Back to home
Draft — not yet reviewed by a lawyer. This is a binding contract template; replace bracketed placeholders and get legal review before asking any tenant to rely on it.

Data Processing Agreement

Last updated: [DATE]

Parties

This Data Processing Agreement (“DPA”) is entered into between [COMPANY NAME] (“Processor”, “we”), based in [JURISDICTION], and the business entity that has registered a tenant account for the Service (“Controller”, “you”). It supplements and is incorporated by reference into our Terms of Service, and applies whenever we process personal data on your behalf as part of the Service.

1. Definitions

  • “Applicable Data Protection Law” — GDPR, UK GDPR, and any other data protection law applicable to the processing under this DPA.
  • “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor” — as defined in Applicable Data Protection Law.
  • “Sub-processor” — any third party engaged by us to process Personal Data on your behalf in providing the Service (see Appendix B).
  • “End Customer Data” — Personal Data of your customers, contacts, or leads that is processed through the Service (e.g. WhatsApp/Instagram/Facebook message content, phone numbers, names, images, and voice recordings).

2. Subject Matter, Duration, Nature and Purpose

The subject matter, duration, nature, and purpose of processing, the categories of data subjects, and the categories of Personal Data are set out in Appendix A. This DPA remains in effect for as long as we process End Customer Data on your behalf under the Terms of Service.

3. Processor Obligations

We will:

  • Process End Customer Data only on your documented instructions — including as set out in the Terms of Service and this DPA, or as otherwise agreed in writing — unless required to do otherwise by law, in which case we will inform you before processing (unless prohibited from doing so).
  • Ensure persons authorized to process End Customer Data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Appendix C.
  • Engage Sub-processors only as permitted under §4 below.
  • Taking into account the nature of the processing, assist you by appropriate technical and organizational measures, insofar as reasonably possible, in responding to requests from data subjects exercising their Applicable Data Protection Law rights.
  • Assist you in ensuring compliance with your obligations relating to the security of processing, breach notification, and data protection impact assessments, taking into account the information available to us.
  • At your election, delete or return all End Customer Data at the end of the provision of the Service, and delete existing copies unless we are required by law to retain it — see Privacy Policy §4 and the current retention timeline.
  • Make available to you information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable notice, confidentiality, and no more than [FREQUENCY, e.g. once per 12 months] absent a suspected breach.

4. Sub-processors

You authorize us to engage the Sub-processors listed in Appendix B as of the date of this DPA. We will give you notice of any intended addition or replacement of a Sub-processor at least [NOTICE PERIOD, e.g. 30 days] in advance (e.g. by email or in-app notice), giving you an opportunity to object on reasonable data-protection grounds. Each Sub-processor is bound by written terms that impose data protection obligations no less protective than this DPA, and we remain liable for each Sub-processor’s performance of those obligations.

5. International Transfers

Where processing of End Customer Data involves a transfer outside the EEA/UK, such transfer will be made subject to an appropriate safeguard recognized under Applicable Data Protection Law (e.g. the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision) — [CONFIRM ACTUAL MECHANISM WITH COUNSEL AND EACH SUB-PROCESSOR’S OWN TRANSFER TERMS before relying on this clause].

6. Personal Data Breach Notification

We will notify you without undue delay, and in any event within [TIMEFRAME, e.g. 72 hours] of becoming aware, after becoming aware of a Personal Data Breach affecting End Customer Data, and will provide information reasonably necessary for you to meet any breach-notification obligations you have to a supervisory authority or affected data subjects.

7. Liability

[Liability, indemnification, and limitation-of-liability terms for this DPA — coordinate with the Limitation of Liability clause in the Terms of Service and get counsel review. Not drafted here; a generic clause risks either under-protecting you or creating unintended exposure.]

8. Term and Termination

This DPA takes effect on the date you accept the Terms of Service and continues until the Service is terminated and all End Customer Data has been deleted or returned under §3.

9. Governing Law

This DPA is governed by the laws of [JURISDICTION], consistent with the Terms of Service.

10. Contact

Questions about this DPA, Sub-processor changes, or to exercise an audit right: [SUPPORT EMAIL].

Appendix A — Details of Processing

  • Subject matter: provision of an AI-powered messaging assistant that generates and sends replies to your customers over WhatsApp, Instagram, and Facebook on your behalf.
  • Duration: for the term of your subscription to the Service, as described in §8.
  • Nature and purpose: receiving inbound messages, generating AI replies (including text generation, voice transcription, image and — as of [DATE] — document/video analysis), storing conversation history for context and your review, and providing you with a dashboard to view and manage conversations.
  • Categories of data subjects: your customers, leads, and contacts who message your connected WhatsApp/Instagram/Facebook account.
  • Categories of personal data: phone number or platform identifier, name (where provided), message content (text, images, voice recordings, documents, videos), and any personal data your customers choose to include in their messages.

Appendix B — Authorized Sub-processors

  • OpenAI — processes message content to generate AI replies, transcriptions, and image/document analysis. [Location / transfer mechanism to confirm.]
  • Supabase — hosts the application database and handles authentication. [Location / transfer mechanism to confirm.]
  • Stripe — processes credit purchases; does not receive End Customer Data. [Location / transfer mechanism to confirm.]
  • Meta (WhatsApp/Instagram/Facebook) — the messaging platforms End Customer Data is transmitted through. [Location / transfer mechanism to confirm.]

This list must be kept in sync with the subprocessor list in the Privacy Policy — treat one as the source of truth and link the other, rather than maintaining both independently.

Appendix C — Technical and Organizational Security Measures

  • Per-tenant data isolation enforced at the database level via row-level security (RLS), not application-level filtering alone.
  • Password hashing; credentials are never stored in plain text.
  • Payment card data is handled entirely by Stripe and never touches our servers.
  • Access to production data is limited to [ROLES/PROCESS — describe actual internal access controls].
  • [Add: encryption at rest/in transit specifics, backup policy, incident response process, employee confidentiality/training — describe what is actually in place, not aspirational measures.]