This Data Processing Agreement (“DPA”) forms part of and is incorporated into the applicable Service Agreement, Terms of Service, Order Form or other written agreement governing the provision of QuickReply Services to the Customer (the “Customer Agreement”).
This DPA is entered into between the Customer and the QuickReply entity identified as the service provider in the applicable Customer Agreement (“QuickReply”, “Processor”, “we”, “us” or “our”).
This DPA applies where QuickReply processes Personal Data on behalf of the Customer in connection with the Services.
Where applicable, QuickReply Affiliates may process Personal Data in connection with the Services in accordance with this DPA.
If there is a conflict between this DPA and the Customer Agreement regarding the processing and protection of Personal Data, this DPA shall prevail solely with respect to such processing, except where the Customer Agreement expressly provides a higher standard or more specific obligation.
1. Definitions
1.1 Affiliate
“Affiliate” means an entity that directly or indirectly controls, is controlled by or is under common control with a Party.
1.2 Applicable Data Protection Law
“Applicable Data Protection Law” means privacy, data-protection and data-security laws and regulations applicable to the processing of Personal Data under this DPA, including, where applicable:
- Regulation (EU) 2016/679 (“GDPR”);
- the UK GDPR and Data Protection Act 2018;
- the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”);
- India's Digital Personal Data Protection Act, 2023 and applicable rules or notifications thereunder;
- Singapore's Personal Data Protection Act 2012; and
- other applicable privacy or data-protection laws, together with any amendments, replacements or successor legislation.
1.3 Controller
“Controller” means the Customer where the Customer determines the purposes and means of processing Personal Data, and includes equivalent terms such as Business or Data Fiduciary where applicable.
Where the Customer itself acts as a Processor on behalf of another Controller, references in this DPA to QuickReply as Processor shall, where appropriate, mean that QuickReply acts as a Sub-Processor.
1.4 Customer Data
“Customer Data” means data, information, content or material submitted, transmitted, uploaded, collected, generated, integrated or otherwise made available to QuickReply by or on behalf of the Customer through the Services.
1.5 Data Subject
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
1.6 Personal Data
“Personal Data” means any information relating to an identified or identifiable individual contained within Customer Data and protected as personal data, personal information or an equivalent concept under Applicable Data Protection Law.
1.7 Personal Data Breach
“Personal Data Breach” means a confirmed or reasonably suspected security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by QuickReply on behalf of the Customer.
1.8 Processing
“Processing” means any operation performed on Personal Data, including collection, receipt, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, disclosure, combination, restriction, deletion or erasure.
1.9 Processor
“Processor” means QuickReply where QuickReply processes Personal Data on behalf of the Customer.
1.10 Sensitive Personal Data
“Sensitive Personal Data” means Personal Data subject to heightened legal protections under Applicable Data Protection Law, including special-category data where applicable.
1.11 Services
“Services” means the products, platforms, applications, APIs, communications services, integrations, AI-enabled services and other services provided by QuickReply under the Customer Agreement.
1.12 Standard Contractual Clauses
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for transfers of Personal Data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended, replaced or superseded from time to time.
1.13 Sub-Processor
“Sub-Processor” means any third party or QuickReply Affiliate engaged by QuickReply to process Personal Data on behalf of the Customer in connection with the Services.
2. Roles of the Parties
For Personal Data processed through the Services on behalf of the Customer:
The Customer generally acts as Controller, Business, Data Fiduciary or equivalent; and QuickReply acts as Processor, Service Provider, Data Processor or equivalent.
Where the Customer processes Personal Data on behalf of another Controller, QuickReply may act as the Customer's Sub-Processor.
The Customer determines:
- the Personal Data submitted to the Services;
- the Data Subjects whose Personal Data is processed;
- the purposes for which the Services are used;
- communications sent using the Services;
- integrations and channels enabled by the Customer; and
- the Customer's legal basis for processing Personal Data.
QuickReply processes Personal Data on behalf of the Customer in accordance with this DPA, the Customer Agreement and the Customer's documented instructions.
3. Customer Instructions and Scope of Processing
QuickReply shall process Personal Data only:
- to provide, operate, support, secure and maintain the Services;
- in accordance with the Customer Agreement and this DPA;
- according to configurations, integrations, workflows, campaigns or features enabled by the Customer;
- in accordance with other documented instructions provided by the Customer and accepted by QuickReply; or
- where processing is required by applicable law.
