Data processing
Data processing addendum
This addendum applies where an organisation (“Customer”) uses RelayLink under the terms of service and personal data protection law makes PillarStack LLC, a Virginia limited liability company that operates the RelayLink service (in this addendum, “RelayLink”), a processor of personal data on Customer's behalf. It forms part of the terms and is entered by Customer's acceptance of them. Last updated 5 September 2026.
1. Definitions
- “Data protection law” means every law that applies to the processing of personal data under this addendum, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the US state laws that give residents rights over personal data, including the Virginia Consumer Data Protection Act and the California Consumer Privacy Act as amended.
- “Customer Data” means personal data that Customer or its users submit to the service and that RelayLink processes on Customer's behalf, as described in Annex I.
- “Standard Contractual Clauses” means the clauses in the European Commission's Implementing Decision (EU) 2021/914, and “UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- “Controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” have the meanings the GDPR gives them, and their equivalents under other data protection law (a “business” and a “service provider” or “contractor” under California law, a “controller” and a “processor” under Virginia law).
2. Roles and scope
- Customer is the controller of Customer Data and RelayLink is its processor, for the processing described in Annex I.
- RelayLink is an independent controller of the personal data it processes for its own purposes: the account records of Customer's users, the correspondence and account of any recipient who is not a user of Customer, the delivery record, security, abuse prevention, billing and legal compliance. The privacy policy governs that processing. Where a briefing passes between a user of Customer and a person outside Customer, each side's copy is that side's correspondence; RelayLink does not treat a recipient's copy as Customer Data.
- Each party will comply with data protection law in its role. Customer is responsible for the lawfulness of the Customer Data it submits, for the instructions it gives, and for having a legal basis for what its users send.
3. Processing on instructions
- RelayLink will process Customer Data only on Customer's documented instructions, which are: the terms of service, this addendum, the configuration of the service by Customer's users, and each act a user takes in it (composing, approving, sending, replying, blocking, exporting, closing). RelayLink will not process Customer Data for any other purpose, and in particular will not sell it, share it for advertising, combine it with data from other customers to build a profile, or use it to train a machine-learning model.
- If RelayLink believes an instruction breaches data protection law, it will tell Customer and may suspend the processing concerned until the instruction is confirmed or withdrawn.
- If the law of the EU, a Member State, the UK or the US requires RelayLink to process Customer Data otherwise, RelayLink will tell Customer before doing so unless that law forbids the notice.
4. Confidentiality
RelayLink will make sure that every person it authorises to process Customer Data is bound to confidentiality, by contract or by a statutory duty, and has access only to the extent their role needs. RelayLink's staff do not read correspondence in the ordinary course of running the service; access to production data is limited to the people who operate it and is used to investigate a fault, a security event or a report of abuse.
5. Security
RelayLink will implement and maintain the technical and organisational measures set out in Annex II, and will not reduce the overall level of protection they give during the term. Customer has assessed those measures and finds them appropriate to the risk of the processing, taking account of the nature of Customer Data and the state of the art.
6. Subprocessors
- Customer authorises RelayLink to engage the subprocessors listed on the subprocessor page as at the date Customer accepts this addendum, and authorises RelayLink in general to engage further subprocessors on the terms of this section.
- Notice of a change. RelayLink will update that page, and email Customer's account holders who have asked to be told, at least thirty days before a new subprocessor begins processing Customer Data, except where a subprocessor has to be replaced urgently to keep the service secure or running, in which case RelayLink will give notice as soon as it can.
- Objection. Customer may object within that period on reasonable grounds relating to data protection. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected subscription and receive a refund of any period paid for beyond the termination date.
- Flow-down. RelayLink will impose on each subprocessor, by written contract, data protection obligations that protect Customer Data to at least the standard of this addendum, and remains liable to Customer for a subprocessor's performance of them.
7. Assistance
- Data subject requests. The service lets a user export, correct and delete their own data and disconnect an assistant without RelayLink's involvement. If RelayLink receives a request from a data subject about Customer Data, it will refer the person to Customer where it can identify Customer, and will not answer on Customer's behalf except as instructed. RelayLink will help Customer respond to a request, by appropriate technical measures, as far as it reasonably can.
