This Data Processing Agreement ("DPA") reflects the parties' agreement with regard to the Processing of Personal Data. Hybrid Reply ("Processor") and the Customer ("Controller") agree to comply with the following provisions with respect to any Personal Data processed via the Hybrid Reply AI Engine.
"GDPR" means the EU General Data Protection Regulation 2016/679.
"CCPA" means the California Consumer Privacy Act of 2018.
"Data Incident" means a breach of Hybrid Reply's security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Customer Data.
Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country.
Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to:
Controller provides a general authorization to Processor to engage onward sub-processors. Processor shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
| Entity Name | Processing Activity | Entity Location |
|---|---|---|
| Google Cloud / Vertex AI | AI Infrastructure & Engine Processing | United States |
| AWS / DigitalOcean | Cloud Hosting & Data Storage | United States |
| Stripe, Inc. | Payment Processing & Billing | United States |
| SendGrid | Transactional Email Delivery | United States |
Processor shall notify Controller without undue delay (and in any event within 72 hours) after becoming aware of a Data Incident. Processor shall take reasonable steps to mitigate the effects and to minimize any damage resulting from the Data Incident.
Upon termination of the Service, Processor shall, at the choice of the Controller, delete or return all personal data to the Controller, unless applicable law requires continued storage of the personal data.
Questions regarding our data processing? Email security@hybridreply.com