1. Parties and scope

This agreement is between the organisation that uses DevReply (the "Customer", the controller) and S.Z. CODE AXOL LTD, 27 Despoinas Nikou Pattichi, Flat/Office 2, 3071 Limassol, Cyprus ("DevReply", the processor). It covers personal data about the Customer's app users that DevReply processes on the Customer's behalf through the DevReply SDKs, API, dashboard and MCP server (the "Service"). It forms part of the terms under which the Customer uses the Service (the terms of service). Where they conflict on data protection, this agreement wins.

Data about the Customer's own team (dashboard accounts) is outside this agreement: DevReply is its controller, as the privacy policy describes.

2. Details of the processing

Subject matterRunning an in-app support chat between the Customer and its app users.
DurationAs long as the Customer uses the Service, plus the deletion period in section 9.
Nature and purposeReceiving, storing, showing and delivering messages; sending replies by push notification and email; keeping the Service secure.
Data subjectsPeople who use the Customer's apps and websites and open the DevReply chat.
Personal dataName; email address (optional); messages and their times; attached photos and files; a DevReply user ID and install token; push tokens; device model, OS version, app and SDK version, language, platform (on the web: browser, OS, site); custom attributes the Customer chooses to send; email opt-out status. See Privacy details for your app.
Special categoriesNone intended. App users type free text and may attach files, so the Customer should not invite them to send special-category data through the chat.

3. Instructions

DevReply processes the personal data only on the Customer's documented instructions. This agreement, the Customer's configuration of the Service (settings, keys, what the app sends) and actions taken in the dashboard, API or MCP server are those instructions. DevReply does not process the data for its own purposes, sell it, or use it for advertising or to train AI models. If DevReply believes an instruction breaks data protection law, it tells the Customer. If law requires other processing, DevReply tells the Customer first unless the law forbids that.

4. Confidentiality

Everyone at DevReply who can access the personal data is bound to keep it confidential, and has access only as far as their work needs.

5. Security

DevReply takes the technical and organisational measures in the annex, appropriate to the risk, as Article 32 requires. It may improve them over time but won't lower the overall level of protection.

6. Subprocessors

The Customer authorises DevReply to use the subprocessors listed on devreply.com/privacy.html. DevReply will announce a new or replaced subprocessor on that page, and email the Customer's owners, at least 30 days before it starts processing personal data. The Customer may object on reasonable data protection grounds within that time; if the parties can't resolve it, the Customer may stop using the Service and DevReply deletes its data as in section 9. DevReply binds each subprocessor to data protection terms at least as protective as these, and remains responsible for it.

Push notifications go through the Customer's own Apple Push Notification service key and Firebase project, and any AI agent the Customer connects to the MCP server is chosen by the Customer; the Customer is responsible for its agreements with those providers.

7. International transfers

DevReply's servers and database are in Germany. Where a subprocessor handles personal data outside the EEA or the UK, the transfer relies on an adequacy decision (including the EU–US Data Privacy Framework and its UK extension, for certified providers) or on the European Commission's Standard Contractual Clauses (and the UK Addendum), which DevReply has in place with that subprocessor.

8. Helping the Customer

9. Deletion at the end

The Customer can delete a single user (see section 8) or a whole app at any time in the dashboard; deleting an app removes its users, conversations, messages and files at once. When the Customer stops using the Service, DevReply deletes the remaining personal data within 30 days, unless the Customer asks for a copy first or law requires keeping it. Encrypted backups, kept only to recover from a disaster, roll off after that: daily copies within 30 days, monthly copies within 12 months.

10. Information and audits

DevReply makes available the information needed to show it meets Article 28, and answers reasonable written questions. If that isn't enough, the Customer (or an auditor bound to confidentiality) may audit DevReply once a year, with 30 days' notice, during business hours and at the Customer's cost, or at any time a supervisory authority requires it.

11. The Customer's part

The Customer has a legal basis for the processing, gives its app users the required information (for example in its privacy policy), decides what it sends to DevReply (such as custom attributes), and handles its app users' requests.

12. General

Liability under this agreement follows the limits in the Customer's terms with DevReply, where the law allows. DevReply may update this agreement to reflect changes in law or in the Service, and announces material changes 30 days ahead by email to the Customer's owners. This agreement is governed by the laws of the Republic of Cyprus, and its courts have jurisdiction. Questions: [email protected].

Annex: technical and organisational measures