Last Updated: July 26, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Riblai ("Processor", "Riblai", "we", "our", or "us") and the Customer ("Controller" or "Customer").
This DPA applies whenever Riblai processes Personal Data on behalf of the Customer while providing the Services.
1. Purpose
The purpose of this Agreement is to define the obligations of both parties regarding the processing of Personal Data in connection with the Services provided by Riblai.
This Agreement is intended to support the Customer's compliance with applicable data protection and privacy laws where they apply, including, where applicable: GDPR, UK GDPR, CCPA/CPRA, KVKK, and other applicable data protection and privacy law.
2. Roles of the Parties
For Customer Data processed through the Services, the Customer acts as the Data Controller (or Processor where applicable) and Riblai acts as the Data Processor.
The Customer determines the purposes and means of processing. Riblai processes Personal Data only on documented instructions from the Customer unless required by applicable law.
3. Scope of Processing
Riblai processes Personal Data solely for the purpose of providing the Services, including customer relationship management, omnichannel messaging, AI-powered customer service, AI workflow automation, revenue attribution, marketing campaign management, website visitor identification, analytics and reporting, customer journey tracking, product catalog services, sales automation, and platform administration.
4. Categories of Personal Data
Depending on how the Customer uses the Services, Personal Data may include names, email addresses, phone numbers, company information, user identifiers, IP addresses, device information, browser information, CRM records, conversation history, marketing attribution data, website interaction events, AI conversation inputs, and files and attachments uploaded by the Customer.
5. Categories of Data Subjects
Data Subjects may include customers, leads, prospects, employees, website visitors, platform users, business contacts, sales representatives, and customer support representatives.
6. Customer Responsibilities
The Customer represents and warrants that it has all necessary rights to process Personal Data, provides appropriate privacy notices where required, obtains any legally required consent, ensures its instructions comply with applicable law, and remains responsible for determining the lawful basis for processing.
7. Riblai Responsibilities
Riblai agrees to process Personal Data only on documented instructions, maintain confidentiality obligations, implement appropriate technical and organizational security measures, restrict access to authorized personnel, maintain reasonable administrative, technical, and physical safeguards, notify the Customer of confirmed Personal Data Breaches without undue delay, and assist the Customer in fulfilling applicable data protection obligations where reasonably required.
8. Security Measures
Riblai maintains security measures appropriate to the risks associated with processing Personal Data, including encryption in transit, encryption at rest, access controls, RBAC, MFA where enabled, infrastructure monitoring, logging and audit trails, backup and disaster recovery, secure software development practices, and vulnerability management.
Additional information is available in the Riblai Security documentation.
9. AI Processing
Where Customers use AI-powered features, AI services process Customer Data only to provide requested functionality. AI processing follows Customer permissions, AI actions remain subject to platform access controls, and unless expressly agreed in writing, Customer Data is not used to train generalized AI models for other customers.
Customers remain responsible for reviewing AI-generated content before using it in business-critical situations.
10. Subprocessors
Riblai may engage trusted subprocessors to deliver the Services, including providers of cloud infrastructure, data storage, authentication, email delivery, messaging infrastructure, AI services, monitoring, security, and payment processing.
Riblai remains responsible for ensuring subprocessors are contractually bound to provide appropriate data protection safeguards. An up-to-date list of subprocessors is available upon request or through the Riblai Trust Center.
11. International Data Transfers
Where Personal Data is transferred internationally, Riblai will implement appropriate safeguards as required by applicable law, including Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms where applicable.
12. Data Subject Requests
Taking into account the nature of processing, Riblai will provide reasonable assistance to enable the Customer to respond to requests relating to access, correction, deletion, restriction, portability, objection, and withdrawal of consent where applicable.
13. Security Incidents
If Riblai becomes aware of a confirmed Personal Data Breach affecting Customer Data, we will notify the Customer without undue delay and provide available information necessary to support the Customer's legal obligations.
14. Data Retention and Deletion
Customer Data is retained only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, or enforce agreements. Upon termination of the Services and subject to applicable law, Customer Data will be deleted or returned in accordance with the Agreement and Customer instructions.
15. Audits
Upon reasonable written request and subject to appropriate confidentiality obligations, Riblai may provide information demonstrating compliance with this DPA through security documentation, certifications, audit reports, or other reasonable means.
16. Confidentiality
Riblai ensures that all personnel authorized to process Personal Data are subject to confidentiality obligations or appropriate statutory duties of confidentiality.
17. Governing Law
This DPA shall be governed by the law specified in the applicable Terms of Service unless otherwise agreed in writing.
18. Contact
Questions regarding this Data Processing Agreement may be directed to:
Privacy Team
Email: privacy@ribl.ai
Website: https://ribl.ai