Data Processing Agreement
Last updated: a completer : publication date
This data processing agreement (the "DPA") governs the processing of personal data carried out by Reponse on behalf of its customers in connection with the service. It is published so that any customer can review it before subscribing. It supplements the terms of sale and terms of use of the service and prevails over them on all matters relating to the protection of personal data.
This agreement does not cover the trackers set on Reponse's public website, which are dealt with in a separate document, the cookie policy, published separately and carrying its own date of last update.
a valider : alignment of the title displayed in the website navigation, which announces "Data processing agreement (DPA) and cookie policy" while this document does not deal with cookies
This agreement is published in French and in English. In the event of a discrepancy in interpretation, the French version prevails, in accordance with section 19.2.
Drafting note: in both language versions, the items still to be verified or completed before publication are flagged with the markers {{A_VALIDER}}, {{A_VERIFIER}} and {{A_COMPLETER}}, deliberately kept in French so that they can be tracked as a single list. All of these markers must be resolved before the document is published.
1. Parties
**The processor**: Shmore, a simplified joint stock company (societe par actions simplifiee) with share capital of 1,000 euros, registered office at 26 Thubert, 44118 La Chevroliere, France, registered with the Paris trade and companies register under number 978 743 013, publisher of the Reponse service available at reponse.ai. Referred to below as "Reponse" or "the processor".
a verifier : consistency between registered office and register, the stated office is in Loire Atlantique while the register indicated is Paris
Contact for matters relating to this agreement: hello@reponse.ai. Technical support: support@reponse.ai.
a completer : EU VAT number a completer : name of the publication director a completer : telephone number a completer : data protection officer, if one has been appointed, and contact details
**The controller**: the customer, a legal entity or a natural person, who subscribes to the Reponse service and creates one or more workspaces. Referred to below as "the customer" or "the controller".
The service is designed for professional use. Where, by exception, a natural person subscribes to the service outside any professional activity, that person is a consumer within the meaning of the French Consumer Code and section 18.3 applies to them.
Hereinafter jointly referred to as "the parties".
2. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them by Article 4 of the General Data Protection Regulation.
"GDPR" means Regulation (EU) 2016/679 of 27 April 2016.
"French Data Protection Act" means Law no. 78-17 of 6 January 1978 as amended.
"Standard contractual clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission by implementing decision (EU) 2021/914 of 4 June 2021.
"Service" means the Customer Experience suite published by Reponse, its web interfaces, its chat widget, its API and its MCP server.
"Customer Data" means the personal data that the customer, its users, its own customers or its connected systems transmit to the service, or that is generated within it on the customer's behalf.
"Sub-processor" means any third party to which Reponse entrusts part of the processing of Customer Data. That term never designates Reponse itself.
3. Roles of the parties
The customer acts as controller for Customer Data. It determines the purposes and essential means of the processing, chooses which features to enable and decides what data it places into the service.
Reponse acts as processor for that same data. Reponse processes Customer Data only on the documented instructions of the customer.
Reponse acts as an independent controller, not as a processor, for its own processing activities: management of its customer accounts and billing, security and fraud prevention, support, audience measurement on its own website, and compliance with its legal and accounting obligations. Those activities are described in the service privacy policy and, as regards trackers, in the cookie policy, and not in this agreement.
Where the customer is itself a processor acting for a third party, for instance an agency operating the service on behalf of a brand, it warrants that it holds the authorisations needed to enter into this agreement. Reponse then acts as a further processor within the meaning of Article 28(4) GDPR. Throughout this agreement, the defined term "Sub-processor" remains reserved for third parties to which Reponse entrusts part of the processing.
4. Subject matter, duration, nature and purpose of the processing
**4.1 Subject matter.** This agreement sets out the conditions under which Reponse processes, on behalf of the customer, the personal data required to provide the service.
**4.2 Duration.** This agreement takes effect on the date the service terms are accepted or on first use of the service, whichever is earlier. It remains in force for as long as Reponse processes Customer Data, and thereafter until that data has been fully deleted or returned in accordance with section 16.
**4.3 Nature of the processing.** Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to the sub-processors listed in Annex 2, alignment, restriction, erasure and destruction.
