Data Processing Addendum
Last updated: June 22, 2026
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the agreement between you (“Customer”) and WickScout Finance LLC (“Reply Desk,” “we,” “us,” or “our”) governing your use of the Reply Desk service at desk.replyline.io (the “Service”), comprising our Terms of Service and any applicable order (together, the “Agreement”). This DPA applies whenever, and to the extent that, Reply Desk processes Customer Personal Data (as defined below) on the Customer's behalf in the course of providing the Service. By accepting the Agreement, or by using the Service, the Customer accepts this DPA.
Reply Desk is a business-to-business platform that turns service requests into tickets; schedules and dispatches technicians; documents jobs (photos, signatures, checklists); supports optional invoicing and payments through Stripe Connect; offers a self-service intake portal, email-to-ticket, and SMS/email notifications; and provides single sign-on (Google Workspace / SAML) and reporting. In delivering these features, Reply Desk acts as a service provider that processes data the Customer chooses to put into the Service.
1. Definitions
Capitalized terms used but not defined in this DPA have the meaning given in the Agreement. For this DPA:
- Applicable Data Protection Law means all privacy and data-protection laws that apply to the processing of Customer Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 (“UK GDPR”), and U.S. state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
- Controller means the entity that determines the purposes and means of the processing of Personal Data. Under the CCPA, “Controller” corresponds to “Business.”
- Processor means the entity that processes Personal Data on behalf of the Controller. Under the CCPA, “Processor” corresponds to “Service Provider.”
- Customer Personal Data means Personal Data that Reply Desk processes on the Customer's behalf in the course of providing the Service, as described in Annex A.
- Personal Data means any information relating to an identified or identifiable natural person (“Data Subject”), and includes “personal information” as defined under the CCPA.
- Processing (and “process”) means any operation performed on Personal Data, whether or not by automated means, such as collection, recording, storage, use, disclosure, or erasure.
- Data Subject means the identified or identifiable natural person to whom Personal Data relates.
- Sub-processor means any third party engaged by Reply Desk to process Customer Personal Data in connection with the Service.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Standard Contractual Clauses or SCCs means (a) for transfers subject to the GDPR, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914; and (b) for transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner.
2. Roles of the Parties
The parties acknowledge and agree that, with respect to the processing of Customer Personal Data:
- the Customer is the Controller (or, where the Customer is itself a processor acting on behalf of a third-party controller, a processor) and the Business under the CCPA; and
- Reply Desk is the Processor and the Service Provider under the CCPA, acting on the Customer's behalf.
The Customer decides what Personal Data to enter into the Service and why. The Customer is responsible for the lawfulness of the Customer Personal Data and of the Customer's collecting, instructing on, and otherwise processing of it, including providing all required notices to and obtaining all required consents from Data Subjects. Reply Desk processes Customer Personal Data only as a Processor and does not determine the purposes or means of processing it.
3. Subject Matter, Nature, Purpose, and Duration
The subject matter, nature, and purpose of the processing, the duration, the types of Customer Personal Data, and the categories of Data Subjects are set out in Annex A to this DPA. In summary, Reply Desk processes Customer Personal Data to provide, maintain, secure, and support the Service for the Customer, for the duration of the Agreement and the limited post-termination period described in Section 12.
4. Processing Only on Documented Instructions
Reply Desk will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Reply Desk will, where that law permits, inform the Customer of the legal requirement before processing). The Customer's instructions are set out in this DPA and the Agreement, and are given through the Customer's configuration and use of the Service. Reply Desk will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. The Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law.
5. Confidentiality of Personnel
Reply Desk ensures that persons authorized to process Customer Personal Data are subject to an appropriate duty of confidentiality (whether contractual or statutory), are made aware of the confidential nature of the Customer Personal Data, and access it only on a need-to-know basis to perform their duties in connection with the Service.
6. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects, Reply Desk implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, consistent with Article 32 of the GDPR. These measures include, as appropriate:
- Encryption of Customer Personal Data in transit over public networks (TLS) and at rest;
- Access control based on least-privilege and role-based permissions, with authentication managed through our identity provider, and support for customer-configured single sign-on (Google Workspace / SAML);
- measures to ensure the ongoing confidentiality, integrity, availability, and resilience of the systems and services that process Customer Personal Data;
- the ability to restore the availability of and access to Customer Personal Data in a timely manner in the event of a physical or technical incident, including regular backups; and
- a process for regularly testing, assessing, and evaluating the effectiveness of these measures, including logging and monitoring.
