Explain in plain EnglishClaudeChatGPTMarkdown

Data Processing Addendum

Last updated: October 5, 2026

The short version

  • When you send us your recipients' data, we process it only to run SimpleSMS for you.
  • We tell you before adding a new subprocessor, and you can object.
  • We report a breach to you within 72 hours of confirming it.
  • We delete your data within 90 days after you leave.
  • It applies automatically: no signature needed. A countersigned copy is available from legal@deliveredsms.com.

This Data Processing Addendum ("DPA") is part of the Terms of Service between Truelabel Inc d/b/a SimpleSMS ("SimpleSMS") and the Customer, and applies whenever SimpleSMS processes Customer Personal Data. Capitalized terms not defined here have the meaning in the Terms or in Data Protection Laws.

1. Definitions

  • Data Protection Laws: all privacy and data protection laws that apply to the processing, including the GDPR, UK GDPR, Swiss FADP, the CCPA as amended by the CPRA, and other US state privacy laws.
  • Customer Personal Data: personal data within Customer Content, including recipient phone numbers, message content and metadata, contact records, and consent records, that SimpleSMS processes on the Customer's behalf.
  • Account Data: information about the Customer's account, users, and billing, which SimpleSMS processes as an independent controller under its Privacy Policy and which this DPA does not cover.

2. Roles and Instructions

The Customer is the controller (or business) and SimpleSMS is the processor (or service provider) of Customer Personal Data. SimpleSMS processes it only on the Customer's documented instructions, which are the Terms, this DPA, and the Customer's use and configuration of the Service, unless the law requires otherwise (in which case SimpleSMS will tell the Customer first, unless the law forbids it). SimpleSMS will tell the Customer if it believes an instruction violates Data Protection Laws. The Customer is responsible for the lawfulness of the data it provides and for having the consent or other legal basis needed to message each recipient.

3. Permitted Purposes

SimpleSMS processes Customer Personal Data only to provide, secure, and support the Service; to detect and prevent fraud, spam, and abuse and to enforce the Messaging Policy; to honor opt-outs; and to comply with law. SimpleSMS may create aggregated or de-identified data that cannot reasonably identify any person, and will not attempt to re-identify it.

4. US State Law (CCPA) Terms

As a service provider, SimpleSMS will not sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than the business purposes in Section 3, or outside the direct business relationship with the Customer; or combine it with personal data from other sources except as Data Protection Laws permit. SimpleSMS will provide the same level of protection the law requires of the Customer, will notify the Customer if it can no longer meet these obligations, and allows the Customer to take reasonable steps to stop and remediate unauthorized use. SimpleSMS certifies that it understands these restrictions.

5. Confidentiality and Personnel

SimpleSMS ensures that everyone authorized to process Customer Personal Data is bound by confidentiality obligations and has access only as needed.

6. Security

SimpleSMS maintains the technical and organizational measures in Annex 2 and may update them, provided the overall level of protection does not decrease.

7. Subprocessors

The Customer authorizes SimpleSMS to use the subprocessors described on the Subprocessors page. SimpleSMS will give the Customer the named list on request to legal@deliveredsms.com; it is confidential information. SimpleSMS imposes data protection terms on each subprocessor that protect Customer Personal Data at least as well as this DPA, and is liable for its subprocessors' performance.

SimpleSMS will give at least 10 days' notice before a new subprocessor processes Customer Personal Data, to Customers who have asked for notices at legal@deliveredsms.com. The Customer may object on reasonable data protection grounds within that period; the parties will then work in good faith toward a solution, and if none is found the Customer may terminate the affected Service and receive a refund of prepaid fees for it. Where a change is needed urgently to keep the Service running or secure, SimpleSMS may make it first and notify promptly afterward.

8. Assistance

Taking into account the nature of the processing, SimpleSMS will assist the Customer with requests from individuals exercising their rights, with data protection impact assessments and prior consultations, and with security obligations. SimpleSMS will promptly forward requests it receives directly from an individual about Customer Personal Data and will not answer them itself except to confirm the request was forwarded or as the law requires. Recipients' STOP replies are honored automatically, as the Customer instructs by using the Service.

9. Personal Data Breaches

SimpleSMS will notify the Customer without undue delay, and in any case within 72 hours, after confirming a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. The notice will describe the breach, the data and individuals affected as far as known, its likely consequences, and the measures taken, and SimpleSMS will update it as it learns more. Notifying the Customer is not an admission of fault.

