← Back to legal

Data Processing Agreement

Last updated July 20, 2026

This DPA forms part of the Terms of Service between Anthony Casauria (sole trader) (“Processor”, “we”) and the customer (“Controller”, “you”) and applies where we process Personal Data on your behalf to provide the Service. Terms like “controller”, “processor”, “personal data”, and “processing” have the meanings given in the UK GDPR / EU GDPR.

01Roles & scope

You are the Controller and we are the Processor of the “Customer Personal Data” — the end-customer message content and identifiers processed through your connected channels. You are responsible for the lawfulness of your instructions and for having a valid basis (including any required consent) to message your customers.

Plain English

You control your customers’ data; we process it only on your instructions to run the Service.

02Processing details

  • Subject matter: providing the HyperDM Service.
  • Duration: the term of your subscription plus deletion periods below.
  • Nature & purpose: receiving inbound messages; generating and sending replies; storing conversations and consent state; analytics for you.
  • Data types: message content, platform-scoped identifiers, usernames/profile images, opt-in/opt-out state.
  • Data subjects: your end-customers who message your connected accounts.
Plain English

What we process, why, for whom, and for how long.

03Our obligations

  • Process Customer Personal Data only on your documented instructions (including via the Service’s settings), unless legally required otherwise.
  • Ensure personnel are bound by confidentiality.
  • Implement the security measures in §6 (Art. 32).
  • Assist you, taking account of the nature of processing, with data-subject requests and with your obligations under Art. 32–36 (security, breach notification, DPIAs).
  • Not sell Customer Personal Data and not use it for our own purposes or to train third-party foundation models.
Plain English

We follow your instructions, keep staff confidential, secure the data, and never sell it or train third-party models on it.

04Sub-processors

You authorize us to engage the sub-processors below. We impose data-protection terms on each and remain responsible for their performance. We will give notice of new sub-processors and a reasonable opportunity to object.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, storageUnited States
OpenAIReply generation & embeddings (no training on your data)United States
Meta PlatformsInstagram messaging; WhatsApp (not yet active — coming soon)United States / global
TikTokMessaging (not yet active — coming soon)Global
StripePayment processing (billing metadata only)United States
VercelApplication hostingUnited States
Plain English

The vendors we use, with notice and a chance to object before we add a new one.

05International transfers

Where we transfer Customer Personal Data outside the UK/EEA, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference and available on request.

Plain English

Cross-border transfers ride on the standard EU SCCs and UK IDTA.

06Security

  • Encryption in transit (TLS) and encryption of stored channel access tokens.
  • Strict tenant isolation via database row-level security and an application scoping layer.
  • Signed-webhook verification, least-privilege access, and audit logging of sends and policy checks.
  • Ongoing monitoring and access controls appropriate to the risk.
Plain English

Encryption, tenant isolation, signed webhooks, least-privilege access, and audit logging.

07Data-subject requests & breach

We will promptly notify you of a data-subject request we receive relating to your data and assist you in responding. We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide the information you reasonably need to meet your notification obligations.

Plain English

We flag relevant requests to you and notify you without undue delay of a personal-data breach.

08Deletion & return

On termination or your instruction, we will delete or return Customer Personal Data and delete existing copies within a commercially reasonable period, except where retention is legally required. You may also delete data during the term via the Service.

Plain English

On exit we delete or return the data, minus what law makes us keep.

09Audit

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits (including via third-party reports or a questionnaire) on reasonable notice, subject to confidentiality.

Plain English

We’ll provide what you reasonably need to confirm we’re compliant.

10Contact

Data-protection contact: hello@hyperdm.app Anthony Casauria (sole trader), St Helena, Victoria 3088 (full registered address available on request), Victoria, Australia.

Plain English

The data-protection contact.