Skip to document
SMSifyBusiness SMS policies

Effective August 22, 2026

Data Processing Addendum and Subprocessor Notice

Processor terms and production-provider disclosures for customer-controlled personal data.

1. Processing roles and instructions

For customer message content, recipient information, imported contacts, and related customer-controlled data, the customer is generally the controller or business and SMSify is generally its processor or service provider. SMSify processes that data only on documented instructions in the agreement, including instructions necessary to provide, secure, support, and lawfully operate the service.

2. Processing details

  • Subject matter: hosted business messaging, dedicated-number routing, call forwarding, support, security, billing support, and compliance operations.
  • Data subjects: customer users, representatives, message senders and recipients, contacts, and support participants.
  • Data: identity and contact data, telephone numbers, consent and suppression records, message or media content, routing and delivery metadata, usage, and support records.
  • Duration: the service term plus only the approved deletion, legal-hold, backup, and statutory-retention periods.

3. Processor commitments

  • Confidentiality, need-to-know access, proportionate technical and organizational security, and personnel obligations.
  • Assistance with rights requests, security incidents, impact assessments, regulator consultations, and deletion or return, considering the nature of processing.
  • Auditable records and information reasonably necessary to demonstrate compliance, subject to reasonable security, confidentiality, frequency, and cost protections.
  • Notification if an instruction appears unlawful, unless law prohibits notice.

4. Subprocessor categories

The production list must identify each legal entity, service, processing purpose, hosting or processing country, transfer mechanism, and notice date. Expected categories include communications carriers, cloud hosting, database and storage, payments, business verification, tax and regulatory compliance, authentication, transactional email, support, monitoring, and security.

Twilio, Stripe, the final hosting/database providers, and every other production vendor remain candidates rather than approved subprocessors until the list and contract review are complete. SMSify must provide the agreed notice and objection process before adding or replacing a subprocessor.

5. International and Quebec transfers

Restricted EEA transfers require an approved adequacy basis or transfer instrument, supplementary measures where necessary, and a documented assessment. For a Quebec enterprise sending personal information outside Quebec, the customer and SMSify must complete the applicable privacy impact assessment and written agreement before processing begins.

6. Return, deletion, and legal holds

At the customer’s choice and subject to law, SMSify returns or deletes customer personal data after service ends. Each production store, replica, queue, log, backup, carrier record, and derived dataset must be covered by an approved retention/deletion rule. A legal hold must be documented, access-limited, periodically reviewed, and lifted when no longer required.

7. Incident cooperation

SMSify notifies the customer without undue delay after confirming a personal-data breach affecting customer-controlled data and provides available facts needed for the customer’s assessment. Contact channels, evidence preservation, regulator coordination, and allocation of costs follow applicable law and the documented incident process.

Fail-closed launch gate

Customer-controlled production data is not persisted until the Article 28 terms, US and Canadian privacy addenda, subprocessor list, vendor contracts, transfer assessments, Quebec process, security schedule, incident workflow, and deletion verification are approved. If a provider cannot meet the approved controls, it is not used for production data.