BUSINESS DATA RESPONSIBILITIES

Data Processing Addendum

1. Roles and instructions

Customer determines the purpose of its queue and the information it asks people to provide. Customer is the controller or business for that data, and LinesFly is the processor or service provider, except where LinesFly independently determines processing for account security, billing, fraud prevention, legal compliance, or service administration. Customer instructs LinesFly to process Customer Personal Data only to provide, secure, support, and improve the contracted service; follow documented product settings; and comply with law.

2. Processing details

3. Customer responsibilities

Customer will provide lawful instructions, a valid legal basis and required notice; collect only necessary fields; protect credentials and private links; assign least-privilege staff roles; respond to people’s requests; and ensure its use complies with privacy, messaging, employment, public-sector, and sector-specific law. Customer will not submit protected health information without a separate signed Business Associate Agreement or otherwise violate the Acceptable Use Policy.

4. LinesFly obligations

LinesFly will:

  • process Customer Personal Data only on documented instructions, unless law requires otherwise;
  • ensure personnel with access are bound by appropriate confidentiality duties;
  • maintain safeguards appropriate to the sensitivity and risk of the service;
  • reasonably assist Customer with verified rights requests, security incidents, and legally required assessments;
  • notify Customer without undue delay after confirming a breach of Customer Personal Data and provide information reasonably available for Customer’s response;
  • delete or return Customer Personal Data at termination as described in Section 7, unless law requires retention; and
  • make available information reasonably necessary to demonstrate these obligations.

5. Security measures

Measures include encrypted transport; hashed passwords, sessions, status tokens, and protected recipient references; organization and role authorization; signed provider webhooks; abuse prevention and rate limits; audit and lifecycle events; secure environment-secret handling; provider access controls; and a recurring data lifecycle. Security measures may evolve without materially reducing overall protection.

6. Subprocessors and transfers

Customer generally authorizes the providers listed on the Subprocessor List. LinesFly will require subprocessors to protect personal data consistently with their role and applicable law. We may update the list to support the service. Customer may raise a reasonable, data-protection-based objection by emailing privacy@linesfly.com; the parties will work in good faith on a practical solution. Where applicable law requires a transfer mechanism, the parties will use an appropriate contractual or legal mechanism.

7. Return, deletion, and retention

Customer can access current operational data through LinesFly while the account is active. Customer-identifying queue fields are normally anonymized after 90 days. A verified organization-deletion request schedules tenant service data for deletion after a seven-day recovery period. LinesFly may retain limited consent, suppression, billing, security, backup, or legal records as permitted or required, protecting them under this DPA until deletion.

8. Reviews and audits

On reasonable written request, LinesFly will provide relevant policy, architecture, control, or provider information that can be shared without compromising other customers or service security. If that is insufficient and law requires an audit, the parties will agree on a qualified independent reviewer, reasonable scope and timing, protection of confidential information, and Customer payment of costs. Audits are limited to once per year unless a confirmed incident or regulator requires otherwise.

9. Conflict and termination

If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. Other Terms remain in effect. This DPA ends when LinesFly no longer processes Customer Personal Data, except provisions that must survive to protect retained information.