Recepsi Data Processing Addendum (DPA)
Version 0.11 · Last updated 11 October 2026
Part of the Recepsi Terms of Service. If this DPA conflicts with the Terms on personal data, this DPA wins.
Parties: the Customer (the business using Recepsi) and Xevix Pte. Ltd., UEN 202425094Z, a company registered in Singapore ("Recepsi").
1. Roles
| Data | Customer is | Recepsi is |
|---|---|---|
| End-Customer Data — chat messages and replies, transcripts, contact details, booking requests, anonymous widget session IDs, and any personal data inside knowledge sources the Customer uploads | Controller (GDPR/UK GDPR) / organisation (SG PDPA) / data controller (MY PDPA, as amended 2024) / business (CCPA) | Processor / data intermediary (SG PDPA s4(2)) / data processor (MY PDPA) / service provider (CCPA) |
| Customer's account, billing and usage data | — | Controller, under the Privacy Policy — not covered by this DPA |
| Messages on Telegram's platform | Controller of its own use | Not responsible for Telegram's own processing: Telegram Messenger Inc. is an independent controller (no DPA available). |
| WhatsApp messages (later phase) | Controller | Processor; Meta Platforms Ireland Limited acts as a processor (sub-processor in the chain) under the Meta Global Processor Terms — not a separate controller |
2. Details of processing
- Purpose: providing the Recepsi Super Intelligent receptionist — answering enquiries, qualifying leads, taking booking requests, sending hand-over alerts to the owner, showing transcripts in the dashboard, sending the owner a digest of questions the receptionist couldn't answer so the Customer can improve its answers — plus security, support and fixing errors.
- Data subjects: the Customer's end-customers and prospects (who may include minors, e.g. tuition-centre students), and any individuals named in knowledge sources.
- Categories of data: names, phone numbers, emails, Telegram usernames/IDs, anonymous widget session IDs, message content, booking details (date, time, service, note), contact-form leads submitted when the receptionist is busy (contact details and the customer's question; on the web widget, the first message, up to 500 characters, is included only when the form is submitted; phone numbers, emails and NRIC numbers in the name or question fields are masked; same retention as contacts), and unanswered questions (the question as typed, with the conversation ID, business ID and time, and no contact fields; same retention as chat transcripts; deleted with the conversation or the Customer's account, or on an erasure request). Sensitive data is not intended (AUP §5); the widget warns customers not to share NRIC, card or health details.
- Duration: for the term of the Terms plus the deletion periods in section 9.
- Retention: transcripts, contacts and bookings are kept for the period the Customer selects — 30, 90, 180 or 365 days (default 12 months) — and then deleted by a nightly job; technical logs are short-lived and contain no message bodies; all End-Customer Data is purged within 30 days of account deletion; Recepsi is setting up nightly backups, encrypted with Recepsi's own key before leaving the database, stored in Cloudflare R2 and kept for 8 days; until they're live, Recepsi keeps no backup copies, so deleted data is gone once it's deleted from the database.
3. Customer's responsibilities
The Customer:
- is responsible for having a lawful basis / consent for End-Customer Data (including parental consent where needed for minors) and for giving end-customers a privacy notice that mentions use of an automated assistant and of service providers like Recepsi;
- accepts that the automated-assistant disclosure is mandatory and cannot be removed;
- obtains WhatsApp opt-ins (later phase) and complies with DNC and anti-spam rules;
- gives only lawful instructions and doesn't upload or solicit sensitive data contrary to the AUP;
- handles end-customer requests (access, correction, deletion, withdrawal of consent) using the dashboard tools (section 8), with our help.
4. Recepsi's obligations
Recepsi will:
- process End-Customer Data only on the Customer's documented instructions (the Terms, this DPA and the Customer's configuration), unless the law requires otherwise (we'll tell the Customer first where lawful), and tell the Customer if we think an instruction breaks data-protection law;
- not sell or share End-Customer Data, not use it for our own purposes, and not use it to train or fine-tune language models, and require our language-model providers not to do so; we record usage metrics with no content (chat/message counts, token and spend totals, response times, error/status codes) against the Customer's business ID, keep usage counters for 24 months, and on account deletion reduce them to anonymous totals that can't be linked to the Customer;
- ensure anyone authorised to access the data is bound by confidentiality; there is no routine human access by Recepsi personnel to transcripts;
- meet the SG PDPA obligations that apply directly to data intermediaries (protection, retention limitation, and notifying the Customer of breaches) and, under the Malaysian PDPA as amended in 2024, the security principle that now applies directly to processors;
- help the Customer with security, breach notification, data-protection impact assessments and regulator consultations, as reasonably needed.
