Data Processing Agreement
Last updated: July 14, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between relaybell, operated by Nexistech(nexistech.in) (“Processor”), and the Customer (“Controller”) for use of the relaybell web push service. It reflects the parties’ obligations under the GDPR, UK GDPR, and CCPA.
1. Roles
The Customer is the controller of Subscriber personal data. relaybell is the processor, processing that data only on the Customer’s documented instructions (the service configuration, dashboard, and API calls).
2. Scope of processing
- Subject matter: delivery of web push notifications and related analytics.
- Duration: for the term of the agreement, plus any configured retention window.
- Categories of data: push subscription tokens, device/browser type, language, country, consent records, and Customer-supplied tags and events.
- Data subjects: the Customer’s website visitors who opt in to notifications.
3. Confidentiality & security
relaybell maintains appropriate technical and organizational measures, including encryption in transit, access controls, and least-privilege administration. Personnel with access are bound by confidentiality obligations.
4. Sub-processors
The Customer authorizes relaybell to engage sub-processors (e.g. cloud hosting and transactional email) under written terms no less protective than this DPA. A current list is available on request, and relaybell will give notice of material changes.
5. Data subject requests
relaybell provides self-service tools to help Customers respond to access, correction, deletion, and portability requests, and will provide reasonable assistance for requests we cannot fulfil automatically.
6. Personal data breach
relaybell will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, with information reasonably available to assist the Customer’s own notification obligations.
7. International transfers
Where personal data is transferred across borders, the parties rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses) as applicable.
8. Deletion & return
On termination, or on the Customer’s instruction, relaybell will delete or return the Customer’s personal data, subject to any legal retention requirements. Configured retention windows delete event logs automatically.
9. Requesting a signed DPA
To execute a countersigned copy of this DPA, contact privacy@relaybell.com.