Effective Date: August 10, 2026
Last Updated: August 19, 2026

Purpose

This Data Processing & Security Addendum (“DPSA”) forms part of the agreement between MessageWatcher and Customer and supplements the Services Terms and Conditions.

This Addendum describes how MessageWatcher processes Customer Data while providing the Services and outlines our respective responsibilities regarding privacy, confidentiality, and information security.

If an executed Order Form or written agreement contains provisions that conflict with this Addendum, the executed agreement controls to the extent of that conflict.

Scope

This Addendum applies whenever MessageWatcher processes Customer Data on behalf of Customer while providing the Services.

It applies regardless of whether Customer Data includes:

  • communications;
  • archived messages;
  • files;
  • attachments;
  • metadata;
  • account information; or
  • other information submitted to or processed by the Services.

This Addendum does not govern personal information MessageWatcher collects directly through its public website, which is addressed in our Privacy Policy.

Roles and Responsibilities

For Customer Data processed through the Services:

  • Customer acts as the organization determining the purposes and means of processing Customer Data.
  • MessageWatcher processes Customer Data only on Customer’s documented instructions and as necessary to provide the Services.

Customer is responsible for:

  • determining what information is collected;
  • establishing appropriate retention policies;
  • obtaining required authorizations or consents;
  • complying with applicable employment, privacy, and regulatory requirements; and
  • responding to requests from individuals concerning Customer Data.

MessageWatcher is responsible for processing Customer Data in accordance with the applicable agreements and implementing appropriate technical and organizational safeguards.

Processing Instructions

MessageWatcher will process Customer Data only as reasonably necessary to:

  • provide the Services;
  • maintain and support the Services;
  • improve the security, reliability, and availability of the Services;
  • comply with applicable law; and
  • fulfill obligations under the applicable agreement.

We will not process Customer Data for our own marketing purposes.

We will not sell Customer Data.

Except as required by law or expressly authorized by Customer, we will not disclose Customer Data to third parties except to authorized service providers performing services on our behalf.

MessageWatcher may use artificial intelligence technologies to assist in creating policies, rules, or other criteria used by the Services. Customer Data is not submitted to or processed by third-party artificial intelligence providers for this purpose. Any searching, analysis, or evaluation of Customer Data using those policies, rules, or criteria occurs within MessageWatcher’s systems.

Security Program

MessageWatcher maintains a comprehensive information security program designed to protect Customer Data against unauthorized access, disclosure, alteration, and destruction.

Our security program includes administrative, technical, and physical safeguards appropriate to the nature of the Services and the information entrusted to us.

Security measures include, as appropriate:

  • access controls;
  • authentication procedures;
  • encryption where appropriate;
  • network security controls;
  • vulnerability management;
  • system monitoring;
  • employee security awareness;
  • change management procedures;
  • backup and recovery procedures; and
  • incident response processes.

We continually review and improve our security program to address evolving risks and industry practices.

SOC 2

MessageWatcher maintains a SOC 2 Type II examination covering the applicable systems and controls within the scope of the assessment.

Upon reasonable request and subject to appropriate confidentiality protections, MessageWatcher may make relevant assurance documentation available to qualified customers to support security and compliance reviews.

Nothing in this Addendum requires MessageWatcher to disclose information that could compromise the security of its systems or other customers.

Confidentiality

All MessageWatcher personnel with access to Customer Data are subject to appropriate confidentiality obligations.

Access to Customer Data is limited to personnel who require access to perform their assigned responsibilities.

MessageWatcher maintains policies and procedures designed to prevent unauthorized access to Customer Data.

Authorized Service Providers

MessageWatcher may engage carefully selected third-party service providers to assist in operating the Services.

Where those providers process Customer Data on MessageWatcher’s behalf, MessageWatcher requires appropriate contractual obligations designed to protect Customer Data consistent with applicable law and this Addendum.

Current providers may include services supporting:

  • website hosting;
  • cloud infrastructure;
  • website security;
  • email delivery;
  • website analytics; and
  • other operational functions necessary to provide the Services.

