Data Processing Agreement
Last updated July 20, 2026This DPA forms part of the Terms of Service between Anthony Casauria (sole trader) (“Processor”, “we”) and the customer (“Controller”, “you”) and applies where we process Personal Data on your behalf to provide the Service. Terms like “controller”, “processor”, “personal data”, and “processing” have the meanings given in the UK GDPR / EU GDPR.
01Roles & scope
You are the Controller and we are the Processor of the “Customer Personal Data” — the end-customer message content and identifiers processed through your connected channels. You are responsible for the lawfulness of your instructions and for having a valid basis (including any required consent) to message your customers.
You control your customers’ data; we process it only on your instructions to run the Service.
02Processing details
- Subject matter: providing the HyperDM Service.
- Duration: the term of your subscription plus deletion periods below.
- Nature & purpose: receiving inbound messages; generating and sending replies; storing conversations and consent state; analytics for you.
- Data types: message content, platform-scoped identifiers, usernames/profile images, opt-in/opt-out state.
- Data subjects: your end-customers who message your connected accounts.
What we process, why, for whom, and for how long.
03Our obligations
- Process Customer Personal Data only on your documented instructions (including via the Service’s settings), unless legally required otherwise.
- Ensure personnel are bound by confidentiality.
- Implement the security measures in §6 (Art. 32).
- Assist you, taking account of the nature of processing, with data-subject requests and with your obligations under Art. 32–36 (security, breach notification, DPIAs).
- Not sell Customer Personal Data and not use it for our own purposes or to train third-party foundation models.
We follow your instructions, keep staff confidential, secure the data, and never sell it or train third-party models on it.
04Sub-processors
You authorize us to engage the sub-processors below. We impose data-protection terms on each and remain responsible for their performance. We will give notice of new sub-processors and a reasonable opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | United States |
| OpenAI | Reply generation & embeddings (no training on your data) | United States |
| Meta Platforms | Instagram messaging; WhatsApp (not yet active — coming soon) | United States / global |
| TikTok | Messaging (not yet active — coming soon) | Global |
| Stripe | Payment processing (billing metadata only) | United States |
| Vercel | Application hosting | United States |
The vendors we use, with notice and a chance to object before we add a new one.
05International transfers
Where we transfer Customer Personal Data outside the UK/EEA, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference and available on request.
Cross-border transfers ride on the standard EU SCCs and UK IDTA.
06Security
- Encryption in transit (TLS) and encryption of stored channel access tokens.
- Strict tenant isolation via database row-level security and an application scoping layer.
- Signed-webhook verification, least-privilege access, and audit logging of sends and policy checks.
- Ongoing monitoring and access controls appropriate to the risk.
Encryption, tenant isolation, signed webhooks, least-privilege access, and audit logging.
07Data-subject requests & breach
We will promptly notify you of a data-subject request we receive relating to your data and assist you in responding. We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide the information you reasonably need to meet your notification obligations.
We flag relevant requests to you and notify you without undue delay of a personal-data breach.
08Deletion & return
On termination or your instruction, we will delete or return Customer Personal Data and delete existing copies within a commercially reasonable period, except where retention is legally required. You may also delete data during the term via the Service.
On exit we delete or return the data, minus what law makes us keep.
09Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits (including via third-party reports or a questionnaire) on reasonable notice, subject to confidentiality.
We’ll provide what you reasonably need to confirm we’re compliant.
10Contact
Data-protection contact: hello@hyperdm.app — Anthony Casauria (sole trader), St Helena, Victoria 3088 (full registered address available on request), Victoria, Australia.
The data-protection contact.