Script
  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement

Data Processing Agreement

Last updated: 5 July 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between the Customer and Script. It governs the processing by Script of personal data on behalf of the Customer. Where this DPA conflicts with the Terms of Service on the subject of data protection, this DPA prevails.


1. Parties, Roles, and Scope

1.1. This DPA is entered into between: (a) the Customer (as defined in the Terms of Service), acting as the data controller; and (b) Individual Entrepreneur Andrii Iskra, registered in Ukraine, operating the Service under the name "Script" ("Script", "we", "us"), acting as the data processor.

1.2. Subject matter. This DPA applies where Script processes personal data on behalf of the Customer in the course of providing the Service — in particular, the personal data that the Customer collects about its own contacts and leads through connected messaging Channels ("Customer Personal Data", referred to as "Contact Data" in the Terms of Service).

1.3. Roles. With respect to Customer Personal Data, the Customer is the controller and Script is the processor. Where Script determines the purposes and means of processing (for example, account and billing data of the Customer itself), Script acts as a controller, and that processing is governed by our Privacy Policy rather than this DPA.

1.4. Instructions. Script processes Customer Personal Data only on the documented instructions of the Customer, including as set out in this DPA, the Terms of Service, and the Customer's use of the Service, unless required to do otherwise by applicable law (in which case Script will, where legally permitted, inform the Customer of that requirement before processing).

1.5. Applicable data protection law. In this DPA, "Data Protection Law" means the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Ukrainian Law "On Protection of Personal Data", and any other data protection or privacy laws applicable to the processing under this DPA. This DPA is drafted for a customer base in the EU/EEA and Ukraine; if Script later serves customers in other jurisdictions (for example, the UK or Switzerland), this DPA will be extended to cover the corresponding transfer mechanisms.


2. Details of Processing

2.1. Nature and purpose. Script processes Customer Personal Data to provide the Service — receiving, storing, organizing, displaying, and enabling the Customer to respond to messages exchanged with the Customer's contacts through connected Channels, together with related hosting, storage, delivery, security, and support functions.

2.2. Duration. Script processes Customer Personal Data for the duration of the Customer's use of the Service, followed by deletion or return in accordance with Section 8 and the retention stages described in the Terms of Service and Privacy Policy.

2.3. Categories of data subjects. The Customer's contacts and leads, and any other individuals whose personal data the Customer submits to or collects through the Service.

2.4. Categories of personal data. Identifiers and contact details (such as names, usernames, profile names, phone numbers, and social profile identifiers), the content of messages and attachments exchanged through the Channels, and related metadata (such as timestamps and channel identifiers).

2.5. Special categories of personal data. The Service is not intended for special categories of personal data (as defined in Article 9 GDPR). The Customer must not submit such data unless it has a lawful basis and appropriate safeguards, as set out in the Terms of Service.


3. Obligations of Script (Processor)

3.1. Processing on instructions. Script processes Customer Personal Data only as described in Section 1.4. Script will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

3.2. Confidentiality. Script ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and are granted access only to the extent necessary to perform their functions.

3.3. Security. Script implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex 2.

3.4. Sub-processors. Script may engage sub-processors as set out in Section 4.

3.5. Assistance to the Customer. Taking into account the nature of the processing and the information available to it, Script assists the Customer, by appropriate technical and organizational measures and insofar as possible, in: (a) responding to requests from data subjects exercising their rights under Data Protection Law (see Section 6); (b) ensuring compliance with the Customer's obligations regarding security, personal data breaches, and data protection impact assessments, and prior consultation with supervisory authorities.

3.6. Personal data breach. Script notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the Customer with the information reasonably necessary to enable the Customer to meet its own breach-notification obligations.

3.7. Records. Script maintains records of the processing carried out on behalf of the Customer, to the extent required by Article 30(2) GDPR.


4. Sub-processors

4.1. General authorization. The Customer grants Script general authorization to engage sub-processors to support the provision of the Service, subject to this Section.

4.2. Current sub-processors. As at the "Last updated" date, Script uses the following sub-processors:

Sub-processorPurposeLocation
DigitalOcean, LLCServer infrastructure and hostingData center: Germany (EU). Provider: USA
Cloudflare, Inc.Media storage and content delivery (CDN); DNS; DDoS protectionGlobal
monobank (JSC "Universal Bank")Payment processingUkraine
Meta Platforms, Inc.Instagram and Facebook messaging channelsUSA / EU
ResendTransactional email deliveryUSA

4.3. Terms with sub-processors. Script imposes on each sub-processor, by contract, data protection obligations that are substantially the same as those set out in this DPA, in particular the obligation to implement appropriate technical and organizational measures. Where a sub-processor is engaged in a banking capacity, applicable banking confidentiality obligations apply instead.

4.4. Liability for sub-processors. Script remains responsible to the Customer for the performance of each sub-processor's obligations.

4.5. Changes. Script may add or replace sub-processors. Script will give the Customer at least 30 days' notice of any intended change (for example, by updating this list and notifying the Customer through the Service or by email) before the new sub-processor begins processing Customer Personal Data. During that period the Customer may object on reasonable data-protection grounds. If the Customer objects and the parties cannot reach a resolution, the Customer may terminate the affected part of the Service.


5. International Data Transfers

5.1. Customer Personal Data is stored on servers located in Germany (European Union). Where possible, Script keeps Customer Personal Data within the EU.