5. Sub-processors
The Customer gives general authorisation for Recepsi to use sub-processors. Current list (contracting entities taken from each provider's published terms, checked 10 Oct 2026):
| Sub-processor (contracting entity) | Service | End-Customer Data involved | Location | Source |
|---|---|---|---|---|
| Cloudflare, Inc. | Application hosting (Workers, global edge) and spam protection (Turnstile); once live, nightly backup job (scheduled Worker) and backup storage (R2) | All traffic; once live, full database backups, encrypted with Recepsi's own key before leaving Supabase | Global edge, so processing may happen outside Singapore. Workers Logs are kept for at most 7 days, with no message bodies. R2 backups (once live) will use the APAC location hint, which Cloudflare applies on a best-effort basis, so they may be stored outside Singapore | cloudflare.com/terms; Cloudflare Customer DPA v6.4 (eff. 3 Apr 2026); developers.cloudflare.com/r2/reference/data-location; developers.cloudflare.com/workers/observability/logs/workers-logs |
| Supabase Pte. Ltd. (Singapore) | Database, authentication, storage, vector search | All stored data | Singapore (ap-southeast-1). Free plan: no provider backups; Recepsi's own encrypted backups are being set up (none until live) | supabase.com/terms (definition of "Supabase"); supabase.com/docs/guides/platform/backups |
| OpenAI OpCo, LLC (USA) — main language-model provider | Chat replies and embeddings | Message, recent history, relevant knowledge snippets | US/global. No training on API data; abuse-monitoring logs up to 30 days (longer only if required by law or to prevent harm). Singapore endpoint offers storage only, not processing, and needs approval | openai.com/policies/services-agreement (§4.2, §17 "OpenAI Contracting Party"); developers.openai.com/api/docs/guides/your-data |
| Plus Five Five, Inc. (USA), trading as Resend | Transactional email from @recepsi.com to owners only: alerts, hand-over summaries, sign-in links. Never emails end-customers | Hand-over summaries may include a chat snippet and the end-customer's contact details | United States (Resend's own hosting/sending sub-processor: Amazon Web Services, Inc., USA) | resend.com/legal/terms-of-service (§1: agreement with Plus Five Five, Inc.; California law); resend.com/legal/dpa (last updated 31 Dec 2025: breach notice "without undue delay" §8.6; 14 days' notice of new sub-processors §4.2; EU SCCs Module Two §6.2.2); resend.com/legal/subprocessors (updated 27 Aug 2026) |
| Meta Platforms Ireland Limited — later phase (WhatsApp) only | WhatsApp Cloud API messaging | WhatsApp messages and phone numbers | Meta data centres internationally; Singapore local storage will be turned on where available (message content at rest in SG after up to 60 min of processing) | whatsapp.com/legal/meta-terms-whatsapp-business; Meta Global Processor Terms; developers.facebook.com/docs/whatsapp/cloud-api/overview/local-storage; …/cloud-api/reference/registration (lists SG as a supported data_localization_region, checked 10 Oct 2026) |
Possible future sub-processor: Anthropic, PBC (USA), as a fallback language-model provider. It is not used at launch and will only be added with the notice described below.
Not sub-processors for End-Customer Data: Stripe (owner subscription billing only: Stripe Payments Singapore Pte. Ltd.; DPA party Stripe Payments Europe, Limited; transfers to Stripe, LLC, US); Telegram Messenger Inc. (independent controller; see section 1).
- We impose data-protection obligations on each sub-processor no less protective than this DPA, to the extent their standard terms allow, and remain responsible for them as the law requires.
- We'll give at least 14 days' notice of new or replacement sub-processors (by email or on https://recepsi.com/legal/subprocessors). The Customer may object on reasonable data-protection grounds; if we can't resolve it, the Customer may terminate the affected Service and get a pro-rata refund of prepaid fees.
6. Security
Recepsi maintains appropriate technical and organisational measures, including:
- TLS in transit; provider-managed AES-256 at rest; once live, backups encrypted with Recepsi's own key before they leave the database;
- row-level security isolating each Customer's data, with public widget and Telegram webhook traffic handled server-side and scoped to the right business;
- secrets kept server-side; Telegram bot tokens encrypted at rest; Telegram webhooks verified with a secret token;
- no message bodies, names, phone numbers or emails in logs; short log retention;
- rate limits on the widget and sign-up; prompt-injection safeguards; the receptionist can only create booking requests and hand-overs;
- a nightly retention job deleting data past the Customer's chosen period;
- multi-factor authentication on admin and provider accounts, regular access reviews, backup restore testing (starting once backups are live) and a documented breach response plan, all owned by our security team.