Where QuickReply is legally required to process Personal Data other than on the Customer's instructions, QuickReply shall, unless prohibited by law, inform the Customer of that legal requirement before processing.
If QuickReply reasonably believes that a Customer instruction violates Applicable Data Protection Law, QuickReply shall immediately inform the Customer and may suspend performance of the relevant instruction until the Parties have clarified its lawfulness.
Details regarding the subject matter, nature and purpose of Processing, categories of Data Subjects and categories of Personal Data are set out in Appendix 1.
4. Customer Obligations
The Customer represents and warrants that:
- it will comply with Applicable Data Protection Law in connection with its use of the Services;
- it has all necessary rights, permissions, notices, consents and lawful bases required to collect and process Customer Data and instruct QuickReply to process it;
- its instructions to QuickReply are lawful;
- it will not use the Services in a manner that causes QuickReply to violate Applicable Data Protection Law;
- it is responsible for the accuracy, quality and lawfulness of Customer Data; and
- It will appropriately configure its account, users, permissions, integrations and security controls.
The Customer is responsible for complying with laws applicable to its communications with its customers, prospects and other Data Subjects, including requirements relating to consent, marketing communications, messaging and opt-outs.
Sensitive Personal Data
QuickReply does not generally require Sensitive Personal Data to provide the Services.
If the Customer chooses to process Sensitive Personal Data through the Services, the Customer is responsible for determining whether such processing is lawful and for implementing any notices, consents, contractual terms, technical controls or additional safeguards required by Applicable Data Protection Law.
The Customer should minimise the collection and processing of Sensitive Personal Data and process only information reasonably necessary for its intended business purposes.
5. QuickReply's Obligations
QuickReply shall:
- process Personal Data only in accordance with this DPA, the Customer Agreement and the Customer's documented instructions;
- ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations;
- provide appropriate privacy and information-security training to relevant personnel;
- maintain appropriate technical and organisational measures designed to protect Personal Data;
- provide reasonable assistance to the Customer with Data Subject requests, regulatory obligations and Personal Data Breaches as described in this DPA;
- maintain appropriate controls relating to access to Customer Data; and
- require applicable Sub-Processors to protect Personal Data in accordance with this DPA.
6. Security Measures
QuickReply shall maintain appropriate technical and organisational measures designed to protect the confidentiality, integrity and availability of Personal Data and to protect against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
QuickReply's security programme includes measures such as:
- role-based access controls;
- least-privilege access principles;
- multi-factor authentication for privileged access;
- network and infrastructure security controls;
- encryption controls;
- vulnerability and patch management;
- logging and monitoring;
- incident-response procedures;
- backup and disaster-recovery processes;
- personnel confidentiality obligations; and
- security awareness and training.
QuickReply currently maintains ISO 27001 certification and undergoes SOC 2 Type II assessment.
Further details regarding QuickReply's technical and organisational security measures may be provided through QuickReply's then-current Security & Data Protection documentation.
The Customer acknowledges that security practices evolve over time. QuickReply may update or replace security controls provided that such changes do not materially reduce the overall security of the Services.
7. Access to Customer Data
Access to Customer Data by QuickReply personnel shall be limited according to legitimate business need and least-privilege principles.
Access may be provided for purposes such as:
- customer support and troubleshooting;
- security and incident response;
- service operation and maintenance;
- investigating abuse or platform misuse;
- fulfilling legal or regulatory obligations; or
- other purposes necessary to provide the Services.
Where customer-controlled support access functionality is available, support access may be subject to customer authorisation and time-based restrictions.
Emergency, security, compliance or service-protection access may be granted to specifically authorised personnel under controlled procedures where reasonably necessary.
8. Artificial Intelligence and AI-Enabled Services
QuickReply may provide AI-enabled functionality, including AI chatbots, voice bots, generative AI features, language-processing services or other artificial-intelligence functionality.
Where the Customer enables such functionality, relevant Customer Data may be processed by one or more authorised AI Sub-Processors to the extent reasonably necessary to provide the requested feature.
QuickReply does not use Customer Data, including Customer Personal Data, to train QuickReply's own AI models.
