Last updated: July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and InstantResponse.AI ("Processor") and applies whenever InstantResponse.AI processes personal data on behalf of the customer in providing the service. A countersigned version can be requested by writing to Info@InstantResponse.AI.
1. Scope and roles
The customer is the Controller of personal data submitted to the service. InstantResponse.AI is the Processor and processes personal data only on documented instructions from the Controller, including as set out in the Terms of Service, the account configuration, and this DPA.
2. Subject matter and duration
The subject matter is the provision of the InstantResponse.AI SaaS platform. Processing continues for the duration of the customer's subscription plus any period required to return or delete data as described below.
3. Nature and purpose
Processing enables InstantResponse.AI to receive inbound lead messages from connected channels, generate and deliver replies, produce reporting, and maintain the account.
4. Categories of data and data subjects
- Data subjects: the customer's staff (users of the platform) and the customer's leads and end customers who message through connected channels.
- Personal data: name, contact details, message content submitted through connected channels, metadata about conversations, and, where enabled, call metadata and recordings.
5. Processor obligations
- Process personal data only for the documented purposes above and in accordance with applicable data-protection laws
- Ensure personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Section 7)
- Assist the Controller with data-subject requests and, where applicable, with data-protection impact assessments and regulator consultations
- Notify the Controller without undue delay after becoming aware of a personal-data breach affecting their data
6. Subprocessors
The customer authorizes InstantResponse.AI to engage subprocessors to help deliver the service, including cloud infrastructure, database, communications, payment, and AI providers. A current list is available on request from Info@InstantResponse.AI. InstantResponse.AI remains responsible for the acts and omissions of its subprocessors.
7. Security measures
InstantResponse.AI implements technical and organizational measures designed to protect personal data, including encryption in transit, access controls, account-level data separation, monitoring, and secure development practices. See our Security page for detail.
8. International transfers
Personal data may be transferred to and processed in the United States and other countries where InstantResponse.AI or its subprocessors operate. Where required by applicable law, appropriate safeguards (such as Standard Contractual Clauses) will apply.
9. Data-subject rights
InstantResponse.AI will provide reasonable assistance to the Controller in responding to requests from data subjects to exercise their rights under applicable law (access, correction, deletion, portability, objection, and restriction).
10. Return or deletion of data
Upon termination of the service, InstantResponse.AI will, at the Controller's choice, return or delete personal data processed on the Controller's behalf, subject to retention required by law and reasonable backup cycles.
11. Audits
The Controller may request information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is required by law, the parties will agree on scope and timing in advance to minimize disruption to the service.
12. Contact
To request a signed DPA, an updated subprocessor list, or to raise a data-protection question, contact Info@InstantResponse.AI.
