SMS.to DATA PROCESSING TERMS

These Data Processing Terms (the “DPA“) form part of the Acceptable Use Policy and Agreement of SMS.to (the “Agreement“) between Intergo Telecom Ltd, a company registered in the Republic of Cyprus under registration number HE 352115, with its registered office at Tepeleniou 17, Office 102-103, 8010 Paphos, Cyprus (“Intergo Telecom“, “we“, “us” or “our“), and the customer using the Services (“Customer“, “you” or “your“).

This DPA applies automatically when you accept the Agreement, and no separate signature is required. It sets out the terms required by Article 28 of the GDPR for the processing of personal data that we carry out on your behalf when providing the Services. If you need a countersigned copy for your records, please contact dpo@intergotelecom.com; a countersigned copy will be on the same terms as this DPA.

1. Definitions

1.1       Capitalised terms not defined in this DPA have the meaning given in the Agreement. In this DPA:

(a)        “Communications Provider” means a mobile network operator, carrier, aggregator or other provider of electronic communications services that conveys a message, in whole or in part, between our platform and the recipient’s device (or between the recipient and our platform, in the case of replies and delivery reports);

(b)        “Customer Personal Data” means the personal data described in Annex 1 that we process on your behalf in providing the Services;

(c)        “Data Protection Laws” means Regulation (EU) 2016/679 (the “GDPR“), Directive 2002/58/EC (the “ePrivacy Directive“) and its national implementing laws, the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (Law 125(I)/2018), and any other data protection laws applicable to the processing of Customer Personal Data, each as amended or replaced;

(d)        “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data;

(e)        “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914;

(f)         “Sub-processor” means any third party we engage to process Customer Personal Data on your behalf.

1.2       The terms “controller”, “processor”, “data subject”, “personal data”, “processing” and “supervisory authority” have the meanings given in the GDPR.

2. Scope and roles

2.1       For Customer Personal Data, you are the controller and we are your processor. Where you act as a processor on behalf of a third-party controller, we act as your sub-processor, and you confirm that the relevant controller has authorised your instructions and our engagement.

2.2       Annex 1 describes the subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects.

2.3       This DPA does not apply to personal data that we process as an independent controller. This includes your account and contact data, and the traffic, billing and routing data we need to invoice the Services, prevent fraud and misuse, maintain network and information security, meet our obligations as an electronic communications provider, and comply with legal requirements. That processing is described in our Privacy Statement at https://sms.to/privacy-statement/.

3. Processing on your instructions

3.1       We will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless Union or Member State law requires otherwise. In that case, we will inform you of the legal requirement before processing, unless the law prohibits this on important grounds of public interest.

3.2       Your documented instructions consist of the Agreement, this DPA, and your configuration and use of the Services (including the messages, recipients, sender IDs and settings you submit through the platform or API). Any additional instructions must be given in writing and must be consistent with the Agreement.

3.3       We will inform you immediately if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected processing until you confirm or modify the instruction.

4. Your responsibilities

4.1       You are responsible for the lawfulness of the processing you instruct, including having a lawful basis for sending each message, providing any required information to recipients, and obtaining and recording any consents and opt-outs required by Data Protection Laws or marketing rules.

4.2       You must not include in message content special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR), except to the extent strictly necessary for the purpose of the communication and permitted by a lawful basis under Article 9(2) or Article 10 GDPR. Ordinary appointment, booking and account notifications (for example, the date, time, location and type of an appointment, or a booking, consent or verification link or code) are permitted, provided you limit their content to what is necessary.

4.3       You are responsible for configuring the security features made available to you in the Services that are appropriate to the personal data you process, including multi-factor authentication, API key management and the message log privacy (“Secure”) mode, and for keeping your account credentials confidential.

5. Confidentiality

5.1       We will ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide the Services.

6. Security

6.1       We will implement and maintain the technical and organisational measures described in Annex 2, which are designed to ensure a level of security appropriate to the risk in accordance with Article 32 GDPR.

6.2       We may update these measures from time to time, provided that the updates do not materially reduce the overall level of security of the Services.

7. Sub-processors

7.1       You give us general written authorisation to engage Sub-processors. Annex 3 lists the Sub-processors we currently engage, their processing activities and locations.

7.2       We will notify you of any intended addition or replacement of a Sub-processor at least thirty (30) days before the change takes effect, by email to the primary contact address on your account. The notice will state the name and category of the Sub-processor, the processing location and the transfer mechanism relied on, and we will update Annex 3 accordingly.