QuickReply shall also not intentionally instruct or authorise an AI Sub-Processor to use Customer Personal Data for training that Sub-Processor's general-purpose or foundation models.
AI Sub-Processors that process Customer Personal Data are subject to the applicable Sub-Processor obligations of this DPA.
The specific AI provider used may vary depending on the functionality, configuration, geography or Service selected by the Customer.
9. Sub-Processors
The Customer provides QuickReply with general written authorisation to engage Sub-Processors in connection with the Services.
QuickReply shall require Sub-Processors that process Customer Personal Data to be subject to data-protection obligations materially consistent with those applicable to QuickReply under this DPA.
QuickReply remains responsible for the performance of its Sub-Processors to the extent required by Applicable Data Protection Law and subject to the limitations of liability contained in the Customer Agreement.
Current Sub-Processor List
QuickReply's current Sub-Processors that may process Customer Personal Data are identified in Appendix 2.
The particular Sub-Processors applicable to a Customer may depend on the channels, features, integrations and Services enabled or used by that Customer.
Changes to Sub-Processors
QuickReply may update the Sub-Processor List from time to time.
Where required by Applicable Data Protection Law, QuickReply shall provide the Customer with at least ten (10) days' prior notice, by email, in-application notification or another reasonable method, before authorising a new or replacement Sub-Processor to process Customer Personal Data.
If the Customer has a reasonable and documented data-protection objection to a new Sub-Processor, the Customer must notify QuickReply during the applicable notice period.
The Parties shall work in good faith to identify a commercially reasonable alternative.
If QuickReply cannot reasonably provide the affected Services without the Sub-Processor, the Customer may discontinue or terminate only the affected Services. Any refund or financial consequence arising from such termination shall be governed by the Customer Agreement.
10. International Data Transfers
QuickReply operates internationally and may use Affiliates and Sub-Processors located in different jurisdictions.
QuickReply's primary production infrastructure and databases are hosted in the AWS Mumbai region, India, although certain Sub-Processors may process or store limited Customer Personal Data in other jurisdictions depending on the Services used.
Where Applicable Data Protection Law requires a legal mechanism for an international transfer of Personal Data, QuickReply shall use an appropriate transfer mechanism, which may include:
- an adequacy decision;
- Standard Contractual Clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- Binding Corporate Rules; or
- another transfer mechanism permitted by Applicable Data Protection Law.
EU and UK Restricted Transfers
Where Customer Personal Data is transferred in circumstances requiring appropriate safeguards under the GDPR, the EU Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated into this DPA.
Module Two applies where the Customer is a Controller and QuickReply is a Processor, and Module Three applies where the Customer is a Processor and QuickReply is a Sub-Processor. Clause 7 applies, Clause 9(a) Option 2 (General Written Authorisation) applies with the notice period specified in Section 9 of this DPA, and the optional wording in Clause 11 does not apply. For Clauses 17 and 18, the EU SCCs are governed by the laws of the Netherlands and disputes shall be submitted to the courts of the Netherlands.
For purposes of the EU SCCs, the Customer is the data exporter and the applicable QuickReply contracting entity is the data importer. Appendix 1 constitutes Annex I.B, Appendix 3 constitutes Annex II, and Appendix 2 constitutes Annex III. The competent supervisory authority shall be determined in accordance with Clause 13 of the EU SCCs.
Transfers may occur on an ongoing, recurring or Customer-initiated basis during the applicable Service term. For Sub-Processor transfers, the subject matter and nature of Processing are the applicable service functions identified in Appendix 2, and the duration is for so long as the relevant Sub-Processor is engaged to provide the applicable Services, subject to Section 13.
Where the UK GDPR applies to a Restricted Transfer, the UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner's Office (“UK Addendum”) is incorporated into this DPA. The Parties, applicable EU SCC module and Appendix information shall be determined in the same manner described above. For purposes of the UK Addendum, the Part 1 Tables are completed using the Parties and SCC selections described above and the information in Appendices 1–3. For Table 4, neither Party is selected as entitled to end the UK Addendum under Section 19.
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
For Annex I.A of the EU SCCs, the identities, addresses and contact details of the data exporter and data importer are those specified in the applicable Customer Agreement, Order Form, account or other contracting records. QuickReply's privacy contact is [email protected]. The relevant activities are the Customer's use of and QuickReply's provision of the Services, the Parties' roles are determined by the applicable Module, and the date this DPA becomes effective under Section 20 shall be the applicable date of the SCCs.
