Data Processing Addendum
Version and last updated: August 3, 2026
This document is provided in English.
This Data Processing Addendum describes processing performed by Responses for a workspace owner under the Terms of Service. It applies to Customer Content that the owner supplies directly or receives through a connected account or webchat site.
1. Parties, roles and instructions
The processor under this addendum is:
- Provider
- Andrii Serhiiovych Tretiakov — Individual Entrepreneur (FOP), Ukraine
- Contact
- support@responses.me
- Legal information
- Full provider details
The controller is the workspace owner that accepted the Terms of Service for its workspace. Accepting the Terms accepts this addendum for that workspace; no separate signature is exchanged. The record of that acceptance is the account identifier, the accepted Terms version, the surface used and the acceptance time stored by the service, and the addendum version published here on that date. A countersigned copy for a customer's own records can be requested at support@responses.me.
The workspace owner is the controller of its Customer Content and Responses is the processor providing the tool. The owner instructs processing through its use and configuration of the service: connected channels, team roles, assistant instructions, knowledge, reply mode, retention and deletion controls. The owner is responsible for its authority, notices and lawful basis for those instructions.
2. Processing details
- Subject matter and purpose: business messaging, shared-inbox operation, AI-assisted classification and replies, delivery, safety, support, security and workspace administration.
- People: workspace members, customers and other people represented in Customer Content, and webchat visitors.
- Data: names and identifiers, contact data supplied in messages or webchat, message and attachment-reference content, channel and thread metadata, knowledge content, assistant instructions, generated replies, moderation reports and usage records.
- Operations: receipt, organization, storage, retrieval, display, redaction, AI generation, transmission, reporting, export and deletion.
- Duration: while the data remains in the service under the configured plan retention, explicit deletion controls and the database TTLs disclosed in the Privacy Policy.
3. Confidentiality, access and security
Workspace content is scoped by workspace membership and role. Connected-platform credentials are stored separately and encrypted with AES-256-GCM. Passwords use argon2id; refresh and one-time auth tokens are stored as hashes. Webhook transports authenticate platform requests. Operational logs are designed to omit message text, bodies, prompts and credentials.
Authorized Responses operators can access reported content and minimum context for safety, abuse handling, support and enforcement. Each report-content view is audited. Report decisions identify the reviewing operator and time. Reports are not forwarded to the connected platform.
4. Subprocessors
The controller authorizes the subprocessors below. Each is engaged under a written contract with data-protection terms no less protective than this addendum.
| Subprocessor | Service | Processing location |
|---|---|---|
| IONOS SE / IONOS Inc. | Application, database and log hosting | United States (Missouri) |
| Cloudflare, Inc. | Encrypted database backup storage (R2) | European Union jurisdiction |
| OpenAI, L.L.C. | AI classification and reply drafts, when configured | United States |
| Google LLC / Google Ireland Limited | Gemini AI when configured; Firebase analytics, crash diagnostics and Android push when separately enabled | United States, European Union |
| Anthropic PBC | Claude AI, when configured | United States |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Web subscription billing | United States, Ireland |
| Postmark (ActiveCampaign, LLC) | Transactional and support email | United States |
| Functional Software, Inc. (Sentry) | Server exception reporting, when configured | United States |
| Apple Inc. | iOS push delivery (APNs); App Store purchase verification | United States, European Union |
Connected platforms — Meta Platforms, Telegram, Google, Microsoft and Apple — receive and deliver the Customer's communications through their official APIs under their own terms and act for their own purposes as independent controllers of the platform accounts involved, not as subprocessors of Responses. Where the Customer connects an App Store or Google Play app, the reviews read and the developer responses published are public content on those storefronts, hosted and controlled by Apple or Google. Apple and Google Play are also the sellers of record for in-app purchases and process purchase data under their own terms.
A new or replacement subprocessor is announced at least 30 days before it starts processing, by email to workspace owners and by updating this page. The controller can object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the controller can terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees.
Application data is processed in IONOS SE hosting, United States (Missouri) and backups in Cloudflare R2, European Union jurisdiction. Transfers out of the European Economic Area or the United Kingdom rely on the European Commission's Standard Contractual Clauses with the UK Addendum where applicable, or on another mechanism the subprocessor makes available, including an adequacy decision covering the recipient.
OpenAI and Gemini requests set store: false; Anthropic requests use its Messages API without application-managed provider conversation state. These technical controls do not replace the provider's own contractual retention and transfer terms.
AI processing defaults off for each connected channel. The workspace operator sees the third-party data-sharing scope and must explicitly confirm before enabling that channel.
5. Data minimization
AI context is limited to recent messages, active assistant instructions and selected knowledge snippets. Before transmission, Responses masks detected email addresses, phone numbers, payment-card numbers and IBANs. This is not anonymization: names, postal addresses and other free-form personal data may remain. Attachment binaries are not stored in the message collection; platform references are stored instead.
6. Return, retention and deletion
An account holder can export account-level records without authentication secrets, and the owner can export workspace data without platform credentials or token hashes. Conversation deletion removes the conversation, its messages and its reports. Workspace deletion cascades through content, reports, credentials, knowledge, memberships and workspace configuration. Account deletion deletes owned workspaces and removes the account's memberships and account-level records. Automated retention and TTL values are listed in the Privacy Policy.
On termination, the controller can export workspace data and delete the workspace with the product controls. A workspace that is not deleted keeps its data under the retention of the plan then in effect. On written request within 30 days of termination, remaining Customer Content is deleted; encrypted backups age out under the backup rotation described in the Privacy Policy, and a restored backup is re-processed for outstanding erasure requests before the restored data is used.
7. Security incidents
Responses notifies the affected workspace owner of a personal-data breach involving Customer Content without undue delay after becoming aware of it and, where feasible, within 72 hours. The notice goes to the workspace owner's account email and states what is known at the time: the nature of the incident, the categories and approximate volume of data and people affected, the likely consequences, the measures taken or proposed, and a contact point. Information that is not yet available is provided in stages as the investigation progresses. Notifying regulators and affected individuals remains the controller's decision and obligation.
8. Assistance
- Data-subject requests: the export, conversation-deletion, workspace-deletion and account-deletion controls are the primary means of responding. If a request cannot be met with those controls, Responses provides reasonable assistance within 10 business days of a request sent to the contact address.
- Impact assessments and regulator consultation: Responses provides the information it holds about its processing, security measures and subprocessors to support a DPIA or a prior consultation, to the extent the controller cannot obtain that information from the published documentation.
- Cost: assistance is provided at no charge unless a request is repetitive or manifestly excessive, in which case a reasonable fee is agreed in advance.
9. Audits
The controller can verify compliance once per 12-month period, on at least 30 days written notice, through a documentation review and a written security questionnaire answered within 30 days. An on-site or third-party audit is available where a supervisory authority requires it or after a confirmed breach affecting the controller's data; it is limited to systems used to process that controller's Customer Content, must not disrupt the service or expose another customer's data, and its costs are borne by the controller. All audit material is confidential, and any auditor must be bound by confidentiality and must not be a competitor of the provider.
10. Requests and contact
Workspace owners can use the available export and deletion controls when responding to a data request. End users should normally direct requests to the business that controls their conversation. Questions about this addendum can be sent to support@responses.me.