**4.4 Purposes.** The processing is carried out for the sole purpose of providing and maintaining the service subscribed to by the customer, namely:
- live chat with a human agent and with an AI agent, on the customer's site and in connected channels,
- management of tickets and of the shared inbox,
- collection and display of customer reviews,
- loyalty and referral programmes,
- contact management and CRM,
- sending of transactional emails triggered by the customer or by its rules,
- access to the customer's catalogue and orders,
- access to the service through the API and the MCP server,
- technical assistance provided to the customer at its request,
- security of the service, prevention of abuse and technical logging.
**4.5 Detailed description.** The full description of the processing is set out in Annex 1.
5. Documented instructions of the controller
**5.1** Reponse processes Customer Data only on the documented instructions of the customer, including with regard to transfers outside the European Union.
**5.2** Taken together, the customer's documented instructions consist of:
- this agreement and its annexes,
- the general terms of the service and the technical documentation,
- the configuration settings chosen by the customer in its workspace, in particular the integrations it enables, the automation rules it writes and the retention periods it selects where the service allows,
- the calls made by the customer to the service's programming interfaces,
- any additional written instruction sent to hello@reponse.ai and accepted in writing by Reponse.
**5.3** If Reponse considers that an instruction from the customer infringes the GDPR or another provision of Union or Member State law on data protection, it shall inform the customer without delay and may suspend performance of the instruction concerned until it is confirmed or amended.
**5.4** If Reponse is required to process Customer Data under Union law or French law outside the customer's instructions, it shall inform the customer before processing, unless that law prohibits such information on important grounds of public interest.
**5.5** Reponse does not sell Customer Data, does not rent it, does not use it for advertising purposes and does not exploit it for its own account outside the cases set out in section 3.
**5.6 Aggregated data.** Reponse may produce aggregated statistics on the use of the service for operational, billing, security and service improvement purposes. Those statistics contain no conversation content and are produced without any direct identifier of data subjects.
a completer : anonymisation method applied to those statistics, minimum aggregation threshold, removal of technical identifiers and of workspace identifiers
a valider : irreversibility of the anonymisation, failing a demonstration of that irreversibility those statistics amount to pseudonymisation and remain subject to the GDPR and to this agreement
6. Customer obligations
The customer warrants that:
- it has a valid legal basis for each processing operation it entrusts to Reponse and, where consent is required, that it has obtained it in accordance with the GDPR,
- it has informed data subjects of the processing, of the use of Reponse as a processor and, where relevant, of the use of AI agents to handle their requests,
- the data it transmits is accurate, relevant and limited to what is necessary,
- it does not place into the service, in particular in conversations, contact records or imported files, any data covered by Article 9 GDPR (special category data, in particular health data, political opinions, religious beliefs, sexual orientation, biometric data), any data relating to criminal convictions, any payment card numbers or any authentication credentials, unless Reponse has agreed in writing in advance and appropriate safeguards have been put in place,
- it correctly configures the access rights of its own users and promptly revokes access that is no longer needed,
- it verifies that the integrations it enables towards third party services are compatible with its own commitments,
- it determines the minimum age applicable to its own services and, where minors are likely to use the chat widget or the other connected channels, it provides appropriate information and, where applicable, obtains the consent of the holder of parental responsibility in accordance with Article 8 GDPR and Article 45 of the French Data Protection Act.
a completer : minimum age of use of the service stated by Reponse in its general terms, and measures provided for where the service is used by a minor
The customer remains solely responsible for the content of the messages it sends and for the decisions it takes on the basis of information returned by the service.
7. Confidentiality and personnel
**7.1** Reponse treats Customer Data as confidential information. This obligation survives the end of the agreement.
**7.2** Reponse undertakes that persons authorised to process Customer Data are bound by an obligation of confidentiality, through a contractual clause or an appropriate undertaking, and remain bound by that obligation after the end of their engagement.
a valider : confidentiality undertaking actually signed by each authorised person, employees and contractors alike, and retention of those undertakings
**7.3** Access to Customer Data is limited to team members who need it to provide, operate or secure the service, or to answer a support request.
a valider : actual maintenance of a named and up to date list of the persons authorised to access Customer Data
**7.4** Reponse ensures that those persons are made aware of personal data protection requirements.
a completer : description of the training programme and its frequency
**7.5 Location of personnel and remote access.** Access to Customer Data by Reponse's personnel and by its independent contractors takes place remotely from workstations under its control. Where access is carried out from a country outside the European Union, including in the context of remote working, that access constitutes a transfer within the meaning of Chapter V GDPR and must be governed by one of the mechanisms set out in section 14.
a completer : list of countries from which access to Customer Data is possible, status of the persons concerned, employees or contractors, and measures applied to their workstations
8. Security measures
**8.1** Reponse implements the appropriate technical and organisational measures required by Article 32 GDPR, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of individuals.
