1. Parties and instructions
The customer is the controller and HookMessage is the processor for customer-submitted recipient, message, template, attachment, and webhook data. The Terms, configured workspace actions, API calls, and written support instructions form the customer's documented instructions.
HookMessage will process that data only to provide, secure, troubleshoot, and improve the contracted Service, or as required by law.
2. Customer obligations
- Maintain a lawful basis and required notices for all personal data submitted.
- Limit data to what is necessary and avoid unsupported sensitive or regulated data.
- Configure retention, permissions, senders, API roles, and integrations appropriately.
- Respond to recipient requests and ensure instructions do not violate applicable law.
3. HookMessage obligations
- Require confidentiality from personnel with access to customer data.
- Maintain proportionate technical and organizational security measures.
- Assist with verified data-subject requests, impact assessments, and regulator inquiries where reasonably required.
- Notify the customer without undue delay after confirming a personal-data breach affecting its data.
- Delete or return processor data after termination, subject to backups, immutable billing records, and legal preservation duties.
4. Subprocessors and transfers
The customer authorizes the subprocessors listed on the Subprocessor page. HookMessage remains responsible for imposing appropriate data-protection obligations on subprocessors.
Customers may object to a new subprocessor on reasonable data-protection grounds. Cross-border processing is subject to applicable CNDP requirements and any other mandatory transfer mechanism.
5. Security and audits
Security controls include tenant isolation, authorization, encrypted transport, secret management, private storage controls, audit records, rate limiting, session revocation, and provider access restrictions.
On reasonable written request, HookMessage will provide available compliance information. Audits must protect other customers, confidentiality, and platform security and may be limited to documentation or a qualified independent assessor.
6. Priority and contact
If this DPA conflicts with the Terms on processing customer personal data, this DPA controls. Privacy and DPA requests may be sent to [email protected].