For purposes of the UK Addendum, the Part 1 Tables are completed using the Parties and SCC selections described above and the information in Appendices 1–3. For Table 4, neither Party is selected as entitled to end the UK Addendum under Section 19.
Acceptance of the applicable Customer Agreement and this DPA constitutes the Parties' agreement to and execution of the applicable EU SCCs and/or UK Addendum.
If the EU SCCs or UK Addendum conflict with this DPA or the Customer Agreement in relation to a Restricted Transfer, the applicable transfer mechanism shall prevail.
11. Data Subject Requests
Taking into account the nature of Processing, QuickReply shall provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising rights under Applicable Data Protection Law.
If QuickReply receives a request directly from a Data Subject relating to Customer Personal Data, QuickReply may:
- refer the Data Subject to the Customer;
- forward the request to the Customer where reasonably possible; and
- provide reasonable assistance to the Customer in responding.
Unless required or permitted by law, QuickReply will not independently access, alter, correct or delete Customer Personal Data in response to a Data Subject request without instructions from the Customer.
The Customer remains responsible for responding to Data Subjects and determining whether a request is valid.
Where assistance requires material engineering work, recovery services, customised data extraction or other work beyond functionality ordinarily included in the Services, QuickReply may charge reasonable fees after notifying the Customer in advance.
12. Personal Data Breaches
QuickReply shall notify the Customer without undue delay and, in any event, within twenty-four (24) hours after becoming aware of a confirmed or reasonably suspected Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, QuickReply shall provide information concerning:
- the nature of the Personal Data Breach;
- the categories of Personal Data affected;
- the categories of affected Data Subjects, where reasonably identifiable;
- the likely or known impact;
- mitigation or containment measures taken; and
- contact information for reasonable follow-up.
QuickReply may provide information in phases as further details become available.
QuickReply shall take commercially reasonable measures to contain, investigate and mitigate a Personal Data Breach.
QuickReply shall reasonably cooperate with the Customer in connection with legally required regulatory or Data Subject notifications.
Notification of or response to a Personal Data Breach shall not constitute an admission of fault, negligence or liability by QuickReply.
The Customer remains responsible for determining whether notification to regulators, Data Subjects or other third parties is legally required, except to the extent Applicable Data Protection Law imposes a direct obligation on QuickReply.
13. Data Retention, Return and Deletion
Active Accounts
Customer Personal Data may be retained for the period during which the Customer's account remains active and for as long as reasonably necessary to provide the Services.
Following Termination or Deactivation
Termination or deactivation of the Services does not automatically result in immediate deletion of all Customer Personal Data.
Unless the Customer submits a valid deletion instruction or Applicable Data Protection Law requires earlier deletion or return, Customer Personal Data associated with an inactive account may generally be retained for up to approximately three (3) years after account deactivation or termination, subject to contractual, legal, security and operational requirements.
During such a period, QuickReply may restrict or disable ordinary access to the account.
Where the GDPR or UK GDPR applies, following termination of the relevant processing Services and upon the Customer's instruction, QuickReply shall, at the Customer's choice, return or delete the applicable Customer Personal Data and delete existing copies, unless applicable law requires continued retention.
Customer Deletion Requests
The Customer may request deletion of its Customer Personal Data.
Upon receipt and validation of a deletion request, QuickReply will generally permanently delete the applicable Customer Personal Data from active production databases within fourteen (14) days.
Backups
Following deletion from active production systems, residual Customer Personal Data contained in ordinary system backups and disaster-recovery archives will generally be deleted or overwritten within an additional thirty (30) days, subject to applicable law and normal backup processes.
Backup copies are not ordinarily restored except for disaster recovery, service continuity or other legitimate technical purposes.
If deleted Customer Personal Data is restored from a backup, QuickReply shall take reasonable steps to ensure that the applicable deletion instruction is reapplied.
Data Export
Before deletion, the Customer may request an export of Customer Data in a commonly used machine-readable format where technically supported.
Data export, recovery, customised extraction or other assistance may be subject to applicable fees under the Customer Agreement or fees notified to the Customer in advance.
