
Data Processing Agreement
Last updated: September 2, 2026
How this agreement is signed
This page is the template. It is not executed automatically when you sign up. To put it in force, email hello@feerasta.ai with the name of your business and the workspace it covers; we return a countersigned copy that references your order, and it applies from the date on that copy. Your own paper is welcome too: send it and we will redline it in writing.
This agreement applies where Feerasta processes personal data on a customer’s behalf. The customer is the controller and decides why the data is processed. Feerasta is the processor and acts on the customer’s documented instructions.
Parties
The processor is Feerasta Industries LLC, a limited liability company formed in the State of Delaware, United States. Registration number and registered address: provided on request to hello@feerasta.ai, and written into the countersigned copy. The controller is the customer named in the order this agreement attaches to.
This agreement is governed by the laws of the State of Delaware, consistent with the terms of service.
1. Subject matter and duration
Processing continues for the term of the services agreement. On termination, and at the customer’s election, data is returned or deleted. Inside the product that is done by taking a JSON export, with secrets redacted, and then scheduling deletion, which runs after a 30-day window in which the customer can cancel it. Three records survive deletion because they are the evidence that a STOP was honoured and what was approved: the consent record, the opt-out list and the audit trail. Data is otherwise deleted within 30 days of the window closing, except where law requires retention.
2. Nature and purpose
Reading, classifying, extracting from and drafting responses to the customer’s own business records: invoices, statements, contracts, leases, email and messages. Answering calls and messages on the customer’s behalf from the customer’s approved rules. Categorising and reconciling transactions. Every action that sends, pays, posts or replies is a draft until an owner or approver the customer appointed enables it.
3. Categories of data and data subjects
Business contact details, correspondence, transaction records, consent records, and whatever personal data the customer’s own documents happen to contain. Data subjects are the customer’s employees, customers, suppliers and counterparties.
Special category data is out of scope unless separately agreed in writing. Health, biometric and financial identity data require controls we do not offer by default on the shared platform; where they are needed, the private deployment and the right agreement (for example a HIPAA Business Associate Agreement) come first.
4. Our obligations
- Process only on the customer’s documented instructions.
- Ensure everyone with access is bound by confidentiality.
- Maintain the security measures described on the security page, including what that page says is not yet in place.
- Not engage a new subprocessor without notice: the list is published at /subprocessors and is updated before a new provider processes customer data.
- Assist with data subject requests, and with breach notification, within the statutory windows.
- Notify the customer without undue delay, and in any event within 72 hours, on becoming aware of a personal data breach.
- Make available the information needed to demonstrate compliance, and allow audit.
5. Model training and model calls
Customer data is not used to train any model, ours or a subprocessor’s. Customer-facing conversations on the web widget, SMS, WhatsApp and voice are answered from the customer’s approved rules and make no model call. Model-backed drafting runs on a model key the customer brings, stored encrypted in the workspace, in which case the customer’s own provider terms govern those calls; or, where the platform supplies the model, on the providers listed below. Each AI provider is used with training on customer data disabled where the provider offers that setting; the subprocessor list names the providers.
6. Subprocessors
As at the date above, and kept current at /subprocessors:
- Hetzner (Germany): the server running the application and its PostgreSQL database.
- Cloudflare (global edge): website delivery, DNS and DDoS protection, and Workers AI, which matches questions asked on our FAQ page to our published answers.
- Hostinger (European Union): domain and mail hosting.
- Twilio (United States): phone numbers, calls and SMS.
- ElevenLabs (United States): speech synthesis and recognition for voice agents.
- Meta (United States): the WhatsApp Business API, for WhatsApp messages and approvals.
- Resend (United States, on Amazon SES infrastructure): transactional email.
- Stripe (United States): payments and billing.
- Google (United States): business data and maps, and the encrypted offsite copy of nightly backups.
- Anthropic and OpenAI (United States): the model behind drafting that waits for approval, only where the customer has not brought a key of their own.
- NVIDIA (United States): the vision model behind the WhatsApp Assistant demo, and search embeddings for the platform memory feature.
7. International transfers
The processor is a United States entity and the platform runs in Germany, so personal data originating in the EEA or the UK may be transferred outside it. Where that happens, the transfer relies on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), incorporated by reference and prevailing over this agreement in the event of conflict, together with the UK Addendum where UK data is involved.
The private deployment option exists precisely so that a customer who cannot accept a transfer does not have to make one: the system runs on the customer’s own infrastructure and no personal data reaches us at all.
8. Audit
The customer may audit compliance once in any twelve-month period on 30 days’ notice, or more often if a supervisory authority requires it. We answer written security questionnaires, the standing answers are on the security page, and we will say in writing where an answer is no.
Questions about anything on this page: hello@feerasta.ai. The plain-language version of what we keep, export and delete is on the trust page.