- Impact assessments and consultation. RelayLink will give Customer the information it reasonably needs to carry out a data protection impact assessment or a prior consultation with a supervisory authority, to the extent that information is not already on the privacy policy, the security page or this addendum.
- Cost. Assistance that goes beyond what the service already provides, and that takes RelayLink more than a trivial amount of work, may be charged at a reasonable rate agreed in advance.
8. Personal data breach
RelayLink will tell Customer without undue delay, and in any case within forty-eight hours of becoming aware, of a personal data breach affecting Customer Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact; RelayLink will supply what it learns later as it learns it. Notice is not an admission of fault. RelayLink will not notify Customer's users or any authority about a breach of Customer Data on Customer's behalf unless Customer asks it to or the law requires it.
9. International transfers
- RelayLink processes Customer Data in the United States, and its subprocessors process it where the subprocessor page says.
- Where Customer is in the EEA or Switzerland, or transfers Customer Data from there, the Standard Contractual Clauses, Module Two (controller to processor), are incorporated into this addendum, with Customer as data exporter and RelayLink as data importer, and with these choices: Clause 7 (docking) applies; option 2 of Clause 9(a) applies with the notice period in section 6; the optional language in Clause 11 does not apply; the governing law under Clause 17 and the courts under Clause 18 are those of Ireland; Annex I and Annex II below are the annexes to the clauses; and for Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
- Where Customer is in the UK or transfers Customer Data from there, the UK Addendum is incorporated and applies to the Standard Contractual Clauses as above, with Tables 1 to 3 completed by this addendum and its annexes, and with either party able to end the UK Addendum as its section 19 provides.
- If a transfer mechanism above is found invalid or is replaced, the parties will cooperate in good faith to put a valid mechanism in its place without delay.
10. Audits and information
RelayLink will make available to Customer the information necessary to show compliance with this addendum: this document, the security page, the subprocessor list, the results of any third-party assessment it has obtained, and written answers to reasonable questions. Where that is not enough to meet a legal requirement, Customer, or an independent auditor it appoints who is bound to confidentiality and is not a competitor of RelayLink, may audit RelayLink's compliance once in any twelve-month period, or after a personal data breach, on thirty days' written notice, during business hours, in a way that does not disrupt the service or expose other customers' data. Customer bears the cost of an audit unless it reveals a material breach of this addendum.
11. Return and deletion
Customer's users can export their correspondence from the service at any time, and closing an account deletes what identifies its holder as the privacy policy describes. On termination of the subscription, RelayLink will, at Customer's choice and within thirty days of a written request, return Customer Data in a machine-readable form or delete it, and will then delete remaining copies within the backup period stated in the privacy policy, except where the law requires RelayLink to keep something, and except that a briefing already delivered to a recipient outside Customer is that recipient's correspondence and stays with them. RelayLink will confirm deletion in writing on request.
12. United States state law
To the extent a US state law applies to Customer Data and treats RelayLink as Customer's service provider, contractor or processor: RelayLink will process Customer Data only for the business purpose of providing the service; will not sell or share it, retain, use or disclose it outside the direct business relationship with Customer, or combine it with personal data it receives from another source except as that law permits; will comply with the law's obligations on a processor and give the same level of protection it requires; will tell Customer if it decides it can no longer meet those obligations; and grants Customer the right to take reasonable and appropriate steps to stop and remedy unauthorised use. RelayLink certifies that it understands these restrictions.
13. Liability, precedence and term
- Each party's liability under this addendum, taken together with the terms of service, is subject to the limits in the terms of service, except to the extent data protection law or the Standard Contractual Clauses do not allow a limit.
- Where this addendum and the terms of service conflict on personal data, this addendum governs; where this addendum and the Standard Contractual Clauses conflict, the clauses govern.
- This addendum lasts as long as RelayLink processes Customer Data, and its obligations on deletion, confidentiality and liability survive after that.
