Data Processing Agreement
Last updated: August 2026
This Data Processing Agreement ("DPA") describes how Allopy ("Processor") handles personal data on behalf of a customer ("Controller") in the course of providing the Allopy service. It supplements the Terms of Service and applies whenever Allopy processes personal data — including data about a Controller's own customers contained in support requests, emails, or billing records — on the Controller's behalf.
1. Roles
The Controller determines the purposes and means of processing personal data submitted to Allopy. Allopy acts as a Processor, handling that data only as instructed by the Controller through the rules, integrations, and configuration the Controller sets within the product.
2. Scope of Processing
- Nature of processing: reading, classifying, and acting on incoming requests (email content, billing records, scheduling requests) under Controller-defined rules.
- Categories of data: contact details, communication content, and transaction/billing details of the Controller's customers, to the extent contained in the systems the Controller connects (Gmail, Stripe, Calendar).
- Duration: for as long as the Controller's account is active, plus any retention period described in the Privacy Policy.
3. Processor Obligations
- Process personal data only on documented instructions from the Controller, as expressed through the Controller's configured rules and connected integrations.
- Ensure personnel authorized to process the data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures, including encryption in transit, access controls, and scoped credentials.
- Assist the Controller, where reasonably possible, in responding to data subject requests (access, deletion, correction) relating to data processed on the Controller's behalf.
- Notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data.
- Delete or return all personal data to the Controller at the end of the service relationship, except where retention is required by law.
4. Sub-Processors
The Controller authorizes Allopy's use of the following sub-processors, each engaged strictly to operate the service and bound by data protection terms consistent with this DPA:
- Supabase — database and storage infrastructure
- OpenAI — request classification (processes request content; does not retain data for model training under Allopy's API terms)
- Resend — transactional email delivery
- Vercel — application hosting
- Stripe — payment processing (for accounts the Controller connects)
Allopy will provide reasonable advance notice of any new sub-processor added to this list, giving the Controller the opportunity to object on reasonable data-protection grounds.
5. International Transfers
Where personal data is transferred outside the Controller's jurisdiction, Allopy relies on appropriate safeguards consistent with applicable data protection law, including standard contractual clauses where required.
6. Audit Rights
Upon reasonable request, Allopy will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA, including responding to reasonable written questionnaires.
7. Liability
Liability under this DPA is governed by the limitation of liability provisions in the Terms of Service.
8. Contact
Questions about this DPA, or requests for a signed/countersigned version for your records, can be sent to legal@allopy.com.