Data Processing Agreement
Rapprt Ltd, 124 City Road, London, EC1V 2NX
This Data Processing Agreement (“DPA”) forms part of the agreement between Rapprt Ltd (“Rapprt”, “we”, “us”) and the customer identified in the applicable order or account signup (“Customer”). It applies automatically to every Rapprt plan — Starter, Pro, Team, and Enterprise — from the point the Customer creates an account and accepts Rapprt's Terms of Service. Enterprise customers may request negotiated variations to specific clauses (see Section 9).
1. Roles of the parties
For the purposes of UK GDPR and the Data Protection Act 2018:
The Customer is the Data Controller in respect of personal data relating to its own business contacts (names, job titles, business email addresses, and any interest/sport data associated with those contacts) that it submits to or generates within Rapprt.
Rapprt is the Data Processor, processing that personal data solely on the Customer's documented instructions, as set out in this DPA and Rapprt's Terms of Service.
Where Rapprt determines the means of processing shared, non-customer-specific data (for example, cached public sports or news topic data not linked to an identifiable individual), Rapprt acts as an independent controller for that limited dataset only.
2. Subject matter and duration
Rapprt processes personal data submitted by the Customer, or derived from public sources and associated with the Customer's contacts, for the purpose of generating automated contact briefs, weekly digests, and dashboard views for the Customer's sales or account management users. Processing continues for the duration of the Customer's subscription and for the retention period set out in Section 6.
3. Nature and purpose of processing
- Storing business contact details (name, job title, employer, business email) provided by the Customer.
- Enriching contact records with publicly available personal interest data (sport, and in future phases, hobbies such as cooking, gardening, photography, and travel).
- Generating summarised contact briefs via AI models (cost-controlled models only — see Rapprt's internal AI usage policy) using cached, shared topic-level data combined with Customer-specific contact associations.
- Displaying briefs via the Outlook add-in, weekly email digest, and web dashboard to the Customer's authorised users.
4. Categories of data subjects
- Business contacts of the Customer (the Customer's prospects, clients, or partners) — typically business card level detail plus inferred personal interest data.
- The Customer's own users (sales reps, account managers, admins) — account login and usage data.
5. Sub-processors
Rapprt uses the following categories of sub-processor. The Customer provides general authorisation for Rapprt to engage sub-processors, subject to Rapprt imposing data protection obligations on them no less protective than this DPA, and notifying the Customer of any material change.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and authentication | EU/US (per Supabase project region) |
| Microsoft Azure / Microsoft Graph | Outlook add-in authentication, calendar and contact access | EU/UK region |
| Stripe | Payment processing and billing | US / global |
| 3rd Party AI model provider | Generating contact brief summaries from topic data | US |
| TheSportsDB | Public sports data enrichment | EU |
| World News API | Public news enrichment | EU |
Where a sub-processor is located outside the UK/EEA (for example, Stripe or the AI model provider), Rapprt relies on that sub-processor's Standard Contractual Clauses or equivalent UK-recognised transfer mechanism, and will provide evidence of this on reasonable request.
6. Data retention
Retention periods are set out in full in Rapprt's Data Retention Policy (referenced in Section 9 and published alongside the Privacy Policy). In summary:
- Active account data is retained for the life of the subscription.
- On cancellation (subscription lapses without a deletion request), Customer and contact data is retained for 12 months to allow reactivation without re-onboarding, then deleted from primary systems, with backups purged 90 days later.
- Where the Customer or a data subject makes an explicit deletion request (via the in-app delete function, or a right-to-erasure request), the 12-month grace period does not apply: the relevant record is removed from primary systems immediately (or within 30 days for full account deletion), with backup purge within 90 days.
- Shared, non-identifiable topic-level cache data (e.g. general sports results not linked to a specific contact) is not personal data once de-linked, and is not subject to this retention schedule.
7. Security measures
- Encryption of data in transit (TLS) and at rest, as provided by Supabase and Azure infrastructure.
- Role-based access control — only authorised Rapprt personnel (currently the two founders) have production data access.
- Authentication via Microsoft Entra ID (MSAL) for the Outlook add-in, avoiding storage of Microsoft account credentials by Rapprt.
- Deletion functionality available directly within the Customer's account, without requiring a support request.
8. Breach notification
Rapprt will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Customer's data, providing sufficient information to allow the Customer to meet its own regulatory notification obligations.
9. Enterprise variations
Standard Starter, Pro, and Team customers accept this DPA as published, incorporated by reference into Rapprt's Terms of Service at signup — no separate signature is required. Enterprise customers may request a countersigned version of this DPA, and may negotiate variations to notice periods, audit rights, and liability provisions specific to Section 8 and Section 5. All other terms remain as published.
10. Audit rights
On reasonable written notice, and no more than once per 12-month period, the Customer may request evidence of Rapprt's compliance with this DPA (such as a summary of security measures and sub-processor list). Enterprise customers may request an on-site or remote audit, at the Customer's cost, subject to reasonable confidentiality safeguards.
11. Data subject rights
Where a data subject (for example, a contact whose data Rapprt processes on the Customer's behalf) exercises a right under UK GDPR directly with Rapprt, Rapprt will inform the Customer promptly and will not respond substantively without the Customer's instruction, save where required by law.
This DPA is incorporated by reference into Rapprt's Terms of Service and takes effect automatically upon account creation. For questions, contact joe@rapprt.com.