Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms between Remoxus, as operator of WA FollowUp Manager, and the account holder using the service.

Roles

For account administration, security, billing, and direct service communications, Remoxus may act as a controller or equivalent responsible party. For contact lists, message content, campaigns, and related records uploaded or configured by the user, the user generally determines the purposes and means of processing, and Remoxus processes that data to provide the service.

Subject Matter and Duration

Processing covers hosting, organizing, scheduling, transmitting, logging, securing, supporting, exporting, and deleting account and messaging data for the duration of the account, applicable retention periods, and any legally required preservation period.

Data and People Concerned

Data may include names, phone numbers, email addresses, tags, notes, consent evidence, opt-out records, message content, campaign schedules, provider identifiers, technical logs, and support information. People concerned may include account users, staff, customers, leads, subscribers, and message recipients.

User Instructions and Responsibilities

The user instructs Remoxus through use of the application and must ensure that instructions are lawful. The user is responsible for required notices, consent or other lawful basis, data accuracy, campaign content, access authorization, retention decisions, and responses to recipients where the user is the responsible controller.

Authorized Managers and Sub Accounts

The account holder may authorize a manager or sub account to process operational data through an invitation that expires after 24 hours. The account holder determines whether the manager is authorized and remains responsible for the manager’s instructions, confidentiality, lawful access, and removal when access is no longer required. A manager acts as a person authorized by the account holder and must process data only for the account holder’s permitted purposes.

Remoxus provides controls to switch between authorized workspaces and to disconnect access. Owner-only billing, transaction history, credential changes, and account deletion are not delegated through the managed-account selector. Access and disconnection events may be logged for security and accountability.

Confidentiality and Security

Remoxus applies reasonable access controls, password hashing, session protections, rate limiting, audit logging, suppression controls, and encryption for supported stored provider credentials. No system can guarantee absolute security. Users must protect their devices, accounts, exported files, API credentials, and connected providers.

Subprocessors

Remoxus may use hosting, email, authentication, payment, network, security, and messaging providers to deliver the service. Current categories are described on the Subprocessors page. The user authorizes those subprocessors where reasonably necessary to operate the service.

Requests and Incidents

Remoxus will provide reasonable assistance with verified privacy requests and security incidents, taking into account the nature of processing and information available. Requests may be submitted through the Privacy Request page. Security handling is described in the Security & Incident Policy.

Deletion and Return

Users may delete supported operational data and may request account deletion. On termination or expiry of the applicable retention period, operational data may be deleted or anonymized, except limited records retained for legal, accounting, security, fraud-prevention, dispute, or backup-cycle purposes.

International Processing

Connected providers and infrastructure may process data in more than one jurisdiction. Users must assess whether their use requires additional contractual, notice, or transfer safeguards.