10. Deletion and Return

During the subscription the Customer can export its data through the API. Within 90 days after the subscription ends, SimpleSMS will delete Customer Personal Data, except for copies the law requires it to keep, opt-out and consent records kept to enforce suppression and defend claims, and data in backups, which are deleted on their normal cycle. Retained data remains protected by this DPA.

11. Audits

SimpleSMS will make available the information reasonably necessary to demonstrate compliance with this DPA, including by answering security questionnaires. If that is not sufficient, or a regulator requires it, the Customer may audit SimpleSMS's compliance once per year, at its own cost, with 30 days' notice, during business hours, under confidentiality, and in a way that does not compromise other customers' data.

12. International Transfers

SimpleSMS processes Customer Personal Data in the United States. For transfers from the EEA, the EU Standard Contractual Clauses (Commission Decision 2021/914) are incorporated by reference: Module 2 where the Customer is a controller, Module 3 where it is a processor, with clause 7 (docking) included, option 2 (general authorization) in clause 9 with the notice period in Section 7, the optional language in clause 11 omitted, Irish law and courts in clauses 17 and 18, and Annexes I and II completed by Annexes 1 and 2 of this DPA. For transfers from the UK, the UK International Data Transfer Addendum is incorporated, with the Clauses above as the approved EU SCCs. For transfers from Switzerland, the same Clauses apply with the Swiss FADP in place of the GDPR and the FDPIC as the competent authority.

13. General

Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Laws do not allow it. If this DPA conflicts with the Terms, this DPA governs as to Customer Personal Data; if it conflicts with the Standard Contractual Clauses, the Clauses govern. This DPA lasts as long as SimpleSMS processes Customer Personal Data.

Annex 1: Description of Processing

  • Data subjects: the Customer's message recipients and contacts, and people who message the Customer's numbers.
  • Categories of data: phone numbers; message content and media; message metadata (timestamps, IDs, delivery status, carrier and routing information) and delivery statistics derived from it; contact attributes the Customer stores (names, email addresses, company, state or province, tags, custom fields, notes, source, and the import a contact came from), the segments and subscription topics the Customer defines, and which broadcasts a number was included in; opt-in, opt-out, and consent records, including who changed them, opt-in evidence the Customer records (source, time, page, disclosure wording, IP address, user agent), and each number's subscription preference per topic; verification outcomes; lookup results; records the Customer keeps about its own customers in the customers API (names, identifiers, metadata) and per-customer usage counts; events the Customer sends about its users for automations (event names, the Customer's user identifiers, phone numbers, and event properties) and the record of each automation run; and any personal data the Customer includes in the example messages it writes for a registration, and in the filed copies of them (examples should use made-up names and values).
  • Sensitive data: none intended. The Customer must not send special category data, payment card data, government ID numbers, or protected health information (Terms §6.5).
  • Frequency: continuous, for the duration of the subscription.
  • Nature and purpose: transmitting and receiving messages, verifying numbers, provisioning numbers, storing message history for the Customer, screening for fraud and abuse, enforcing opt-outs, and support.
  • Retention: as set out in Data Retention and Section 10.
  • Subprocessors: as set out on the Subprocessors page, for the same nature and purpose.
  • Exporter: the Customer. Importer: Truelabel Inc, 5830 E 2nd St, Ste 7000, PMB 35111, Casper, WY 82609, USA, legal@deliveredsms.com.

Annex 2: Security Measures

  • Encryption of data in transit (TLS) and at rest.
  • API keys and verification codes stored only as salted hashes; keys shown once, rotatable at any time, and restrictable to scopes.
  • Customer-side access control: admin, member, and read-only viewer roles, and an audit log of account changes (keys, team, webhooks, spend limits, numbers, consent overrides, settings) recording the actor, time, and IP address, available to the Customer's admins.
  • Access to production systems limited to personnel who need it, with strong authentication, and logged.
  • Separate test and live environments; test keys cannot send carrier traffic.
  • Signed webhooks so customers can verify that events come from SimpleSMS.
  • Automated fraud and abuse monitoring, rate limits, and content screening.
  • Logs designed to exclude message content and verification codes where they are not needed.
  • Subprocessors selected for their security practices and bound by data protection terms.
  • An incident response process with customer notification as in Section 9.

Contact

Truelabel Inc (d/b/a SimpleSMS) 5830 E 2nd St, Ste 7000, PMB 35111, Casper, WY 82609, USA legal@deliveredsms.com