Data Processing Agreement
Effective Date: September 2, 2026
Last Updated: September 2, 2026
This Data Processing Agreement (“DPA”) forms part of the Reachd.ai Terms of Service at https://reachd.ai/terms/ (the “Terms”) between Reachd Inc., a Delaware corporation (“Reachd”), and the customer identified in the account that accepted the Terms (“Customer”). It applies to the extent Reachd processes Personal Data on Customer’s behalf in providing the Service, and it takes effect automatically wherever Data Protection Law requires a written data processing contract. Capitalized terms not defined here have the meaning given in the Terms. Where a signed order form or other written agreement between the parties covers the same subject, that document prevails over this DPA to the extent of any conflict; this DPA prevails over the Terms and the Privacy Policy on the processing of Personal Data.
1. Definitions
- “Data Protection Law” means all laws applicable to the processing of Personal Data under this DPA, including Regulation (EU) 2016/679 (“GDPR”), the GDPR as it forms part of the law of the United Kingdom (“UK GDPR”) and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
- “Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the GDPR. Under the CCPA, “controller” reads as “business”, “processor” as “service provider”, and “Personal Data” as “personal information”.
- “Customer Personal Data” means Personal Data contained in Customer Data (Terms, Section 7.2) that Reachd processes on Customer’s behalf, described in Annex 1.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914.
- “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- “Subprocessor” means a third party engaged by Reachd to process Customer Personal Data.
2. Roles of the Parties
2.1 Reachd as processor. For Customer Personal Data, Customer is the controller (or, where Customer acts for its own clients under Section 6.3 of the Terms, a processor acting on its clients’ instructions) and Reachd is the processor (or subprocessor). Reachd processes Customer Personal Data only as described in Annex 1 and in accordance with Section 3.
2.2 Reachd as independent controller. Reachd is an independent controller, not a processor, for: (a) account, billing, security, and usage data about Customer and its Authorized Users, which Reachd processes to operate its business as described in the Privacy Policy; (b) information Reachd collects on its own initiative from public websites, public registries, and AI Platforms about businesses, markets, and competitors, including the responses of AI Platforms to queries the Service submits, which Reachd collects for every customer alike and not on any single customer’s instructions; and (c) Aggregated Data under Section 7.5 of the Terms. Reachd is responsible for its own compliance with Data Protection Law for that processing. Customer’s responsibilities under this DPA extend to Customer Personal Data only.
2.3 Customer’s responsibilities. Customer is responsible for the lawfulness of the Customer Personal Data it provides and of the instructions it gives, for providing any notices and obtaining any consents required from data subjects, and for configuring the Service, including who it invites as an Authorized User and which businesses it registers.
3. Processing on Instructions
3.1 Reachd will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law applicable to Reachd, in which case Reachd will inform Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
3.2 The Terms, this DPA, and Customer’s use of the Service’s features and settings are Customer’s complete and final instructions. Further instructions require written agreement.
3.3 Reachd will inform Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law. Reachd is not obliged to perform a legal review of Customer’s instructions.
4. Confidentiality and Personnel
Reachd ensures that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process Customer Personal Data only to the extent needed to perform their role.
5. Security
5.1 Reachd implements and maintains the technical and organizational measures described in Annex 2, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to data subjects. Reachd may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
5.2 Customer is responsible for the security of its own systems and accounts, including the credentials of its Authorized Users, API keys, and connectors (Terms, Sections 4 and 8.4), and for reviewing whether the measures in Annex 2 are appropriate for the Customer Personal Data it chooses to submit.
6. Subprocessors
6.1 General authorization. Customer authorizes Reachd to engage Subprocessors, including the affiliates and third parties listed in Annex 3, to process Customer Personal Data.
6.2 Obligations. Reachd will impose on each Subprocessor, by written contract, data protection obligations that provide at least the level of protection required by this DPA, and Reachd remains liable to Customer for the performance of each Subprocessor’s obligations.
6.3 Changes. Reachd will give Customer at least 30 days’ prior notice of any intended addition or replacement of a Subprocessor by updating Annex 3 at https://reachd.ai/dpa/ and, where Customer has enabled such notices in its account or asked for them at hello@reachd.ai, by email. Customer may object in writing within that period on reasonable grounds relating to data protection. The parties will discuss the objection in good faith; if no resolution is found within 30 days of the objection, Customer may terminate the affected subscription by written notice, and Reachd will refund any prepaid fees for the period after termination. Continued use of the Service after the notice period without objection is acceptance of the new Subprocessor.
