SmartReply

Data Processing Agreement

Last updated: 11 July 2026  ·  SmartReply, a product of Made in Graphic Ltd  ·  Company No: 13094248 (England & Wales)

This Data Processing Agreement (“DPA”) forms part of the agreement between Made in Graphic Ltd (“Processor”, “we”) and the customer who uses SmartReply (“Controller”, “you”) and governs the processing of personal data carried out on your behalf. It is designed to satisfy Article 28 of the UK GDPR and the EU GDPR, and applies automatically to every SmartReply account. Capitalised terms not defined here have the meaning given in the GDPR.

1. Roles of the Parties

For personal data contained in the conversations, contacts, and media that your customers send to your connected messaging channels (your WhatsApp Business number and, where enabled, your Facebook Page, Instagram account and website web-chat widget), you are the Controller and we are the Processor acting only on your documented instructions (which include your use of the SmartReply product and its settings). We remain an independent Controller for our own account, billing, support and security data, which is governed by our Privacy Policy.

2. Subject Matter, Duration, Nature and Purpose

3. Categories of Data Subjects and Personal Data

4. Processor Obligations (Art. 28(3))

We will:

5. Sub-Processors

You grant general authorisation for us to engage the sub-processors listed below to deliver the service. Each operates under its own data-processing terms and appropriate safeguards. We will inform you of intended changes (additions or replacements) and give you the opportunity to object on reasonable data-protection grounds.

Sub-processorPurposeRegion
Meta Platforms (WhatsApp Business Platform, Messenger, Instagram)Message and media deliveryEU / US
GoogleGoogle Calendar — appointment scheduling (only when you connect your calendar)EU / US
AnthropicAI response generationUS
OpenAIAI / embeddingsUS
StripeBilling and paymentsEU / US
ResendTransactional and notification emailUS
CloudflareTurnstile bot protection, network securityGlobal
HostingerServer and database hostingEU (UK / Netherlands)

6. Security Measures (Art. 32)

We maintain technical and organisational measures appropriate to the risk, including:

7. Retention, Return and Deletion

When your account is terminated or you request deletion in the panel, the account enters a 90-day grace window during which the request can be cancelled; at the end of this window personal data is permanently deleted. You may request earlier deletion at any time. Media files are automatically deleted 90 days after receipt. Billing records may be retained for up to 7 years for legal compliance. On request, we will return your data in a structured, commonly used format before deletion. Conversation message content is anonymised after a configurable retention period (24 months by default), permanently removing message text and customer identifiers while retaining only non-identifying analytics. Following deletion or anonymisation, residual copies may persist in our encrypted rolling backups for up to 30 days, after which they are overwritten and put beyond use; backups are not selectively restored to reinstate deleted personal data. These periods are described in more detail in our Privacy Policy.

8. Personal Data Breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information reasonably available to help you meet your own notification obligations under Articles 33–34.

9. Audit and Compliance

We will make available, on reasonable written request and no more than once per year (or following a breach), the information necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an independent auditor mandated by you, subject to confidentiality and reasonable scheduling.

10. International Transfers

Where personal data is transferred outside the UK or EEA (for example to US-based sub-processors), the transfer is protected by an appropriate safeguard such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, together with supplementary measures where required.

11. Data Subject Rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection).

12. General

This DPA is governed by the laws of England & Wales. In the event of a conflict between this DPA and the Terms of Service or Privacy Policy regarding the processing of personal data, this DPA prevails. If any provision is held invalid, the remainder continues in effect.

13. Contact

Made in Graphic Ltd · Company No: 13094248 · info@madeingraphic.co.uk · Privacy Policy · Terms of Service