7.3       You may object to an intended change on reasonable data protection grounds by notice to dpo@intergotelecom.com  within the notice period. We will discuss your objection in good faith. If we cannot resolve it, you may terminate the affected Services by written notice before the change takes effect. Notwithstanding clauses 4 and 6 of the Agreement, no early termination charges will apply and we will refund any unused prepaid credit for the terminated Services.

7.4       Where an immediate replacement of a Sub-processor is necessary for security reasons or to maintain continuity of the Services, we may make the replacement with shorter notice. We will notify you as soon as reasonably possible, and your right to object under clause 7.3 will apply.

7.5       We will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, in particular providing sufficient guarantees of appropriate technical and organisational measures. We remain fully liable to you for the performance of each Sub-processor’s obligations.

7.6       Communications Providers are not our Sub-processors. In conveying a message, a Communications Provider acts as a mere conduit: it does not initiate the transmission, select the recipient, or select or modify the content, and it does not store the message except transiently for the sole purpose of carrying out the transmission. When conveying a message, each Communications Provider acts as a provider of electronic communications services in its own right: it transmits the communication over its network or interconnections and, in doing so, is bound by the confidentiality of communications and the other obligations imposed on it by the electronic communications laws of its jurisdiction (including, where it is established in the EEA, the national laws implementing the ePrivacy Directive). It processes message content only to convey the message, and it processes the traffic data it generates as a controller for its own purposes, such as billing, network security and compliance with its legal obligations. The conveyance of messages through Communications Providers is inherent in the Services you instruct us to provide. Clauses 7.1 to 7.5 therefore do not apply to Communications Providers.

7.7       Any provider that performs services for us beyond conveying messages (for example, storing message content, carrying out number lookups, filtering or otherwise processing message content on our behalf, or delivering messages through an over-the-top messaging channel such as Viber or WhatsApp) is a Sub-processor in respect of those services, and clauses 7.1 to 7.5 apply to it.

7.8       On request, we will identify the Communications Provider that delivered the messages sent to a specific recipient, to the extent that information is available to us, so that you can respond to a request from that recipient.

7.9       We select Communications Providers with care and require them, by contract, to keep communications confidential, to apply appropriate security measures, and to use the data they receive only to convey and bill for messages, to prevent fraud and misuse, and to comply with their legal obligations.

8. International transfers

8.1       We will transfer Customer Personal Data outside the European Economic Area (“EEA“) only in compliance with Chapter V GDPR, relying on an adequacy decision of the European Commission or, where none applies, on the SCCs (Module 3, processor to processor) with the relevant Sub-processor, supplemented by additional measures where our transfer impact assessment requires them.

8.2       Where you instruct us to deliver a message to a recipient number in a country outside the EEA, you acknowledge that the message and associated data must be conveyed to Communications Providers in or serving that country in order to be delivered. Such transmission is made on your instruction and is inherent in the delivery of the message.

8.3       Where you are established outside the EEA and not subject to the GDPR, Module 4 (processor to controller) of the SCCs is incorporated into this DPA by reference, with Intergo Telecom as data exporter and you as data importer, and with the options set out in Annex 1.

9. Personal Data Breaches

9.1       We will notify you without undue delay, and in any event within twenty four  (24) hours after becoming aware of a Personal Data Breach. We will notify the primary contact address on your account.

9.2       Our notification will include, to the extent available, the information required by Article 33(3) GDPR. Where the information is not available at the same time, we will provide it in phases without undue further delay.

9.3       We will take reasonable steps to contain, investigate and mitigate the Personal Data Breach, and will co-operate with you so that you can meet your obligations under Articles 33 and 34 GDPR. You decide whether to notify supervisory authorities or data subjects in your capacity as controller. This does not restrict our own notification obligations under laws that apply to us directly, including network and information security and electronic communications laws.

9.4       Our notification of a Personal Data Breach is not an acknowledgement of fault or liability.

10. Assistance

10.1     If we receive a request from a data subject relating to Customer Personal Data, we will forward it to you without undue delay and will not respond to it ourselves except to direct the data subject to you, unless you instruct us otherwise or the law requires it.

10.2     Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to enable you to respond to data subject requests, meet your security obligations, and carry out data protection impact assessments and prior consultations with supervisory authorities. Where available, you will first use the self-service features of the Services (including export and deletion functions). We may charge reasonable costs for assistance that goes beyond those features and our obligations under Data Protection Laws.

11. Requests from public authorities

11.1     If we receive a request from a court, law enforcement agency or other public authority for access to Customer Personal Data, we will notify you promptly unless the law prohibits this. We will review the legality of the request, including against Article 48 GDPR in the case of requests from authorities outside the EU. We will challenge the request where we consider there are reasonable grounds to do so, and we will disclose only the minimum data required.

