Data Processing Addendum

Last updated: July 27, 2026

This document is provided in English.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and Responses when Responses processes personal data on the Customer's behalf. Capitalized terms not defined here have the meanings in the Terms or applicable data protection law.

1. Roles and Instructions

The Customer is the controller or business and Responses is the processor or service provider for Customer Personal Data. Responses will process Customer Personal Data only to provide, secure and support the service; follow the Customer's documented configuration and use of the service; comply with this DPA and the Terms; or comply with law. Responses will notify the Customer if an instruction infringes applicable data protection law unless prohibited by law.

2. Customer Responsibilities

The Customer is responsible for its lawful basis, notices, consents, channel permissions, data-subject request handling and instructions to Responses. The Customer will not submit personal data that is unnecessary for its support workflows and will not use the service for regulated or sensitive processing without the required authority and safeguards.

3. Confidentiality and Security

Responses will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain technical and organizational safeguards appropriate to the risk, including encrypted transport, role-based workspace access, encrypted platform credentials, webhook verification, tenant-scoped data access, restricted logging, retention controls and account deletion and export tools.

4. Subprocessors

The Customer authorizes Responses to use subprocessors needed to provide the service. Responses remains responsible for their processing to the extent required by applicable law and will impose data-protection obligations appropriate to the services they perform.

Depending on deployment configuration, Responses uses one of the following AI subprocessors for each request:

Each provider receives only the recent conversation, active assistant instructions and selected knowledge base snippets. Before transmission, Responses masks detected email addresses, phone numbers, payment-card numbers and IBANs in all of those text sources. Names, postal addresses, free-form identifiers and other personal data may remain in the selected context.

OpenAI and Gemini requests set store: false to disable provider application state for the request; this setting alone is not Zero Data Retention. OpenAI's default abuse-monitoring logs may contain inputs and outputs for up to 30 days. Gemini production use requires a paid project without log sharing; separate limited abuse-monitoring may apply unless the project has approved Zero Data Retention. Anthropic's standard commercial API retention deletes inputs and outputs from its backend within 30 days, subject to Usage Policy, legal and contractual exceptions. Responses does not opt in to sharing API inputs or outputs for provider model training or improvement. Current terms are available in the providers' OpenAI, Gemini and Anthropic documentation.

Channex is an additional connectivity subprocessor when a Customer enables Booking.com or Airbnb. Channex processes guest messages, property and thread identifiers and attachment references to relay inbound events and outbound replies between the selected OTA and Responses. The Customer authorizes this processing by connecting the Channex property. Current terms are available in Channex's terms and privacy policy.

5. Assistance

Taking into account the nature of processing and information available to it, Responses will reasonably assist the Customer with data-subject requests, security obligations, data protection impact assessments and regulator consultations. Responses may require the Customer to use available export, deletion and workspace controls first.

6. Security Incidents

Responses will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data and will provide information reasonably available to help the Customer meet applicable notification obligations.

7. Return and Deletion

During the subscription, the Customer may export or delete workspace data using product controls. At the end of processing, Responses will delete or return Customer Personal Data at the Customer's choice, except where law requires retention. Data in backups and provider systems is removed according to the applicable backup and subprocessor retention cycles.

8. International Transfers

If Customer Personal Data is transferred across borders, the parties will use the transfer mechanism required by applicable law. The Customer authorizes Responses and its subprocessors to process data in the countries needed to provide the service subject to those safeguards.

9. Information and Audits

Responses will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, the Customer may request a proportionate audit no more than once per year, subject to confidentiality, security and non-disruption requirements, unless a regulator or confirmed incident requires otherwise.

10. Processing Details

11. Order of Precedence and Contact

If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. The Privacy Policy describes processing for transparency but does not reduce the parties' obligations under this DPA. DPA and privacy questions may be sent to privacy@responses.me.

Data Processing Addendum - Responses · Responses