This Addendum forms part of the agreement between you (the “Controller”) and Skiwo AS (the “Processor”) and governs the processing of personal data on your behalf under the GDPR.
1. Roles & scope
You are the controller of the customer personal data processed in your workspace; SoftReply is the processor. This Addendum prevails over conflicting terms on the subject of data protection.
2. Details of processing
Subject matter: provision of the SoftReply service. Duration: the term of your subscription plus the deletion window.
Nature & purpose: storing and displaying messages, drafting and reviewing replies, analytics, and outbound campaigns.
Data subjects: your customers and contacts. Categories: contact details and the content of communications they send you.
3. Processor obligations
We process personal data only on your documented instructions, including those given through the product, unless required otherwise by law (in which case we notify you where permitted).
4. Confidentiality
Personnel authorised to process personal data are bound by confidentiality and access it only as needed to provide the service.
5. Security measures
We implement appropriate technical and organisational measures, including encryption in transit and at rest, access control, tenant isolation, logging and tested backups, as described on our Security page.
6. Subprocessors
You authorise the subprocessors listed in our Privacy Policy and Security page, including AWS for EU hosting and your own AWS account for outbound.
We maintain a current list and give notice before adding or replacing a subprocessor, so you may object on reasonable data-protection grounds.
7. Assistance with data-subject requests
Taking account of the nature of processing, we assist you with appropriate measures to fulfil your obligation to respond to data-subject requests, including export and deletion tools in the product.
8. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification duties.
9. International transfers
Processing takes place in the EU. Where a transfer outside the EEA is necessary, it is covered by Standard Contractual Clauses or another lawful transfer mechanism.
10. Return & deletion
On termination, at your choice, we return or delete the personal data and existing copies within the deletion window, unless retention is required by law.
11. Audits
We make available information necessary to demonstrate compliance and allow for audits, including by an auditor you mandate, on reasonable notice and subject to confidentiality.
12. Liability & precedence
The liability provisions of the main agreement apply to this Addendum. In case of conflict on data-protection matters, this Addendum controls.
Questions about this document? Write to legal@softreply.com.