Legally Required Retention
QuickReply may retain limited Personal Data for longer where reasonably necessary to comply with:
- applicable law;
- tax or accounting requirements;
- audit obligations;
- security and fraud-prevention requirements;
- litigation or legal claims; or
- regulatory requirements.
Any Personal Data retained for these purposes shall remain subject to appropriate safeguards and shall not be processed for unrelated purposes.
Where Applicable Data Protection Law requires Customer Personal Data to be deleted or returned following termination notwithstanding the retention provisions above, QuickReply shall comply with such requirement.
14. Audits and Compliance Information
QuickReply shall make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under Applicable Data Protection Law and this DPA.
QuickReply may satisfy audit requests in the first instance by providing relevant materials such as:
- independent audit reports;
- certifications;
- summaries or extracts of security assessments;
- security documentation;
- compliance questionnaires; or
- other appropriate evidence.
QuickReply currently maintains ISO 27001 certification and undergoes SOC 2 Type II assessment.
If the Customer reasonably determines that such documentation is insufficient to satisfy a legal audit requirement specifically applicable to the Customer, the Customer may request a further audit.
Unless an identifiable material security or compliance issue requires otherwise, any such audit shall:
- be conducted no more than once in a twelve-month period;
- be subject to at least four (4) weeks' prior written notice;
- occur during normal business hours;
- be limited to systems and matters relevant to the Customer's Personal Data;
- avoid accessing the confidential information or Personal Data of other QuickReply customers;
- be performed in a manner that does not unreasonably interfere with QuickReply's business;
- be subject to appropriate confidentiality requirements; and
- be conducted at the Customer's expense.
QuickReply may charge reasonable fees for personnel time and costs associated with an audit where permitted by Applicable Data Protection Law.
Nothing in this Section limits mandatory audit rights that cannot legally be restricted.
15. Regulatory Cooperation
Taking into account the nature of Processing and information available to QuickReply, QuickReply shall provide reasonable assistance to the Customer with obligations relating to:
- security of Processing;
- Personal Data Breach assessment;
- data-protection impact assessments;
- consultations with data-protection authorities; and
- other obligations imposed on the Customer under Applicable Data Protection Law.
If QuickReply receives a legally binding request from a regulator or governmental authority specifically concerning Customer Personal Data, QuickReply shall, where legally permitted, notify the Customer.
QuickReply and the Customer shall reasonably cooperate with competent supervisory authorities where required by Applicable Data Protection Law.
QuickReply may charge reasonable fees for material assistance requested by the Customer beyond the ordinary scope of the Services where permitted by law and after giving advance notice of such fees.
16. U.S. State Privacy Laws
To the extent the CCPA/CPRA or another applicable U.S. state privacy law applies to Customer Personal Data processed under this DPA, QuickReply shall act as a Service Provider, Contractor or Processor, as applicable.
QuickReply shall not:
- sell Customer Personal Data;
- sell or share Customer Personal Data, as those terms are defined under the CCPA/CPRA;
- retain, use or disclose Customer Personal Data for purposes outside the business purposes specified in the Customer Agreement, this DPA or the Customer's documented instructions, except as permitted by applicable law;
- retain, use or disclose Customer Personal Data outside the direct business relationship between QuickReply and the Customer except as permitted by applicable law; or
- combine Customer Personal Data with Personal Data received from or on behalf of another person or collected from QuickReply's own interactions with an individual, except where such combination is permitted under applicable law and reasonably necessary to provide the Services.
For purposes of the CCPA/CPRA, the limited and specified business purposes are the Processing activities described in Section 3 and Appendix 1, solely as necessary to provide, operate, support, secure and maintain the Services and carry out the Customer's documented instructions. The Customer discloses Customer Personal Data to QuickReply only for those limited and specified purposes. QuickReply shall comply with applicable requirements of the CCPA/CPRA and provide the same level of privacy protection required of businesses under the CCPA/CPRA.
QuickReply certifies that it understands and will comply with the restrictions applicable to it as a Service Provider, Contractor or Processor under Applicable Data Protection Law.
