1. Parties and scope
This agreement is between the organisation that uses DevReply (the "Customer", the controller) and S.Z. CODE AXOL LTD, 27 Despoinas Nikou Pattichi, Flat/Office 2, 3071 Limassol, Cyprus ("DevReply", the processor). It covers personal data about the Customer's app users that DevReply processes on the Customer's behalf through the DevReply SDKs, API, dashboard and MCP server (the "Service"). It forms part of the terms under which the Customer uses the Service (the terms of service). Where they conflict on data protection, this agreement wins.
Data about the Customer's own team (dashboard accounts) is outside this agreement: DevReply is its controller, as the privacy policy describes.
2. Details of the processing
| Subject matter | Running an in-app support chat between the Customer and its app users. |
| Duration | As long as the Customer uses the Service, plus the deletion period in section 9. |
| Nature and purpose | Receiving, storing, showing and delivering messages; sending replies by push notification and email; keeping the Service secure. |
| Data subjects | People who use the Customer's apps and websites and open the DevReply chat. |
| Personal data | Name; email address (optional); messages and their times; attached photos and files; a DevReply user ID and install token; push tokens; device model, OS version, app and SDK version, language, platform (on the web: browser, OS, site); custom attributes the Customer chooses to send; email opt-out status. See Privacy details for your app. |
| Special categories | None intended. App users type free text and may attach files, so the Customer should not invite them to send special-category data through the chat. |
3. Instructions
DevReply processes the personal data only on the Customer's documented instructions. This agreement, the Customer's configuration of the Service (settings, keys, what the app sends) and actions taken in the dashboard, API or MCP server are those instructions. DevReply does not process the data for its own purposes, sell it, or use it for advertising or to train AI models. If DevReply believes an instruction breaks data protection law, it tells the Customer. If law requires other processing, DevReply tells the Customer first unless the law forbids that.
4. Confidentiality
Everyone at DevReply who can access the personal data is bound to keep it confidential, and has access only as far as their work needs.
5. Security
DevReply takes the technical and organisational measures in the annex, appropriate to the risk, as Article 32 requires. It may improve them over time but won't lower the overall level of protection.
6. Subprocessors
The Customer authorises DevReply to use the subprocessors listed on devreply.com/privacy.html. DevReply will announce a new or replaced subprocessor on that page, and email the Customer's owners, at least 30 days before it starts processing personal data. The Customer may object on reasonable data protection grounds within that time; if the parties can't resolve it, the Customer may stop using the Service and DevReply deletes its data as in section 9. DevReply binds each subprocessor to data protection terms at least as protective as these, and remains responsible for it.
Push notifications go through the Customer's own Apple Push Notification service key and Firebase project, and any AI agent the Customer connects to the MCP server is chosen by the Customer; the Customer is responsible for its agreements with those providers.
7. International transfers
DevReply's servers and database are in Germany. Where a subprocessor handles personal data outside the EEA or the UK, the transfer relies on an adequacy decision (including the EU–US Data Privacy Framework and its UK extension, for certified providers) or on the European Commission's Standard Contractual Clauses (and the UK Addendum), which DevReply has in place with that subprocessor.
8. Helping the Customer
- Data subject requests. The dashboard shows each user's data and conversations. The Customer can delete a single user itself: in the dashboard, from its app through the SDK, or from its backend through the API. DevReply helps with requests the Customer can't serve that way, such as exporting a user's data, when the Customer writes to [email protected]. If an app user writes to DevReply directly, DevReply passes the request to the Customer and does not answer it on its own unless the Customer asks.
- Breaches. DevReply tells the Customer without undue delay after becoming aware of a personal data breach affecting its data, with what it knows, and keeps it updated so the Customer can meet its own notification duties.
- Assessments. DevReply gives reasonable help with data protection impact assessments and consultations with authorities, as far as they concern the Service.
9. Deletion at the end
The Customer can delete a single user (see section 8) or a whole app at any time in the dashboard; deleting an app removes its users, conversations, messages and files at once. When the Customer stops using the Service, DevReply deletes the remaining personal data within 30 days, unless the Customer asks for a copy first or law requires keeping it. Encrypted backups, kept only to recover from a disaster, roll off after that: daily copies within 30 days, monthly copies within 12 months.
10. Information and audits
DevReply makes available the information needed to show it meets Article 28, and answers reasonable written questions. If that isn't enough, the Customer (or an auditor bound to confidentiality) may audit DevReply once a year, with 30 days' notice, during business hours and at the Customer's cost, or at any time a supervisory authority requires it.
11. The Customer's part
The Customer has a legal basis for the processing, gives its app users the required information (for example in its privacy policy), decides what it sends to DevReply (such as custom attributes), and handles its app users' requests.
12. General
Liability under this agreement follows the limits in the Customer's terms with DevReply, where the law allows. DevReply may update this agreement to reflect changes in law or in the Service, and announces material changes 30 days ahead by email to the Customer's owners. This agreement is governed by the laws of the Republic of Cyprus, and its courts have jurisdiction. Questions: [email protected].
Annex: technical and organisational measures
- Encryption in transit: HTTPS/TLS on every connection; Cloudflare in Full (strict) mode to the origin.
- Secrets: secret API keys, install tokens, invite links, OAuth codes and tokens are stored only as SHA-256 hashes. Push credentials are encrypted with AES-256-GCM. Secret keys never go into apps.
- Isolation: every public API query is scoped to the app and the install or user; an install can only ever read its own conversations, and automated tests check this for every endpoint.
- On the device: the install token lives in the iOS Keychain or is encrypted with an Android Keystore key; photos are re-encoded before upload, removing EXIF and location data; the SDKs carry no third-party analytics or crash SDKs.
- Files: a private storage bucket with closed access rules, reachable only through short-lived signed URLs; the server's storage account can reach that one bucket only.
- Access control: dashboard sign-in through Firebase Authentication; sign-up requires a verified email; team roles (owner, agent, viewer); AI agents connect with OAuth 2.1 and PKCE, read-only or read-write as the person chooses, revocable at any time; text written by app users is marked untrusted for agents.
- Infrastructure: servers at Hetzner in Germany; administrative access over a private network only; the database accepts only local connections; services restart automatically and are monitored.
- Resilience: daily database backups on the server (14 days) and encrypted off-site in the EU (Cloudflare R2: 30 daily, 12 monthly copies), with a weekly automatic restore test.
- Change control: database migrations only go forward; the server's test suite replays the API contract of every released SDK version, so a change can't silently break apps already in the stores.