Legal
Data Processing Agreement
Last updated: July 27, 2026
This Data Processing Agreement ("DPA") is entered into between the Customer (hereinafter the "Controller") and Jérôme Gambiez, a sole trader (EI), with its registered office at Quai de France, 38000 Grenoble, France(hereinafter the "Processor" or "Responz").
This agreement is established pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and applies to all processing of personal data carried out by Responz on behalf of the Customer in connection with the use of the platform available at https://www.responz.io.
The DPA forms an integral part of the Terms of Service and takes precedence over them in matters of personal data processing.
1. Subject matter and scope of processing
As part of the provision of the Responz service, the Processor processes personal data on behalf of the Controller. This data includes in particular:
- the Customer's Intercom conversation data (message content, agent and end-user identifiers, timestamps);
- data of the Customer's support team members (name, email address, individual metrics);
- platform usage metadata generated by the Customer's actions.
This data is processed solely for the purposes of providing, maintaining and improving the Responz service, in accordance with the Controller's instructions.
2. Roles of the parties
- Data Controller
- The Customer using the Responz service
- Processor
- Jérôme Gambiez (Responz)
- Legal basis
- Performance of the service contract (Art. 6(1)(b) GDPR)
- Categories of persons
- Support agents, Customer's end users
- Processing duration
- Contract duration + 30 days for deletion
3. Processing instructions
The Processor processes personal data only on documented instruction from the Controller, including with respect to transfers of personal data to a third country or international organisation, unless required to do so by law.
The Processor immediately informs the Controller if, in its opinion, an instruction constitutes a breach of the GDPR or other applicable data protection provisions.
The settings of the Responz platform (retention periods, member access, data deletion) constitute the Controller's documented instructions within the meaning of this article.
4. Sub-processors
The Customer authorises the use of the following sub-processors for the provision of the service:
- Application hosting
- Vercel Inc. — EU regions (Frankfurt, Paris)
- Database
- Railway (EU)
- AI analysis (scoring, clustering)
- Anthropic / OpenAI — régions UE
- Transactional emails
- Resend
- Payment
- Stripe
Responz ensures that each sub-processor provides sufficient guarantees under the GDPR (standard contractual clauses or recognised adequacy mechanism).
Any addition or replacement of a sub-processor is notified in advance by email at least 14 days before its implementation. The Customer may object in writing within that period on legitimate data protection grounds; failing which, the change is deemed accepted.
5. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risks, Responz implements the following technical and organisational measures:
Technical measures
- Encryption of data in transit (TLS 1.2+) and at rest;
- Mandatory strong authentication (MFA) for administrator access;
- Least-privilege access control: engineers access production data only on justified and traceable request;
- Strict logical segregation of data between different customers;
- Access logging with 12-month retention;
- Regular backups with restoration testing.
Organisational measures
- Access to data limited to persons with a proven operational need;
- Confidentiality commitment for all persons accessing data;
- Documented security incident response procedure.
6. Notification of personal data breaches
In the event of a personal data breach within the meaning of Article 4(12) of the GDPR, the Processor notifies the Controller without undue delay and, where possible, within 72 hours of becoming aware of the breach.
The notification includes, where possible:
- the nature of the breach and the categories of data concerned;
- the approximate number of persons and records affected;
- the likely consequences of the breach;
- the measures taken or proposed to remedy the breach and mitigate its effects.
Breach notifications are sent to the email address associated with the Customer's account.
7. Assistance with data subjects' rights
Responz implements appropriate technical and organisational measures to assist the Controller in fulfilling its obligation to respond to requests for the exercise of data subjects' rights (Articles 15 to 22 of the GDPR): access, rectification, erasure, restriction, portability, objection.
Requests for deletion or export of data may be made from the platform settings or by sending a request to hello@responz.io. Responz undertakes to respond within 7 working days.
8. Deletion or return of data
At the end of the contract or at the Customer's request, Responz deletes or returns all personal data within a maximum of 30 days, unless legally required to retain it.
Before any permanent deletion, the Customer may request an export of their data in a machine-readable format (JSON or CSV). This request must be made before the expiry of the 30-day period.
Billing data is retained for 10 years in accordance with statutory accounting obligations, irrespective of contract termination.
9. Audit and inspection rights
Responz makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and contributes to audits, including inspections, carried out by the Controller or an auditor mandated by them.
Audits are conducted upon written request with a minimum of 30 days' notice, at most once per year, and must not disrupt the Processor's normal operations. Their costs are borne by the Controller.
10. Duration
This DPA enters into force on the date of acceptance of the Terms of Service by the Customer and remains in force for the duration of the service contract. It terminates automatically at the end of the deletion period set out in Article 8.
11. Contact
For any question regarding this DPA or data protection: hello@responz.io
Jérôme Gambiez — Quai de France, 38000 Grenoble, France