Skip to content

Data Processing Addendum

How RelayLine handles client information on your firm’s behalf. It forms part of the Terms of Service. Last updated October 3, 2026.

Roles and instructions

  • Your firm is the controller of Customer Data and RelayLine is its processor. We process Customer Data only to provide the service and on your documented instructions, which are these terms, your settings, and what your admins do in the product.
  • Subject matter: client relationship communications your firm chooses to send. Data subjects: your staff, your clients’ staff, and other people in those communications. Data types: names, email addresses, job titles, message and meeting content, call transcripts, and opinions expressed in them. We don’t ask for special category data; don’t send it unless you’ve decided you can.

Our commitments

  • Confidentiality of everyone with access; access limited to what’s needed.
  • The security measures on our Security page, including separate storage per firm, encryption in transit, encryption of stored email and transcript text, encrypted backups, two-factor sign-in, and audit logs.
  • Notice of a personal data breach affecting your Customer Data without undue delay, and within 72 hours of confirming it, with the information you need to meet your own obligations.
  • Help with data subject requests, security questionnaires, and impact assessments, using the export and delete tools in the product where possible.
  • At the end of the service: deletion of Customer Data within 30 days of account closure (after your export window), with backups expiring within 35 days.
  • Reasonable information to show compliance, and answers to your security questionnaire. We don’t yet hold a SOC 2 report.

Subprocessors

  • You authorize the subprocessors listed in our Privacy Policy. We’ll email your admins at least 30 days before adding or replacing one that processes Customer Data; you can object, and if we can’t resolve it, end the service for the affected part with a pro-rata refund.
  • We impose data protection terms on subprocessors at least as protective as these and remain responsible for them.

International transfers

  • Customer Data is processed in the United States. Where EU, UK, or Swiss law requires, the Standard Contractual Clauses (and UK addendum) apply and are incorporated by reference.