On this page
1. Scope and roles
This DPA applies only to Customer Personal Data. It does not cover personal data that Reuily handles for its own business purposes, such as account, billing, security and service usage information. That processing is described in the Privacy Notice.
The customer acts as the controller or business for Customer Personal Data, and Reuily acts as its processor or service provider. If the customer is itself a processor, Reuily acts as its subprocessor. Each party will comply with the Data Protection Laws that apply to its role.
2. Definitions
- Agreement means the Terms of Service or another written agreement that covers the customer's use of Reuily.
- Customer Personal Data means personal data included in forms, responses, uploaded files, signatures or other content that Reuily processes on the customer's behalf through the service.
- Data Protection Laws means the privacy and data protection laws that apply to the processing covered by this DPA.
- Subprocessor means a provider Reuily engages to process Customer Personal Data.
- Security Incident means a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data.
Terms such as controller, processor, business, service provider, personal data and processing have the meanings given to them by applicable Data Protection Laws.
3. Customer instructions
Reuily will process Customer Personal Data only as needed to provide, secure and support the service in accordance with the Agreement and the customer's documented instructions. The Agreement, the customer's product settings and authorized support requests make up those instructions.
Reuily may also process Customer Personal Data when required by law. Where the law permits, Reuily will tell the customer about that requirement before processing. Reuily will notify the customer if it reasonably believes an instruction violates applicable Data Protection Laws.
4. Customer responsibilities
The customer is responsible for:
- having a lawful basis to collect and use Customer Personal Data;
- providing required notices and obtaining required permissions or consent;
- ensuring its instructions and use of the service comply with Data Protection Laws;
- configuring form fields, retention settings, workspace access and integrations appropriately;
- not using the service to collect data prohibited by the Agreement or unsupported regulated data.
If the customer provides instructions for another controller, it confirms that it is authorized to do so.
5. Confidentiality and security
Reuily limits access to Customer Personal Data to personnel and providers who need it to provide or support the service. Anyone authorized to process that data must be subject to appropriate confidentiality obligations.
Reuily maintains administrative, technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction or damage. These measures include, as appropriate to the service and risk:
- encrypted transmission and protected storage;
- role-based access controls and separation between customer workspaces;
- restricted access to private files and generated exports;
- upload validation, monitoring, recovery and deletion controls;
- maintenance and review of relevant technical safeguards.
The customer is responsible for securing its accounts, connected destinations, downloaded exports and any copies stored outside Reuily.
6. Security incidents
Reuily will notify the customer without undue delay after becoming aware of a Security Incident. Reuily will provide available information reasonably needed for the customer to meet its notification obligations and will take reasonable steps to contain, investigate and address the incident.
Reuily's notice of or response to a Security Incident is not an acknowledgment of fault or liability.
7. Subprocessors
The customer gives Reuily general authorization to use subprocessors to provide the service. Reuily will require each subprocessor to protect Customer Personal Data under written terms that provide substantially the same level of protection required by this DPA. Reuily remains responsible for its subprocessors' performance of those obligations.
Reuily publishes its current subprocessor list and a mechanism to subscribe to change notices. Reuily will publish and email subscribed customers at least thirty days before a new subprocessor begins processing Customer Personal Data. The customer may raise a reasonable objection based on data protection concerns by emailing privacy@reuily.com during that notice period. The parties will work in good faith to address the concern.
A third-party integration or destination that the customer chooses, such as Google Sheets or a customer webhook, is controlled by the customer and is not a Reuily subprocessor merely because the service sends data to it at the customer's direction.
8. International transfers
Reuily will not transfer Customer Personal Data from the European Economic Area, Switzerland or the United Kingdom to a country that has not been recognized as providing adequate protection unless it uses a lawful transfer mechanism. Where required, the applicable European Commission Standard Contractual Clauses, UK International Data Transfer Addendum or another valid safeguard are incorporated into this DPA and take priority for the transfer.
Reuily will document relevant transfer assessments, implement supplementary technical or organizational measures where reasonably necessary, and provide information reasonably needed for the customer to evaluate the transfer mechanism. Reuily will notify the customer if it can no longer comply with an applicable transfer safeguard.
9. California service-provider terms
To the extent the California Consumer Privacy Act applies to Customer Personal Data, Reuily acts as the customer's service provider or contractor. Reuily will comply with applicable obligations, provide the same level of privacy protection required of the customer for that data, and process it only for the specific business purposes described in the Agreement and this DPA.
- Reuily will not sell or share Customer Personal Data.
- Reuily will not retain, use or disclose Customer Personal Data outside the direct business relationship with the customer or for a commercial purpose other than the permitted purposes, except as allowed by applicable law.
- Reuily will not combine Customer Personal Data with personal information received from another person or collected from Reuily's own interactions with a consumer, except where applicable law permits that combination.
- Reuily will notify the customer if it determines it can no longer meet these obligations.
The customer may take reasonable and appropriate steps to monitor Reuily's compliance, including requesting relevant documentation, an annual assessment, or additional review following a Security Incident or reasonable compliance concern. The customer may require Reuily to stop and remediate unauthorized use of Customer Personal Data. Reuily will cooperate with those reasonable steps, enable the customer to fulfill applicable consumer requests, and require applicable subprocessors to observe equivalent restrictions.
10. Requests and assistance
Taking into account the nature of the processing, Reuily will provide reasonable assistance through the service and available support channels so the customer can respond to requests to access, correct, export, restrict or delete Customer Personal Data.
If Reuily receives a request concerning Customer Personal Data, Reuily will promptly notify the Customer and provide reasonable assistance in responding. Reuily will act only on the Customer's documented instructions, except where applicable law requires otherwise.
Reuily will also provide reasonable assistance so the customer can meet its obligations relating to data security, breach notifications, data protection impact assessments and consultations with regulators. The assistance provided will reflect the nature of the processing and the information available to Reuily.
11. Return and deletion
During the subscription, the customer can export responses and delete forms or individual submissions using the service. When the Agreement ends, Reuily will delete or return Customer Personal Data in accordance with the Agreement and its standard deletion process, unless applicable law requires retention.
Deleted data may remain in protected backups until those backups are overwritten or expire under Reuily's backup cycle. Reuily will keep that data protected and will not use it for ordinary business purposes while it remains in backup.
12. What Reuily processes for customers
This section explains what personal data Reuily handles when providing the service for a customer. The customer chooses what information its forms collect and how it uses the service.
- What this covers
- The forms, responses, files, signatures, analytics, exports and integrations that the customer chooses to use.
- What Reuily does
- Reuily receives, stores, organizes, displays, exports, sends and deletes data as directed by the customer through the service.
- Why Reuily does this
- To provide, secure, maintain and support the service for the customer.
- Whose data is involved
- People who complete the customer's forms, members of the customer's team and anyone else whose personal data the customer submits.
- What data is involved
- Whatever information the customer chooses to collect or submit, such as names, contact details, work information, survey or application answers, uploaded files, signatures, device information and how a respondent reached a form.
- How long
- While the Agreement is in effect, followed by the deletion and backup period described in this DPA.
13. About this DPA
This DPA is part of the Agreement and sets the rules for how Reuily handles Customer Personal Data on the customer's behalf. These rules take priority over any different data-processing terms in the Agreement. All other parts of the Agreement continue to apply.
This DPA starts when the Agreement starts and continues for as long as Reuily handles Customer Personal Data for the customer. Questions about data processing may be sent to privacy@reuily.com.
See also our Privacy Notice and Terms of Service.