ will delete or, on request, return Personal Information processed on Customer's behalf within a reasonable period, except where retention is required by law. Customers can also self-serve full deletion at any time (Settings → Danger zone).
ResponiQ will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once per year, will respond to a reasonable security questionnaire, subject to confidentiality.
ResponiQ's primary database and application hosting are located in the United States, and the Sub-processors listed in Annex C process data primarily in the United States. Where Customer Personal Data originates in the EEA, UK, or Switzerland, its processing under this DPA therefore involves a transfer to the United States. For such transfers the parties enter into the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), incorporated by reference, together with the supplementary measures described in Section 10.
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
Where Customer uses the text-message review-request feature, Customer is the Controller and determines who is contacted. Customer warrants that it has obtained prior express consent from each recipient sufficient under applicable law, including the U.S. Telephone Consumer Protection Act and, for recipients in the EEA or UK, the ePrivacy Directive and GDPR. ResponiQ does not verify consent and cannot do so.
ResponiQ applies the following controls as a matter of processing design: messages identify the sending business, carry opt-out instructions, are suppressed permanently for any number that opts out, and are sent only between 08:00 and 21:00 in the location's local time zone. These controls reduce risk; they do not transfer Customer's consent obligation to ResponiQ, and Customer remains responsible for the lawfulness of each send it initiates.
Opt-out records are retained for as long as Customer's account remains active, and are deliberately not deleted on request, since deleting a suppression record would cause a person who asked not to be contacted to be contacted again.
Encryption in transit (TLS); encryption of stored OAuth tokens (AES-256-GCM); tenant isolation and row-level security; role-based access controls and least privilege; rate limiting and abuse protection; logging and error monitoring; secret rotation; restricted administrative access.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | United States (Oregon) |
| Vercel | Application hosting | United States / global edge |
| Stripe | Payment processing | United States |
| Anthropic | AI model provider (draft generation) | United States |
| Resend | Transactional email | United States |
| Twilio | SMS delivery for review requests | United States |
| Upstash | Rate limiting | United States / EU |
| Sentry | Error monitoring | United States |
| PostHog | Product analytics (consent-based) | United States / EU |
ResponiQ LLC, 522 W Riverside Ave, Suite N, Spokane, WA 99201-0581, United States, legal@responiq.app