12. Audits

12.1     We will make available to you, on written request, the information reasonably necessary to demonstrate our compliance with Article 28 GDPR. This includes a summary of our security measures and any relevant certifications or independent audit reports we hold, which you will treat as our confidential information.

12.2     If that information is insufficient to demonstrate compliance, if a supervisory authority requires it, or following a Personal Data Breach, you (or an independent auditor bound by confidentiality and reasonably acceptable to us) may carry out an audit or inspection. Audits require at least thirty (30) days’ written notice (except following a Personal Data Breach or where a supervisory authority requires otherwise), may take place no more than once in any twelve-month period, and must be conducted during normal business hours in a way that minimises disruption to our business and does not compromise the security or confidentiality of other customers’ data.

12.3     You will bear the costs of an audit under clause 12.2, unless it reveals a material breach of this DPA by us, in which case we will bear our own costs and reimburse your reasonable audit costs.

13. Deletion and return

13.1     During the term of the Agreement, you may delete Customer Personal Data through the Services. Message logs and delivery records are retained in your account according to our Retention Policy, unless you delete them earlier.

13.2     You may export Customer Personal Data using the export functions of the Services at any time before termination. Within thirty (30) days after termination of the Agreement, we will delete all Customer Personal Data, unless Union or Member State law requires us to store it. In that case, we will inform you of the data retained, the legal basis and the retention period, will keep it confidential, and will process it only as that law requires.

13.3     Customer Personal Data held in back-up systems will be isolated from further processing and deleted when the back-ups are overwritten in our ordinary back-up cycle, and in any event within 90 days after termination.

13.4     On written request, we will confirm in writing that deletion has taken place.

14. Liability

14.1     Our liability under or in connection with this DPA is subject to the exclusions and limitations of liability in clause 15 of the Agreement, save as set out in clause 14.2. The aggregate cap in clause 15.3 of the Agreement applies to all claims under the Agreement and this DPA taken together.

14.2     The exclusion in clause 15.2(c) of the Agreement for loss or corruption of data and for unauthorised access to or alteration of data shall not apply to losses directly caused by our breach of clause 6 of this DPA, which remain subject to the aggregate cap in clause 15.3 of the Agreement.

14.3     Nothing in this DPA limits either party’s liability to data subjects under Article 82 GDPR, or any liability that cannot be limited or excluded under applicable law.

15. Term, changes and precedence

15.1     This DPA remains in force for as long as the Agreement is in force and, after that, for as long as we process any Customer Personal Data.

15.2     We may update this DPA to reflect changes in Data Protection Laws, guidance or decisions of supervisory authorities or courts, or changes to the Services, provided that the update does not materially reduce the protection of Customer Personal Data. We will give you at least thirty (30) days’ notice of any material update by email to the primary contact address on your account. Changes to Sub-processors are governed by clause 7.

15.3     In the event of conflict: (a) this DPA prevails over the Agreement in relation to the processing of Customer Personal Data; (b) the SCCs, where they apply, prevail over this DPA; and (c) a data processing agreement signed by both you and Intergo Telecom prevails over this DPA.

16. Governing law and jurisdiction

16.1     This DPA is governed by the laws of the Republic of Cyprus. The courts of Paphos, Cyprus have exclusive jurisdiction over any dispute arising out of or in connection with it, without prejudice to the rights of data subjects or supervisory authorities under Data Protection Laws. Where the SCCs apply, their governing law and forum provisions prevail.

Annex 1 – Description of the processing

Item

Description

Parties

Controller (data exporter where applicable): the Customer.

Processor (data importer where applicable): Intergo Telecom Ltd, operator of SMS.to. Contact: dpo@intergotelecom.com.

Subject matter and purpose

Provision of the SMS.to messaging services under the Agreement, including sending SMS and other messages initiated by the Customer (such as notifications, reminders, recall notices, alerts, marketing messages, and one-time passwords, verification or consent links and codes), delivery reporting, two-way messaging, opt-out management, number lookup, link shortening and click tracking, and related customer support.

Nature of the processing

Receipt, storage, transmission and routing of messages to Communications Providers for delivery; generation and storage of delivery reports and message logs; number lookup queries; processing of inbound replies and opt-outs; provision of account-level reporting; deletion.

Categories of data subjects

Recipients of messages sent by the Customer (including the Customer’s customers, patients, members, employees and prospects).

Persons who reply to or interact with the Customer’s messages or links.

The Customer’s authorised users of the Services, where their data is processed as part of Customer content.

Categories of personal data

Mobile telephone numbers and, where included by the Customer, names and other identifiers.

Message content composed by the Customer, and inbound replies.

