RightMessage
RightMessage

Data Processing Agreement

The RightMessage Data Processing Agreement covers how we process personal data on behalf of customers under the GDPR, UK GDPR, and Swiss data protection law.

This Data Processing Agreement (the “DPA”) forms part of the RightMessage Terms of Service and any other agreement between RightMessage Inc. (“RightMessage”) and the customer that uses the RightMessage service (the “Customer”) (together, the “Agreement”). It applies whenever RightMessage processes Customer Personal Data on the Customer’s behalf and that processing is subject to Data Protection Law.

The Customer accepts this DPA by accepting the Terms of Service or by using the Service. No signature is required. If the Customer needs a countersigned copy for its records, contact support@rightmessage.com.

1. Definitions

  • “Data Protection Law” means the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); the GDPR as it forms part of UK law and the UK Data Protection Act 2018 (“UK GDPR”); and the Swiss Federal Act on Data Protection (“FADP”), in each case as amended or replaced, to the extent they apply to the processing.
  • “Customer Personal Data” means personal data that RightMessage processes on behalf of the Customer in providing the Service, as described in Schedule 1.
  • “Service” has the meaning given in the Terms of Service.
  • “Subprocessor” means any third party RightMessage engages to process Customer Personal Data.
  • “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • “SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

“Controller,” “processor,” “data subject,” “personal data,” “processing,” and “supervisory authority” have the meanings given in Data Protection Law.

2. Roles and scope

The Customer is the controller of Customer Personal Data, or a processor acting for its own controller. RightMessage is the Customer’s processor, or subprocessor where the Customer is itself a processor. Where the Customer acts as a processor, it confirms that its controller has authorized the Customer’s instructions and the appointment of RightMessage.

RightMessage acts as an independent controller, and this DPA does not apply, for personal data it processes for its own purposes: account administration, billing, support communications, security and fraud prevention, its own marketing, and visitors to RightMessage’s own websites. That processing is described in the Privacy Policy.

3. Customer responsibilities

  • The Customer is responsible for having a lawful basis for the processing, and for giving any notices and obtaining any consents required, including for cookies and similar technologies on its own websites.
  • The Customer’s instructions must comply with Data Protection Law.
  • The Service is not designed to process special categories of personal data or data relating to criminal convictions. The Customer will not configure the Service to collect such data unless it has determined that it may lawfully do so.

4. RightMessage obligations

4.1 Instructions

RightMessage will process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law. If so required, RightMessage will inform the Customer of that legal requirement before processing unless the law prohibits it. The Agreement, this DPA, and the Customer’s configuration and use of the Service are the Customer’s complete instructions. Additional instructions require written agreement.

RightMessage will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law. RightMessage may then suspend the affected processing until the instruction is confirmed or changed.

4.2 Confidentiality

RightMessage will ensure that people it authorizes to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

4.3 Security

RightMessage will implement appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as required by Article 32 GDPR. The current measures are described in Schedule 2. RightMessage may update them, provided the overall level of protection is not reduced.

4.4 Assistance

Taking into account the nature of the processing and the information available to it, RightMessage will provide reasonable assistance to the Customer:

  • by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects exercising their rights;
  • with the Customer’s obligations regarding security, Security Incident notification, data protection impact assessments, and prior consultation with supervisory authorities.

If RightMessage receives a request directly from a data subject about Customer Personal Data, it will forward the request to the Customer and will not respond except to direct the data subject to the Customer, unless required by law.

4.5 Security Incidents

RightMessage will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. The notice will describe, to the extent then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. RightMessage will provide further information as it becomes available and will take reasonable steps to contain and remediate the incident. Notice is not an acknowledgement of fault or liability.

4.6 Deletion and return

On the Customer’s written request, during the Agreement or after it ends, RightMessage will delete Customer Personal Data or, where reasonably practicable, return a copy of it in a commonly used format, at the Customer’s choice. Requests should be sent to support@rightmessage.com from the account owner’s email address. Customer Personal Data in backups will be removed as backups are overwritten in the ordinary course and will remain protected under this DPA until then. RightMessage may retain Customer Personal Data where law requires it, and will continue to protect it under this DPA.

4.7 Information and audits

RightMessage will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, by the Customer or an independent auditor it mandates. RightMessage will first answer written requests for information. If those answers are not sufficient to demonstrate compliance, or a supervisory authority requires it, the Customer may conduct an audit on at least 30 days’ written notice, no more than once in any 12-month period unless required by a supervisory authority or following a Security Incident, during normal business hours, in a way that minimizes disruption and protects the confidentiality of other customers’ data. Each party bears its own audit costs.

5. Subprocessors

The Customer gives RightMessage general authorization to engage Subprocessors. The current Subprocessors are listed in Schedule 3. RightMessage will impose on each Subprocessor, by written contract, data protection obligations that offer at least the same level of protection as this DPA, and remains responsible to the Customer for each Subprocessor’s performance.

RightMessage will update Schedule 3 at least 14 days before a new Subprocessor begins processing Customer Personal Data. Customers who want email notice of changes can request it at support@rightmessage.com. The Customer may object on reasonable data protection grounds by writing to that address within the notice period. The parties will discuss the objection in good faith. If they cannot resolve it, the Customer may terminate the affected part of the Service as its sole remedy, and RightMessage will refund any prepaid fees for the unused period.

