Data Processing Addendum
The terms on which WAPGROWAI processes personal data as your processor - the subject matter, the security measures, sub-processors, transfers, and what happens on termination.
Roles
You are the controller of the personal data you send through the service - your contacts and their messages. WAPGROWAI is the processor. We process that data only on your documented instructions, which include your use of the product's features.
Meta acts as an independent controller for the data it processes in operating the WhatsApp Business Platform. That relationship is between you, Meta, and the platform terms you accepted when your number was onboarded.
Annex 1 - Details of processing
| ITEM | DETAIL |
|---|---|
| Subject matter | Provision of the WAPGROWAI messaging platform and related services |
| Duration | For the term of the agreement, plus the retention period you configure |
| Nature and purpose | Storing, transmitting, and displaying messages; automating conversations; analytics you configure |
| Categories of data subject | Your customers and prospects who message your WhatsApp number, and your own team members who use the product |
| Categories of personal data | Phone numbers, WhatsApp profile names, message content, attachments, conversation metadata, opt-in records, and any attributes you choose to store |
| Special category data | Not requested and not required. If your use case involves it — health, for example — you are responsible for having a lawful basis and for telling us, so we can assess whether additional measures apply |
Our obligations
- Process personal data only on your documented instructions, unless the law requires otherwise — in which case we will tell you first, unless the law forbids that too.
- Ensure that everyone authorised to access the data is bound by confidentiality.
- Implement the technical and organisational measures set out in Annex 2.
- Assist you, taking account of the nature of the processing, in responding to data subject requests.
- Assist you with data protection impact assessments and with consultations with a supervisory authority.
- Notify you without undue delay after becoming aware of a personal data breach, and in any event within 7 Days.
- Delete or return the data at the end of the agreement, as set out below.
- Make available the information needed to demonstrate compliance, and allow for audits as set out below.
Your obligations
- Ensure you have a lawful basis for the processing you instruct us to perform - including a valid opt-in for every contact you message.
- Provide the privacy notices your customers are entitled to. We cannot do this on your behalf.
- Configure retention, access, and deletion in the product in line with your own obligations.
- Not instruct us to do anything that would put us in breach of applicable data protection law. If you do, we will tell you and decline.
Annex 2 - Security measures
We maintain the following measures, and we may update them provided the level of protection is not reduced.
- Encryption of personal data in transit (TLS) and at rest.
- Role-based access control, with access granted on a least-privilege basis and reviewed periodically.
- Multi-factor authentication for administrative access to production systems.
- Logging of administrative access and privileged actions, retained for [LOG RETENTION].
- Network segregation, firewalling, and regular vulnerability scanning.
- Backups, with restoration tested at least [BACKUP TEST FREQUENCY].
- A documented incident response process, including breach notification.
- Personnel screening, confidentiality obligations, and mandatory security training.
- A secure development lifecycle, including code review and dependency scanning.
Sub-processors
You give general authorisation for us to engage sub-processors. The current list is maintained at [SUB-PROCESSOR LIST URL].
- We will give you at least 7 Days notice before adding or replacing a sub-processor.
- You may object on reasonable data protection grounds within that period.
- If we cannot resolve the objection, you may terminate the affected part of the service without penalty for the unexpired term.
- We impose data protection obligations on every sub-processor that are no less protective than those in this addendum, and we remain liable for their performance.
International transfers
Where we transfer personal data outside the UK or the EEA, we do so on the basis of an adequacy decision where one applies, and otherwise under the Standard Contractual Clauses (and the UK Addendum where relevant), supported by a transfer risk assessment.
You acknowledge that delivering a message through WhatsApp necessarily involves Meta's global infrastructure, and that this is inherent in the service you have asked us to provide.
Data subject requests
If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will tell them to contact you, and we will tell you about it promptly.
The product gives you the tools to search, export, and delete a contact's data yourself. Where you need more than the product provides, we will assist you.
Audit
On reasonable notice, no more than once a year (unless a regulator requires otherwise or a breach has occurred), you may audit our compliance with this addendum. In the first instance we will offer our current certification report and completed security questionnaire, which will usually satisfy the request.
Deletion and return
- On termination, you may export your data through the product for India.
- After that window, we delete the data from active systems within 7 Days.
- Backups age out on our normal cycle, within 7 Days, after which they are irretrievable.
- We may retain data where the law requires, and only for as long as it requires - for example, invoices for tax purposes.
Liability
Liability under this addendum is subject to the limitations in the Terms of Service, except where applicable data protection law says otherwise.