**8.2** Those measures are described in Annex 3. They are described factually, as actually implemented at the date of last update of this agreement. Items still to be verified or formalised are flagged there with a marker and do not constitute a commitment.
**8.3** Reponse makes no claim in this agreement to any security certification, any label or any quantified availability commitment. Any certification obtained in the future will be recorded in Annex 3.
**8.4** The measures may evolve, in particular to reflect changes in risks and technology. Reponse will not make any change that materially lowers the security level of the service.
9. Sub-processors
**9.1 General authorisation.** The customer gives Reponse a general written authorisation to engage sub-processors for the performance of the service, subject to this section.
**9.2 List.** The list of sub-processors is set out in Annex 2. It is published and kept up to date at a completer : URL of the public sub-processor page.
**9.3 Contract.** Reponse undertakes to impose on each sub-processor, by contract, data protection obligations that are substantially equivalent to those in this agreement. Reponse remains fully liable to the customer for the performance by the sub-processor of its obligations.
a valider : existence and actual signature of a data processing agreement or data protection addendum with each of the sub-processors listed in Annex 2, and retention of those documents
**9.4 Prior notice and objection.** Reponse informs the customer of any addition or replacement of a sub-processor at least thirty days before it takes effect, by email to the workspace contact address or by a dated entry on the page referred to in section 9.2, to which the customer may subscribe.
The customer may object to that addition or replacement on reasonable and documented data protection grounds, within thirty days of being informed, in writing to hello@reponse.ai. The parties will then seek an alternative solution in good faith. Failing agreement within thirty days, the customer may terminate, without charge or penalty, the part of the service affected by the sub-processor concerned, with a pro rata refund of amounts paid in advance and not used.
**9.5 Integrations enabled by the customer.** When the customer enables an integration towards a third party service, in particular Shopify, Klaviyo, Notion or TikTok Shop, it instructs Reponse to transmit to that third party the data required for the integration to work. That third party then acts either as a sub-processor of Reponse or as an independent controller, depending on the contractual relationship between the customer and that third party. Customers are invited to review the terms applicable to each of those services.
10. Assistance with data subject rights
**10.1** Reponse makes available to the customer, within the service, the features needed to access a contact's data and to correct it. The customer may also ask Reponse, in writing to hello@reponse.ai, to export or delete a contact's data.
a valider : export and deletion features for a contact actually available in the service interface, failing which those operations are carried out by Reponse on request and this section must be adjusted accordingly
**10.2** If a data subject sends a rights request relating to Customer Data directly to Reponse, Reponse does not answer the request on the merits. It informs the customer without undue delay and forwards the request, unless applicable law requires Reponse to answer directly.
**10.3** Reponse assists the customer, insofar as possible and taking into account the nature of the processing, in responding to requests to exercise the rights of access, rectification, erasure, restriction, portability and objection, as well as the right not to be subject to a decision based solely on automated processing.
**10.4** This assistance is provided at no additional cost where it can be performed using the standard features of the service. Where it requires specific and significant technical work, Reponse informs the customer in advance and the parties agree in writing on the conditions and the cost before any expense is incurred.
a valider : free standard assistance and the principle of charging for exceptional requests a completer : rate card applicable to exceptional assistance work, daily rate, billing unit and annual cap
11. Assistance with security, impact assessments and prior consultation
Reponse assists the customer, taking into account the nature of the processing and the information available to it, in:
- ensuring compliance with the security obligations set out in Article 32 GDPR,
- notifying personal data breaches to the supervisory authority (Article 33) and communicating them to data subjects where required (Article 34),
- carrying out a data protection impact assessment (Article 35), by providing the necessary technical information about the service, in particular on how the AI agents operate,
- conducting, where applicable, prior consultation with the supervisory authority (Article 36).