7. Assistance to Customer
7.1 Data subject requests. Reachd will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to requests from data subjects exercising their rights under Data Protection Law. If Reachd receives such a request directly and can identify Customer, it will forward the request to Customer without undue delay and will not respond on the merits except as instructed by Customer or required by law.
7.2 Compliance assistance. Reachd will provide reasonable assistance to Customer in meeting its obligations regarding security, notification of personal data breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to Reachd. Reachd may charge reasonable fees for assistance that goes beyond the standard functionality of the Service and beyond what Data Protection Law requires it to provide free of charge.
8. Personal Data Breach
Reachd will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Reachd may provide the information in phases as it becomes available. A notification is not an acknowledgement of fault or liability.
9. Deletion and Return
On termination of the Service, Reachd will, at Customer’s choice made within the 30 days provided in Section 13.5 of the Terms, return Customer Personal Data in a commonly used machine-readable format or delete it, and will delete existing copies, except to the extent Reachd is required by law to retain them or they remain in routine backups, which are overwritten on their regular cycle of no more than 90 days and are not restored to a live system except for disaster recovery. Reachd may retain and continue to use Aggregated Data under Section 7.5 of the Terms.
10. Audit and Information
10.1 Reachd will make available to Customer the information necessary to demonstrate compliance with this DPA. On written request no more than once in any 12-month period, Reachd will respond to a reasonable written security and data protection questionnaire within 30 days.
10.2 Where Data Protection Law grants Customer a right of audit that the information under Section 10.1 cannot satisfy, or a supervisory authority requires one, or a personal data breach has occurred, Customer or an independent auditor bound by confidentiality and reasonably acceptable to Reachd may conduct an audit of Reachd’s relevant processing on at least 30 days’ written notice, during normal business hours, no more than once a year, in a manner that does not unreasonably interfere with Reachd’s operations, and at Customer’s expense. The audit is limited to Reachd’s own systems and does not extend to Subprocessors; for them, Reachd will make available the audit reports and certifications they provide to Reachd.
11. International Transfers
11.1 Reachd is established in the United States and processes Customer Personal Data there and in the locations listed in Annex 3. Customer authorizes those transfers subject to this Section.
11.2 EEA. For transfers of Customer Personal Data subject to the GDPR to countries not recognized by the European Commission as providing adequate protection, the parties enter into the SCCs, which are incorporated into this DPA by reference, as follows: Module Two (controller to processor) applies where Customer is a controller and Module Three (processor to processor) where Customer is a processor; in Clause 7, the optional docking clause does not apply; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 6.3; in Clause 11, the optional language does not apply; in Clause 13, the supervisory authority is that of the EU member state in which Customer is established or, where Customer is not established in the EU, that of the member state in which Customer’s EU representative is established or, failing that, in which the data subjects are located; in Clause 17, the SCCs are governed by the law of Ireland; in Clause 18, disputes are resolved before the courts of Ireland; Annex I of the SCCs is completed with Annex 1 of this DPA and the parties’ details in the Terms, Annex II with Annex 2 of this DPA, and Annex III with Annex 3 of this DPA. Customer is the data exporter and Reachd the data importer.
11.3 United Kingdom. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, completed with the information in this DPA, with Reachd as importer and Customer as exporter, and with either party able to end the UK Addendum as set out in its Section 19.
11.4 Switzerland. For transfers subject to the FADP, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR read as references to the FADP, the competent supervisory authority is the Swiss Commissioner, data subjects in Switzerland may enforce their rights before Swiss courts, and the SCCs protect the data of legal entities until the FADP no longer does so.
11.5 Alternative mechanisms. If Reachd later adopts another lawful transfer mechanism recognized under Data Protection Law, such as certification under the EU-U.S. Data Privacy Framework, Reachd may rely on it by notifying Customer, and the SCCs will then apply only to the extent that mechanism ceases to be valid.
11.6 Conflict. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
12. California
To the extent the CCPA applies, Reachd acts as a service provider to Customer. Reachd will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than the business purposes described in Annex 1 or outside the direct business relationship with Customer, and will not combine it with personal information it receives from other sources except as permitted for service providers under the CCPA. Reachd will notify Customer if it determines it can no longer meet its obligations under the CCPA. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
13. Liability
Each party’s liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations set out in Section 10 of the Terms, and the parties’ total aggregate liability under the Terms and this DPA together is subject to the cap stated there. Nothing in this Section limits the rights of data subjects under the SCCs or any liability that Data Protection Law does not permit to be limited.
14. Term and General
14.1 This DPA takes effect when Customer accepts the Terms, or on the Effective Date above if later, and remains in force for as long as Reachd processes Customer Personal Data.