The Customer may take reasonable and appropriate steps to ensure that QuickReply uses Customer Personal Data in a manner consistent with the Customer's obligations under the CCPA/CPRA, subject to Section 14 of this DPA. QuickReply shall notify the Customer if QuickReply determines that it can no longer meet its applicable obligations under the CCPA/CPRA. Upon notice of an unauthorised use of Customer Personal Data, the Customer may take reasonable and appropriate steps to stop and remediate such unauthorised use, and QuickReply shall reasonably cooperate with those steps.
Nothing in this Section prevents QuickReply from processing aggregated or de-identified information in accordance with Section 17.
17. Aggregated and De-identified Information
QuickReply may generate and use statistical, aggregated or de-identified information derived from use of the Services where such information does not identify an individual and does not reasonably identify the Customer as the source of the underlying data.
QuickReply may use such information for purposes including:
- service analytics;
- product and feature improvement;
- performance measurement;
- delivery optimisation;
- fraud and abuse prevention;
- capacity planning;
- benchmarking; and
- research and development.
QuickReply shall not attempt to re-identify information treated as de-identified except where necessary to verify that de-identification processes are effective or as otherwise permitted by Applicable Data Protection Law.
For clarity, QuickReply does not acquire ownership of Customer Data through this Section.
18. Customer Integrations and Third-Party Services
The Customer may choose to integrate the Services with third-party applications, ecommerce platforms, CRM systems, order management systems, messaging providers, telephony providers, payment services or other third-party systems.
Where the Customer directs QuickReply to exchange Customer Data with such a third party:
- the Customer's configuration constitutes an instruction to QuickReply to make the relevant disclosure;
- the Customer is responsible for ensuring that it has the legal right to use the third-party service and transfer the relevant data; and
- where the third party acts independently of QuickReply rather than as QuickReply's Sub-Processor, that third party's privacy and security terms govern its processing.
QuickReply is not responsible for independent processing undertaken by third-party services selected or controlled by the Customer.
19. Liability
The limitations and exclusions of liability contained in the Customer Agreement shall apply to this DPA and to all claims arising from or relating to Processing under this DPA, to the maximum extent permitted by applicable law.
Nothing in this DPA increases or creates liability beyond that provided under the Customer Agreement unless Applicable Data Protection Law expressly requires otherwise.
The Customer remains responsible for acts, omissions and instructions of its users, Affiliates, agents and service providers to the extent provided under the Customer Agreement and applicable law.
20. Term and Termination
This DPA becomes effective when the Customer Agreement becomes effective or when QuickReply first processes Personal Data on behalf of the Customer, whichever occurs first.
This DPA shall remain in force while QuickReply processes Customer Personal Data.
Obligations that by their nature should survive termination, including confidentiality, security, deletion, liability and international-transfer obligations, shall survive for as long as QuickReply retains relevant Personal Data.
21. Order of Precedence
In the event of a conflict:
- mandatory provisions of Applicable Data Protection Law shall prevail;
- applicable Standard Contractual Clauses or other mandatory transfer mechanisms shall prevail with respect to the relevant Restricted Transfer;
- this DPA shall prevail with respect to the processing of Personal Data; and
- the Customer Agreement shall otherwise govern the commercial relationship between the Parties.
Nothing in this DPA reduces a higher privacy or security obligation expressly agreed between the Parties in the Customer Agreement.
22. Governing Law and Jurisdiction
Except where mandatory Applicable Data Protection Law or the applicable Standard Contractual Clauses require otherwise, this DPA shall be governed by the governing-law and dispute-resolution provisions of the applicable Customer Agreement.
23. Changes to this DPA
QuickReply may update this DPA from time to time to reflect:
- changes in Applicable Data Protection Law;
- changes in the Services;
- changes to Sub-Processors;
- changes in security or operational practices; or
- changes reasonably necessary to maintain legal compliance.
QuickReply shall not materially reduce the overall level of protection provided for Customer Personal Data during the applicable Service term without appropriate notice where required by law or the Customer Agreement.
Material changes shall be identified through an updated “Last Updated” date or other reasonable notice.
24. Privacy Contact
Questions concerning this DPA or QuickReply's processing of Personal Data may be directed to: [email protected]
Appendix 1
Details of Processing
A. Subject Matter
Processing of Customer Personal Data as necessary to provide, operate, maintain, secure and support the QuickReply Services selected, configured or instructed by the Customer.
B. Duration of Processing
For the duration of the Customer Agreement and thereafter for the applicable retention periods described in this DPA, unless earlier deletion is requested or required by Applicable Data Protection Law.
