Data Processing Agreement (DPA)

Version 1.0 · Codifies the data-protection practices in place since the service launched (April 2026) · Effective for each customer from their first use of the service · The English version is authoritative.

1. Parties, scope and incorporation

This Data Processing Agreement ("DPA") is entered into between the business customer using the Reply in DM service ("Controller", "you") and Reply in DM and its operators ("Processor", "we"), and forms an integral part of the Terms of Service. It applies automatically — without signature — whenever you use the service to process personal data of third parties (such as commenters, message senders, and subscribers) in the course of your business, and takes effect for each Controller from the moment of their first use of the service, covering all processing performed on their behalf since that date. Upon request we will provide a countersigned copy of this DPA: contact us via the contact form (category "Privacy request").

This DPA implements Article 28 of Regulation (EU) 2016/679 ("GDPR"). In case of conflict between this DPA and the Terms of Service, this DPA prevails with regard to the processing of personal data. Terms used but not defined here have the meaning given in Article 4 GDPR.

2. Roles of the parties

You are the controller of the personal data of your end users (commenters, message senders, subscribers) processed through the service; we are your processor. For the personal data of your own account (name, email, billing), we act as an independent controller as described in the Privacy Policy. Meta Platforms acts as an independent controller for its own platforms; its terms and privacy policy apply to your use of Instagram and Facebook alongside this DPA.

3. Details of the processing

The subject matter, duration, nature and purpose of the processing, the categories of personal data, and the categories of data subjects are set out in Annex 1.

4. Processor obligations (Art. 28(3) GDPR)

We process personal data only on your documented instructions — given through your configuration of the service (connected accounts, rules, lists, broadcasts, AI-assistant instructions, inbox actions) — unless required otherwise by EU or member-state law, in which case we will inform you before processing unless the law prohibits it. We will inform you immediately if, in our opinion, an instruction infringes the GDPR.

We ensure that persons authorized to process personal data have committed themselves to confidentiality. We implement and maintain the technical and organizational measures set out in Annex 2 and keep them current with the state of the art (Art. 32 GDPR).

Taking into account the nature of the processing, we assist you with appropriate technical and organizational measures in fulfilling your obligation to respond to data-subject requests under Chapter III GDPR. If a data subject contacts us directly with a request concerning your processing, we forward it to you without undue delay, at the latest within five (5) business days.

We assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to us.

We notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf — at the latest within 72 hours of becoming aware — including, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you — in the first instance through written responses and the certifications of our infrastructure providers (e.g. Google Cloud’s ISO 27001 / SOC 2), and, where these are insufficient, through a reasonable on-request audit with at least 30 days’ notice, no more than once per year, during business hours, and without access to other customers’ data.

5. Sub-processors

You grant a general authorization for the engagement of the sub-processors listed below. Each sub-processor is bound by a written agreement imposing data-protection obligations materially equivalent to those in this DPA, and we remain fully liable to you for their performance.

We will notify you of any intended addition or replacement of a sub-processor at least fourteen (14) days in advance via the email address on your account. If you object on reasonable data-protection grounds and no resolution is found, you may terminate your account; data deletion then follows Section 7.

Sub-processorPurposeLocation / transfer mechanism
Google Cloud EMEA Ltd.Cloud infrastructure, database, and processing functions for core service dataEU (Firestore multi-region Europe; functions in Frankfurt, europe-west3)
Google LLCAI-assisted features (Gemini API): message drafting and, where enabled by the Controller, automated chat repliesUSA — EU Standard Contractual Clauses / EU-US Data Privacy Framework
Sinch (Mailgun Technologies)Transactional email deliveryEU region (api.eu.mailgun.net)
Stripe, Inc.Payment processing — receives the Controller’s billing data only, never data of the Controller’s end usersUSA — EU Standard Contractual Clauses / EU-US Data Privacy Framework
Vercel, Inc.Website and dashboard application hostingUSA — EU Standard Contractual Clauses / EU-US Data Privacy Framework
Meta Platforms Ireland Ltd.Instagram and Facebook platform APIs. Meta additionally acts as an independent controller for its platforms under its own termsEU/USA — Meta’s own GDPR transfer mechanisms

6. International transfers

Core service data is stored and processed in the EU (see Annex 2). Where a sub-processor processes personal data outside the EU/EEA or may access it from a third country, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework for certified US providers) and/or the EU Standard Contractual Clauses, as indicated in the sub-processor table. We do not transfer personal data to third countries on any other basis.

