Recepsi Data Processing Addendum (DPA)

Version 0.11 · Last updated 11 October 2026

Part of the Recepsi Terms of Service. If this DPA conflicts with the Terms on personal data, this DPA wins.

Parties: the Customer (the business using Recepsi) and Xevix Pte. Ltd., UEN 202425094Z, a company registered in Singapore ("Recepsi").

1. Roles

DataCustomer isRecepsi is
End-Customer Data — chat messages and replies, transcripts, contact details, booking requests, anonymous widget session IDs, and any personal data inside knowledge sources the Customer uploadsController (GDPR/UK GDPR) / organisation (SG PDPA) / data controller (MY PDPA, as amended 2024) / business (CCPA)Processor / data intermediary (SG PDPA s4(2)) / data processor (MY PDPA) / service provider (CCPA)
Customer's account, billing and usage data—Controller, under the Privacy Policy — not covered by this DPA
Messages on Telegram's platformController of its own useNot responsible for Telegram's own processing: Telegram Messenger Inc. is an independent controller (no DPA available).
WhatsApp messages (later phase)ControllerProcessor; Meta Platforms Ireland Limited acts as a processor (sub-processor in the chain) under the Meta Global Processor Terms — not a separate controller

2. Details of processing

3. Customer's responsibilities

The Customer:

  1. is responsible for having a lawful basis / consent for End-Customer Data (including parental consent where needed for minors) and for giving end-customers a privacy notice that mentions use of an automated assistant and of service providers like Recepsi;
  2. accepts that the automated-assistant disclosure is mandatory and cannot be removed;
  3. obtains WhatsApp opt-ins (later phase) and complies with DNC and anti-spam rules;
  4. gives only lawful instructions and doesn't upload or solicit sensitive data contrary to the AUP;
  5. handles end-customer requests (access, correction, deletion, withdrawal of consent) using the dashboard tools (section 8), with our help.

4. Recepsi's obligations

Recepsi will:

  1. process End-Customer Data only on the Customer's documented instructions (the Terms, this DPA and the Customer's configuration), unless the law requires otherwise (we'll tell the Customer first where lawful), and tell the Customer if we think an instruction breaks data-protection law;
  2. not sell or share End-Customer Data, not use it for our own purposes, and not use it to train or fine-tune language models, and require our language-model providers not to do so; we record usage metrics with no content (chat/message counts, token and spend totals, response times, error/status codes) against the Customer's business ID, keep usage counters for 24 months, and on account deletion reduce them to anonymous totals that can't be linked to the Customer;
  3. ensure anyone authorised to access the data is bound by confidentiality; there is no routine human access by Recepsi personnel to transcripts;
  4. meet the SG PDPA obligations that apply directly to data intermediaries (protection, retention limitation, and notifying the Customer of breaches) and, under the Malaysian PDPA as amended in 2024, the security principle that now applies directly to processors;
  5. help the Customer with security, breach notification, data-protection impact assessments and regulator consultations, as reasonably needed.

5. Sub-processors

The Customer gives general authorisation for Recepsi to use sub-processors. Current list (contracting entities taken from each provider's published terms, checked 10 Oct 2026):

Sub-processor (contracting entity)ServiceEnd-Customer Data involvedLocationSource
Cloudflare, Inc.Application hosting (Workers, global edge) and spam protection (Turnstile); once live, nightly backup job (scheduled Worker) and backup storage (R2)All traffic; once live, full database backups, encrypted with Recepsi's own key before leaving SupabaseGlobal edge, so processing may happen outside Singapore. Workers Logs are kept for at most 7 days, with no message bodies. R2 backups (once live) will use the APAC location hint, which Cloudflare applies on a best-effort basis, so they may be stored outside Singaporecloudflare.com/terms; Cloudflare Customer DPA v6.4 (eff. 3 Apr 2026); developers.cloudflare.com/r2/reference/data-location; developers.cloudflare.com/workers/observability/logs/workers-logs
Supabase Pte. Ltd. (Singapore)Database, authentication, storage, vector searchAll stored dataSingapore (ap-southeast-1). Free plan: no provider backups; Recepsi's own encrypted backups are being set up (none until live)supabase.com/terms (definition of "Supabase"); supabase.com/docs/guides/platform/backups
OpenAI OpCo, LLC (USA) — main language-model providerChat replies and embeddingsMessage, recent history, relevant knowledge snippetsUS/global. No training on API data; abuse-monitoring logs up to 30 days (longer only if required by law or to prevent harm). Singapore endpoint offers storage only, not processing, and needs approvalopenai.com/policies/services-agreement (§4.2, §17 "OpenAI Contracting Party"); developers.openai.com/api/docs/guides/your-data
Plus Five Five, Inc. (USA), trading as ResendTransactional email from @recepsi.com to owners only: alerts, hand-over summaries, sign-in links. Never emails end-customersHand-over summaries may include a chat snippet and the end-customer's contact detailsUnited States (Resend's own hosting/sending sub-processor: Amazon Web Services, Inc., USA)resend.com/legal/terms-of-service (§1: agreement with Plus Five Five, Inc.; California law); resend.com/legal/dpa (last updated 31 Dec 2025: breach notice "without undue delay" §8.6; 14 days' notice of new sub-processors §4.2; EU SCCs Module Two §6.2.2); resend.com/legal/subprocessors (updated 27 Aug 2026)
Meta Platforms Ireland Limited — later phase (WhatsApp) onlyWhatsApp Cloud API messagingWhatsApp messages and phone numbersMeta data centres internationally; Singapore local storage will be turned on where available (message content at rest in SG after up to 60 min of processing)whatsapp.com/legal/meta-terms-whatsapp-business; Meta Global Processor Terms; developers.facebook.com/docs/whatsapp/cloud-api/overview/local-storage; …/cloud-api/reference/registration (lists SG as a supported data_localization_region, checked 10 Oct 2026)

Possible future sub-processor: Anthropic, PBC (USA), as a fallback language-model provider. It is not used at launch and will only be added with the notice described below.

Not sub-processors for End-Customer Data: Stripe (owner subscription billing only: Stripe Payments Singapore Pte. Ltd.; DPA party Stripe Payments Europe, Limited; transfers to Stripe, LLC, US); Telegram Messenger Inc. (independent controller; see section 1).

6. Security

Recepsi maintains appropriate technical and organisational measures, including:

7. Personal data breaches

8. Data subject requests

9. Return and deletion

The Customer can export End-Customer Data at any time before deleting its account. On account deletion, Recepsi purges End-Customer Data within 30 days; there are no backup copies until Recepsi's planned encrypted backups are live; once live, copies in backups expire within 8 days. Data that the law requires us to keep is kept protected and used only for that purpose. Copies held by Telegram (independent controller) or Meta under their own terms are outside our control.

10. International transfers

11. Audits

Recepsi will make available information reasonably needed to show compliance (this document, sub-processor terms, security summaries). Where required by law, the Customer may audit on 30 days' notice, once a year, at its own cost, without disrupting the Service or breaching others' confidentiality; questionnaires first.

12. US state privacy (CCPA/CPRA)

Where applicable, Recepsi acts as a service provider: it won't sell or share End-Customer Data, or retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, or combine it with other data except as the CCPA allows, and will tell the Customer if it can no longer meet these obligations.

13. Liability

Each party's liability under this DPA is subject to the Terms §15, except that each party's total liability for breach of its data-protection obligations under this DPA is capped at twice the general cap in Terms §15. Lawyer review recommended before paid launch (interim position).

Contact: Xevix Pte. Ltd. (Recepsi), UEN 202425094Z · DPO: Sky Fam · dpo@recepsi.com