SURFF-AI: DATA PROCESSING AGREEMENT (DPA)

Last Updated: [Insert Date]

Jurisdiction: Ireland (GDPR Article 28 Compliant)

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement between Surff-AI ("Processor") and the Client ("Controller").

1. NATURE AND PURPOSE OF PROCESSING

The Processor provides an AI-driven communication and review automation platform. To facilitate this, the Processor will handle personal data (primarily names and phone numbers) provided by the Controller for the following specific purposes:

  • Review Funnel Automation: Sending automated review requests via WhatsApp/SMS.
  • Instant Text-Back: Facilitating immediate AI-driven responses to missed calls or inbound inquiries.
  • Lead Management: Organising and displaying communication history within the LeadConnector interface.

2. SCOPE OF DATA

The personal data processed includes:

End-Customer Data: Name, Phone Number, Email Address, and the content of messages sent to the Controller’s business.

3. OBLIGATIONS OF THE PROCESSOR

The Processor (Surff-AI) agrees to:

  • Process on Instruction: Only process personal data according to the Controller’s documented instructions (e.g., via the settings configured in the LeadConnector app).
  • Confidentiality: Ensure that all personnel authorized to process the data have committed themselves to confidentiality.
  • Security: Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, utilizing enterprise-grade encryption provided by the underlying software stack.
  • Data Subject Rights: Assist the Controller in responding to requests from individuals exercising their GDPR rights (e.g., requests for data deletion).

4. SUB-PROCESSORS

The Controller provides general authorization for the Processor to engage the following sub-processors to deliver the service:

  • LeadConnector / GoHighLevel (GHL): CRM and core automation infrastructure.
  • Meta Platforms, Inc. (WhatsApp/FB/IG): Messaging delivery and API interface.
  • Google Cloud: Hosting and data storage infrastructure.
  • Telecommunications Providers: Integrated providers within GHL (e.g., LC Communications) for the provisioning of business numbers and message routing.

5. SECURITY STANDARDS

The Processor utilizes enterprise-grade software infrastructure. All data processed through the Surff-AI protocol is:

  • Encrypted in transit (SSL/TLS).
  • Hosted on secure servers (Google Cloud/AWS) managed via the LeadConnector protocol.
  • Protected by multi-factor authentication for administrative access.

6. DATA TRANSFERS

Data may be processed in regions outside the European Economic Area (EEA) where our sub-processors (e.g., Google or Meta) maintain infrastructure. These transfers are governed by Standard Contractual Clauses (SCCs) to ensure a level of protection equivalent to that in Ireland.

7. AUDITS AND TERMINATION

The Processor shall make available to the Controller information necessary to demonstrate compliance with Article 28 of the GDPR. Upon termination of the 40-day Demo or the Subscription, the Processor shall, at the choice of the Controller, delete or return all personal data, unless Irish or EU law requires further storage.

BY ACTIVATING THE SURFF-AI SERVICE, THE CONTROLLER AGREES TO THE TERMS OF THIS DATA PROCESSING AGREEMENT.