replyk.io

Data Processing Agreement

Effective date: October 7, 2026 · Replyk, VERSAAS LLC

Table of Contents

1. Scope

This Data Processing Agreement ("DPA") is part of the Terms of Service between VERSAAS LLC and each business that uses Replyk (the "Client"). It applies whenever we process personal data on the Client's behalf ("Client Personal Data"). It takes effect when the Client accepts the Terms, with no signature needed.

Where this DPA and the Terms conflict on the protection of personal data, this DPA prevails. A Client that needs a signed copy can ask for one at legal@replyk.io.

2. Roles of the Parties

The Client is the controller of Client Personal Data and we are its processor. For our own data, such as account, billing and website data, we are the controller, as described in our Privacy Policy. Each party complies with the data protection laws that apply to it, including the GDPR and the UK GDPR where they apply.

3. Processing on the Client's Instructions

We process Client Personal Data only on the Client's documented instructions: the Terms, this DPA, and the Client's settings and use of the Service, including how it configures its Agent. We tell the Client if we believe an instruction breaks data protection law.

The Client is responsible for the lawfulness of the data it gives us, including the legal basis, the notices to its customers and any opt-in it needs.

4. Details of the Processing

  • Subject matter and duration: Providing the Service for as long as the Client uses it, plus the deletion period in this DPA.
  • Nature and purpose: Hosting, storing and transmitting messages, running the AI Agent, managing orders, catalogs and shipping, analytics and support.
  • Data subjects: The Client's customers and prospects who message it or appear in its orders, and the Client's own team members.
  • Categories of data: Names, phone numbers, messaging identifiers, addresses, order and delivery details, message content, images, documents and voice notes, and conversation metadata.
  • Sensitive data: Not intended. The Client must not send special categories of data through the Service unless the law and Meta's policies allow it.
  • Continuous, for as long as the Client uses the Service.

5. Confidentiality

Only staff who need access to provide or support the Service can reach Client Personal Data, and each of them is bound by confidentiality.

6. Security Measures

We protect Client Personal Data with technical and organizational measures, including:

  • Our main database and application servers are hosted in the European Union, and data is encrypted in transit with TLS
  • Credentials, access tokens and integration secrets are encrypted with AES-256-GCM
  • Every query is scoped to the Client's business, and team members get role-based access
  • Two-factor authentication, sign-in lockout after repeated failures, new-device alerts and session revocation
  • Network protection and rate limiting in front of the Service
  • Signature checks on incoming webhooks from Meta, Stripe and Shopify
  • Automated security tests for authentication, tenant isolation and webhooks
  • Raw webhook payloads are deleted after 7 days and webhook event logs after 30 days
  • Production access is limited to authorized staff

We may change these measures, but never in a way that lowers the overall level of protection.

7. Sub-processors

The Client gives us general authorization to use sub-processors. The current list is at https://replyk.io/subprocessors/. We bind each sub-processor to data protection terms at least as protective as this DPA, and we remain responsible for its work.

We email the owner of every account at least 30 days before a new sub-processor starts processing Client Personal Data. The Client can object on reasonable data protection grounds by writing to legal@replyk.io within that period. If we cannot address the objection, the Client may stop using the affected part of the Service and we refund any prepaid fees for the unused period.

8. Assistance and Data Subject Requests

If a data subject contacts us about Client Personal Data, we pass the request to the Client and do not answer it ourselves unless the Client asks us to. We help the Client respond to requests, carry out data protection impact assessments and consult supervisory authorities, as far as reasonably possible given the nature of the processing.

9. Personal Data Breaches

We notify the Client without undue delay after we become aware of a breach affecting Client Personal Data. We share what we know about its nature, the data and people affected, its likely consequences and the measures taken, and we update the Client as we learn more. We take reasonable steps to contain the breach and limit its effects.

10. International Transfers

Our main database is in the European Union, but our staff and some sub-processors may access Client Personal Data from other countries. Where such a transfer from the EEA needs a transfer mechanism, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 apply and are incorporated into this DPA by reference:

  • Module Two (controller to processor), or Module Three (processor to processor) where the Client is itself a processor
  • Clause 7 (docking clause) applies
  • Clause 9: Option 2, general written authorization, with the 30-day notice in this DPA
  • Clause 11: the optional wording does not apply
  • Clause 13: the supervisory authority competent for the Client
  • Clauses 17 and 18: the law and the courts of Ireland
  • Annex I is the "Details of the Processing" section, Annex II the "Security Measures" section and Annex III our sub-processor list

For transfers from the United Kingdom, the UK International Data Transfer Addendum issued by the Information Commissioner applies on the same terms. For transfers from Switzerland, the clauses apply with the changes required by Swiss law, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

11. Audits

On request, we give the Client the information it needs to check our compliance with this DPA. If that is not enough, or a supervisory authority requires it, the Client may audit us once a year, with 30 days' notice, during business hours, at its own cost and under confidentiality.

12. Return and Deletion

When the Client stops using the Service, it can request an export of its data within 14 days. We then delete Client Personal Data within 30 days, except what the law requires us to keep. Backup copies are overwritten in the normal backup cycle.

13. Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms, except where the law does not allow it to be limited.

14. Contact Information

If you have questions about this DPA, please contact us:

Legal Inquiries
legal@replyk.io
Privacy Team
privacy@replyk.io
Mailing Address
VERSAAS LLC8206 Louisiana Blvd Ne, Ste A #7849, Albuquerque, New Mexico 87113, United States

View Sub-processors