Data processing agreement
Draft, not yet in force. Text in square brackets is filled in before publication.
Last updated: 30 September 2026.
reright is a service of interpt, Av. Nuno Alvares Pereira 52, 2300-532 Tomar, Portugal, VAT number PT253648920. You can reach us at [email protected]. In these documents "interpt", "we" and "us" mean that business.
This agreement applies when you use reright for your business and the text you submit contains personal data of other people. It forms part of the terms. You are the controller and interpt is your processor under Article 28 of the GDPR.
1. Subject matter and duration
interpt processes personal data on your behalf to provide the reright review service. The agreement lasts as long as you have an account and for the time it takes to delete your data afterwards.
2. Details of processing
| Nature and purpose | Storing, showing, editing, approving and rejecting text you or your agents submit, checking approvals, sending notifications, counting usage. |
|---|---|
| Types of personal data | Whatever your text, context, diffs and targets contain. This can include names, email addresses and other contact details of people you write to or about. You decide what is submitted. |
| Data subjects | Your own staff and the recipients or subjects of the messages you draft. |
| Retention | Message text is deleted from the live database at the retention the customer chooses, counted from the decision: 1 day on Free, or 1 to 90 days (default 30) on Starter, Pro and Unlimited. Undecided drafts expire on the same schedule, counted from submission. Text is deleted from every backup within 48 hours after that. Counts and billing records stay. |
3. Our obligations
- We process the data only on your documented instructions, which are these terms, the docs and your use of the service. We tell you if we think an instruction breaks the law.
- Everyone who can access the data is bound by confidentiality.
- We apply the security measures in section 6.
- We engage subprocessors only as set out in section 4.
- We help you answer requests from data subjects and meet your own obligations on security, breach notification and impact assessments, taking into account what we can see. Because text is encrypted per user, we can only act on it through the service.
- We tell you without undue delay after we become aware of a personal data breach affecting your data.
- When your account ends, we delete your data as described in the privacy policy, unless the law requires us to keep it.
- We give you the information needed to show that we comply with Article 28 and allow reasonable audits, by written request and with reasonable notice. Audits do not extend to other customers' data.
4. Subprocessors
You give general authorisation to the subprocessors on the subprocessor list. We will update the list and email you at least 30 days before adding or replacing one. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may end the agreement and delete your account. We stay responsible for our subprocessors and bind them to obligations equivalent to these.
5. International transfers
If processing involves a transfer of personal data outside the EEA, it relies on an adequacy decision or on the standard contractual clauses, which are incorporated here by reference where needed.
6. Security measures
- TLS on all connections.
- AES-256-GCM encryption at rest for text fields, with a separate data key per user, wrapped by a master key stored outside the database.
- Every query is limited to the account that owns the data, and tests check that one account cannot read another's drafts.
- Passwords are stored as argon2id hashes. Device tokens can be revoked.
- Rate limits on login and signup.
- Regular backups: a continuous copy to Amazon S3 in Ireland that keeps 24 hours of history and removes anything older than 2 days, and a nightly copy on the server that keeps only the newest copy. Point-in-time recovery reaches back about a day. Text fields are encrypted inside the backups, other account data is not.
- A list of one-way hashes of deleted account emails, used to delete those accounts again if a backup is restored.
- Deletion of text past its retention period every hour and once at every server start, so a restored backup is purged before it is used.
7. Contact
Questions about this agreement go to [email protected].