Data processing agreement
Last updated November 10, 2025Sagency International LLCabout 7 min readSee also: Trust centre, Subprocessors, Security overview, Privacy Policy
Blue Reacher acts as processor and you act as controller. This agreement forms part of every contract and is published in full so you can read it before you sign anything, rather than after.
What this covers
Who plays which role, exactly what gets processed and why, the security measures that are contractually guaranteed, how subprocessors are handled, what happens on a breach, how long data is kept, how deletion works, and how transfers out of the United States are covered.
1. Purpose and scope
This Data Processing Agreement governs how Sagency International LLC, trading as Blue Reacher, processes personal data on behalf of a customer using the Blue Reacher platform. It supplements and forms part of the Blue Reacher Terms of Service, and it applies automatically to every customer without a separate signature request.
Blue Reacher processes Customer Data solely to provide the services described in the Terms of Service. This agreement reflects both parties' obligations under applicable data protection law, and a countersigned copy is available on request for customers whose procurement process requires one on file.
2. Definitions
- Customer Data
- Any personal data processed by Blue Reacher on behalf of the customer in connection with the service, including contact records imported from a CRM, message content, delivery states and reply history.
- Recipient
- An individual the customer sends messages to through the platform. Recipients are the data subjects for most of the data processed here.
- Data Protection Laws
- The EU General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and any other data protection legislation applicable to a party.
- Subprocessor
- A third-party service provider engaged by Blue Reacher to assist in processing Customer Data. The current list is published at /subprocessors.
- Personal Data Breach
- Unauthorised access to, accidental loss of, or unlawful destruction or disclosure of Customer Data.
3. Roles of the parties
Blue Reacher acts as processor and the customer acts as controller. The customer decides who is contacted, on what basis, and with what message; Blue Reacher provides the platform that carries it.
Blue Reacher processes Customer Data only on documented instructions from the customer, as set out in this agreement and the Terms of Service. Where Blue Reacher believes an instruction breaches applicable law, it will say so rather than carry it out, and the Anti-Spam Policy names the categories of program Blue Reacher declines at any price.
4. Scope of processing
Blue Reacher processes Customer Data for the following purposes only: delivering messages the customer initiates, receiving and routing replies back to the customer, recording delivery and read states, enforcing opt-outs and do-not-contact suppression, providing reporting and campaign history in the dashboard and over the API, and maintaining the security, reliability and performance of the platform.
Blue Reacher will not process Customer Data for any other purpose without the customer's explicit written instruction. Customer Data is never used to build features, benchmarks or audiences for any other customer.
5. Categories of data processed
- Contact identifiers
- Name, mobile number, and any additional fields the customer chooses to sync from its CRM for personalisation.
- Message content
- The text, images and media the customer sends, and the replies recipients send back.
- Delivery metadata
- Sent, delivered, read and failed states, the channel each message travelled on, timestamps, and message identifiers.
- Consent and suppression records
- Opt-out events, do-not-contact entries, and the timestamps needed to evidence enforcement.
- Account data
- Names, work email addresses and authentication records for the customer's own users of the platform.
Blue Reacher does not request, require or knowingly process special category data as defined by GDPR Article 9. A customer operating under a business associate agreement may process protected health information through the platform, and the additional terms of that agreement govern where they differ from this one.
6. Customer ownership of data
Customer Data belongs to the customer. Blue Reacher claims no ownership of contact records, message content or the reply history generated through the platform, and asserts no licence over them beyond what is needed to run the service.
On termination, Customer Data is returned or deleted at the customer's election within 30 days of the request. Written certification of deletion is available on request.
7. Technical and organisational measures
Blue Reacher implements appropriate technical and organisational measures to protect Customer Data, appropriate to the risk, and reviews them at least annually. The full description lives in the Security Overview and the measures below are the contractual floor.
- Encryption
- TLS 1.3 for Customer Data in transit, falling back no lower than TLS 1.2, and AES-256 for Customer Data at rest, with keys managed through the cloud provider's key management service.
- Access control
- Role-based access on a least-privilege basis, with no standing access to production data, mandatory multi-factor authentication for every account that can reach production, and access reviewed on a recurring schedule.
- Isolation
- Customer workspaces are logically isolated from one another, and production, staging and development environments are separated.