7. Term, termination, deletion and return

This DPA applies for as long as we process personal data on your behalf. Upon termination of your account, we delete the personal data processed on your behalf within 30 days, unless EU or member-state law requires further storage. Before deletion you may export your data via the dashboard or request a copy via support. Deletion also covers backups within the backup rotation period of our infrastructure provider.

8. Liability and governing law

Liability under this DPA follows the limitation of liability in the Terms of Service, except where the GDPR mandates otherwise (Art. 82 GDPR). This DPA is governed by the laws of Sweden, and disputes are subject to the exclusive jurisdiction of the courts of Sweden, consistent with the Terms of Service.

Annex 1 — Details of the processing

Subject matter
Provision of comment-to-DM automation, direct-message automation (keyword rules, AI-assisted replies, inbox), subscriber lists, broadcasts, and related dashboard features for the Controller’s connected Instagram and Facebook accounts.
Duration
The duration of the Controller’s account, plus the 30-day deletion period.
Nature and purpose
Collection, storage, organization, use, and transmission of the data below, strictly as needed to deliver the contracted service on the Controller’s configuration and instructions.
Categories of data subjects
Persons who comment on the Controller’s posts, send messages to the Controller’s connected accounts, or subscribe to the Controller’s lists; members of the Controller’s team using the dashboard.
Categories of personal data
Platform user IDs; usernames and display names; comment and message content; subscription status and list membership; interaction metadata (timestamps, delivery status, matched rules); conversation history for chat features.
Special categories
None by design. The Controller agrees not to use the service to collect special categories of personal data (Art. 9 GDPR).

Annex 2 — Technical and organizational measures (Art. 32 GDPR)

Encryption
All data is encrypted in transit (TLS 1.2+) and at rest (Google Cloud default AES-256 encryption).
EU data residency
Core service data (accounts, connections, rules, comments, messages, subscriber lists, conversation state) is stored in Google Cloud Firestore, multi-region Europe, and processed by functions in europe-west3 (Frankfurt). Transactional email is sent through Mailgun’s EU region.
Access control
Access to production systems is restricted to authorized personnel on a least-privilege basis, protected by strong authentication. Customer-facing access is controlled through workspace membership: the service enforces tenant isolation so each workspace can only ever read its own data.
Platform credential security
Instagram/Facebook access tokens are stored server-side, never exposed to browsers of third parties, and their lifecycle (refresh, expiry, invalidation) is managed automatically. A dead or revoked token immediately stops all sending for that connection.
Availability and resilience
The service runs on Google Cloud managed, replicated infrastructure. Delivery pipelines are idempotent: every comment and message is tracked by a unique identifier, so retries and re-deliveries can never cause duplicate messages to data subjects.
Monitoring and incident response
Automated health checks run daily across the delivery pipeline, connection validity, and revenue-critical paths, alerting the operator on failure. Incidents are triaged the day they are detected.
Data minimization
The service stores only the data needed to operate: it does not sell data, use advertising trackers, or process special categories of data by design. Conversation history retained for chat features is capped per conversation.
Deletion
On account deletion, personal data, rules, subscriber lists, and broadcasts are removed within 30 days (see the Privacy Policy). Subscribers can opt out at any time via STOP or unsubscribe controls, which removes them from all lists immediately.

Version history

Version 1.0 — initial publication of this document. It codifies the technical and organizational practices in place since the service launched in April 2026 (EU data residency, encryption, deletion policy, and the sub-processors listed above) and applies retroactively to all processing performed for each Controller since their first use of the service.