This assistance takes the form of available documentation and written answers to the customer's questions. It does not transfer to Reponse any of the obligations that fall to the controller.
12. Personal data breach notification
**12.1** Reponse notifies the customer of any personal data breach affecting Customer Data, without undue delay and no later than forty eight hours after becoming aware of it. Becoming aware means the moment at which Reponse has a reasonable degree of certainty that a security incident has compromised Customer Data, at the end of the initial technical qualification of the incident.
a valider : fixed forty eight hour deadline, stricter than the GDPR, its operational feasibility in the absence of a formalised on-call rota, and the starting point chosen
**12.2** The notification is sent by email to the contact address recorded in the customer's workspace, from the address hello@reponse.ai. The customer keeps its contact address up to date. No other channel constitutes notification for the purposes of this section.
**12.3** The notification describes, to the extent the information is available at the time of sending:
- the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned,
- the likely consequences of the breach,
- the measures taken or proposed to address it and to mitigate its effects,
- the point of contact from which further information may be obtained.
**12.4** Where all the information cannot be provided at once, it is provided in phases without undue delay.
**12.5** It is for the customer, as controller, to decide on and carry out notification to the supervisory authority and communication to data subjects. Reponse does not notify a breach to a supervisory authority on the customer's behalf without written instructions from the customer.
**12.6 Reciprocal obligation of the customer.** The customer notifies Reponse, without undue delay and in writing to hello@reponse.ai, of any security incident on its side that is liable to affect Customer Data hosted in the service, of any compromise or suspected compromise of one of its users' access, and of any complaint or request from a data subject whose handling requires Reponse's involvement. The customer promptly revokes any compromised access.
13. Processing by AI models
**13.1** The service includes features that rely on artificial intelligence models. To generate a reply, the required content, in particular the data subject's message, the conversation history and the context elements selected by the customer, is transmitted to the model providers listed in Annex 2, which act as sub-processors of Reponse.
**13.2** Reponse does not develop or train models on Customer Data. Reponse uses the business offerings of the model providers, whose terms exclude, according to those providers, the use of data submitted through the programming interface for training their models. Reponse does not knowingly opt into any contractual option that would allow such training.
a valider : contract by contract verification that no training occurs on the data transmitted, including for the specific plans and tiers actually subscribed to with each provider, and retention of the terms applicable at the date of subscription
**13.3** The service may route a given request to one or another of the providers listed in Annex 2 based on technical and economic criteria. The customer may ask Reponse for information on the providers likely to be used for its workspace.
**13.4** Automatically generated replies are proposals intended to be used by the customer. Where the customer enables a fully automated mode, it is for the customer to assess whether the processing falls within Article 22 GDPR and to draw the appropriate conclusions, in particular by informing data subjects and providing for human intervention.
14. International transfers
**14.1 Location.** The country and, where known, the hosting region of each sub-processor are set out in Annex 2. Reponse aims to have Customer Data hosted within the European Union or the European Economic Area. That location cannot be guaranteed for all sub-processors as at the date of last update of this agreement.
a completer : actual hosting region for each sub-processor, in particular Supabase and Netlify, as recorded in the administration consoles
**14.2** Some sub-processors are established outside the European Union, in particular in the United States, or may carry out all or part of the processing there. In that case, the transfer is governed by one of the mechanisms provided for in Chapter V GDPR:
- an adequacy decision of the European Commission, including, where applicable, the recipient's participation in the EU-US Data Privacy Framework,
- failing that, the standard contractual clauses, supplemented by appropriate additional measures.
**14.3** The customer instructs Reponse to carry out those transfers for the purposes of the service and authorises Reponse to enter into the standard contractual clauses with the sub-processors concerned, on the customer's behalf.
**14.4** Annex 2 specifies, for each sub-processor, the country of processing and the applicable transfer mechanism.
a completer : verification, sub-processor by sub-processor, of the transfer mechanism and the supporting documentation
**14.5 Applicable module of the standard contractual clauses.** Where the standard contractual clauses are used for a transfer between the customer and Reponse, or between Reponse and a sub-processor, the applicable module is:
- module 2, controller to processor, where the customer acts as controller,
- module 3, processor to processor, where the customer itself acts as a processor within the meaning of section 3.
