Data Processing Agreement (DPA)
Version 1.0 — effective September 30, 2026
This Data Processing Agreement (the « DPA ») is entered into between the customer holding a Resply account (the « Customer »), acting as controller, and WL Creators, a sole proprietorship registered under SIRET 910 157 312 00018, publisher of the Resply platform (« Resply »), acting as processor within the meaning of Article 28 of Regulation (EU) 2016/679 (« GDPR »).
The DPA forms an integral part of the Terms of Use (the « Terms ») and is accepted by the Customer when accepting the Terms. In case of conflict between the Terms and the DPA regarding personal data protection, the DPA prevails. The French version is the reference version. A signed copy can be provided on request at contact@resply.io.
Purpose and definitions
The DPA sets out the conditions under which Resply processes, on behalf of the Customer, the personal data required to provide the automated customer support service (the « Service »). The terms « personal data », « processing », « controller », « processor », « data subject » and « personal data breach » have the meaning given to them in the GDPR.
Data relating to the accounts of the Customer's users (its team members) and to billing is processed by Resply as a controller; it is covered by the Privacy Policy and not by the DPA.
Description of the processing
The data subjects, categories of data, nature, purpose and duration of the processing are described in Annex 1.
Customer instructions
Resply processes personal data only on the Customer's documented instructions. Documented instructions consist of the Terms, the DPA and the configuration of the Service made by the Customer (settings, knowledge sources, AI tools, webhooks, mailbox connections).
Resply immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other applicable provisions.
Resply does not use the Customer's personal data for its own purposes, does not sell it and does not use it to train artificial intelligence models. Resply may produce aggregated operational data (conversation volumes, Service consumption) that does not contain the content of conversations, for billing and to operate the Service.
Customer obligations
- Have a legal basis for the processing entrusted to Resply and inform data subjects, in particular by mentioning in its own privacy policy the use of an AI-powered customer support provider.
- Not solicit, through the Service, special categories of data (Article 9 GDPR) or data relating to criminal convictions, unless necessary and under its own responsibility.
- Ensure that the content it adds to its knowledge base is lawful.
- Configure the Service in line with its own obligations (retention periods, enabled features such as screen recording or mailbox connection).
Confidentiality
Resply ensures that any person authorized to process the Customer's personal data is bound by a confidentiality obligation. At the date of the DPA, only the publisher has access to production systems.
Security
Resply implements the technical and organizational measures described in Annex 2 to ensure a level of security appropriate to the risk (Article 32 GDPR). Resply may update these measures provided that the overall level of protection is not reduced.
Sub-processors
The Customer grants Resply a general authorization to engage the sub-processors listed in Annex 3.
Resply informs the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds by writing to contact@resply.io. If no satisfactory solution is found, the Customer may terminate its subscription before the change takes effect.
Resply contractually imposes on each sub-processor data protection obligations at least equivalent to those of the DPA and remains liable to the Customer for their performance.
Transfers outside the European Union
Some sub-processors may process data outside the European Economic Area (see Annex 3). Such transfers are governed by an adequacy decision of the European Commission (in particular the EU-U.S. Data Privacy Framework, where the sub-processor is certified) or by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
Data subject rights
The Customer is responsible for responding to data subject requests. Resply assists it through appropriate technical and organizational measures:
- export of conversations from the dashboard (CSV format);
- deletion of a data subject's data upon the Customer's written request to contact@resply.io, within 30 days;
- forwarding to the Customer, without delay, any request received directly from a data subject, without responding itself unless instructed by the Customer.
Personal data breaches
Resply notifies the Customer of any personal data breach affecting it without undue delay and no later than 72 hours after becoming aware of it, by email to the address of the administrator account.
The notification describes, where possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information not available at the time of the first notification is provided as soon as possible.
Assistance to the Customer
Resply provides the Customer, to a reasonable extent and taking into account the information available to it, with the assistance required to carry out data protection impact assessments and, where applicable, prior consultation with the supervisory authority.
Duration and end of processing
The DPA applies for as long as Resply processes personal data on behalf of the Customer.
The Customer may export its conversations at any time and then delete its account from its settings. Account deletion immediately erases the Customer's data from the production database. Associated files (attachments, screen recordings) and any backup copies are erased within 30 days. Cancelling the subscription without deleting the account does not erase the data; the Customer may request its deletion at any time.
Audits
Resply makes available to the Customer, on request, the information necessary to demonstrate compliance with the DPA, in particular by answering a written questionnaire, no more than once a year.
The Customer may also have an audit carried out by an independent auditor bound by confidentiality, with 30 days' written notice, no more than once a year (except in the event of a confirmed data breach), at the Customer's expense and without disrupting the Service.
Liability and governing law
Each party's liability under the DPA is subject to the limitations set out in the Terms, without prejudice to the mandatory provisions of the GDPR, in particular Article 82.
The DPA is governed by French law. Disputes are submitted to the courts designated in the Terms.
Annexes
Annex 1 — Description of the processing
| Item | Description |
|---|---|
| Data subjects | Visitors and end customers of the Customer who use the chat widget or write to a mailbox connected to the Service. |
| Categories of data | Identity and contact details provided by the person (name, email — pre-chat form, email verification); content of exchanges (messages, attachments, emails received through a connected mailbox, screen recordings if the Customer enables this feature); metadata (timestamps, detected language, information sent by the Customer's website, satisfaction rating); IP address, processed transiently for abuse rate limiting. Any personal data present in the Customer's knowledge base. |
| Sensitive data | None is intended. The Customer undertakes not to solicit any through the Service. |
| Nature of processing | Collection, hosting, indexing and search (including vector search), AI response generation, forwarding to the Customer's team, email sending, export and deletion. |
| Purpose | Providing the automated customer support Service to the Customer. |
| Duration | For as long as the Customer's account exists (see « Duration and end of processing »). Technical search logs (question, excerpts) are purged after 30 days; expired chat sessions are deleted automatically. |
Annex 2 — Technical and organizational measures
- Database hosted in the European Union (AWS eu-west-1, Ireland); server functions run in Paris.
- Encryption in transit (HTTPS/TLS) and encryption at rest by the hosting provider.
- Data isolation per organization: Row Level Security policies and server-side access controls.
- AES-256-GCM encryption of integration secrets (mailbox connection tokens).
- Files (attachments, screen recordings) stored in private buckets, accessible only through temporary signed links.
- Two-factor authentication (TOTP) available to users; bot protection on sign-up and sign-in; rate limiting against abuse.
- Detection of prompt injection attempts in messages sent to the AI.
- Logging of sensitive actions and application errors.
- Access to production systems limited to the publisher.
- Data breach procedure: analysis, containment, notification to the Customer within the time limits set by the DPA.
Annex 3 — Authorized sub-processors
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Ireland) | DPA |
| Vercel Inc. | Application hosting | Functions in Paris; global delivery network | DPA, standard contractual clauses / Data Privacy Framework |
| OpenAI | Response generation and indexing (embeddings) | United States | DPA, standard contractual clauses / Data Privacy Framework. No training on data; possible retention up to 30 days for abuse monitoring. |
| Amazon Web Services (SES) | Email delivery | EU (Paris) | DPA |
| Upstash Inc. | Abuse rate limiting (IP address, transient) | Depends on database region | DPA, standard contractual clauses |
When the Customer connects a Google or Microsoft mailbox, these providers act on behalf of the Customer under its own agreement with them; they are not sub-processors of Resply.
A question about this DPA?
For any question, or to obtain a signed copy, write to us.
contact@resply.io