- Logging
- Access to production data generates audit entries, and application and access logs are retained for a minimum of 90 days.
- Resilience
- Automated backups with periodic restore-integrity verification, and zero-downtime deployments with automated rollback.
- Vulnerability management
- Automated dependency scanning, code review before production, and secrets held in environment vaults rather than in source control.
8. Confidentiality
Blue Reacher ensures that every person authorised to access Customer Data is bound by confidentiality obligations, and limits authorisation to individuals who need the access to perform their role. Those obligations continue after the individual's engagement with Blue Reacher ends.
9. Subprocessors
Blue Reacher engages third-party subprocessors to deliver the service. By agreeing to the Terms of Service, the customer gives general authorisation for Blue Reacher to use subprocessors, and the current list is published at /subprocessors rather than held back for a request.
Blue Reacher gives at least 30 days notice before adding or replacing a subprocessor, imposes data protection obligations no less protective than those in this agreement on each one, and remains liable to the customer for every subprocessor's performance. A customer with a reasonable objection to a new subprocessor may raise it during the notice period.
10. Artificial intelligence and model training
Customer Data and message content are never used to train public artificial intelligence or machine learning models, never shared with or used to build features for another customer, and never sold to third parties, data brokers or advertising networks.
Where a customer enables an AI feature inside the product, the processing runs only to serve that customer's own account, and any subprocessor providing the model appears at /subprocessors under a contractual bar on training against the data it sees. Aggregated and anonymised platform metrics such as error rates and delivery performance may be used to improve reliability and security, and cannot identify a customer or a recipient.
11. Data subject rights
Blue Reacher assists the customer in meeting its obligations to respond to data subject requests, including access, rectification, erasure, restriction of processing, portability and objection. Where a request reaches Blue Reacher directly, it is routed to the relevant customer rather than actioned unilaterally, because the customer is the controller.
Requests can be submitted through the customer's account or by email to support@bluereacher.com, and the mechanics of access, export and erasure are documented at /delete-data.
12. Breach notification
Blue Reacher notifies affected customers within 48 hours of discovering a confirmed Personal Data Breach, a window set to sit comfortably inside the GDPR Article 33 obligation the customer carries as controller.
The notification states the nature and likely cause of the breach, the categories of Customer Data involved, the estimated number of records affected, and the measures taken or planned to contain and remediate it. Blue Reacher provides reasonable cooperation with any regulatory notification the customer must make.
13. Retention
Blue Reacher retains Customer Data for the duration of the service relationship and for up to 90 days after termination, purely so that an export remains possible. After that period the data is deleted, unless the customer has requested earlier deletion or applicable law requires a longer period.
Suppression records are the deliberate exception. A do-not-contact entry is retained after deletion of the surrounding record, because deleting the evidence that someone opted out is how a suppressed contact gets messaged again.
14. Deletion
Customers may request deletion of Customer Data at any time through the dashboard or by email to support@bluereacher.com. Deletion completes within 30 days of a verified request, covers active databases and associated storage, and written certification is available on request.
Where a legal obligation requires a subset of data to be retained, for tax, fraud prevention or an active dispute, that subset is isolated from further processing and deleted as soon as the obligation expires.
15. International transfers
Blue Reacher processes Customer Data in United States infrastructure. Where Customer Data originates in the European Economic Area, the United Kingdom or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses, incorporated into this agreement by reference, with the UK International Data Transfer Addendum applied where relevant.
Blue Reacher carries out a transfer risk assessment for each such transfer and applies supplementary technical measures, encryption in transit and at rest chief among them, so that data in transit and at rest is unreadable to any party without the keys.
16. Audit and evidence
Blue Reacher makes available the information reasonably necessary to demonstrate compliance with this agreement, including a control mapping against the SOC 2 Trust Services Criteria, the subprocessor list, and a completed security questionnaire.
Where a customer's own regulatory obligation requires an audit, Blue Reacher will cooperate with a reasonable, scoped request at the customer's expense, no more than once in any twelve-month period outside of a breach.
17. Contact
Questions about this agreement, requests for a countersigned copy, business associate agreements, and data subject requests all go to support@bluereacher.com. Sagency International LLC is the contracting entity.
A countersigned copy, a completed security questionnaire and the SOC 2 control mapping are available on request. Ask on a demo call or by email and they come back the same week.