Annexes I, II and III to the standard contractual clauses are completed separately from the annexes to this agreement. Annexes 1 and 3 to this agreement may be incorporated there by reference, without replacing the annexes proper to the clauses.
a completer : drafting and signature of Annexes I, II and III to the standard contractual clauses, module by module a completer : designation of the lead supervisory authority and of the competent court under the standard contractual clauses
**14.6 Transfer impact assessment.** For each transfer outside the European Union based on the standard contractual clauses, a transfer impact assessment is prepared, covering the law of the destination country, the technical, contractual and organisational supplementary measures adopted and the residual risks. Reponse provides that assessment to the customer on written request.
a completer : actual completion of the transfer impact assessment for each sub-processor located outside the European Union, and date of its last review
**14.7 Invalidation, suspension or amendment of the transfer mechanism.** If the transfer mechanism used is invalidated, suspended or materially amended by a decision of a competent authority or court, the parties will confer without undue delay in order to put in place a replacement mechanism within a reasonable time. In the meantime, Reponse will apply the supplementary measures available and, if no replacement mechanism is workable, will suspend the transfer concerned. If that suspension makes the service impossible to provide, the customer may terminate the part of the service concerned without charge or penalty, with a pro rata refund of amounts paid in advance and not used.
**14.8 Binding requests from public authorities.** If Reponse, or one of its sub-processors, receives from a public, judicial or administrative authority, including outside the European Union, a binding request for disclosure of Customer Data, Reponse will:
- inform the customer without undue delay, unless applicable law prohibits it from doing so, in which case it will seek to have that prohibition lifted or its scope reduced, and will inform the customer as soon as it becomes possible to do so,
- review the lawfulness of the request and challenge, through the available remedies, including by seeking interim measures, any request that appears to it unlawful under Union law or the law of the Member State concerned, or manifestly disproportionate,
- disclose only the minimum data strictly required by the request, after a reasonable assessment of its scope,
- document the requests received, the items disclosed and the action taken, and make that information available to the customer on request, to the extent that disclosure is lawful.
a completer : existence, format and frequency of a transparency report recording the number and nature of requests received from public authorities
15. Audit and documentation
**15.1** Reponse makes available to the customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, in particular this agreement, its annexes and the technical documentation of the service.
**15.2** The customer may request, once in any twelve month period, additional written information on the security measures implemented. That request may take the form of a security questionnaire completed by Reponse, subject to a limit of one questionnaire per twelve month period and of a completer : maximum number of questions per questionnaire questions. Reponse responds within thirty days of the request, where appropriate by referring to its existing documentation where that documentation answers the question asked.
**15.3** The customer may carry out an on-site audit, or have one carried out by an independent third party bound by confidentiality, in the following cases: following a data breach affecting its data, at the reasoned request of a supervisory authority, or where the information provided under section 15.2 is manifestly insufficient.
**15.4** The audit is notified in writing at least thirty days in advance, takes place during business hours, does not disproportionately disrupt Reponse's operations, does not cover confidential information relating to other customers, and does not include penetration testing without the prior written agreement of Reponse and, where relevant, of its hosting providers. The cost of the audit is borne by the customer, unless the audit reveals a material failure by Reponse to meet its obligations. Time spent by Reponse on an audit, or on a questionnaire exceeding the limits of section 15.2, is charged in accordance with the rate card referred to in section 10.4.
**15.5** Each party maintains a record of categories of processing activities in accordance with Article 30 GDPR.
16. Fate of the data at the end of the agreement
**16.1 Return and reversibility.** Throughout the term of the agreement and for thirty days after it ends, the customer may export its data from the service in the formats made available by Reponse.
a completer : export formats actually available, CSV, JSON or other, and export channel, interface or API a completer : scope exported by category of data, conversations, tickets, contacts, reviews, loyalty and referral data, attachments, technical logs, and scope expressly excluded from the export a completer : conditions and pricing of migration assistance beyond the standard export a valider : thirty day retrieval window
**16.2 Deletion.** At the customer's written election, made before the end of that period, Reponse deletes Customer Data or returns it. Absent an express election, Reponse deletes Customer Data at the end of that period.
