Data Processing Addendum

This Data Processing Addendum ('DPA') forms part of the agreement between Furcata and the customer ('Customer') governing the use of the Furcata messaging platform (the 'Services'). It applies where Furcata processes personal data on behalf of the Customer in the course of providing the Services.

This DPA is incorporated into and subject to the Terms of Use. Capitalized terms not defined here have the meanings given in the Terms of Use. In the event of a conflict between this DPA and the Terms of Use on matters of personal data protection, this DPA controls.

1. Definitions

'Applicable Data Protection Law' means the data protection and privacy laws applicable to the processing of personal data under the agreement, including, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, the Brazilian LGPD, the Canadian PIPEDA, and applicable United States state privacy laws such as the CCPA/CPRA.

'Controller', 'Processor', 'Data Subject', 'Personal Data', 'Processing', and 'Supervisory Authority' have the meanings given in Applicable Data Protection Law.

'Customer Personal Data' means Personal Data that Furcata processes on behalf of the Customer in connection with the Services, including contact data, message content, and message metadata that the Customer submits to or generates through the Services.

2. Roles of the Parties

The Customer is the Controller (or a Processor acting on behalf of a Controller) of Customer Personal Data. Furcata acts as a Processor (or sub-processor) and processes Customer Personal Data only on the Customer's documented instructions.

The Customer is solely responsible for the lawfulness of the personal data it submits to the Services, for obtaining and maintaining all required consents and notices, and for the accuracy of its recipient lists.

3. Scope and Applicability

This DPA applies to the extent Furcata processes Customer Personal Data that is subject to Applicable Data Protection Law. Where the Customer's use of the Services does not involve such data, this DPA does not apply.

4. Our Obligations as Processor

Furcata will:

  1. process Customer Personal Data only on the Customer's documented instructions, including as set out in the agreement and this DPA, unless required to do otherwise by law;
  2. ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
  3. implement appropriate technical and organizational measures to protect Customer Personal Data;
  4. assist the Customer, taking into account the nature of the processing, in responding to Data Subject requests and in meeting its obligations under Applicable Data Protection Law;
  5. notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data; and
  6. make available information reasonably necessary to demonstrate compliance with this DPA.

5. Sub-processors

The Customer authorizes Furcata to engage sub-processors to support the delivery of the Services. Furcata engages sub-processors in the following categories: cloud infrastructure and hosting providers; carrier and messaging network partners; payment and billing processors; customer support and communication tooling; and analytics and monitoring providers.

Furcata imposes data protection obligations on its sub-processors that are no less protective than those set out in this DPA. Furcata remains responsible for the performance of its sub-processors' obligations.

A current list of sub-processors by category is available on request. The Customer may subscribe to notifications of changes to the sub-processor list and may object to a new sub-processor on reasonable data protection grounds.

6. International Transfers

Where Customer Personal Data is transferred outside the jurisdiction in which it was collected, Furcata will implement appropriate safeguards, such as standard contractual clauses approved by the relevant authority or another lawful transfer mechanism, and will apply supplementary measures where required.

7. Data Subject Rights

Furcata will provide reasonable assistance to the Customer in responding to requests from Data Subjects to exercise their rights. Where Furcata receives a request directly, it will, unless legally prohibited, refer the request to the Customer and will not respond to the Data Subject directly except to confirm that the request has been referred.

8. Security

Furcata maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, alteration, or disclosure. These measures are described in our Security page and include encryption in transit and at rest, access controls, and environment segregation.

9. Breach Notification

Furcata will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide information reasonably required for the Customer to meet its own notification obligations.

10. Deletion and Return of Data

On termination or expiry of the agreement, Furcata will delete or return Customer Personal Data in accordance with our Data Retention and Deletion Policy, except where retention is required by law or for legitimate business purposes such as dispute resolution.

11. Audits

Furcata will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality and security requirements and no more than once per year absent a legal requirement.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use.

13. Contact

Questions about this DPA or data protection at Furcata can be sent to support@furcata.com.