R
R
RERIGHT
  • Products
    PLATFORMS
    AI Chatbot PlatformMulti-model. Voice-enabled. Proactive.Agent Orchestration PlatformAutonomous agent squads for your operations.Enterprise Analytics DashboardThe intelligence layer your AI is missing.View All Products →
    PROPRIETARY FRAMEWORKS
    AI Governance PlaybookComplete governance framework — NIST, ISO 42001, EU AI ActAI Agent BlueprintArchitecture for replacing middleware with agentsRAG in Banking Playbook6-layer RAG designed for regulated financial servicesAI Risk Detection SystemReal-time monitoring and routing for AI governanceView All Frameworks →
  • Services
    CONSULTING SERVICES
    AI Governance AuditComplete AI footprint visibility in 5 daysRAG Implementation6-layer architecture for regulated industriesEnterprise Agent DeploymentReplace middleware with AI agentsFintech & Document AIAutomated extraction for financial documentsE-Commerce AIAI agents for SFCC, SAP Commerce, MagentoMiddleware ReplacementReplace MuleSoft/TIBCO at 20% of costView All Services →
    INDUSTRY SOLUTIONSAI built for your specific sector
    Financial ServicesHealthcare & Life SciencesLegal & ProfessionalManufacturing & IndustrialRetail & E-CommerceView all 51 industries →
  • BY SECTOR
    Financial ServicesBanking, insurance, asset management, fintechHealthcare & Life SciencesHospitals, health systems, pharma, medtechLegal & Professional ServicesLaw firms, legal operations, complianceManufacturing & IndustrialFactory AI, SCADA replacement, supply chainRetail & E-CommerceSFCC, SAP Commerce, Magento, Shopify Plus
    ENTERPRISE FUNCTIONS
    Finance & Accounting AIReconciliation, reporting, document extractionHR & Talent AIScreening, onboarding, compliance, analyticsLegal & Compliance AIContract review, regulatory monitoring, e-discoverySales & Marketing AILead intelligence, content, outreach, analyticsOperations & Supply Chain AIMiddleware replacement, agent orchestration, monitoring
    Browse all 51 industries →
  • Free Tools
    FREE DIAGNOSTIC TOOLS
    AI Governance Score10 questions. Score out of 100. 4 minutes.RAG Pipeline CalculatorBuild cost + monthly ops + break-even. 2 minutes.Middleware Savings CalculatorYour exact savings vs current platform. 2 minutes.All Free Tools →
  • Blog
  • News
·

LEGAL

Data Processing Agreement

Last updated: May 18, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between RERIGHT ("Processor") and the entity engaging RERIGHT's consulting services or subscribing to RERIGHT's platform services ("Controller") for the processing of personal data. This DPA applies when RERIGHT processes personal data on behalf of a client in connection with consulting engagements, platform access, or API services. This DPA does not apply to RERIGHT's processing of personal data as a controller (e.g., website visitor data, newsletter subscribers), which is governed by our Privacy Policy.

On this page

  1. 01Definitions
  2. 02Scope of Processing
  3. 03RERIGHT's Obligations
  4. 04Subprocessors
  5. 05Data Transfers
  6. 06Security Measures
  7. 07Data Breach Notification
  8. 08Audits
  9. 09Term and Termination
  10. 10Contact

01Definitions

"Personal Data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, or destruction. "Subprocessor" means any third party engaged by RERIGHT to process Personal Data on behalf of the Controller.

02Scope of Processing

RERIGHT processes Personal Data only as necessary to perform the services described in the applicable engagement agreement or service terms. The categories of data, data subjects, and purposes of processing are defined in the specific engagement agreement between the parties.

03RERIGHT's Obligations

RERIGHT shall:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law
  • Ensure that persons authorized to process Personal Data have committed to confidentiality
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
  • Assist the Controller in responding to data subject access requests and other rights requests
  • Assist the Controller in ensuring compliance with data breach notification obligations
  • Delete or return all Personal Data to the Controller at the end of the engagement, unless retention is required by law
  • Make available to the Controller all information necessary to demonstrate compliance with these obligations

04Subprocessors

RERIGHT maintains a current list of subprocessors. The list is provided to Controllers under signed DPA upon request — email vijay@reright.io. RERIGHT will notify the Controller of any intended changes to subprocessors, giving the Controller a reasonable opportunity to object. If the Controller raises a reasonable objection and RERIGHT cannot accommodate it, either party may terminate the affected services upon written notice.

05Data Transfers

If Personal Data is transferred outside the jurisdiction of the Controller, RERIGHT will ensure appropriate safeguards are in place, including standard contractual clauses or other mechanisms recognized under applicable data protection law.

06Security Measures

  • Encryption of data in transit using TLS/HTTPS and at rest where applicable
  • Access controls limiting data access to authorized personnel only
  • Regular encrypted backups to secure offsite storage (Backblaze B2)
  • Monitoring for unauthorized access or anomalous activity
  • Secure server infrastructure hosted in professional data centers (Hetzner, Helsinki, EU)

07Data Breach Notification

RERIGHT will notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

08Audits

Upon reasonable request and subject to confidentiality obligations, RERIGHT will make available information necessary to demonstrate compliance with this DPA. RERIGHT will allow and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable advance notice and scope limitations.

09Term and Termination

This DPA remains in effect for the duration of the engagement agreement. Upon termination, RERIGHT will delete or return all Personal Data processed on behalf of the Controller within 30 days, unless retention is required by applicable law.

10Contact

For DPA inquiries or to request an executed copy:

Organization:RERIGHT
Email:vijay@reright.io
Website:reright.io
→ Privacy Policy→ Terms of Service→ Cookie Policy→ Acceptable Use PolicyQuestions? Contact us →
R
R
RERIGHT

Redefine. Rebuild. Rewrite.

Enterprise AI. Deployed. We build AI systems enterprises own forever — governed from day one, grounded in your data, running in weeks.

PRODUCTS

  • AI Chatbot Platform
  • Agent Orchestration
  • Enterprise Analytics
  • Frameworks & Playbooks

SERVICES

  • AI Governance
  • RAG Implementation
  • Enterprise Agents
  • Middleware Replacement
  • E-Commerce AI
  • Fintech & Document AI

SOLUTIONS

  • Financial Services
  • Healthcare
  • Legal
  • Manufacturing
  • E-Commerce
  • All 51 Industries

FREE TOOLS

  • Governance Score
  • RAG Calculator
  • Middleware Savings
  • All Free Tools

COMPANY

  • About
  • Blog
  • News
  • Pricing
  • Contact

© 2026 Reright.io — Enterprise AI. Deployed.

PrivacyTermsDPACookiesAcceptable Use