**16.3 Deletion timeline.** Deletion from production systems takes place within a valider : thirty days of the end of the retrieval period. Data held in backups, where backups exist, is deleted when the backup rotation cycle expires.
a completer : length of the backup rotation cycle
**16.4 Dormant free workspaces.** A scheduled job deletes free plan workspaces that have remained inactive for an extended period.
a valider : inactivity period that triggers the purge a valider : whether an advance notice email is actually sent before the purge, the length of that notice and the recipient address, failing which this clause must be corrected
**16.5 Legal retention.** Reponse may retain certain data beyond those periods where Union law or French law requires it, in particular for accounting and tax purposes, and only to the extent and for the duration required. Such data is then archived with restricted access and is no longer processed for any other purpose.
**16.6** Reponse certifies deletion in writing at the customer's request.
**16.7 Identification data and connection logs.** Reponse retains the identification data provided on subscription and the connection logs whose retention is required by the French Act for confidence in the digital economy and by decree no. 2021-1362 of 20 October 2021, for the period laid down by those texts and for the sole purpose of responding to requests from authorised authorities. That retention applies regardless of the retention periods chosen by the customer.
a completer : exact scope of the data retained on that basis and the retention periods applied, to be confirmed by counsel in the light of decree no. 2021-1362
17. Liability and insurance
**17.1** Each party's liability under this agreement is governed by the liability provisions of the general terms of the service, within the limits permitted by applicable law and without those limits restricting the rights of data subjects or the enforcement powers of supervisory authorities.
**17.2** Each party bears the consequences of its own breaches of the GDPR.
**17.3** a completer : existence of a professional liability insurance policy, insurer, address, policy number, insured amounts and geographic coverage, no insurance may be mentioned in this agreement until the policy is taken out and produced
18. Governing law and jurisdiction
**18.1** This agreement is governed by French law and by the GDPR.
**18.2** The parties will seek an amicable resolution of any dispute. Failing agreement, the dispute will be brought before the competent courts.
a completer : designated competent court, consistent with the general terms and with Article 48 of the French Code of Civil Procedure for business to business relationships
**18.3** The service is intended for professionals. The website is nonetheless accessible to individuals. Where a contract is concluded with a consumer within the meaning of the French Consumer Code, in the case referred to in section 1, jurisdiction clauses cannot be enforced against that consumer and the protective rules of the Consumer Code apply, including the right to refer the matter free of charge to a consumer mediator.
a completer : name and contact details of the consumer mediator
19. Amendments, language and contact
**19.1** Reponse may amend this agreement to reflect legal, regulatory, case law or technical developments. Any material change is communicated to the customer at least thirty days before it takes effect.
**19.2** This agreement is published in French and in English. In the event of a discrepancy in interpretation, the French version prevails.
**19.3** Any question relating to this agreement may be sent to hello@reponse.ai. Technical support requests should be sent to support@reponse.ai.
20. Assignment, change of control and insolvency proceedings
**20.1** Reponse may assign this agreement, in particular in the event of a merger, partial contribution of assets, sale of its business or change of control of Shmore, provided that the assignee assumes all of the obligations under this agreement. Reponse will inform the customer in writing within thirty days of the transaction.
**20.2** If the assignee or the new controlling shareholder is established outside the European Union, or if the transaction materially changes the conditions of processing, security or location of Customer Data, the customer may terminate the agreement without charge or penalty within thirty days of being informed, with a pro rata refund of amounts paid in advance and not used.
**20.3** In the event of the opening of safeguard, receivership or judicial liquidation proceedings, Reponse or the appointed officer will implement, to the extent permitted by law and by the applicable court decisions, the measures allowing the customer to export its data before any discontinuation of the service.
a completer : reversibility mechanism in the event of insolvency proceedings, in particular the minimum notice of service discontinuation and the arrangements for accessing data during the proceedings
21. General provisions
**21.1 Order of precedence.** In the event of a conflict between the contractual documents, the order of precedence is as follows:
- the signed standard contractual clauses, solely as regards the international transfers they govern,
- this agreement and its annexes,
- the terms of sale and terms of use of the service,
- the technical documentation of the service and any other document.
**21.2 Severability.** If any provision of this agreement is held void, unlawful or unenforceable by a competent court or authority, that provision is deemed not to have been written and the remaining provisions remain in force. The parties will negotiate in good faith a replacement provision with as close an economic and legal effect as possible.
**21.3 No waiver.** The failure of a party to rely on a breach by the other party of any of its obligations may not be construed as a waiver of the right to rely on it subsequently.
