Legal
Data Processing Addendum
Last updated: July 29, 2026
You do not need to sign this
This addendum is part of the Terms of Service and applies automatically to every BetterReply account, from the moment you create one. There is nothing to countersign and nothing to request. If your own compliance process needs a signed copy on letterhead, email privacy@betterreply.com and we will send one, but the protections below are already in force either way.
Who is responsible for what
BetterReply is operated by REmomentum LLC. When we handle the personal data inside your workspace, you are the controller and we are the processor. Plainly: you decide what accounts to connect, what gets sent, and what gets kept, and we act on those decisions. We do not decide to do anything else with it.
Your own account data (your email, your plan, your settings) is different. We are the controller for that, and our Privacy Policy governs it.
What we process, and why
- Subject matter and purpose. Running a unified inbox for you: reading comments, DMs, and email from accounts you connect, drafting replies in your voice, sending what you or your automations instruct, and publishing posts you schedule.
- Duration. For as long as your account is active, plus the retention windows in the Privacy Policy.
- Types of personal data. Names, handles, profile pictures, platform user ids, email addresses, and the content of messages, comments, and replies. Whatever else a person chooses to put in a message to you comes with it.
- Categories of people. Your followers, commenters, DM senders, email correspondents, and any teammates you invite.
Our commitments
- We process this data only to provide BetterReply to you and only on your instructions, including the standing instructions you give by configuring an automation. Nothing else. If a law ever forced us to process it for another reason, we would tell you first unless that law forbids it.
- We do not sell it, share it for cross-context behavioural advertising, combine it with data from anywhere else, or use it for our own purposes. We do not use it to train AI models, ours or a vendor’s.
- Everyone with access is bound to confidentiality, and access is limited to the people who need it to operate or support the service.
- We keep appropriate technical and organisational security measures: encryption in transit and at rest, encrypted OAuth tokens, database-level tenant isolation that is verified automatically rather than assumed, least-privilege access, and audit logging. Our written security program is documented internally and available on request under NDA.
- We help you answer requests from the people whose data this is. If one of them contacts us directly, we point them to you rather than acting unilaterally, because it is your workspace.
- We help you with data protection impact assessments and regulator consultations to the extent the processing is ours to explain.
- On termination we delete your workspace data within 30 days, or return it first if you ask. You can also export it yourself at any time from Settings.
- You may request the information you need to confirm we are doing all of this. For a service at our scale that means documentation and answers rather than an on-site audit, and we would rather say so than promise a process we do not run.
If there is a breach
We will tell you without undue delay after becoming aware of a personal data breach affecting your workspace, and in any case fast enough for you to meet your own 72-hour obligation. We will tell you what happened, what data was involved, what we have done, and what we recommend. We will send a first notice while facts are still incomplete rather than waiting for a tidy one.
Subprocessors
You authorise us to use subprocessors to run the service. The current list, what each one does, and where it runs is at betterreply.com/subprocessors. Every one of them is bound to data protection terms at least as protective as these, and we stay responsible to you for what they do.
Before we add or replace one, we will update that page and give you at least 30 days’ notice by email if you have asked to be notified. If you have a reasonable, data-protection-based objection, tell us and we will work with you on it; if we cannot resolve it, you can terminate the affected part of the service and we will refund any prepaid time you have not used.
Where the data goes
BetterReply runs in the United States. If you are in the UK, the EEA, or Switzerland, providing the service means transferring data there. Where a transfer mechanism is required, we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two where you are a controller and we are your processor, with the UK International Data Transfer Addendum for UK transfers and the equivalent recognition for Switzerland. Those clauses are incorporated here by reference, and the details in this addendum populate their annexes.
US state privacy laws
Where laws like the CCPA apply, we are a service provider (or processor, depending on the state) and not a third party. We certify that we understand the restrictions in this addendum and will comply with them: we will not sell or share the personal information you send us, we will not retain, use, or disclose it outside the direct business purpose of providing BetterReply, and we will not combine it with personal information from any other source except as those laws permit for a service provider.
How this fits with the rest
If this addendum and the Terms of Service disagree about how we handle personal data, this addendum wins. Everything else in the Terms, including the limitation of liability, still applies. We will update this page as the service or the law changes, and material changes get the same notice as changes to the Terms.
Questions: privacy@betterreply.com.