Reply Desk never stores full payment card numbers; payment card data is handled by Stripe as described in Section 14.
7. Sub-processing
The Customer provides general authorization for Reply Desk to engage Sub-processors to process Customer Personal Data in connection with the Service. The Customer specifically authorizes the Sub-processors listed in Annex B. Reply Desk:
- imposes on each Sub-processor, by written contract, data-protection obligations that are substantially equivalent to those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures;
- remains responsible to the Customer for the performance of each Sub-processor's obligations; and
- will give the Customer prior notice of any intended addition or replacement of a Sub-processor (for example, by updating Annex B or by email or in-product notice), giving the Customer a reasonable opportunity to object on reasonable, data-protection-related grounds. If the Customer reasonably objects and the parties cannot resolve the objection, the Customer may terminate the affected portion of the Service as its exclusive remedy.
8. Assistance with Data-Subject Requests
Taking into account the nature of the processing, Reply Desk assists the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights (such as access, rectification, erasure, restriction, portability, and objection) under Applicable Data Protection Law. The Service provides functionality allowing the Customer to access, correct, export, and delete Customer Personal Data. If Reply Desk receives a request directly from a Data Subject relating to Customer Personal Data, it will, unless legally prohibited, promptly inform the Customer and direct the Data Subject to the Customer.
9. Assistance with Security, Breach Notice, and DPIAs
Taking into account the nature of the processing and the information available to it, Reply Desk assists the Customer in ensuring compliance with the Customer's obligations regarding security of processing, notification of Personal Data Breaches, communication of breaches to Data Subjects, data protection impact assessments (DPIAs), and prior consultation with supervisory authorities.
10. Personal Data Breach Notification
Reply Desk will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent the relevant information is available, the notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects. Reply Desk will cooperate reasonably with the Customer and take reasonable steps to mitigate the breach. Reply Desk's notification is not an acknowledgment of fault or liability.
11. Audits and Information
Reply Desk makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. To the extent permitted, the Customer's audit rights are satisfied by Reply Desk providing relevant documentation, security summaries, and responses to reasonable security questionnaires. Any on-site audit must be requested on reasonable prior written notice (and no more than once per year, except where required by a supervisory authority or following a Personal Data Breach), conducted during business hours, without unreasonably disrupting the Service, subject to confidentiality obligations, and at the Customer's expense.
12. Return or Deletion on Termination
Upon termination or expiry of the Agreement, Reply Desk will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage of the Customer Personal Data. For a limited period after termination, the Customer may export Customer Personal Data through the Service. After that period, Reply Desk will delete Customer Personal Data in the ordinary course, subject to retention required by law and to backups that are deleted on their ordinary cycle.
13. International Transfers
Reply Desk and its Sub-processors are located primarily in the United States, and Customer Personal Data may be transferred to and processed in the United States and other countries. Where Reply Desk processes Customer Personal Data that is subject to the GDPR or UK GDPR and transfers it to a country that has not been recognized as providing an adequate level of protection, the parties agree that the Standard Contractual Clauses are incorporated into and form part of this DPA by reference and apply to such transfers. For these purposes, the Customer is the data exporter and Reply Desk is the data importer; the module governing controller-to-processor transfers applies; and the annexes to the SCCs are populated by Annex A (subject matter and details), Annex B (Sub-processors), and Section 6 (security measures) of this DPA. If there is a conflict between the SCCs and this DPA, the SCCs prevail with respect to the in-scope transfers.
14. Payments (Stripe Connect)
Where the Customer uses the optional invoicing and payments features, payments are processed by Stripe through Stripe Connect. The Customer is the merchant of record, and Stripe's Connected Account Agreement governs the Customer's relationship with Stripe. Reply Desk is not a party to the payment transaction, is not a money transmitter, and does not store full payment card numbers. With respect to payment-card and transaction data handled by Stripe, Stripe acts as an independent controller (or processor) under its own terms, and that processing is not governed by this DPA except to the extent Stripe is listed as a Sub-processor for related ticket and account data.
15. Notifications (TCPA / CAN-SPAM)
The Service can send SMS and email notifications (such as status updates, “on my way” messages, and appointment reminders) to the Customer's end-customers and contacts. These messages are sent on the Customer's behalf and at the Customer's direction. The Customer is the sender for purposes of applicable communications laws and is solely responsible for obtaining and maintaining all consents and providing all disclosures and opt-out mechanisms required by law (including the Telephone Consumer Protection Act (TCPA) and the CAN-SPAM Act) from the recipients of those messages.