Annex I — the processing
- Parties. Data exporter: Customer, a controller, at the address on its account. Data importer: PillarStack LLC, a processor, 406 Shafer St, Richmond, VA 23220, United States, hello@relaylink.ai.
- Subject matter and nature. Storing, transmitting, rendering and delivering briefings and replies composed by Customer's users, with the provenance labels attached to them; managing Customer's users' accounts, contacts, connected assistants and keys; and making the correspondence available to those users and to the assistants they connect.
- Purpose. Providing the RelayLink service to Customer under the terms of service.
- Duration. The term of Customer's subscription, plus the return and deletion period in section 11.
- Categories of data subjects. Customer's users; the people they correspond with, to the extent Customer instructs the processing of their data; and any third party mentioned in a briefing.
- Categories of personal data. Names, email addresses, the content of briefings and replies (which may include whatever the author chose to write), the provenance labels on them, contact relationships and nicknames, delivery events and their timestamps, and credentials in hashed form. No special categories of data are requested by the service; Customer instructs its users not to include them unless it has a legal basis.
- Frequency. Continuous, for as long as the service is used.
- Competent supervisory authority (Standard Contractual Clauses, Clause 13): the authority of the EEA Member State in which Customer is established, or, where Customer is not established in the EEA, the Irish Data Protection Commission.
Annex II — technical and organisational measures
- Transport. Every connection to the service is over TLS; plain HTTP is redirected and HTTP Strict Transport Security is set.
- Authentication. No passwords: a person signs in with a single-use emailed code, stored as a keyed hash and valid for ten minutes. API keys are stored as SHA-256 hashes, are generated from a cryptographic random source, can be named, revoked and replaced by their owner, and are capped in number. Assistants hold OAuth 2.1 tokens with PKCE, a one-hour access token lifetime, and revocation that the person can perform without the assistant's cooperation.
- Access control. A person sees only their own correspondence; a recipient's copy is theirs and a sender's is theirs. Sending to an account holder requires that person's accepted contact request, enforced on every send. Blocking is symmetric and silent.
- Content isolation. Content written by other people is HTML-encoded on the way to every web page, and every page that renders it forbids scripts entirely by Content Security Policy. Content is neutralised before it reaches an assistant or an email, so it is shown as text and never treated as an instruction.
- Infrastructure. Hosted on Microsoft Azure in the United States: App Service, Azure SQL Database, Key Vault for secrets, Log Analytics for logs. The database accepts no SQL logins; the service and the deployment pipeline authenticate as managed identities. Production and a sandbox are separate resource groups, databases, vaults and email domains, and the sandbox cannot read production secrets.
- Encryption at rest. Azure SQL, Azure Storage and Key Vault encrypt stored data with Microsoft-managed keys.
- Logging. Application logs are kept thirty days and are tested never to contain recipient addresses, link tokens or credentials; the framework's own debug logging of tokens is capped in code so that raising a log level cannot expose them.
- Backups and resilience. Database backups are kept fourteen days and stored geo-redundantly. Inbound email is retried by the provider for hours if the service is unavailable, and every reply is de-duplicated so a retry cannot create a second copy.
- Change control. All code is in version control, every change is reviewed and passes an automated test suite, and infrastructure is declared as code and applied by a pipeline rather than by hand. Database schema changes are applied by a dedicated migrator before new code serves traffic.
- Vulnerability handling. Dependencies are audited for known vulnerabilities on every build, and the security page gives researchers a route to report and a safe harbour for doing so.
- Data minimisation. No IP address is stored against any content event; the rate limiter holds addresses in memory only. Email open and click tracking is disabled at the provider. Attachments on inbound replies are discarded.
- People. A small team, each member of which is bound to confidentiality, with production access limited to those who operate the service.
Contact
To ask for a countersigned copy of this addendum, to nominate the address that receives subprocessor notices, or for anything else about it, write to hello@relaylink.ai, or by post to PillarStack LLC, 406 Shafer St, Richmond, VA 23220, United States. The whole set of policies is listed at relaylink.ai/legal.