7. Personal data breaches
- Recepsi will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting End-Customer Data. The notice will include the information available at the time, and we'll update it as more is known. This meets the SG PDPA duty of a data intermediary to notify the organisation without undue delay (s26C(3)(a)), the Malaysian requirement that controllers contractually require prompt processor notification (DBN Guideline para 12.2), and GDPR Art. 28/33(2). It also supports the Customer's own deadlines: SG: assess, then notify the PDPC within 3 calendar days of assessing a breach as notifiable (s26D(1)). MY: notify the Commissioner within 72 hours, a clock that starts when Recepsi notifies the Customer (DBN Guideline para 6), and data subjects within 7 days after that if there is significant harm. GDPR/UK GDPR: notify the authority within 72 hours (Art. 33).
- The Customer decides whether to notify regulators and individuals for End-Customer Data; Recepsi will help. Notifying is not an admission of fault.
8. Data subject requests
- Requests made to Recepsi or to the receptionist. If an end-customer asks Recepsi, or asks the receptionist in a chat, to access, correct or delete their personal data (or makes another data-subject request), Recepsi, as processor, passes the request to the Customer without undue delay and does not answer it itself unless the Customer authorises us in writing or the law requires it. In a chat, the receptionist replies that the request has been passed to the business. The owner is alerted in the dashboard and by email, and the handover is logged.
- Helping the Customer respond. The dashboard lets the Customer search transcripts, export a single chat or all chats (CSV/JSON), delete a single chat or all chats with a particular customer, and delete its account. We'll give reasonable further help so the Customer can meet its deadlines (for example, 30 days under the Singapore PDPA and 21 days under Malaysia's PDPA for access requests).
9. Return and deletion
The Customer can export End-Customer Data at any time before deleting its account. On account deletion, Recepsi purges End-Customer Data within 30 days; there are no backup copies until Recepsi's planned encrypted backups are live; once live, copies in backups expire within 8 days. Data that the law requires us to keep is kept protected and used only for that purpose. Copies held by Telegram (independent controller) or Meta under their own terms are outside our control.
10. International transfers
- End-Customer Data is stored in Singapore (Supabase) but is processed outside Singapore by Cloudflare (global edge; once live, R2 backups under a best-effort APAC location hint, so possibly outside Singapore), OpenAI (US/global), Resend (US) and, later, Meta (WhatsApp; Singapore local storage where available). For Malaysian Customers, storage in Singapore is itself a transfer out of Malaysia.
- Singapore PDPA s26: Recepsi ensures recipients are bound by legally enforceable obligations (their DPAs/terms) giving comparable protection. Provider DPAs (OpenAI, Cloudflare, Supabase, Resend) are accepted as each account is set up and filed in Recepsi's records.
- Malaysia PDPA s129 (as amended 2024): transfers only to places with substantially similar law or adequate protection, or where another exception applies.
- EU/EEA and UK data: where the Customer is subject to GDPR/UK GDPR, the parties incorporate the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 (controller-to-processor), with Recepsi as importer, and the UK International Data Transfer Addendum. Clause 7 applies; Clause 9 option 2 (14 days' notice); Clause 11 optional language omitted; Clauses 17–18: governed by Irish law; courts of Ireland. Annex I = section 2; Annex II = section 6; Annex III = section 5. Onward transfers rely on each sub-processor's own SCCs or EU-US Data Privacy Framework certification, as set out in its DPA. Recepsi does not currently target EU/UK businesses.
11. Audits
Recepsi will make available information reasonably needed to show compliance (this document, sub-processor terms, security summaries). Where required by law, the Customer may audit on 30 days' notice, once a year, at its own cost, without disrupting the Service or breaching others' confidentiality; questionnaires first.
12. US state privacy (CCPA/CPRA)
Where applicable, Recepsi acts as a service provider: it won't sell or share End-Customer Data, or retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, or combine it with other data except as the CCPA allows, and will tell the Customer if it can no longer meet these obligations.
13. Liability
Each party's liability under this DPA is subject to the Terms §15, except that each party's total liability for breach of its data-protection obligations under this DPA is capped at twice the general cap in Terms §15. Lawyer review recommended before paid launch (interim position).
Contact: Xevix Pte. Ltd. (Recepsi), UEN 202425094Z · DPO: Sky Fam · dpo@recepsi.com