Data Processing Agreement
Last updated: 04.08.2025 · WEB-02-DPA · English v3.0
Data Processing Addendum (DPA)
This Data Processing Addendum (“DPA”) supplements the SmartReach AI Terms of Service or other agreement between SmartReach AI (“Company”) and Customer governing Customer's use of the Services (“Agreement”). This DPA applies to the processing of Personal Data in connection with the Services.
1. Definitions
1.1 Applicable Data Protection Law: All laws and regulations applicable to the processing of Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (FADP), and US state privacy laws.
1.2 Customer Data: Personal Data provided by or on behalf of Customer to Company for processing in connection with the Services.
1.3 Personal Data, Controller, Processor, Data Subject, Processing: Shall have the meanings given under Applicable Data Protection Law.
2. Scope and Roles
2.1 Roles of the Parties: Customer is the Controller and Company is the Processor in respect of Customer Data processed under the Agreement.
2.2 Purpose of Processing: Company shall process Customer Data solely for the purpose of providing the Services in accordance with the Agreement and Customer's documented instructions.
3. Obligations of the Processor
3.1 Compliance with Instructions: Company shall process Customer Data only in accordance with Customer's instructions, unless required to do otherwise by law.
3.2 Confidentiality: Company shall ensure that persons authorized to process Customer Data have committed themselves to confidentiality.
3.3 Security: Company shall implement technical and organizational measures appropriate to the risk to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
4. Sub-processors
4.1 Authorization: Customer authorizes Company to engage sub-processors to process Customer Data, provided Company imposes data protection terms no less protective than those in this DPA.
4.2 Notice of Changes: Company shall notify Customer of intended changes concerning the addition or replacement of sub-processors.
5. International Transfers
Where processing involves international transfers of Customer Data subject to European or UK data protection laws, Company shall ensure appropriate safeguards are implemented, such as standard contractual clauses approved by the European Commission or equivalent UK mechanisms.
6. Data Subject Rights & Assistance
Company shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights.
7. Personal Data Breach
Company shall notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Data and shall assist Customer in complying with its breach notification obligations.
8. Deletion or Return
Upon termination or expiration of the Agreement, Company shall, at Customer's choice, delete or return all Customer Data, unless required by law to store the data.
9. Audits
Company shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by Customer or an independent auditor.
10. Contact
For questions regarding this DPA, contact dpo@smartreachai.com.
Questions about this policy? Contact us at legal@smartreachai.com.