16. CCPA Service-Provider Terms
To the extent the CCPA applies, the parties agree that the Customer is a Business and Reply Desk is a Service Provider, and that Customer Personal Data is disclosed to Reply Desk solely for the limited and specified purpose of performing the Service (the “Business Purpose”). Reply Desk:
- will not sell or share Customer Personal Data (as those terms are defined under the CCPA);
- will not retain, use, or disclose Customer Personal Data for any purpose other than the Business Purpose specified in the Agreement, or as otherwise permitted by the CCPA, including outside the direct business relationship between the parties;
- will not combine Customer Personal Data with personal information it receives from, or on behalf of, other parties, or collects from its own interaction with the Data Subject, except as permitted by the CCPA; and
- certifies that it understands and will comply with these restrictions.
The Customer may take reasonable and appropriate steps to help ensure that Reply Desk uses Customer Personal Data consistent with the Customer's CCPA obligations, and to stop and remediate unauthorized use.
17. FERPA (Education Customers)
For Customers that are educational institutions subject to the Family Educational Rights and Privacy Act (FERPA), to the extent Customer Personal Data includes education records, Reply Desk acts as a “school official” with a legitimate educational interest in such records, performing an institutional service or function for which the institution would otherwise use its own employees. Reply Desk uses education records solely to provide the Service to the institution, is under the institution's direct control with respect to the use and maintenance of those records, and does not re-disclose education records or use them for any other purpose, except as permitted by FERPA and directed by the institution.
18. Order of Precedence
This DPA is incorporated into the Agreement. In the event of a conflict between this DPA and the remainder of the Agreement regarding the processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail with respect to the transfers they govern. Except as expressly modified by this DPA, the Agreement remains in full force and effect.
19. Governing Law
This DPA is governed by the laws of the Commonwealth of Pennsylvania, United States, and the dispute- resolution and venue provisions of the Agreement apply, except that the Standard Contractual Clauses are governed by the law specified within them where Applicable Data Protection Law so requires.
20. Annex A - Details of Processing
Subject matter and nature of processing
The provision of the Service to the Customer, including creating and managing tickets; scheduling and dispatching technicians; documenting jobs (photos, signatures, checklists); operating the self-service intake portal and email-to-ticket; sending SMS and email notifications on the Customer's behalf; supporting optional invoicing and payments; providing single sign-on and reporting; and hosting, securing, supporting, and backing up the foregoing.
Purpose
To provide, maintain, secure, troubleshoot, and improve the Service for the Customer in accordance with the Agreement and the Customer's instructions.
Duration
For the term of the Agreement, plus the limited post-termination period described in Section 12.
Types of Customer Personal Data
- Contact information - such as names, email addresses, phone numbers, and service or billing addresses;
- Service and ticket details - such as request descriptions, scheduling and dispatch information, job notes, photos, signatures, checklist responses, and communications;
- Invoicing metadata - such as line items and amounts associated with a ticket (full payment card numbers are handled by Stripe, not Reply Desk); and
- any other Personal Data the Customer chooses to include in the Service.
Categories of Data Subjects
- the Customer's end-customers, clients, students, or other requesters and recipients of service;
- the Customer's staff, technicians, agents, and authorized users; and
- other individuals whose Personal Data the Customer includes in the Service.
Special categories of data
The Service is not intended for the processing of special categories of Personal Data. The Customer is responsible for any such data it chooses to include.
21. Annex B - Authorized Sub-processors
The Customer authorizes Reply Desk to engage the following Sub-processors to process Customer Personal Data in connection with the Service:
| Sub-processor | Purpose / Processing activity |
|---|---|
| Railway | Application hosting and database (storage of Customer Personal Data) |
| Clerk | User authentication and identity management (including SSO) |
| Stripe | Payment processing via Stripe Connect (invoicing and payments) |
| Twilio | Sending SMS notifications on the Customer's behalf |
| Resend | Sending outbound email notifications on the Customer's behalf |
| Postmark | Inbound email processing (the email-to-ticket feature) |
| Google / Microsoft | Calendar synchronization, when the Customer connects a Google or Microsoft account |
Reply Desk will keep this list current and provide notice of changes as described in Section 7. Questions about this DPA may be directed to wickscoutio@gmail.com.