Additional information regarding material service providers may be made available upon reasonable request where appropriate.

International Data Transfers

MessageWatcher is headquartered in the United States. Customer Data may be processed or stored in the United States or other jurisdictions where MessageWatcher or its authorized service providers operate.

Where applicable law requires safeguards for international transfers of personal information, MessageWatcher will implement appropriate transfer mechanisms and contractual protections designed to provide an adequate level of protection for Customer Data.

MessageWatcher will cooperate reasonably with Customer to support Customer’s compliance obligations relating to international data transfers, to the extent required by applicable law and consistent with the Services.

Security Incidents

MessageWatcher maintains policies and procedures designed to identify, investigate, respond to, and recover from security incidents affecting Customer Data.

If MessageWatcher becomes aware of a confirmed security incident involving Customer Data that is reasonably likely to require notification under applicable law or contractual obligation, we will:

  • promptly investigate the incident;
  • take commercially reasonable steps to contain and remediate the incident;
  • notify Customer without unreasonable delay after confirming the incident, taking into account the need to understand its nature and scope; and
  • provide information reasonably necessary to assist Customer in meeting applicable notification obligations.

Nothing in this Addendum requires MessageWatcher to provide information that could compromise ongoing investigations, other customers, or the security of our systems.

Customer Assistance

Taking into account the nature of the processing and the information available to us, MessageWatcher will provide reasonable assistance to Customer regarding:

  • requests from individuals exercising applicable privacy rights;
  • regulatory inquiries relating to Customer Data;
  • privacy impact assessments where appropriate;
  • security documentation reasonably requested during Customer due diligence; and
  • compliance with applicable privacy laws to the extent our assistance is reasonably required.

Where a request relates to Customer Data controlled by Customer, Customer remains responsible for determining how that request should be handled.

Audits and Compliance Information

MessageWatcher recognizes that many customers operate in regulated industries requiring vendor due diligence.

Upon reasonable request and subject to appropriate confidentiality protections, MessageWatcher may provide documentation reasonably necessary to demonstrate our security and compliance program.

Such documentation may include, where appropriate:

  • security policies;
  • SOC 2 reports or summaries;
  • compliance questionnaires;
  • security architecture information at an appropriate level of detail; and
  • other information reasonably necessary for Customer’s vendor review process.

Customer agrees not to disclose confidential security documentation except as necessary to complete legitimate compliance reviews.

Data Return and Deletion

Upon expiration or termination of the Services, Customer may retrieve Customer Data in accordance with the Services Terms and applicable Order Form.

Following the applicable retention period described in the Services Terms, MessageWatcher may securely delete Customer Data from active systems unless:

  • applicable law requires longer retention;
  • Customer requests continued retention under an applicable agreement; or
  • deletion is not technically feasible within the applicable timeframe.

Reasonable backup retention practices may result in temporary continued storage of Customer Data within secure backup systems until those backups are overwritten through normal operational processes.

Changes to this Addendum

MessageWatcher may update this Addendum from time to time to reflect:

  • changes in applicable privacy law;
  • changes in security practices;
  • improvements to the Services;
  • regulatory guidance; or
  • operational requirements.

Material changes will become effective in accordance with the applicable agreement or by providing reasonable notice to affected Customers.

No modification will materially reduce MessageWatcher’s security commitments during an active subscription without providing Customer appropriate notice.

Order of Precedence

If there is a conflict between:

  • an executed Order Form;
  • these Services Terms;
  • this Data Processing & Security Addendum; or
  • another incorporated agreement,

the following order of precedence applies unless expressly stated otherwise in the applicable Order Form:

  • Executed Order Form
  • Data Processing & Security Addendum
  • Services Terms and Conditions
  • Acceptable Use Policy
  • Privacy Policy
  • Website Terms of Use

This ordering applies only to the extent necessary to resolve an actual conflict.

Contact Information

Questions regarding this Data Processing & Security Addendum may be directed to:

MessageWatcher, LLC

Email: [email protected]

Website: messagewatcher.com

Mail:

7900 E. Union Ave.
Suite 1100
Denver, CO 80237

Related Legal Documents