Legal

Data Processing Addendum (DPA)

Scope

This Addendum applies where a Customer's use of the Ellipsend service involves personal data subject to the GDPR, UK GDPR, or comparable data protection law. It sets out how Ellipsend, Inc., a Delaware corporation ("Ellipsend"), processes personal data on the Customer's behalf, and forms part of the agreement between Ellipsend and the Customer.

Roles

Customer = Data Controller for the personal data of their own contacts/leads. Ellipsend = Data Processor, processing that data only on the Customer's documented instructions, to provide the Service. This Addendum governs only the Contact and lead personal data that Ellipsend processes on the Customer's behalf; personal data that Ellipsend collects and uses for its own direct relationship with the Customer falls outside this Addendum and is governed by the Ellipsend Privacy Policy.

Subject matter, duration, nature and purpose of processing

Operating the Ellipsend CRM and its messaging features, its keyword- and rule-based automations, and automated classification of incoming comments, for the duration of the Customer's subscription plus any post-termination data-export window.

Categories of data subjects

The Customer's Instagram/Facebook contacts, leads, and DM/comment participants.

Categories of personal data

Names, social handles, profile photos, contact details volunteered in conversation (email, phone), and the content of DMs/comments.

Sub-processors

Ellipsend's current subprocessors are listed in full, by name, in the companion Subprocessors List, incorporated into this DPA by reference. Ellipsend will maintain that list and notify Customers of material changes. Customers may object to a new subprocessor by contacting privacy@ellipsend.com.

That list includes Slack and Notion, which may carry Contact and lead personal data provided during troubleshooting and onboarding, and Anthropic and OpenAI, accessed through Amazon Bedrock, which perform automated classification of incoming comments and operate on Contact Data for that purpose. Comment classification is a standard component of the Service and is not offered as a per-account opt-out. Intercom processes Contact and lead personal data as well as Customer support data, because support requests may include excerpts of a Customer's conversations with their Contacts.

Security measures

We use encryption in transit and at rest, together with access controls, to protect personal data.

International transfers

Ellipsend's infrastructure is hosted on Amazon Web Services in the United States (US West, Oregon). Where personal data leaves the EU, UK, or Switzerland, this incorporates by reference the Standard Contractual Clauses (Module Two: Transfer Controller to Processor) issued by the European Commission under Implementing Decision (EU) 2021/914, with Ellipsend as "data importer" and the Customer as "data exporter." For transfers originating in Switzerland, this additionally incorporates the Swiss Addendum to those Clauses recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC), under which references to the GDPR are read as references to Switzerland's Federal Act on Data Protection (FADP/revDSG) and the FDPIC is the competent supervisory authority. This transfer mechanism applies regardless of the specific AWS region, should it change.

Data subject requests

Ellipsend will assist the Customer in responding to access, correction, deletion, and portability requests from data subjects, consistent with our Meta Platform Data Deletion Instructions.

Breach notification

Ellipsend will notify the Customer without undue delay (target: within 72 hours of confirming a breach affecting their data) with enough detail for the Customer to meet their own notification obligations.

Audit rights

Ellipsend provides documentation of its security practices and completed security questionnaires on reasonable written request, up to once per 12 months, at the Customer's expense if a third party is involved. Ellipsend does not currently offer on-site or third-party audit rights. Stronger commitments, where required for a specific enterprise agreement, are negotiated case by case in the order form.

Term and deletion

On termination of the underlying subscription, Ellipsend will delete or return Customer personal data within 30 days, except where retention is legally required.

Contact

Questions about this Addendum, requests relating to personal data, and objections to a new subprocessor can be sent to privacy@ellipsend.com.

Ellipsend, Inc.
8 The Green, Ste B
Dover, DE 19901
c/o Northwest Registered Agent Service, Inc.