C. Nature and Purpose of Processing
Processing activities may include:
- collection and receipt;
- transmission and delivery of communications;
- storage and organisation;
- retrieval and display;
- campaign and workflow execution;
- customer-support processing;
- integration with customer-selected systems;
- ecommerce and transaction-related workflows;
- analytics and reporting;
- AI-enabled processing where selected by the Customer;
- voice and telephony processing where selected by the Customer;
- security, monitoring and troubleshooting;
- backup and disaster recovery; and
- deletion or return.
Processing is undertaken for the purpose of providing the Services and carrying out the Customer's documented instructions.
D. Categories of Data Subjects
Depending on the Customer's use of the Services, Data Subjects may include:
- customers;
- prospective customers and leads;
- website visitors;
- users of the Customer's services;
- WhatsApp, SMS, RCS, Instagram or other messaging recipients;
- persons communicating with the Customer;
- employees;
- agents and representatives;
- suppliers and business contacts; and
- other individuals whose Personal Data the Customer chooses to process through QuickReply.
E. Categories of Personal Data
Depending on the Customer's configuration and integrations, Customer Personal Data may include:
- names;
- telephone and WhatsApp numbers;
- email addresses;
- customer and prospect profiles;
- communications and message content;
- images, videos, documents and audio;
- voice messages and voice-bot interactions;
- addresses and location information;
- orders and transaction information;
- shopping-cart information;
- product and purchase information;
- website and engagement activity;
- consent and opt-in information;
- payment status;
- CRM and OMS information;
- custom fields;
- campaign activity;
- identifiers and technical information;
- information imported from ecommerce platforms or other integrated systems; and
- other Personal Data submitted or made available by the Customer.
F. Sensitive Personal Data
The Services are not designed to require Sensitive Personal Data. Where the Customer chooses to process Sensitive Personal Data, the types of such data depend entirely upon the Customer's use case and instructions. The Customer is responsible for ensuring that such Processing complies with Applicable Data Protection Law.
For purposes of Annex I.B of the EU SCCs, where Sensitive Personal Data is transferred, the safeguards described in this DPA and Appendix 3 apply, including strict purpose limitation, least-privilege access controls, encryption controls, logging and monitoring, and applicable restrictions on onward transfers.
Appendix 2
Current Sub-Processor List
The Sub-Processors below may process Customer Personal Data in connection with the Services.
Not every Sub-Processor is used for every Customer. The Sub-Processors applicable to a particular Customer depend on the products, features, communication channels, integrations and functionality enabled by that Customer.
QuickReply may add, remove or replace Sub-Processors in accordance with Section 9 of this DPA.
The current version of this Appendix published with this DPA constitutes QuickReply's current Sub-Processor List.
Appendix 3
Technical and Organisational Measures
QuickReply maintains technical and organisational measures appropriate to the nature of the Services and risk associated with Processing.
These measures include, as applicable:
Access Control
- role-based access controls;
- least-privilege principles;
- unique personnel accounts;
- controlled administrative access;
- multi-factor authentication for privileged access; and
- periodic access review and revocation.
Infrastructure and Network Security
- cloud infrastructure hosted primarily in AWS Mumbai;
- virtual private cloud segregation;
- private network subnets for backend services and databases;
- network access-control rules;
- Web Application Firewall controls;
- security groups and network ACLs; and
- monitoring of infrastructure and critical services.
Encryption
- encryption of Customer Data in transit using appropriate transport encryption;
- encryption of applicable Customer Data at rest using industry-standard encryption; and
- managed encryption-key controls.
Application Security
- secure authentication controls;
- role-based permissions;
- vulnerability monitoring;
- patch management;
- application and infrastructure monitoring; and
- logging and diagnostic controls.
Organisational Measures
- confidentiality obligations;
- employee security and privacy training;
- access based on role and legitimate business need;
- security policies and procedures;
- incident-response processes; and
- security governance.
Business Continuity and Disaster Recovery
- backups;
- infrastructure replication where applicable;
- monitoring and alerting;
- documented incident-response and recovery procedures; and
- disaster-recovery capabilities designed to restore Services following significant infrastructure incidents.
QuickReply may update these measures from time to time provided that the overall level of security of the Services is not materially reduced.