**21.4 Entire agreement.** This agreement, its annexes and the documents it refers to constitute the entire agreement of the parties with regard to the protection of personal data and supersede any prior agreement on the same subject matter.
**21.5 Survival.** Sections 7, 12.6, 16, 17, 18 and 21 survive the end of this agreement for as long as necessary for their performance.
Annex 1: description of the processing
**Subject matter.** Provision of a Customer Experience suite to Shopify merchants and online commerce websites.
**Duration.** The term of the subscription or of use of the free plan, followed by the retrieval period and the deletion timelines set out in section 16.
**Nature of the operations.** Collection, recording, structuring, storage, consultation, use, transmission to sub-processors, generation of replies by AI models, sending of emails, erasure, and where applicable indexing of content for search.
a valider : existence of vector indexing of content, embeddings provider used and the corresponding place of processing, failing which this operation must be removed from the list
**Purposes.** Those listed in section 4.4.
**Categories of data subjects**
- the customer's own customers and prospects, meaning the visitors and buyers of its online store,
- the users of the customer's workspace, meaning its employees, contractors and agents,
- business contacts recorded in the customer's CRM,
- recipients of transactional emails sent by the customer.
**Categories of data processed**
- identification data: last name, first name, email address, telephone number where provided, internal identifiers, the contact's identifier in the customer's systems,
- communication content: chat messages, tickets, attachments sent by the data subject, customer reviews, internal notes,
- order and transaction data: order number, products, amounts, status, delivery and billing address, purchase history,
- loyalty and referral data: points balance, referrals, rewards,
- connection and technical data: IP address, timestamp, browser type, pages viewed in the context of the conversation, session identifier,
- workspace user account data: credentials, roles and permissions, activity logs,
- where applicable, traits and preferences inferred from a conversation, a valider : existence, scope and activation conditions of a contact memory feature, categories of inferred traits and retention period, failing which this category must be removed,
- any other data the customer chooses to place into the service.
**Excluded categories.** Special category data within the meaning of Article 9 GDPR, data relating to criminal convictions, payment card numbers and authentication credentials must not be placed into the service, in accordance with section 6. The service is not designed to process them.
**Retention within the service.** Data is retained for the term of the agreement and deleted in accordance with section 16. Where the service allows, the customer may set shorter periods.
a valider : retention period for conversations, common proposal of three years from last contact a valider : retention period for technical logs, common proposal of six to twelve months a valider : retention period for CRM contact data, common proposal of three years from last contact
Annex 2: list of sub-processors
List current as at the date of last update of this agreement. The version in force is published at a completer : URL of the public sub-processor page.
Infrastructure and core functions
| Sub-processor | Role | Data concerned | Place of processing | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage | All Customer Data | a completer : project region | {{A_COMPLETER}} |
| Netlify | Hosting of the website and of application functions | Data passing through requests, technical logs | a completer : edge and function regions | {{A_COMPLETER}} |
| Stripe | Payment of subscriptions and payment of merchants' orders | Identification and billing data, transaction data | {{A_COMPLETER}} | {{A_COMPLETER}} |
a completer : exact corporate name and postal address of each sub-processor, in particular Netlify
AI models
| Sub-processor | Role | Data concerned | Place of processing | Transfer mechanism |
|---|---|---|---|---|
| OpenAI | Reply generation, multi-provider routing | Message content and context transmitted | {{A_COMPLETER}} | {{A_COMPLETER}} |
| Reply generation, multi-provider routing | Message content and context transmitted | {{A_COMPLETER}} | {{A_COMPLETER}} | |
| Mistral | Reply generation, multi-provider routing | Message content and context transmitted | {{A_COMPLETER}} | {{A_COMPLETER}} |
| Sub-processor | Role | Data concerned | Place of processing | Transfer mechanism |
|---|---|---|---|---|
| Resend | Email delivery | Email address, name, message content | {{A_COMPLETER}} | {{A_COMPLETER}} |
| Amazon SES | Email delivery | Email address, name, message content | a completer : AWS region | {{A_COMPLETER}} |
| Svix | Signing and delivery of email webhooks | Delivery event metadata | {{A_COMPLETER}} | {{A_COMPLETER}} |
Product analytics
| Sub-processor | Role | Data concerned | Place of processing | Transfer mechanism |
|---|---|---|---|---|
| PostHog | Product analytics | Usage events, technical identifier, browsing data | a valider : instance actually used in production, the European instance eu.i.posthog.com is the default value in the code but it can be overridden by an environment variable | {{A_COMPLETER}} |
Tools loaded on Reponse's public website
These tools relate to Reponse's public website, for which Reponse acts as an independent controller within the meaning of section 3. They are listed here for transparency and are described in the cookie policy.