5.2. Where Script transfers Customer Personal Data outside the European Economic Area (EEA) — for example, to sub-processors located in the United States — it does so only where an appropriate transfer mechanism under Chapter V GDPR applies, which may include: (a) an adequacy decision of the European Commission (including, where the recipient is certified, the EU–U.S. Data Privacy Framework); (b) the European Commission's Standard Contractual Clauses (SCCs); or (c) another lawful transfer mechanism.

5.3. Standard Contractual Clauses. Where the SCCs apply to a transfer under this DPA, the parties are deemed to have entered into the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), which are incorporated into this DPA by reference, on the following basis: (a) Module Two (Controller to Processor) applies to transfers from the Customer (as controller and data exporter) to Script (as processor and data importer); (b) in Clause 7, the optional docking clause applies; (c) in Clause 9, Option 2 (general written authorization) applies, with the change-notice mechanism described in Section 4.5; (d) in Clause 11, the optional independent dispute-resolution body does not apply; (e) in Clause 17, the Clauses are governed by the law of Ireland; (f) in Clause 18, disputes are resolved before the courts of Ireland; (g) Annexes I, II, and III to the SCCs are completed with the information set out in Annexes 1 and 2 of this DPA.

5.4. If any transfer mechanism relied on is invalidated or no longer available, the parties will work in good faith to put in place an alternative lawful mechanism.


6. Data Subject Rights

6.1. The Service provides features that allow the Customer to access, correct, export, restrict, and delete Customer Personal Data, which the Customer can use to respond to data-subject requests directly.

6.2. Where a data subject contacts Script directly regarding Customer Personal Data, Script will, unless legally required to respond, refer the request to the Customer and will not otherwise respond without the Customer's authorization.

6.3. Taking into account the nature of the processing, Script assists the Customer in fulfilling its obligations to respond to data-subject requests, as described in Section 3.5(a).


7. Audit and Compliance

7.1. Script makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in this DPA and Article 28 GDPR.

7.2. Script allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality obligations, and frequency limits, and conducted so as to minimize disruption to the Service. Where available, Script may satisfy an audit request by providing relevant documentation, security summaries, or third-party reports.


8. Return and Deletion of Data

8.1. On termination or expiry of the Service, and in accordance with the retention and deletion stages set out in the Terms of Service and Privacy Policy, Script deletes or returns Customer Personal Data at the Customer's choice, unless retention is required by applicable law. On the Customer's written request, Script will confirm in writing that deletion has been carried out.

8.2. The Customer can delete Customer Personal Data directly within the Service at any time, as described in the Privacy Policy.

8.3. Where Customer Personal Data has been transmitted to a sub-processor, deletion is subject to that sub-processor's own deletion practices. Backup copies may persist for a limited period before being securely erased.


9. General

9.1. Term. This DPA takes effect when the Customer accepts the Terms of Service and remains in effect for as long as Script processes Customer Personal Data.

9.2. Liability. The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service.

9.3. Changes. Script may update this DPA where necessary to reflect changes in the Service, its sub-processors, or Data Protection Law. Material changes will be notified in accordance with the Terms of Service.

9.4. Governing law. Except where the SCCs require otherwise (see Section 5.3), this DPA is governed by the same law as the Terms of Service.


Annex 1 — Details of Processing

  • Data exporter: the Customer (controller), as identified in its account.
  • Data importer: Individual Entrepreneur Andrii Iskra, operating as "Script" (processor), Ukraine.
  • Subject matter, nature, and purpose: as set out in Section 2.
  • Categories of data subjects: as set out in Section 2.3.
  • Categories of personal data: as set out in Section 2.4.
  • Special categories: not intended; see Section 2.5.
  • Frequency of transfer: continuous, for the duration of the Service.
  • Duration of processing: for the duration of the Service and applicable retention periods; see Section 8.
  • Competent supervisory authority (for SCC purposes): the Irish Data Protection Commission (as the supervisory authority of Ireland, whose law governs the SCCs under Section 5.3(e)).

Annex 2 — Technical and Organizational Measures

Script maintains, at minimum, the following measures:

  • Encryption in transit: data transmitted to and from the Service is encrypted using industry-standard TLS/SSL.
  • Data location: data is stored on servers located in the European Union (Germany), operated by a third-party infrastructure provider over which Script retains administrative control.
  • Access control: access to production systems is limited to authorized personnel and protected by two-factor authentication (2FA).
  • Tenant isolation: Customer data is logically isolated so that one Customer cannot access another Customer's data.
  • Least privilege: access to personal data is restricted to those who need it to operate, support, or improve the Service, and access is revoked promptly when no longer required.
  • Confidentiality: personnel with access to Customer Personal Data are bound by confidentiality obligations and informed of their responsibilities.
  • Sub-processor safeguards: Script permits sub-processors to access Customer Personal Data only to the extent necessary to provide the Service, under a written agreement imposing equivalent data-protection obligations.
  • Breach response: procedures for detecting, responding to, and notifying the Customer of personal data breaches, as described in Section 3.6.
  • Backups: backup copies may persist for a limited period after deletion, after which they are securely erased.

Annex 3 — List of Sub-processors

As set out in Section 4.2 of this DPA.

On this page

  • 1. Parties, Roles, and Scope
  • 2. Details of Processing
  • 3. Obligations of Script (Processor)
  • 4. Sub-processors
  • 5. International Data Transfers
  • 6. Data Subject Rights
  • 7. Audit and Compliance
  • 8. Return and Deletion of Data
  • 9. General
  • Annex 1 — Details of Processing
  • Annex 2 — Technical and Organizational Measures
  • Annex 3 — List of Sub-processors