R retentup.com ← Back to home

Data Processing Agreement

Last Updated: August 14, 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between you ("Customer," "Data Controller") and RetentUp.com ("Processor," "we," "us," "our") for the use of the RetentUp.com platform (the "Service").

This DPA reflects the parties' agreement with respect to the processing of Personal Data in accordance with the requirements of Data Protection Laws, including the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

1. Definitions

In this DPA:

  • "Data Protection Laws" means all applicable laws and regulations relating to the processing of Personal Data, including GDPR, UK GDPR, and any national implementing laws.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Customer through the Service.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data.

2. Scope and Roles

2.1 Relationship

The Customer is the Data Controller, and the Processor is the Data Processor with respect to Personal Data processed through the Service. The Processor shall process Personal Data only on behalf of and in accordance with the Customer's documented instructions.

2.2 Nature and Purpose of Processing

The Processor processes Personal Data for the purpose of providing the Service, which includes:

  • Storing and managing the Customer's contact and customer data
  • Orchestrating conversations across email, calls, iMessage, Telegram, and SMS on behalf of the Customer
  • Analyzing behavioral signals to time and personalize communications
  • Conducting AI-assisted call conversations, including transcription where enabled
  • Tracking conversation engagement (opens, replies, call outcomes, conversions)
  • Providing analytics and reporting
  • Synchronizing outcomes with the Customer's connected CRM systems

2.3 Types of Personal Data

The Personal Data processed may include:

  • Email addresses and phone numbers
  • Names (first name, last name)
  • Messaging identifiers (e.g., Telegram handles, iMessage addresses)
  • Custom fields defined by the Customer (e.g., company name, location, preferences)
  • Engagement data (opens, clicks, replies, call outcomes)
  • Call recordings and transcripts (where enabled by the Customer)
  • IP addresses and device information (for tracking purposes)

2.4 Data Subjects

The Data Subjects are individuals whose Personal Data is uploaded or synced by the Customer to the Service, including:

  • Existing customers of the Customer
  • Prospective customers and subscribers who have a relationship with the Customer
  • Other contacts designated by the Customer

3. Processor Obligations

3.1 Compliance with Instructions

The Processor shall process Personal Data only in accordance with the Customer's documented instructions, unless required to do so by applicable law. If the Processor believes an instruction violates Data Protection Laws, it shall inform the Customer.

3.2 Confidentiality

The Processor shall ensure that persons authorized to process Personal Data are bound by confidentiality obligations.

3.3 Security Measures

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data in transit and at rest
  • Regular security assessments and testing
  • Access controls and authentication mechanisms
  • Logging and monitoring of data access
  • Incident response procedures
  • Staff training on data protection

3.4 Sub-processors

The Customer authorizes the Processor to engage Sub-processors to process Personal Data. The Processor shall:

  • Notify the Customer of any intended material changes to Sub-processors upon request
  • Ensure Sub-processors are bound by data protection obligations equivalent to this DPA
  • Remain liable for the acts and omissions of Sub-processors

Categories of Sub-processors include:

  • Cloud hosting and infrastructure providers
  • Communication infrastructure providers (email delivery, telephony, messaging routes)
  • Payment processors

3.5 Data Subject Rights

The Processor shall, to the extent possible, assist the Customer in responding to requests from Data Subjects to exercise their rights under Data Protection Laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object

3.6 Data Breach Notification

The Processor shall notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach. The notification shall include:

  • Nature of the breach and categories of Data Subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact details for further information

3.7 Assistance with Compliance

The Processor shall assist the Customer with:

  • Data protection impact assessments (DPIAs)
  • Prior consultations with supervisory authorities
  • Compliance with obligations under Data Protection Laws

3.8 Audits

The Processor shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality obligations.

4. Customer Obligations

4.1 Lawful Basis

The Customer shall ensure it has a lawful basis for processing Personal Data and for transferring Personal Data to the Processor.

4.2 Data Subject Consent

The Customer is responsible for obtaining any necessary consents from Data Subjects for the processing of their Personal Data, including consent for communications via email, calls, iMessage, Telegram, and SMS where required by law.

4.3 Data Accuracy

The Customer shall ensure that Personal Data provided to the Processor is accurate and up to date.

4.4 Instructions

The Customer shall provide clear and lawful instructions for the processing of Personal Data.

5. International Data Transfers

5.1 Transfer Mechanisms

If Personal Data is transferred outside the EU/EEA or UK, the Processor shall ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions
  • Other lawful transfer mechanisms under Data Protection Laws

5.2 Standard Contractual Clauses

To the extent required, the parties agree that the European Commission's Standard Contractual Clauses for the transfer of Personal Data to third countries are incorporated by reference into this DPA.

6. Data Retention and Deletion

6.1 Retention Period

The Processor shall retain Personal Data for the duration of the Service agreement or as instructed by the Customer.

6.2 Deletion or Return

Upon termination of the Service or upon the Customer's request, the Processor shall (at the Customer's choice):

  • Delete all Personal Data; or
  • Return all Personal Data to the Customer in a machine-readable format

The Processor may retain Personal Data to the extent required by applicable law, in which case it shall continue to protect the Personal Data in accordance with this DPA.

7. Liability and Indemnity

7.1 Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms and Conditions.

7.2 Indemnity

The Processor shall indemnify the Customer against any claims, losses, damages, or fines arising from the Processor's material breach of this DPA or Data Protection Laws.

8. Term and Termination

This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Customer. Upon termination of the Service agreement, the provisions of Section 6 (Data Retention and Deletion) shall apply.

9. Amendments

The Processor may amend this DPA to reflect changes in Data Protection Laws or regulatory guidance, provided that such amendments do not materially reduce the Processor's obligations. The Processor shall notify the Customer of any material changes.

10. Governing Law and Jurisdiction

This DPA is governed by the laws of England and Wales. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

11. Contact Information

For questions regarding this DPA or data protection matters, please contact:

RetentUp.com
Email: dpo@retentup.com

← Back to home
Privacy Terms Cookies Fair Use Anti-Spam