6. International transfers

RightMessage and its Subprocessors process Customer Personal Data primarily in the United States. Cloudflare may also process requests at the edge location nearest the visitor. Where Customer Personal Data subject to the GDPR, UK GDPR, or FADP is transferred to RightMessage in a country that has not been found to provide an adequate level of protection, the parties agree to the following, which are incorporated into this DPA by reference:

  • EU transfers: the SCCs, Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor. The Customer is the data exporter and RightMessage is the data importer. Clause 7 (docking clause) applies. Under Clause 9, Option 2 (general written authorization) applies with the notice period in Section 5. The optional language in Clause 11 does not apply. Under Clauses 17 and 18, the SCCs are governed by the law of, and disputes are resolved by the courts of, Ireland. The competent supervisory authority under Clause 13 is determined by the Customer’s establishment or representative, as that clause provides. Annexes I and II are completed by Schedules 1, 2, and 3.
  • UK transfers: the SCCs as amended by the UK Addendum. Table 1 is completed with the party details in Schedule 1. Table 2 selects the modules and options described above. Table 3 is completed by Schedules 1, 2, and 3. For Table 4, either party may end the UK Addendum as permitted by its Section 19.
  • Swiss transfers: the SCCs as set out above, with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and the term “member state” not interpreted to exclude data subjects in Switzerland from exercising their rights in their place of habitual residence.

If RightMessage receives a request from a public authority for access to Customer Personal Data, it will handle the request as Clause 15 of the SCCs requires, including notifying the Customer where legally permitted and challenging requests it concludes are unlawful.

7. Anonymized data

RightMessage may create aggregated or anonymized data from its provision of the Service, as described in the Privacy Policy, only if that data no longer identifies, and cannot reasonably be used to identify, any individual, the Customer, or the Customer’s websites. Such data is not Customer Personal Data.

8. General terms

  • This DPA lasts as long as RightMessage processes Customer Personal Data on the Customer’s behalf.
  • If this DPA conflicts with the Terms of Service or Privacy Policy regarding Customer Personal Data, this DPA prevails. If it conflicts with the SCCs or UK Addendum, those prevail.
  • Each party’s liability under this DPA is subject to the limitations in the Agreement, to the extent Data Protection Law and the SCCs permit.
  • RightMessage may update this DPA to reflect changes in Data Protection Law, the Service, or its Subprocessors, provided updates do not reduce the overall protection of Customer Personal Data. The version in effect is the one published at this page, identified by the version date at the end of this page.
  • Except where the SCCs or Data Protection Law require otherwise, this DPA is governed by the law that governs the Terms of Service.

Schedule 1: Details of processing

Parties

  • Data exporter (controller or processor): the Customer, as identified in its RightMessage account. Contact: the account owner’s email address. Activities: use of the Service to personalize and measure its websites and marketing.
  • Data importer (processor): RightMessage Inc., 2173 NE 63rd Court, Fort Lauderdale, FL 33308, United States. Contact: support@rightmessage.com. Activities: providing the Service.

Categories of data subjects

  • Visitors to Customer websites where the RightMessage script is installed.
  • People who submit RightMessage forms, flows, quizzes, or surveys on Customer websites.
  • The Customer’s subscribers, contacts, leads, and customers whose records are read from or synced with email, CRM, or other platforms the Customer connects to the Service.

Categories of personal data

  • Online identifiers, including cookie and browser-storage identifiers and IP addresses.
  • Device and browser information.
  • Website activity: pages viewed, referral sources, campaign and UTM parameters, and on-site interactions.
  • Contact details, such as email address and name, and identifiers from connected platforms.
  • Form, flow, quiz, and survey responses.
  • Segment assignments derived from the above.
  • Tags, custom fields, and purchase data from connected platforms.
  • Content the Customer submits to AI-assisted features.

Special categories of data

None intended. See Section 3.

Frequency of transfer

Continuous, for as long as the Customer uses the Service.

Nature and purpose of processing

Collecting, storing, and analyzing the data above to provide the Service under the Agreement and the Customer’s instructions: identifying returning visitors after an identification event, segmenting visitors, personalizing website content, syncing data with platforms the Customer connects, running forms, flows, quizzes, and surveys, reporting and analytics for the Customer, and generating content through AI-assisted features.

Duration and retention

For the term of the Agreement, and afterward until deleted under Section 4.6.

Competent supervisory authority

As determined under Clause 13 of the SCCs, or the UK Information Commissioner or Swiss Federal Data Protection and Information Commissioner for UK and Swiss transfers.

Schedule 2: Security measures

  • Customer Personal Data is transmitted between browsers, the Service, and connected platforms over encrypted HTTPS (TLS) connections.
  • The Service runs on managed cloud infrastructure provided by the hosting and infrastructure Subprocessors in Schedule 3, whose own physical, network, and infrastructure security controls apply.
  • Access to Customer Personal Data is limited to RightMessage personnel and contractors who need it to provide, support, or secure the Service, and who are bound by confidentiality obligations.
  • Customer accounts are protected by authentication, and Customers control which team members can access their account.
  • Security Incidents are handled and notified as described in Section 4.5.
  • Subprocessors are bound by written data protection terms as described in Section 5.

Schedule 3: Subprocessors

  • Laravel Cloud: application hosting, databases, and infrastructure. Location: United States.
  • Amazon Web Services: cloud infrastructure and storage. Location: United States.
  • Cloudflare: content delivery, network proxying and security, and edge computing and storage for the Service. Location: United States and Cloudflare’s global edge network.
  • OpenRouter: routing requests to large language model providers for AI-assisted features, including Righty. Location: United States.
  • PostHog: product analytics and telemetry, including diagnostics for requests to connected integrations. Location: United States.
  • Sentry: error monitoring and diagnostics. Location: United States.
  • Help Scout: customer support communications. Location: United States.

Version: October 1, 2026