| Service | Role | Data concerned | Place of processing | Transfer mechanism |
|---|---|---|---|---|
| Google (Google Tag Manager and Google Analytics 4) | Audience measurement on the public website | Browsing data on the public website, measurement identifiers | {{A_COMPLETER}} | {{A_COMPLETER}} |
| Scheduling module loaded on the demo page | Booking of sales meetings | Browsing data, information entered when booking a meeting | {{A_COMPLETER}} | {{A_COMPLETER}} |
a valider : whether Google Analytics 4 and the scheduling module are kept on the public website, and whether their loading is actually made conditional on consent
Integrations enabled at the customer's request
These services are used only if the customer enables the corresponding integration.
| Service | Role | Data concerned |
|---|---|---|
| Shopify | Synchronisation of catalogue, orders and customers | Orders, products, buyer identification data |
| Klaviyo | Marketing synchronisation | Email address, contact events and attributes |
| Notion | Synchronisation of content and knowledge bases | Content selected by the customer |
| TikTok Shop | Synchronisation of orders and messages | Orders, messages, buyer identification data |
a completer : country of processing and transfer mechanism for each of the optional integrations
a valider : completeness of this list, to be established through an inventory of the service's outbound calls and of the scripts loaded by the public website, in particular Google Analytics and the scheduling module
Annex 3: security measures
The measures below are described as implemented at the date of last update. They constitute neither a certification nor a guarantee of result. Items flagged with a marker remain to be verified or formalised and do not constitute a commitment.
1. Encryption in transit
Exchanges between the customer's browser or systems and the service are encrypted in transit using TLS. The service is served over HTTPS only.
a valider : minimum accepted TLS version and HSTS policy
2. Encryption at rest
Data is stored with Supabase. Reponse relies on the encryption at rest mechanisms of the hosting platform, the scope and key management arrangements of which are a matter for that platform.
a valider : written confirmation of encryption at rest and of key management at Supabase and Netlify
3. Data segregation
Each customer has one or more workspaces. Access to data is restricted at database level by row level security rules tied to the workspace and to the user's role. Service credentials with elevated privileges are reserved for server-side processing and are not exposed to the browser.
a valider : table by table and view by view review of row level security coverage and of the objects exposed to the anonymous role, a recent fix having addressed this point
4. Access control
User authentication relies on the platform's authentication service. Internal access to the administration consoles of sub-processors is named and limited to the persons who need it.
a completer : multi-factor authentication enforced on administration accounts, password policy, periodic access reviews
5. Secret management
API keys and secrets are stored in environment variables managed by the hosting platform.
a valider : absence of secrets committed to the source code repository, to be established by scanning the repository history a valider : secret rotation procedure and frequency
6. Logging
The service records technical access and error logs allowing an incident to be detected and analysed.
a completer : log retention period and scope of administrator access logging
7. Minimisation in analytics tooling
Input fields are masked by default in the session recordings of the product analytics tool, and capture is only enabled after the data subject has given consent.
a valider : exact scope of product analytics in production, session recording, heatmaps and automatic capture of interactions
8. Backups and continuity
a valider : existence of backups, plan subscribed to with the database platform and scope actually covered, no backup may be claimed until this point is confirmed
a completer : backup frequency, retention period, restore testing procedure and frequency, recovery objectives
9. Development and change management
Changes to the service go through a version control system and automated deployment.
a valider : whether code review is systematic and whether rollback after deployment is actually possible a completer : automated security checks, management of vulnerable dependencies
10. Incident management
a completer : written formalisation of an internal procedure for qualifying and handling security incidents, including the notification provided for in section 12, the roles, the internal deadlines and the on-call contact details, no procedure may be claimed until it is written down
11. Security testing
a completer : existence, nature and frequency of security tests or external audits, none may be claimed without evidence
12. Certifications
No security certification is claimed to date.