Loading
Loading
This DPA forms part of the Easria Terms of Service and applies to all customers processing personal data through the platform. Last updated: July 2, 2026.
Easria acts as a Data Processor on behalf of the Customer (Data Controller). Easria processes personal data solely on documented instructions from the Customer, including regarding transfers of personal data to a third country, unless required to do so by applicable law. Easria immediately informs the Customer if, in its opinion, an instruction infringes applicable data protection law.
The personal data processed includes: contact information (name, email, phone), business identifiers (company name, address), communication records (calls, SMS, emails, chat), billing data (payment tokens, transaction history), and usage data (IP addresses, device information, session logs). The Customer determines the purposes and means of processing.
Easria assists the Customer in responding to data subject requests including: access, rectification, erasure (right to be forgotten), restriction of processing, data portability, and objection. Easria implements technical and organizational measures to fulfill these requests within 30 days of notification.
Easria maintains: AES-256 encryption at rest and in transit, TLS 1.3 for all connections, role-based access control with least-privilege principle, multi-factor authentication, automated security patching, network segmentation, regular penetration testing, and 24/7 intrusion detection. Data is processed in facilities operating under ISO 27001-aligned security controls, with formal certification in progress (see Section 09).
Easria engages the following categories of sub-processors: cloud infrastructure (AWS), payment processing (Stripe), email delivery (Resend), telecommunications (Twilio), and analytics (PostHog). The list above is the complete current register; customers are notified 30 days in advance of any new sub-processor. Easria is liable for the performance of all sub-processors.
For transfers outside the EU/EEA, Easria relies on Standard Contractual Clauses (SCCs) as approved by the European Commission. Transfers to the United States are made under the EU-US Data Privacy Framework. Easria does not transfer personal data to countries not providing adequate protection without appropriate safeguards.
In the event of a personal data breach, Easria notifies the Customer without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification includes: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach and mitigate adverse effects.
Upon termination of services, Easria returns all personal data to the Customer and deletes existing copies, unless retention is required by applicable law. Data deletion is verified through cryptographic certificates of destruction. Backups are overwritten within 30 days of the retention period.
The Customer has the right to audit Easria's compliance with this DPA, subject to 30 days written notice and confidentiality obligations. Easria is working toward SOC 2 Type II and ISO 27001 certification; current security documentation (controls, architecture, and pen-test summaries) is available to the Customer under NDA upon request, and formal audit reports will be provided once certifications are achieved.
For DPA-related inquiries, breach notifications, or audit requests, contact our Data Protection Officer at privacy@easria.com. Our EU representative is available at eu.rep@easria.com for customers in the European Union.