Data Processing Agreement

This Data Processing Agreement (the "DPA") forms part of the Terms and Conditions (the "Agreement") between WANotifier Inc ("Processor", "WANotifier", "we", "us") and the customer ("Controller", "Customer", "you"), and applies whenever we process personal data on your behalf.

By accepting the Agreement, you accept this DPA. No signature is required. If your organization requires a countersigned copy, email [email protected].

Where this DPA conflicts with the Agreement on matters of personal data, this DPA prevails.


1. Definitions

"GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR and the Data Protection Act 2018. "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Sub-processor" and "Personal Data Breach" have the meanings given in the GDPR.

"Customer Personal Data" means personal data contained in Customer Data that we process on your behalf under the Agreement.


2. Roles of the Parties

You are the Controller of Customer Personal Data. We are the Processor. You determine the purposes and means of processing; we act on your instructions.

Customer warranties. You warrant that you have a lawful basis for the processing you instruct, that you have provided all required notices to your contacts, that you have obtained any consent required under applicable law including the WhatsApp Business Messaging Policy, and that your instructions do not breach applicable law.


3. Scope of Processing

The subject matter, duration, nature, purpose, types of personal data and categories of data subjects are set out in Annex I below.


4. Our Obligations

Processing on documented instructions. We process Customer Personal Data only on your documented instructions, including in relation to international transfers, unless required otherwise by law to which we are subject. In that case we will inform you before processing, unless the law prohibits it. The Agreement, this DPA, and your use of the Service constitute your documented instructions. If we believe an instruction infringes the GDPR, we will inform you.

Confidentiality. Personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive data protection training.

Security. We implement and maintain the technical and organizational measures set out in Annex II, appropriate to the risk, in accordance with Article 32 of the GDPR.

Sub-processors. We engage sub-processors only in accordance with Section 5.

Assistance with data subject rights. Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures in fulfilling your obligation to respond to requests under Chapter III of the GDPR. The Service provides self-service functionality for access, correction, export and deletion of Customer Personal Data. Where further assistance is required, we will provide it, and may charge a reasonable fee where the effort is disproportionate.

Assistance with compliance. We assist you in ensuring compliance with Articles 32 to 36 of the GDPR, including security of processing, personal data breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.

Deletion or return of data. On termination, at your choice, we will delete or return Customer Personal Data.

Unless you instruct otherwise, we retain Customer Personal Data for twelve (12) months after your subscription ends so that you can reactivate your account without loss of data. We will notify you at least thirty (30) days before the end of that period. After it expires, we delete Customer Personal Data from production systems within 30 days. Backups are retained on a rolling 7-day cycle, so deleted data is removed from backups within 7 days thereafter, except where retention is required by law.

You may instruct deletion or return at any time, regardless of account state, and we will action it within 30 days. Your instruction overrides the retention period above. You may also export your data through the Service at any time. This section operates together with Section 10 of the Agreement.

Demonstrating compliance. We make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR and allow for audits in accordance with Section 7 below.


5. Sub-processors

General authorization. You give general written authorization for us to engage sub-processors. Our current sub-processors are listed at https://trust.wanotifier.com/subprocessors.

Notification of changes. We will give at least fourteen (14) days' notice before adding or replacing a sub-processor. You may subscribe to notifications of changes on that page.

Right to object. You may object to a new sub-processor on reasonable data protection grounds within 14 days of notice. We will work with you in good faith to resolve your objection. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid Fees for the unused portion of the Term.

Our liability for sub-processors. We impose data protection obligations on sub-processors that are no less protective than those set out in this DPA, and we remain fully liable to you for their performance.

Group companies. You acknowledge that personnel of Fantastech Solutions Private Limited ("FSPL"), our affiliate in Pune, India, access Customer Personal Data to operate and support the Service under a written intra-group agreement incorporating the obligations in this DPA.


6. International Transfers

We process Customer Personal Data in India. Our sub-processors process it in the locations shown on our sub-processors page.

Where personal data protected by the GDPR or UK GDPR is transferred to a country without an adequacy decision, the transfer is governed by:

  • the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), incorporated into this DPA by reference and completed as set out in Annex III; and
  • for transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, incorporated by reference and completed as set out in Annex III.

Where the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.

We maintain a transfer risk assessment in respect of transfers to India and will provide a copy on request.


7. Audit

We make available a summary of our most recent independent security assessment and respond to reasonable security questionnaires no more than once per twelve (12) months.

Where this is not sufficient to demonstrate compliance with Article 28, you may audit us or appoint an independent auditor to do so, subject to: thirty (30) days' written notice; no more than once per twelve (12) months unless required by a supervisory authority or following a Personal Data Breach; conduct during normal business hours; no unreasonable disruption to our operations; execution of confidentiality undertakings; and at your cost.


8. Personal Data Breach

We will notify you without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and contact details for further information.

Notification is not an acknowledgement of fault or liability. You remain responsible for notifying your supervisory authority and affected data subjects where required.


9. Liability

Each party's liability under this DPA is subject to the limitations set out in Section 12 of the Agreement, except that nothing limits either party's liability to data subjects under Article 82 of the GDPR, or any liability that cannot lawfully be limited.


10. Term

This DPA takes effect when you accept the Agreement and continues until we have deleted or returned all Customer Personal Data in accordance with Section 4.


Annex I - Details of Processing

Controller: the Customer.

Processor: WANotifier Inc, 8 The Green #13143, Dover, DE 19901, USA.

Subject matter. Provision of the WANotifier WhatsApp Business messaging and automation platform.

