Legal ยท Last updated August 4, 2026

Data Processing Addendum

Our commitments when processing personal data on behalf of customers.

These terms apply to the SMS messaging services operated by MassiveSMS.

1. Scope and roles

This Data Processing Addendum applies when we process personal data submitted by a customer to provide the SMS service. The customer is the controller or business, and we are the processor or service provider, unless applicable law provides otherwise.

2. Processing instructions

We process customer data only on documented instructions, to provide and secure the service, comply with law, and perform obligations described in the service agreement. The customer is responsible for lawful collection, consent, notices, and messaging instructions.

3. Confidentiality and security

Personnel authorized to process customer data are subject to confidentiality obligations. We maintain controls appropriate to the nature of the data and risks, including access restrictions, logging, encryption where appropriate, and incident procedures.

4. Subprocessors and transfers

We may use subprocessors for hosting, communications, support, analytics, and payments. We require subprocessors to protect personal data through contractual obligations appropriate to their services. International transfers use legally recognized safeguards where required.

5. Assistance and deletion

Taking into account the nature of processing, we provide reasonable assistance with data subject requests, security incidents, and compliance assessments. At the end of service, customer data is deleted or returned according to contractual and legal retention requirements.

MassiveSMS