Skip to main content

Data Processing Agreement

How ManyRequests processes and protects customer data under GDPR.

Written by Robin Vander Heyden

1. Parties

This Data Processing Agreement (“DPA”) is between:

  • Customer (the data controller)

  • ManyRequests (the data processor)

This DPA forms part of the Terms of Service.


2. Roles

  • The Customer determines what data is collected and why

  • ManyRequests processes personal data only on behalf of the Customer


3. Scope of processing

ManyRequests processes personal data to provide its software platform, including:

  • Managing client requests and projects

  • Storing and organizing customer data

  • Enabling communication between users and their clients

Types of data may include:

  • Names, emails, contact details

  • Billing information

  • Content uploaded by users (messages, files, project data)

  • Technical data (IP address, logs)


4. Purpose of processing

Data is processed solely to:

  • Provide and operate the ManyRequests platform

  • Maintain and improve the service

  • Ensure security and prevent abuse

ManyRequests does not use customer data for its own marketing purposes.


5. Customer responsibilities

The Customer agrees to:

  • Comply with applicable data protection laws

  • Only upload and process data they are legally allowed to use

  • Provide necessary notices to their own users/clients


6. Subprocessors

ManyRequests uses trusted third-party providers to operate the service, including:

  • AWS (hosting)

  • Stripe (payments)

  • Email providers (transactional emails)

These subprocessors:

  • Only process data as needed

  • Are bound by data protection obligations

A current list of subprocessors is available upon request.


7. International data transfers

Data may be processed outside the EU/UK.

When this happens, ManyRequests uses appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs)


8. Security

ManyRequests implements appropriate technical and organizational measures, including:

  • Secure cloud infrastructure

  • Access controls

  • Encryption in transit where applicable


9. Data subject rights

ManyRequests assists Customers, where reasonably possible, in responding to requests from data subjects, including:

  • Access

  • Correction

  • Deletion

  • Data portability


10. Data breaches

ManyRequests will:

  • Notify the Customer without undue delay after becoming aware of a personal data breach

  • Provide reasonable information to help the Customer meet legal obligations


11. Data retention and deletion

  • Data is retained for the duration of the Customer’s account

  • Upon termination, data is deleted within a reasonable timeframe (typically 30–90 days), unless legally required otherwise


12. Return or deletion of data

Upon request or termination:

  • Customer data will be deleted or returned where technically feasible


13. Audits

Formal audits are not supported, but ManyRequests may provide reasonable information about its security practices upon request.


14. Liability

Each party’s liability is subject to the limitations set out in the Terms of Service.


15. Governing law

This DPA is governed by the same law as the Terms of Service.


16. Contact

For any data protection questions:
[email protected]


Did this answer your question?