Duration. The term of the Agreement, plus the retention and deletion period set out in Section 4.

Nature and purpose. Storing, organizing, transmitting and displaying contact and message data so that the Controller can communicate with its contacts via the WhatsApp Business Platform; providing analytics, automation, chatbot, team inbox and support functionality.

Categories of data subjects

  • The Controller's contacts and message recipients
  • The Controller's personnel who use the Service (Administrative Users and Chat Agents)

Categories of personal data

  • Identifiers: name, phone number, email address
  • Contact attributes: tags, custom fields, lifecycle stage, language, opt-in status
  • Communications: message content, media, attachments, timestamps, delivery and read status, conversation notes
  • Technical: IP address, device and browser information, access logs
  • Account: user names, email addresses, roles and permissions

Special categories of personal data

The Service is not designed for the processing of special category data. Depending on the Controller's sector and how it uses the Service, Customer Personal Data may nonetheless include data revealing health or other special categories, for example where a healthcare provider sends appointment reminders. The Controller is responsible for determining its lawful basis under Articles 6 and 9 of the GDPR, for meeting any sector-specific requirements, and for notifying us before processing special category data at scale so that additional safeguards can be agreed.

The Controller acknowledges that WANotifier provides a general-purpose business messaging platform and does not provide healthcare-specific or other sector-specific infrastructure. The Controller remains responsible for determining whether the Service is appropriate for its intended use, taking into account its own regulatory obligations.

WhatsApp phone numbers

For the Service to function, we process the WhatsApp phone numbers of the Controller's contacts. While not special category data, these are treated with additional safeguards given their potential for direct contact with individuals: strict purpose limitation to delivery of the Service; access limited to authorized personnel on a need-to-know basis; the technical and organizational measures set out in Annex II; and processing only on the Controller's instructions.

Frequency of transfer. Continuous.


Annex II - Technical and Organizational Measures

Access control

Role-based access control on the principle of least privilege. Multi-factor authentication on all administrative and production access. Periodic access reviews. Access revoked promptly on termination of employment or engagement.

Encryption

TLS 1.2 or above for data in transit. Encryption at rest for production databases and backups.

Network security

Firewall rules restricting access to production systems. Web application firewall and DDoS protection at the network edge.

Endpoint security

Company devices under centralized management with full-disk encryption, screen lock and operating system patch enforcement.

Secure development

Peer review of code changes before merge to production branches. Branch protection controls on production branches. Automated dependency and secret scanning. Separation of development, staging and production environments.

Logging and monitoring

Access and system logs retained and monitored. Alerting on anomalous activity. Continuous automated monitoring of security controls.

Resilience

Automated backups with a 7-day retention period. Periodic restoration testing to verify backup integrity. Documented business continuity and disaster recovery procedures.

Personnel

Confidentiality obligations for all personnel with access to Customer Personal Data. Security awareness training on joining and periodically thereafter. Acknowledgement of information security policies. Documented joiner, mover and leaver process.

Vendor management

Security assessment of sub-processors before engagement and periodically thereafter. Written data protection terms with each sub-processor.

Governance

Documented information security policies reviewed periodically. Documented incident response plan. Periodic risk assessment.


Annex III - Standard Contractual Clauses and UK Addendum

EU Standard Contractual Clauses - Module Two (Controller to Processor)

  • Clause 7 (Docking clause): does not apply
  • Clause 9 (Use of sub-processors): Option 2, general written authorization, with a notice period of 14 days
  • Clause 11 (Redress): the optional independent dispute resolution provision does not apply
  • Clause 17 (Governing law): the law of Ireland
  • Clause 18 (Choice of forum and jurisdiction): the courts of Ireland
  • Annex I.A (List of parties): as set out in Annex I above
  • Annex I.B (Description of transfer): as set out in Annex I above
  • Annex I.C (Competent supervisory authority): the supervisory authority of the Controller's place of establishment, as determined by application of Clause 13 of the EU SCCs
  • Annex II (Technical and organizational measures): as set out in Annex II above
  • Annex III (List of sub-processors): as published at https://trust.wanotifier.com/subprocessors

UK International Data Transfer Addendum

  • Table 1 (Parties): as set out in Annex I above
  • Table 2 (Selected SCCs): the EU Standard Contractual Clauses as completed above, Module Two
  • Table 3 (Appendix Information): as set out in Annexes I and II above
  • Table 4 (Ending the Addendum): neither party may end the Addendum as set out in Section 19

By entering into the Agreement and this DPA, the parties are deemed to have executed the Standard Contractual Clauses and, where applicable, the UK Addendum. If you require a signed copy in the official EU or UK template format, email [email protected].


Annex IV - Contacts

Privacy queries, data subject requests, and copies of our transfer safeguards or security documentation:

WANotifier Inc
8 The Green #13143,
Dover, DE 19901, USA
[email protected]

EU Representative (Article 27, EU GDPR)

Euverify Ltd (Ireland)
Unit 3D, North Point House, North Point Business Park
New Mallow Road, Cork, T23 AT2P, Ireland
[email protected]

UK Representative (Article 27, UK GDPR)

Euverify Ltd (UK)
3rd Floor, 86–90 Paul Street
London, EC2A 4NE, United Kingdom
[email protected]

Submitting a request

To submit a data subject access request, a deletion request, or any other GDPR-related enquiry, use our secure portal. This link also verifies our appointed representatives. Requests submitted through the portal are logged and tracked.


Last updated: 11th Sept, 2026

Get Started with WANotifier Today!