Last updated: July 11, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ResponiQ LLC (“ResponiQ,” “Processor”) and the customer agreeing to it (“Customer,” “Controller”). It applies to ResponiQ's processing of Personal Information on Customer's behalf. If this DPA conflicts with the Terms, this DPA controls for data protection matters.
“Personal Information” means information relating to an identified or identifiable individual that ResponiQ processes on Customer's behalf under the Terms. “Processing,” “Controller,” “Processor / Service Provider,” and “Sub-processor” have the meanings given under applicable data protection law (including the CCPA/CPRA and other U.S. state privacy laws).
Customer is the Controller and ResponiQ is the Processor / Service Provider. ResponiQ processes Personal Information only to provide the Service and only on Customer's documented instructions. ResponiQ will not “sell” or “share” Personal Information and will not retain, use, or disclose it for any purpose other than performing the Service, except as permitted by law. Details of processing are in Annex A.
Customer warrants that it has provided all required notices and has a lawful basis to provide the Personal Information to ResponiQ, and that its instructions will not cause ResponiQ to violate any law. Customer is responsible for the accuracy and content of data it submits, and must not submit protected health information (PHI) or special-category data into the Service.
ResponiQ ensures that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations.
ResponiQ implements and maintains reasonable technical and organizational measures appropriate to the risk, including those summarized in Annex B.
Customer provides general authorization for ResponiQ to engage Sub-processors. Current Sub-processors are listed in Annex C. ResponiQ imposes data protection obligations on each Sub-processor substantially similar to this DPA and remains responsible for their performance. ResponiQ will give notice of any intended addition or replacement (by updating this page or via email), and Customer may object on reasonable data protection grounds.
ResponiQ will provide reasonable assistance to enable Customer to respond to requests from individuals to exercise their rights (access, deletion, correction, opt-out). If ResponiQ receives such a request directly, it will refer the individual to Customer where appropriate.
ResponiQ will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to unauthorized disclosure of or access to Personal Information processed for Customer, and will provide information reasonably available to assist Customer's own obligations.
On termination of the Service, ResponiQ will delete or, on request, return Personal Information processed on Customer's behalf within a reasonable period, except where retention is required by law. Customers can also self-serve full deletion at any time (Settings → Danger zone).
ResponiQ will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once per year, will respond to a reasonable security questionnaire, subject to confidentiality.
ResponiQ's primary database and application hosting are located in the United States, and the Sub-processors listed in Annex C process data primarily in the United States. Where Customer Personal Data originates in the EEA, UK, or Switzerland, its processing under this DPA therefore involves a transfer to the United States. For such transfers the parties enter into the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), incorporated by reference, together with the supplementary measures described in Section 10.
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
Encryption in transit (TLS); encryption of stored OAuth tokens (AES-256-GCM); tenant isolation and row-level security; role-based access controls and least privilege; rate limiting and abuse protection; logging and error monitoring; secret rotation; restricted administrative access.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | United States (Oregon) |
| Vercel | Application hosting | United States / global edge |
| Stripe | Payment processing | United States |
| Anthropic | AI model provider (draft generation) | United States |
| Resend | Transactional email | United States |
| Upstash | Rate limiting | United States / EU |
| Sentry | Error monitoring | United States |
| PostHog | Product analytics (consent-based) | United States / EU |
ResponiQ LLC — [Registered address — pending LLC formation] — legal@responiq.app