Data Processing Addendum
Last updated: July 27, 2026
This document is provided in English.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and Responses when Responses processes personal data on the Customer's behalf. Capitalized terms not defined here have the meanings in the Terms or applicable data protection law.
1. Roles and Instructions
The Customer is the controller or business and Responses is the processor or service provider for Customer Personal Data. Responses will process Customer Personal Data only to provide, secure and support the service; follow the Customer's documented configuration and use of the service; comply with this DPA and the Terms; or comply with law. Responses will notify the Customer if an instruction infringes applicable data protection law unless prohibited by law.
2. Customer Responsibilities
The Customer is responsible for its lawful basis, notices, consents, channel permissions, data-subject request handling and instructions to Responses. The Customer will not submit personal data that is unnecessary for its support workflows and will not use the service for regulated or sensitive processing without the required authority and safeguards.
3. Confidentiality and Security
Responses will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain technical and organizational safeguards appropriate to the risk, including encrypted transport, role-based workspace access, encrypted platform credentials, webhook verification, tenant-scoped data access, restricted logging, retention controls and account deletion and export tools.
4. Subprocessors
The Customer authorizes Responses to use subprocessors needed to provide the service. Responses remains responsible for their processing to the extent required by applicable law and will impose data-protection obligations appropriate to the services they perform.
Depending on deployment configuration, Responses uses one of the following AI subprocessors for each request:
- OpenAI — generates draft replies and related confidence, language and handoff signals through the Responses API.
- Google — generates the same outputs through the Gemini Interactions API.
- Anthropic — generates the same outputs through the Claude Messages API.
Each provider receives only the recent conversation, active assistant instructions and selected knowledge base snippets. Before transmission, Responses masks detected email addresses, phone numbers, payment-card numbers and IBANs in all of those text sources. Names, postal addresses, free-form identifiers and other personal data may remain in the selected context.
OpenAI and Gemini requests set store: false to disable provider application state for the request; this setting alone is not Zero Data Retention. OpenAI's default abuse-monitoring logs may contain inputs and outputs for up to 30 days. Gemini production use requires a paid project without log sharing; separate limited abuse-monitoring may apply unless the project has approved Zero Data Retention. Anthropic's standard commercial API retention deletes inputs and outputs from its backend within 30 days, subject to Usage Policy, legal and contractual exceptions. Responses does not opt in to sharing API inputs or outputs for provider model training or improvement. Current terms are available in the providers' OpenAI, Gemini and Anthropic documentation.
Channex is an additional connectivity subprocessor when a Customer enables Booking.com or Airbnb. Channex processes guest messages, property and thread identifiers and attachment references to relay inbound events and outbound replies between the selected OTA and Responses. The Customer authorizes this processing by connecting the Channex property. Current terms are available in Channex's terms and privacy policy.
5. Assistance
Taking into account the nature of processing and information available to it, Responses will reasonably assist the Customer with data-subject requests, security obligations, data protection impact assessments and regulator consultations. Responses may require the Customer to use available export, deletion and workspace controls first.
6. Security Incidents
Responses will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data and will provide information reasonably available to help the Customer meet applicable notification obligations.
7. Return and Deletion
During the subscription, the Customer may export or delete workspace data using product controls. At the end of processing, Responses will delete or return Customer Personal Data at the Customer's choice, except where law requires retention. Data in backups and provider systems is removed according to the applicable backup and subprocessor retention cycles.
8. International Transfers
If Customer Personal Data is transferred across borders, the parties will use the transfer mechanism required by applicable law. The Customer authorizes Responses and its subprocessors to process data in the countries needed to provide the service subject to those safeguards.
9. Information and Audits
Responses will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, the Customer may request a proportionate audit no more than once per year, subject to confidentiality, security and non-disruption requirements, unless a regulator or confirmed incident requires otherwise.
10. Processing Details
- Subject matter and purpose: business messaging, shared-inbox operation, AI-assisted reply generation, delivery, security, support and account administration.
- Duration: the Customer's use of the service and the deletion periods described in the Privacy Policy and Customer settings.
- Data subjects: Customer personnel, workspace members, End Users who message the Customer and people included in Customer Content.
- Data categories: identity and contact data, account and role data, channel identifiers, conversation content and metadata, assistant instructions, knowledge base content, generated replies, usage records and security events.
- Operations: collection, receipt, organization, storage, retrieval, consultation, redaction, generation, transmission, restriction, export and deletion.
11. Order of Precedence and Contact
If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. The Privacy Policy describes processing for transparency but does not reduce the parties' obligations under this DPA. DPA and privacy questions may be sent to privacy@responses.me.