# Data Processing Addendum

Source: https://joinsimplesms.com/dpa
Index: https://joinsimplesms.com/llms.txt

**Last updated: October 5, 2026**

> **The short version**
>
> - When you send us your recipients' data, we process it only to run
>   SimpleSMS for you.
> - We tell you before adding a new subprocessor, and you can object.
> - We report a breach to you within 72 hours of confirming it.
> - We delete your data within 90 days after you leave.
> - It applies automatically: no signature needed. A countersigned copy is
>   available from support@joinsimplesms.com.

This Data Processing Addendum ("DPA") is part of the [Terms of
Service](/terms) between Truelabel Inc d/b/a SimpleSMS
("SimpleSMS") and the Customer, and applies whenever SimpleSMS processes
Customer Personal Data. Capitalized terms not defined here have the meaning
in the Terms or in Data Protection Laws.

## 1. Definitions

- **Data Protection Laws:** all privacy and data protection laws that apply
  to the processing, including the GDPR, UK GDPR, Swiss FADP, the CCPA as
  amended by the CPRA, and other US state privacy laws.
- **Customer Personal Data:** personal data within Customer Content,
  including recipient phone numbers, message content and metadata, contact
  records, and consent records, that SimpleSMS processes on the Customer's
  behalf.
- **Account Data:** information about the Customer's account, users, and
  billing, which SimpleSMS processes as an independent controller under its
  [Privacy Policy](/privacy) and which this DPA does not cover.

## 2. Roles and Instructions

The Customer is the controller (or business) and SimpleSMS is the processor
(or service provider) of Customer Personal Data. SimpleSMS processes it only
on the Customer's documented instructions, which are the Terms, this DPA,
and the Customer's use and configuration of the Service, unless the law
requires otherwise (in which case SimpleSMS will tell the Customer first,
unless the law forbids it). SimpleSMS will tell the Customer if it believes
an instruction violates Data Protection Laws. The Customer is responsible
for the lawfulness of the data it provides and for having the consent or
other legal basis needed to message each recipient.

## 3. Permitted Purposes

SimpleSMS processes Customer Personal Data only to provide, secure, and
support the Service; to detect and prevent fraud, spam, and abuse and to
enforce the Messaging Policy; to honor opt-outs; and to comply with law.
SimpleSMS may create aggregated or de-identified data that cannot reasonably
identify any person, and will not attempt to re-identify it.

## 4. US State Law (CCPA) Terms

As a service provider, SimpleSMS will not sell or share Customer Personal
Data; retain, use, or disclose it for any purpose other than the business
purposes in Section 3, or outside the direct business relationship with the
Customer; or combine it with personal data from other sources except as Data
Protection Laws permit. SimpleSMS will provide the same level of protection
the law requires of the Customer, will notify the Customer if it can no
longer meet these obligations, and allows the Customer to take reasonable
steps to stop and remediate unauthorized use. SimpleSMS certifies that it
understands these restrictions.

## 5. Confidentiality and Personnel

SimpleSMS ensures that everyone authorized to process Customer Personal Data
is bound by confidentiality obligations and has access only as needed.

## 6. Security

SimpleSMS maintains the technical and organizational measures in Annex 2 and
may update them, provided the overall level of protection does not decrease.

## 7. Subprocessors

The Customer authorizes SimpleSMS to use the subprocessors described on the
[Subprocessors](/subprocessors) page. SimpleSMS will give the Customer the
named list on request to support@joinsimplesms.com; it is confidential information.
SimpleSMS imposes data protection terms on each subprocessor that protect
Customer Personal Data at least as well as this DPA, and is liable for its
subprocessors' performance.

SimpleSMS will give at least 10 days' notice before a new subprocessor
processes Customer Personal Data, to Customers who have asked for notices at
support@joinsimplesms.com. The Customer may object on reasonable data protection
grounds within that period; the parties will then work in good faith toward
a solution, and if none is found the Customer may terminate the affected
Service and receive a refund of prepaid fees for it. Where a change is
needed urgently to keep the Service running or secure, SimpleSMS may make it
first and notify promptly afterward.

## 8. Assistance

Taking into account the nature of the processing, SimpleSMS will assist the
Customer with requests from individuals exercising their rights, with data
protection impact assessments and prior consultations, and with security
obligations. SimpleSMS will promptly forward requests it receives directly
from an individual about Customer Personal Data and will not answer them
itself except to confirm the request was forwarded or as the law requires.
Recipients' STOP replies are honored automatically, as the Customer
instructs by using the Service.

## 9. Personal Data Breaches

SimpleSMS will notify the Customer without undue delay, and in any case
within 72 hours, after confirming a breach of security leading to the
accidental or unlawful destruction, loss, alteration, unauthorized disclosure
of, or access to Customer Personal Data. The notice will describe the
breach, the data and individuals affected as far as known, its likely
consequences, and the measures taken, and SimpleSMS will update it as it
learns more. Notifying the Customer is not an admission of fault.

