These terms apply to the SMS messaging services operated by MassiveSMS.
1. Scope and roles
This Data Processing Addendum applies when we process personal data submitted by a customer to provide the SMS service. The customer is the controller or business, and we are the processor or service provider, unless applicable law provides otherwise.
2. Processing instructions
We process customer data only on documented instructions, to provide and secure the service, comply with law, and perform obligations described in the service agreement. The customer is responsible for lawful collection, consent, notices, and messaging instructions.
3. Confidentiality and security
Personnel authorized to process customer data are subject to confidentiality obligations. We maintain controls appropriate to the nature of the data and risks, including access restrictions, logging, encryption where appropriate, and incident procedures.
4. Subprocessors and transfers
We may use subprocessors for hosting, communications, support, analytics, and payments. We require subprocessors to protect personal data through contractual obligations appropriate to their services. International transfers use legally recognized safeguards where required.
5. Assistance and deletion
Taking into account the nature of processing, we provide reasonable assistance with data subject requests, security incidents, and compliance assessments. At the end of service, customer data is deleted or returned according to contractual and legal retention requirements.
MassiveSMS