1. Roles and scope
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the SupportCore Terms of Service between Lord Systems, LLC ("Processor," "SupportCore," "we," "us") and the customer organization ("Controller," "you"). By accepting the Terms of Service, you agree to this DPA.
For the personal information contained in Customer Data — the tickets, chat messages, contact records, and attachments that you and your end-users submit through SupportCore — you are the Controller and SupportCore is the Processor, acting only on your documented instructions (your configuration and use of the service constitute those instructions). For your own administrator and billing account data, SupportCore is the Controller, as described in our Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of Customer Data to provide the SupportCore customer-support platform.
- Duration: the term of the Agreement, plus the retention and deletion windows described in Section 11.
- Nature and purpose: receiving, storing, routing, and displaying support communications; generating AI-assisted replies where enabled; producing analytics and reporting for you; and related support operations.
3. Categories of data subjects and personal data
- Data subjects: your end-users who contact your support, and your agents and administrators who use SupportCore.
- Personal data: names, email addresses, and other contact details; the content of support requests, chats, and attachments (which may contain whatever personal information your end-users include); and technical metadata such as IP address and user-agent. SupportCore does not require special-category data; you must not submit it without your own lawful basis.
4. Processor obligations
SupportCore will:
- process Customer Data only on your documented instructions, including for international transfers, unless required otherwise by law (in which case we will inform you unless legally prohibited);
- ensure personnel authorized to process Customer Data are bound by confidentiality;
- implement and maintain the technical and organizational measures in Section 6;
- assist you, taking into account the nature of processing, with data-subject requests (Section 9) and with your obligations regarding security, breach notification, and data-protection impact assessments;
- make available information necessary to demonstrate compliance and allow for audits per Section 10; and
- delete or return Customer Data per Section 11.
We do not sell or share personal information, and we do not use Customer Data for advertising or to train our own or any third party's AI models.
5. Sub-processors
You authorize SupportCore to engage sub-processors to process Customer Data. SupportCore imposes data-protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance. The current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, CDN, DDoS protection, SSL | Global edge |
| Cloudflare R2 | Object storage for ticket and KB attachments | EU / US (per region) |
| Stripe, Inc. | Payment processing and billing | United States |
| Auth0 (Okta, Inc.) | Optional customer-portal SSO and social login | United States / EU (per region) |
| OpenAI, L.L.C. | AI assist and AI bot replies (GPT-4o-mini). Inputs are not used to train OpenAI's models. | United States |
| Resend, Inc. | Transactional and inbound email delivery | United States |
| Sentry (Functional Software, Inc.) | Error monitoring and crash reporting | United States |
| PostHog, Inc. | First-party product analytics (no third-party cookies) | United States / EU |
The following process data about marketing-site visitors or internal operations rather than Customer Data, and are listed for completeness: Google LLC (Workspace) for internal email/collaboration, and Google LLC (Google Analytics 4) for cookieless, aggregate marketing-site analytics (no cookies, no cross-site tracking).
We maintain the authoritative list in our Privacy Policy (§7). We will give you prior notice of any new or replacement sub-processor and a window to object on reasonable data-protection grounds. To subscribe to change notifications, email privacy@supportcore.io.
6. Security measures
- Encryption in transit: TLS 1.2+ enforced for all connections.
- Encryption at rest: AES-256 at the storage layer for the database, backups, and attachments.
- Access control: role-based, least-privilege access; mandatory two-factor authentication for production access; audit logging of access to Customer Data.
- Operational security: vulnerability scanning, monitoring, and a documented incident-response process.
Further detail is available on our Security page.
7. International transfers
SupportCore is operated from the United States. Where Customer Data of data subjects in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses (2021/914) and the UK Addendum, the EU-U.S. Data Privacy Framework and UK Extension where the recipient is self-certified, and supplementary technical and organizational measures. This mirrors our Privacy Policy (§8).
8. Personal data breaches
SupportCore will notify you without undue delay after becoming aware of a personal data breach affecting your Customer Data, with the information reasonably needed for you to meet your own notification obligations.
9. Assistance with data-subject rights
Taking into account the nature of the processing, SupportCore provides tools and reasonable assistance to help you respond to data-subject requests (access, correction, deletion, restriction, objection, and portability) relating to Customer Data held in your workspace. Where an end-user contacts SupportCore directly about data we process on your behalf, we will refer them to you as the controller.
10. Audits
SupportCore will make available information reasonably necessary to demonstrate compliance with this DPA. Where you require further assurance, SupportCore may satisfy audit requests by providing its then-current third-party security reports, certifications, or a completed security questionnaire in lieu of an on-site audit, no more than once per 12-month period (or following a personal-data breach affecting your data), subject to confidentiality.
11. Retention, deletion, and return
We process Customer Data for the duration of your subscription and according to your configuration. When you cancel, we delete your workspace and Customer Data within 30 days, subject to encrypted backup rotation of up to 60 days, except where retention is required by law. On request during the term, we will return or delete Customer Data in a commercially reasonable format.
12. Liability and order of precedence
This DPA forms part of, and is governed by, the SupportCore Terms of Service. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. In the event of a conflict on matters of personal-data processing, this DPA controls; on all other matters, the Terms of Service control.
13. Acceptance and contact
This DPA is incorporated by reference into the SupportCore Terms of Service, which you accept when you create an account; accepting the Terms constitutes acceptance of this DPA. No separate signature is required. Customers who require a countersigned copy may request one at privacy@supportcore.io.
- Privacy: privacy@supportcore.io
- Data protection inquiries: dpo@supportcore.io
- Postal mail: Lord Systems, LLC — Attn: Privacy