RechtlichesUSA

Rechtsdokumente werden derzeit auf Englisch bereitgestellt.

Data Processing Addendum

Effective Date: December 5, 2025

1. Introduction

This Data Processing Addendum ("DPA") forms part of the Terms of Service between helpful bits GmbH ("ReplyContext", "we", "us", or "Processor") and you ("Customer" or "Controller") for the provision of ReplyContext services applicable to United States users.

This DPA reflects the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of applicable data protection laws.

2. Definitions

2.1 Personal Data

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by ReplyContext in the course of providing the Services.

2.2 Processing

"Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, or deletion.

2.3 Services

"Services" means the ReplyContext reply drafting service and related features provided to Customer.

3. Scope and Roles

3.1 Scope of Processing

ReplyContext will process Personal Data as necessary to provide the Services in accordance with Customer's instructions as set forth in the Terms of Service and this DPA.

3.2 Controller and Processor

Customer is the Controller of Personal Data, and ReplyContext is the Processor. Each party will comply with the obligations that apply to it under applicable data protection laws.

3.3 Nature and Purpose

The nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described below:

  • Nature: Transcription of user-recorded dictation, with any user-supplied personal vocabulary as a spelling reference, and reply drafting from user-provided stated intent, instructions, and any captured messages and screenshots; the ReplyContext server in Germany routes each request directly to Google’s Gemini API, and captured content is not persisted in the ReplyContext application database
  • Purpose: To provide reply drafting services to Customer
  • Types of Personal Data: Temporary audio recordings and transcripts, personal vocabulary terms, captured message content (including third-party message content), screenshots, stated intent and instructions, drafted replies, and accepted final text (transient); numeric style signals only as stored memory; user preferences; usage data
  • Categories of Data Subjects: Customer, authorized users of the Services, and third parties whose messages appear in captured content

4. Processor's Obligations

4.1 Instructions

ReplyContext will process Personal Data only in accordance with Customer's documented instructions, unless required to do so by applicable law.

4.2 Confidentiality

ReplyContext will ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations.

4.3 Security

ReplyContext will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data in transit and at rest
  • Measures to ensure ongoing confidentiality, integrity, availability, and resilience
  • Regular testing and evaluation of security measures
  • Procedures for regular backup and recovery of Personal Data

4.4 Sub-processors

Customer authorizes ReplyContext to engage Sub-processors to process Personal Data. ReplyContext will:

  • Enter into a written agreement with each Sub-processor imposing data protection obligations substantially similar to those in this DPA
  • Maintain a list of Sub-processors at replycontext.com/legal/us/subprocessors
  • Provide at least 30 days' notice of any new Sub-processor
  • Remain liable for Sub-processor performance

4.5 Data Subject Rights

ReplyContext will, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise their rights. ReplyContext will assist Customer in responding to such requests.

4.6 Deletion and Return

Upon termination or expiration of the Services, ReplyContext will delete or return all Personal Data to Customer, unless applicable law requires continued storage.

5. Security Measures

ReplyContext implements the following categories of technical and organizational measures:

5.1 Physical Security

Our infrastructure providers maintain SOC 2 Type II certified data centers with physical access controls, surveillance, and environmental controls.

5.2 System Security

  • TLS 1.2 or higher encryption for data in transit
  • AES-256 encryption for data at rest
  • Regular security patches and updates
  • Intrusion detection and prevention systems
  • Firewall protection and network segmentation

5.3 Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication for administrative access
  • Principle of least privilege
  • Regular access reviews and revocation

5.4 Organizational Security

  • Security awareness training for employees
  • Incident response procedures
  • Business continuity and disaster recovery plans
  • Regular security assessments and audits

6. Data Breach Notification

6.1 Notification Obligation

ReplyContext will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's data. Notification will be provided to Customer's designated contact within 72 hours of discovery where feasible.

6.2 Breach Information

The notification will include, to the extent available:

  • The nature of the breach
  • The categories and approximate number of Data Subjects affected
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach

7. Audit Rights

7.1 Compliance Verification

ReplyContext will make available to Customer information necessary to demonstrate compliance with this DPA and allow for audits, including inspections conducted by Customer or an independent auditor.

7.2 Audit Process

Audits will be conducted upon reasonable notice, during business hours, no more than once per year unless required by a Supervisory Authority or in response to a suspected breach. Customer will bear the costs of audits unless they reveal material non-compliance.

8. Liability and Indemnification

8.1 Liability

Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms of Service.

8.2 Indemnification

ReplyContext will indemnify and hold harmless Customer from any claims, damages, or losses resulting from ReplyContext's breach of this DPA, subject to the limitations in the Terms of Service.

9. Term and Termination

This DPA will remain in effect for as long as ReplyContext processes Personal Data on behalf of Customer. Upon termination, ReplyContext will delete or return all Personal Data as described in Section 4.6.

10. Contact

For questions about this DPA or our data processing practices, please contact our Data Protection Officer at Email.

Last Updated: September 30, 2026

Version: 1.0