Data Processing Agreement
Last Updated: August 6, 2026
Effective: Immediately upon acceptance for accounts created on or after July 24, 2026; August 25, 2026 for accounts created earlier
Data Processing Terms
This Data Processing Agreement (DPA) governs the processing of personal data by NextGen Marketing and Automation LLC, operating under the brand name CommentKeyword, on behalf of our customers in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Definitions
For the purposes of this DPA, the following definitions apply:
- "Controller": The customer using CommentKeyword's services who determines the purposes and means of processing personal data
- "Processor": CommentKeyword, which processes personal data on behalf of the Controller
- "Personal Data": Any information relating to Instagram users whose data is processed through CommentKeyword
- "Processing": Any operation performed on personal data, including collection, recording, storage, retrieval, or deletion
- "Data Subject": Instagram users whose personal data is processed through CommentKeyword
- "Sub-processor": Third-party processors engaged by CommentKeyword to assist in data processing
2. Relationship of the Parties
The parties acknowledge and agree that with regard to the processing of personal data:
- The Customer acts as the Controller
- CommentKeyword acts as the Processor
- The Customer shall comply with its obligations as a Controller under applicable data protection laws
- CommentKeyword shall process personal data only on behalf of and in accordance with the Customer's documented instructions
- The Terms, the Customer's lawful configuration and use of the Service, and written support requests constitute the Customer's documented instructions
3. Processing Details
3.1 Subject Matter and Nature of Processing
CommentKeyword processes personal data to provide Instagram automation services, including:
- Monitoring Instagram comments for specified keywords
- Sending automated direct messages to Instagram users
- Managing conversation flows and AI-powered responses
- Providing analytics and reporting on engagement metrics
3.2 Categories of Personal Data
- Identity Data: Instagram usernames, display names, profile information
- Contact Data: Direct message content, comment text
- Behavioral Data: Engagement patterns, response times, interaction history
- Technical Data: Instagram user IDs, post IDs, timestamp data
3.3 Categories of Data Subjects
- Instagram users who comment on the Customer's posts
- Instagram users who receive automated direct messages
- Instagram users who engage with the Customer's content
3.4 Retention Period
Personal data will be retained for the duration necessary to provide the services, typically:
- Active Conversations: Retained while the conversation is ongoing
- Completed Conversations: Retained as needed for inbox history, analytics, export, support, and audit functionality
- Historical Analytics: Aggregated or de-identified analytics may be retained for product and reporting purposes
- Account Termination: Deleted or returned in accordance with Section 10, subject to legal retention duties and backup schedules
4. Customer Obligations
The Customer warrants and undertakes that:
- It has the legal right to process all personal data provided to CommentKeyword
- It has obtained all necessary consents from data subjects where required
- It complies with Instagram's Terms of Service and privacy requirements
- It will use Meta Platform Data only for lawful purposes and in accordance with Meta's Platform Terms, Developer Policies, and applicable product terms
- It will inform CommentKeyword promptly of any data subject requests or regulatory inquiries
- It will not instruct CommentKeyword to process data in violation of applicable laws
5. CommentKeyword Obligations
5.1 Processing Instructions
- Process personal data only in accordance with the Customer's documented instructions
- Inform the Customer without undue delay if instructions appear to violate applicable data protection laws, unless applicable law prohibits that notice
- Not process personal data for any other purposes than providing the contracted services
- Process data received from Meta only as permitted by Meta's Platform Terms, Developer Policies, applicable product terms, and the permissions granted to the Service
- Not sell Meta Platform Data or use it for surveillance, unlawful discrimination, or another purpose prohibited by Meta
5.2 Confidentiality and Security
- Ensure that each person authorized to process personal data is subject to an appropriate duty of confidentiality
- Maintain technical and organizational measures appropriate to the nature of the processing and reasonably available to a service of CommentKeyword's size and risk profile
- Use encrypted transport for production service traffic and rely on configured hosting and database-provider encryption at rest where appropriate
- Encrypt stored Instagram access tokens, restrict access to credentials and Platform Data, and avoid exposing credentials in application logs
- Restrict production access and maintain security or operational logs where appropriate for the Service
5.3 Data Subject Rights
CommentKeyword will assist the Customer in responding to data subject requests, including:
- Access Rights: Providing copies of personal data when requested
- Rectification: Correcting inaccurate personal data
- Erasure: Deleting personal data when legally required
- Portability: Providing data in machine-readable format
- Restriction: Limiting processing when requested
5.4 Current Technical Measures
CommentKeyword's current application-level measures include:
- Server-side authentication, workspace membership checks, and separate authorization for administrative functions
- AES-256-GCM encryption for stored Instagram access tokens, with encryption keys kept in production environment configuration
- Encrypted HTTPS transport for production web and third-party API traffic, with access tokens sent in authorization headers where supported
- Signature or shared-secret verification for supported Meta, Stripe, scheduled-task, and operational endpoints
- Runtime input validation, rate limits for abuse-prone flows, cross-site request protections, and restrictions on customer-configured outbound webhook destinations
- Data minimization in application logs, production restrictions on diagnostic routes, and dependency vulnerability review
- Automated removal or de-identification of applicable Meta Platform Data following a verified Meta deletion request
6. Sub-processors
6.1 Authorized Sub-processors
The Customer consents to CommentKeyword's use of the following sub-processors:
| Service Provider | Service | Processing Region |
|---|---|---|
| Railway | Cloud hosting and infrastructure | Configured Railway deployment region; may include the United States |
| Supabase | Database services | Configured Supabase project region; may include the United States |
| OpenRouter/OpenAI | AI processing for enabled AI features, including prompts, instructions, and conversation context where needed | Varies by selected model and provider; may include the United States |
| Mailgun | Email delivery services | Configured Mailgun sending region; may include the United States |
| Google Analytics | Optional website and product usage analytics when permitted by the user's analytics preference | May include the United States and other Google processing locations |
| Microsoft Clarity | Optional usage diagnostics, heatmaps, and session replay when permitted by the user's analytics preference | May include the United States and other Microsoft processing locations |
6.2 Sub-processor Changes
- CommentKeyword will require each sub-processor to protect Customer Personal Data under written terms appropriate to the processing
- CommentKeyword will provide at least 7 calendar days' advance notice of a new sub-processor where reasonably practicable
- Customers may object to new sub-processors on reasonable data protection grounds
- If objections cannot be resolved, either party may terminate the agreement
- A change may occur sooner where required by law, security needs, service continuity, or a third-party platform requirement; CommentKeyword will provide notice as soon as reasonably practicable
6.3 Independent Platforms and Service Providers
Meta provides the Instagram and Facebook platform services, Google provides optional social login, and Stripe provides payment services. Those providers may act as independent controllers or under their own terms for the data they receive directly and are not treated as CommentKeyword sub-processors merely because the Customer chooses to use the relevant integration. CommentKeyword's use of Meta APIs and Platform Data remains subject to Meta's Platform Terms, Developer Policies, and applicable product terms.
