1. Parties
This Data Processing Agreement (“DPA”) is between:
Customer (the data controller)
ManyRequests (the data processor)
This DPA forms part of the Terms of Service.
2. Roles
The Customer determines what data is collected and why
ManyRequests processes personal data only on behalf of the Customer
3. Scope of processing
ManyRequests processes personal data to provide its software platform, including:
Managing client requests and projects
Storing and organizing customer data
Enabling communication between users and their clients
Types of data may include:
Names, emails, contact details
Billing information
Content uploaded by users (messages, files, project data)
Technical data (IP address, logs)
4. Purpose of processing
Data is processed solely to:
Provide and operate the ManyRequests platform
Maintain and improve the service
Ensure security and prevent abuse
ManyRequests does not use customer data for its own marketing purposes.
5. Customer responsibilities
The Customer agrees to:
Comply with applicable data protection laws
Only upload and process data they are legally allowed to use
Provide necessary notices to their own users/clients
6. Subprocessors
ManyRequests uses trusted third-party providers to operate the service, including:
AWS (hosting)
Stripe (payments)
Email providers (transactional emails)
These subprocessors:
Only process data as needed
Are bound by data protection obligations
A current list of subprocessors is available upon request.
7. International data transfers
Data may be processed outside the EU/UK.
When this happens, ManyRequests uses appropriate safeguards, including:
Standard Contractual Clauses (SCCs)
8. Security
ManyRequests implements appropriate technical and organizational measures, including:
Secure cloud infrastructure
Access controls
Encryption in transit where applicable
9. Data subject rights
ManyRequests assists Customers, where reasonably possible, in responding to requests from data subjects, including:
Access
Correction
Deletion
Data portability
10. Data breaches
ManyRequests will:
Notify the Customer without undue delay after becoming aware of a personal data breach
Provide reasonable information to help the Customer meet legal obligations
11. Data retention and deletion
Data is retained for the duration of the Customer’s account
Upon termination, data is deleted within a reasonable timeframe (typically 30–90 days), unless legally required otherwise
12. Return or deletion of data
Upon request or termination:
Customer data will be deleted or returned where technically feasible
13. Audits
Formal audits are not supported, but ManyRequests may provide reasonable information about its security practices upon request.
14. Liability
Each party’s liability is subject to the limitations set out in the Terms of Service.
15. Governing law
This DPA is governed by the same law as the Terms of Service.
16. Contact
For any data protection questions:
[email protected]