Message metadata: sender ID, timestamps, delivery status, routing and Communications Provider information, and number lookup results.

Link interaction data (click time, device and IP data) where the Customer uses link tracking.

Opt-out and consent records submitted by or collected for the Customer.

Special categories

None required by the Services. The Customer may include such data only as permitted by clause 4.2 of the DPA. The fact that a message is sent by a particular Customer may itself reveal information about the recipient (for example, that they are a patient of a clinic), and the Customer should take this into account.

Frequency

Continuous, for as long as the Customer uses the Services.

Duration and retention

For the term of the Agreement, then deletion in accordance with clause 13 of the DPA.

Transfers

In accordance with clause 8 of the DPA. For SCC Module 4 (clause 8.3): Clause 7 (docking) applies; the governing law and forum are those of the Republic of Cyprus.

Annex 2 – Technical and organisational measures

Area

Measures

Information security management

A written information security management system governs the storage, processing and transmission of personal data. It is aligned with ISO/IEC 27001 principles, reviewed at least annually, and updated in light of risk assessments, security developments and regulatory change, including our obligations under the Cyprus network and information security (NIS2) framework.

Personnel

Pre-employment screening, confidentiality obligations, annual security and data protection training, and role-based responsibilities. Service providers with access to personal data are vetted before engagement and reviewed periodically.

Access control

Access on a need-to-know basis through role-based controls with a default-deny setting; unique user IDs; strong passwords and multi-factor authentication for administrative access; session controls; periodic access reviews. Back-end access is restricted by IP allow-listing.

Customer-side controls

Multi-factor authentication for customer accounts, API key management, and a message log privacy (“Secure”) mode that masks message content in account logs.

Encryption

Encryption of personal data in transit over public networks, and encryption at rest for stored data.

Network and systems security

Firewalls and network segmentation with change management; hardened configurations; separation of test and production environments; secure software development practices aligned with OWASP guidance.

Vulnerability management

Anti-malware protection, regular vulnerability scanning, timely patching, and periodic internal and external penetration testing, with remediation of findings.

Logging and monitoring

Centralised logging and intrusion detection, 24/7 monitoring by engineering staff with alerting on suspicious activity, and audit trails protected against tampering and retained for at least one year.

Incident response

A documented and tested incident response plan defining roles, escalation, customer notification and regulatory notification.

Business continuity

Regular back-ups, disaster recovery and business continuity plans, and periodic restoration testing.

Physical security

Hosting in data centres operated by providers holding recognised certifications (such as ISO/IEC 27001), with controlled physical access. Office access is controlled and logged.

Data minimisation and deletion

Retention limits and self-service deletion tools; secure disposal of media so that data cannot be recovered.

 

 

Annex 3 – Sub-processors

This Annex lists the Sub-processors we engage to process Customer Personal Data on your behalf. Any intended addition or replacement is notified in accordance with clause 7.2 of the DPA.

Part A – Sub-processors

Sub-processor

Category and processing activities

Processing location

Transfer mechanism

Amazon Web Services

Cloud hosting and infrastructure: hosting of the SMS.to platform and API, databases, message logs, delivery records and back-ups.

EU

EEA

Google Cloud

Cloud hosting and infrastructure: [CONFIRM WHICH SERVICES RUN ON GOOGLE CLOUD].

EU

 EEA

Freshdesk (Freshworks)

Customer support: ticketing, support chat and support email, where you share Customer Personal Data with us in a support request.

EU

EEA

Atlassian (Jira/Confluence)

Internal ticketing and documentation: handling of support escalations and incident records, where these contain Customer Personal Data.

EU

EEA

WhatsApp

Over-the-top messaging channel: delivery of messages you choose to send via WhatsApp, including recipient numbers and message content.

EU

[CONFIRM]

Viber

Over-the-top messaging channel: delivery of messages you choose to send via Viber, including recipient numbers and message content.

EU

EEA

Alaris

messaging platform hosted by Alaris (keep row) or self-hosted software (delete row)]

Germany, France

EEA

Part B – Providers that are not Sub-processors

Provider type

Reason

Communications Providers (mobile network operators, carriers and aggregators that convey messages as mere conduits)

They act as providers of electronic communications services in their own right and do not process Customer Personal Data on our behalf (clause 7.6 of the DPA). A provider that performs services beyond conveying messages is a Sub-processor under clause 7.7 and falls within Part A.

Providers we use for our own purposes as controller (for example, payment processors, banking, accounting, CRM and marketing tools)

They process account, billing and business data for which we are the controller (clause 2.3 of the DPA), not Customer Personal Data processed on your behalf.

Â