7. Data Transfers
For transfers of personal data outside the European Economic Area (EEA):
- CommentKeyword implements appropriate safeguards as required by applicable law
- The parties will use applicable Standard Contractual Clauses (SCCs) or another lawful transfer mechanism where required
- CommentKeyword will provide reasonably available information needed to document the applicable transfer mechanism
- Customers will be notified of any changes to transfer mechanisms
8. Data Breach Notification
8.1 Incident Response
In the event of a personal data breach, CommentKeyword will:
- Notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data
- Provide information reasonably available to CommentKeyword about the nature and scope of the breach
- Describe measures taken or proposed to address the breach and mitigate harm
- Provide reasonable assistance with legally required notifications, taking into account the nature of processing and information available to CommentKeyword
8.2 Breach Information
Breach notifications will include:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
9. Data Protection Impact Assessment
CommentKeyword will provide reasonable assistance to the Customer in conducting Data Protection Impact Assessments (DPIAs) where required by law, including:
- Technical and organizational measures implemented
- Security certifications or independent audit reports, if maintained and reasonably available
- Information about data processing activities
- Risk mitigation strategies
10. Return and Deletion of Data
Upon termination of the agreement or upon Customer request:
- At the Customer's choice, CommentKeyword will delete or return Customer Personal Data after termination, unless applicable law requires retention
- Deletion from active systems will be completed within a commercially reasonable period after a valid request
- CommentKeyword will provide written confirmation of deletion upon reasonable request
- Residual backup copies will remain protected and will be deleted or overwritten according to applicable provider backup schedules
- CommentKeyword will delete or de-identify Meta Platform Data when required by Meta's terms, a valid Meta data-deletion request, loss of the relevant permission, or applicable law
Self-service account deletion immediately disables the user account and removes that user's workspace membership. Where a complete workspace-level return, restriction, or deletion is not available through a self-service feature, the Customer must submit a verified request through the contact channel in Section 16. CommentKeyword will then complete the request using available automated and manual administrative tools.
11. Audits and Compliance
11.1 Audit Rights
- CommentKeyword will first satisfy audit requests through current documentation and written responses reasonably sufficient to demonstrate compliance
- If that information is insufficient and applicable law requires additional audit rights, the Customer may conduct one appropriately scoped audit per year, or more frequently following a qualifying breach or regulator request
- Audits require at least 30 days' advance notice unless a shorter period is legally required, must occur during normal business hours, and must not expose other customers' data or security-sensitive information
- The Customer must ensure its auditor is independent, non-competitive, and bound by confidentiality, and will bear its audit costs unless applicable law requires otherwise
11.2 Compliance Documentation
CommentKeyword will make available information necessary to demonstrate compliance, including:
- Security certifications and attestations, if any
- Third-party audit reports, if any and subject to confidentiality and third-party restrictions
- Documentation of technical and organizational measures
- Information about relevant confidentiality, security-awareness, and data-protection practices
12. Liability and Indemnification
- To the maximum extent permitted by applicable law, each party's liability under this DPA is subject to the exclusions and limitations in the Terms
- Nothing in this DPA limits liability or data-subject rights that cannot lawfully be limited
- The Customer remains responsible for its processing purposes, legal basis, notices, consents, instructions, and use of the Service
- The parties will reasonably cooperate in responding to regulatory investigations or third-party claims relating to the processing
13. Term and Termination
- This DPA remains in effect for the duration of the main service agreement
- This DPA terminates when CommentKeyword no longer processes Customer Personal Data, subject to surviving deletion, confidentiality, and legal obligations
- Termination does not affect obligations that arose before termination
- Data return and deletion obligations survive termination
14. Amendments and Updates
This DPA may be updated to reflect:
- Changes in applicable data protection laws
- Regulatory guidance or supervisory authority requirements
- Changes in CommentKeyword's data processing practices
- Updates to sub-processor arrangements
Material changes that materially adversely affect Customer rights will be communicated at least 7 calendar days in advance where reasonably practicable. Changes required by law, security needs, service continuity, or Meta or another third-party platform requirement may take effect sooner, with notice provided as soon as reasonably practicable.
15. Governing Law and Jurisdiction
This DPA is governed by the same law as the main service agreement. Disputes will be resolved in accordance with the dispute resolution procedures set forth in the main agreement.
16. Contact Information
For questions about this DPA or data protection matters:
- Privacy Requests: Submit a privacy request
- Legal Inquiries: Submit a legal inquiry
- Security or Data Protection Questions: Contact us