14.2 Reachd may update this DPA to reflect changes in Data Protection Law, in the Service, or in the mechanisms available under Section 11, by giving the notice described in Section 15.2 of the Terms. Changes to Annex 3 follow Section 6.3.
14.3 Sections 14.5 (Governing Law) and 14 (Dispute Resolution) of the Terms apply to this DPA, except where the SCCs provide otherwise for the matters they govern.
14.4 Questions about this DPA, requests to receive Subprocessor notices by email, and requests for a countersigned copy may be sent to hello@reachd.ai.
Annex 1. Details of Processing
Subject matter. Provision of the Reachd.ai Service under the Terms: analysis of how AI Platforms respond to queries about Customer’s Registered Businesses, and the related reports, recommendations, notifications, and Expert Guidance.
Duration. The term of the Terms plus the deletion period in Section 9.
Nature and purpose. Hosting, storage, organization, and analysis of Customer Data; delivery of dashboards, reports, emails, API and connector responses to Customer; support.
Categories of data subjects. Customer’s Authorized Users and personnel; personnel and contacts of Customer’s clients where Customer is an Agency; individuals who are, or are named in connection with, a Registered Business, such as owners, practitioners, and staff whose names appear in the business’s public materials or in Customer’s own questions and files.
Categories of Personal Data. Names, business email addresses, roles, and account identifiers of Authorized Users; names of individuals contained in the website addresses, questions, keyword lists, locations, and files Customer submits; names of individuals contained in the materials Customer shares in the course of Expert Guidance. The Service is not designed for, and Customer will not submit, special categories of Personal Data, financial account data of individuals, government identifiers, or data about children.
Frequency. Continuous for the duration of the Service, with scheduled analyses at the cadence of Customer’s plan.
Annex 2. Technical and Organizational Measures
- Access control. Authentication of every user of the Service through a dedicated identity provider with signed session tokens; role-based access within workspaces; every record of Customer Data scoped to the workspace that owns it, with workspace membership checked on every read and write; API keys stored as hashes; administrative access to production limited to named personnel over key-based SSH.
- Encryption. TLS for all data in transit between users, the Service, and Subprocessors; encrypted storage volumes and encrypted backups at the hosting provider.
- Data separation. Logical separation of customers’ data by workspace identifier in a shared database, with every query scoped to one workspace; test and development environments run on doubles of external services and never contain production personal data except in scrubbed form, with customer email addresses removed before use.
- Availability and backup. Daily and weekly database backups to object storage in a separate location; a monthly automated restore test into a throwaway database; daily automated monitoring of infrastructure, job execution, and backup integrity, with alerts to Reachd personnel.
- Logging and monitoring. Application, error, and provider call logs with retention limited to operational need; sensitive values filtered from logs; external availability checks of the production hosts every two hours.
- Change management. Source control for all code and infrastructure configuration; automated test suite, including browser tests and a regression corpus, run on every change before deployment; deployments through a single automated pipeline.
- Subprocessor management. Written terms with every Subprocessor; the list in Annex 3 kept current; data sent to AI Platforms limited to the queries the Service generates and the public information needed to answer them, with no Authorized User identifiers included.
- Incident response. Documented process for detecting, assessing, containing, and notifying personal data breaches within the period in Section 8.
- Personnel. Confidentiality obligations for all personnel and contractors with access to Customer Data; access removed on role change or departure.
- Data minimization and deletion. Only the data needed for the Service is collected; Customer may remove businesses, users, and content at any time; deletion on termination as described in Section 9.
Annex 3. Subprocessors
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting of the Service and database; backup storage | United States |
| Clerk, Inc. | Authentication and user account management | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| ActiveCampaign, LLC (Postmark) | Transactional and notification email delivery | United States |
| OpenAI, L.L.C. | Submission of Service-generated queries to AI Platforms; text embeddings; analysis and content generation | United States |
| Google LLC | Submission of Service-generated queries to AI Platforms (Gemini) | United States |
| Anthropic, PBC | Submission of Service-generated queries to AI Platforms (Claude); analysis and content generation | United States |
| xAI Corp. | Submission of Service-generated queries to AI Platforms (Grok) | United States |
| Perplexity AI, Inc. | Submission of Service-generated queries to AI Platforms | United States |
| Bright Data Ltd. | Retrieval of public web pages on behalf of the Service | Israel, United States |
| Cloudflare, Inc. | Bot protection on public forms | United States |
Reachd’s own personnel access Customer Personal Data from the United States and from the locations where its personnel work under the confidentiality obligations in Section 4.
This Data Processing Agreement was last updated on September 2, 2026.