Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written or electronic agreement ("Agreement") between 2morrow.ai, LLC ("2morrow.ai," "Processor") and the business or organization using the yrFeedback service ("Vendor," "Controller").
This DPA governs the Processing of Personal Data by 2morrow.ai on behalf of the Vendor in connection with the provision of the yrFeedback service.
1. Definitions
- "CCPA" means the California Consumer Privacy Act of 2018, as amended (including by the CPRA).
- "Data Protection Laws" means all applicable worldwide legislation relating to data protection and privacy, including without limitation the European General Data Protection Regulation ("GDPR"), the UK GDPR, and the CCPA.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by 2morrow.ai on behalf of the Vendor.
- "Subprocessor" means any third-party data processor engaged by 2morrow.ai to process Personal Data on behalf of the Vendor.
- The terms "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" shall have the meanings given to them in the GDPR.
2. Roles of the Parties
The parties acknowledge and agree that with regard to the Processing of Personal Data under this DPA, Vendor is the Controller and 2morrow.ai is the Processor (or "Service Provider" under the CCPA). 2morrow.ai will process Personal Data only in accordance with Vendor's documented lawful instructions, which include the provisions of the Agreement and this DPA.
3. Details of Processing
The subject matter, nature, purpose, and duration of the Processing, as well as the types of Personal Data and categories of Data Subjects, are described in Schedule 1 to this DPA.
4. Subprocessing
4.1 Authorized Subprocessors. Vendor provides general authorization for 2morrow.ai to engage Subprocessors to fulfill its obligations under the Agreement. A current list of approved Subprocessors is maintained in Schedule 1.
4.2 Notice of Changes. 2morrow.ai shall notify Vendor of any intended changes concerning the addition or replacement of Subprocessors at least thirty (30) days prior to the change. If Vendor reasonably objects to the change on data protection grounds, Vendor may terminate the Agreement by providing written notice.
4.3 Subprocessor Obligations. 2morrow.ai shall enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA. 2morrow.ai remains fully liable for its Subprocessors' acts and omissions.
5. Security and Personal Data Breaches
5.1 Security Measures. 2morrow.ai shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure.
5.2 Breach Notification. If 2morrow.ai becomes aware of a confirmed Personal Data Breach, 2morrow.ai shall notify Vendor without undue delay (and in any event within 48 hours). 2morrow.ai will provide reasonable information and cooperation to assist Vendor in fulfilling its data breach reporting obligations under Data Protection Laws.
6. Data Subject Requests
2morrow.ai shall, to the extent legally permitted, promptly notify Vendor if 2morrow.ai receives a request from a Data Subject to exercise their rights under Data Protection Laws (such as the right to access, correct, or delete Personal Data). 2morrow.ai shall not respond to such requests directly without Vendor's prior written consent, except to direct the Data Subject to the Vendor. 2morrow.ai will provide reasonable assistance to Vendor to fulfill such requests via the service's functionality.
7. International Data Transfers
If the Processing involves the transfer of Personal Data originating from the European Economic Area (EEA), Switzerland, or the United Kingdom to a country not recognized as providing an adequate level of protection, the parties agree that such transfer shall be governed by the relevant standard contractual clauses ("SCCs") adopted by the European Commission, or the UK International Data Transfer Addendum, which are hereby incorporated by reference and completed as follows:
- Vendor is the "data exporter" and 2morrow.ai is the "data importer."
- Module Two (Controller to Processor) applies.
- The governing law shall be the laws of the EU member state in which the Vendor is established (or Ireland, if no such establishment exists).
8. Audits
Upon Vendor's written request at reasonable intervals, 2morrow.ai shall make available to Vendor information reasonably necessary to demonstrate compliance with this DPA, typically in the form of independent security audit reports or certifications. If such documentation is insufficient, Vendor may conduct an audit at its own expense, subject to a mutually agreed-upon scope and confidentiality obligations.
9. Deletion or Return of Data
Upon termination or expiration of the Agreement, Vendor shall have a thirty (30) day window to export their Personal Data. Following this period, 2morrow.ai shall securely delete all Personal Data in its possession or control in accordance with its retention policies, unless applicable law requires continued storage.
Schedule 1: Details of Processing
A. Nature and Purpose of Processing
2morrow.ai will process Personal Data to provide, maintain, and improve the yrFeedback service, including: routing feedback to the Vendor, screening for spam/abuse, classifying and summarizing feedback via AI subprocessors, and providing a dashboard for Vendor review.
B. Duration of Processing
For the duration of the Agreement plus a 30-day export window post-termination.
C. Categories of Data Subjects
End-Users of the Vendor's Calling App who submit feedback.
D. Types of Personal Data
- Free-text feedback submissions.
- Optional attached image files (screenshots).
- Identity data (email address, display name) if asserted by the Vendor via a signed token.
- Opaque user identifiers supplied by the Vendor.
- Environment metadata (OS, browser, viewport size, locale).
- IP addresses (processed transiently for rate-limiting and security).
E. Approved Subprocessors (as of July 2026)
- Google LLC (Gemini API): Automated classification, summarization, and scoring of text feedback. (Data is not used for model training).
- Supabase, Inc.: Database hosting, authentication services, and private file storage (US-West region).
- Vercel Inc.: Application hosting and edge function execution.
- Resend, Inc.: Transactional email delivery for platform notifications and user status updates.