Data Processing Addendum
The terms under which we process personal data on your behalf, and what we promise about it.
This Addendum (“DPA”) forms part of the Terms of Service between you (“Controller”) and Fivebucks Ventures Pte Ltd. (“Processor”, “we”), and applies whenever we process personal data on your behalf.
It applies automatically. There is nothing to sign. Requiring a countersigned PDF would mean most customers operate with no DPA at all, which is the opposite of what Article 28 is for. If your own compliance process needs an executed copy, ask and we will provide one.
1. What this covers, and what it does not
Our Privacy Policy draws the line and this DPA follows it exactly:
- Covered. The conversations your business has through us — on WhatsApp, or in the IMRelay Chat widget on your website — and the documentation you connect so they can be answered. You are the controller; we are your processor.
- Not covered. Your own account data: your name, email, workspace and billing details. We are the controller of that, and the Privacy Policy governs it. A DPA cannot bind us as a processor of data we decide the purposes for.
2. The processing, described
| Subject matter | Providing the Services under the Terms |
| Duration | For as long as your workspace exists, plus the deletion period in clause 8 |
| Nature and purpose | Receiving, storing and displaying conversations; retrieving from your documentation; generating and sending replies; handing over to your team |
| Types of personal data | Message content, and whatever your customers choose to put in it; a phone number and WhatsApp profile name, or a browser-stored identifier and an optional email address; IP address and user agent; the content of documents you connect |
| Categories of data subject | Your customers and website visitors, and the people named in the documentation you connect |
| Special category data | Not requested and not required. If your customers volunteer it in a message we will hold it as part of that conversation, but the Services are not designed for it and you should not solicit it |
3. Our obligations
- We process personal data only on your instructions. Your use of the Services, and the settings you choose in them, are those instructions. If we believe an instruction breaches data protection law we will tell you.
- Everyone with access is bound by confidentiality, and access is limited to those who need it. Our staff cannot read your conversations by default: it requires a grant from you, is time-limited, and every use is written to an audit log you can read.
- We keep the measures in Annex II, and will not materially weaken them.
- We help you respond to data subject requests, and to your obligations on security, breach notification and impact assessments, taking into account what you can see in the product yourself.
- We do not use your data to train AI models and do not permit our sub-processors to, with the one exception in Annex III that is not ours to give.
4. Your obligations
- You confirm you have a lawful basis to process your customers’ data and to have us process it for you, and that you have given them whatever notice the law requires.
- You must tell people they are talking to an AI where an automated answer is sent in your name. You are the deployer of that system.
- You are responsible for the website you install the chat widget on, and for keeping the website address in your account correct.
- You choose your AI provider and hold its key. Their processing of what you send is governed by your agreement with them, not this one.
5. Sub-processors
You give general written authorisation for the sub-processors in Annex III. We impose data protection obligations on each of them no less protective than these, and remain responsible to you for their performance.
We will give at least 30 days’ notice before adding or replacing one, by email to your workspace owners and by updating Annex III. If you reasonably object on data protection grounds within that period, tell us; if we cannot resolve it, you may terminate the affected Services and we will refund any prepaid fees for the unused remainder.
6. International transfers
Where personal data protected by UK or EU law leaves that area, the transfer is made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), and the UK Addendum where the UK GDPR applies, or under another lawful mechanism such as an adequacy decision. Those Clauses are incorporated into this DPA by reference, with Annexes I, II and III below supplying their required annexes. Where they conflict with this DPA, the Clauses win.
7. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at the time: what happened, which data and roughly how many people are affected, what we are doing, and what we suggest you do. We will not wait for a complete picture before telling you, and we will follow up as we learn more.
8. Deletion, return and audits
- You can delete conversations, contacts and knowledge sources yourself at any time, in the product.
- On termination we delete your data within 30 days, except where we must keep records for legal, accounting or tax purposes. Tell us before then if you want an export.
- Two things are deleted much sooner because they exist only to stop abuse: the hashed identifiers behind our rate limits after two days, and per-site daily question counts after 30.
- We will answer reasonable audit requests with our documentation and written responses. On-site audits are available where the law requires them, once in any twelve months unless a regulator or a breach requires otherwise, at your cost and subject to confidentiality.
Annex I · Parties and processing
Data exporter: you, the Controller, as identified by the workspace and billing details in your account. Data importer: Fivebucks Ventures Pte Ltd., Singapore. The subject matter, duration, nature, purpose, data types and data subjects are set out in clause 2 above. The competent supervisory authority is that of your own establishment.
Annex II · Security measures
These are what the system actually does, not a generic list.
- Tenant isolation in the database. Every table carrying customer data is protected by row-level security, so one workspace cannot read another’s rows even if application code asks it to.
- Secrets are encrypted at rest in a dedicated vault — your AI provider key, your documentation tokens — never in plain text, and never displayed again after entry.
- Identifiers are hashed. The identifier we use to recognise a returning contact is a one-way HMAC. So is the one behind our rate limits: a visitor’s raw IP address is not merely avoided, the database constraint refuses it.
- Staff access is off by default, granted by you, time-limited, and audit-logged.
- The chat widget is isolated. It runs in a frame on our own origin, so it cannot read the page it sits on and that page cannot read it, and it answers only on the website address in your account.
- WhatsApp content is walled off from your AI key. On that channel Meta’s own agent answers, and your provider key is not decrypted at all. This is enforced in code before the vault is read, not filtered afterwards.
- Traffic is encrypted in transit. Backups are encrypted at rest.
Annex III · Sub-processors
| Who | Where | What for |
|---|---|---|
| Meta Platforms | US / EU | Carries WhatsApp messages, and its agent generates replies on that channel |
| Supabase | Singapore | Database and encrypted secret storage |
| Vercel | US / global edge | Application hosting |
| Stripe | US / EU | Payments. Card details never reach us |
| OpenAI | US | Embeddings of your documentation, and of questions asked in IMRelay Chat, so they can be searched |
| Postmark | US | Transactional email, including a reply to a chat visitor who closed the tab |
| Notion · Google Drive · Box | US / EU | Only those you connect, and only the documents you grant. We read; we never write |
| The AI provider you choose | Varies | Generates answers in IMRelay Chat. Never for WhatsApp |
The last row is the exception mentioned in clause 3. You choose that provider and hold the key, so we cannot bind it on your behalf or promise what it does with what you send. The Terms require a plan that does not train on API data for exactly this reason.
Contact
Data protection questions, audit requests and breach queries: privacy@imrelay.io. If you are one of our customer’s customers rather than a customer yourself, our Privacy Policy explains how to reach the right person.