## 10. Deletion and Return

During the subscription the Customer can export its data through the API.
Within 90 days after the subscription ends, SimpleSMS will delete Customer
Personal Data, except for copies the law requires it to keep, opt-out and
consent records kept to enforce suppression and defend claims, and data in
backups, which are deleted on their normal cycle. Retained data remains
protected by this DPA.

## 11. Audits

SimpleSMS will make available the information reasonably necessary to
demonstrate compliance with this DPA, including by answering security
questionnaires. If that is not sufficient, or a regulator requires it, the
Customer may audit SimpleSMS's compliance once per year, at its own cost,
with 30 days' notice, during business hours, under confidentiality, and in a
way that does not compromise other customers' data.

## 12. International Transfers

SimpleSMS processes Customer Personal Data in the United States. For
transfers from the EEA, the EU Standard Contractual Clauses (Commission
Decision 2021/914) are incorporated by reference: Module 2 where the
Customer is a controller, Module 3 where it is a processor, with clause 7
(docking) included, option 2 (general authorization) in clause 9 with the
notice period in Section 7, the optional language in clause 11 omitted, Irish
law and courts in clauses 17 and 18, and Annexes I and II completed by
Annexes 1 and 2 of this DPA. For transfers from the UK, the UK International
Data Transfer Addendum is incorporated, with the Clauses above as the
approved EU SCCs. For transfers from Switzerland, the same Clauses apply with
the Swiss FADP in place of the GDPR and the FDPIC as the competent authority.

## 13. General

Each party's liability under this DPA is subject to the limits in the Terms,
except where Data Protection Laws do not allow it. If this DPA conflicts with
the Terms, this DPA governs as to Customer Personal Data; if it conflicts
with the Standard Contractual Clauses, the Clauses govern. This DPA lasts as
long as SimpleSMS processes Customer Personal Data.

## Annex 1: Description of Processing

- **Data subjects:** the Customer's message recipients and contacts, and
  people who message the Customer's numbers.
- **Categories of data:** phone numbers; message content and media;
  message metadata (timestamps, IDs, delivery status, carrier and routing
  information) and delivery statistics derived from it; contact attributes
  the Customer stores (names, email addresses, company, state or province,
  tags, custom fields, notes, source, and the import a contact came from),
  the segments and subscription topics the Customer defines, and which
  broadcasts a number was included in; opt-in, opt-out, and consent records,
  including who changed them, opt-in evidence the Customer records (source,
  time, page, disclosure wording, IP address, user agent), and each number's
  subscription preference per topic; verification outcomes; lookup
  results; records the Customer keeps about its own customers in the
  customers API (names, identifiers, metadata) and per-customer usage counts;
  events the Customer sends about its users for automations (event names,
  the Customer's user identifiers, phone numbers, and event properties) and
  the record of each automation run; and any personal data the Customer
  includes in the example messages it writes for a registration, and in the
  filed copies of them (examples should use made-up names and values).
- **Sensitive data:** none intended. The Customer must not send special
  category data, payment card data, government ID numbers, or protected
  health information (Terms §6.5).
- **Frequency:** continuous, for the duration of the subscription.
- **Nature and purpose:** transmitting and receiving messages, verifying
  numbers, provisioning numbers, storing message history for the Customer,
  screening for fraud and abuse, enforcing opt-outs, and support.
- **Retention:** as set out in [Data Retention](/data-retention) and
  Section 10.
- **Subprocessors:** as set out on the [Subprocessors](/subprocessors) page,
  for the same nature and purpose.
- **Exporter:** the Customer. **Importer:** Truelabel Inc,
  5830 E 2nd St, Ste 7000, PMB 35111, Casper, WY 82609, USA, support@joinsimplesms.com.

## Annex 2: Security Measures

- Encryption of data in transit (TLS) and at rest.
- API keys and verification codes stored only as salted hashes; keys shown
  once, rotatable at any time, and restrictable to scopes.
- Customer-side access control: admin, member, and read-only viewer roles,
  and an audit log of account changes (keys, team, webhooks, spend limits,
  numbers, consent overrides, settings) recording the actor, time, and IP
  address, available to the Customer's admins.
- Access to production systems limited to personnel who need it, with
  strong authentication, and logged.
- Separate test and live environments; test keys cannot send carrier
  traffic.
- Signed webhooks so customers can verify that events come from SimpleSMS.
- Automated fraud and abuse monitoring, rate limits, and content screening.
- Logs designed to exclude message content and verification codes where
  they are not needed.
- Subprocessors selected for their security practices and bound by data
  protection terms.
- An incident response process with customer notification as in Section 9.

## Contact

Truelabel Inc (d/b/a SimpleSMS)
5830 E 2nd St, Ste 7000, PMB 35111, Casper, WY 82609, USA
support@joinsimplesms.com
