DATA PROCESSING AGREEMENT
Document key: DPA · Version: 2.0
2.1 Roles
2.1.1 In respect of personal data contained in Client Data, the Client is the Data Fiduciary and Wapzio is the Data Processor within the meaning of the DPDP Act, 2023.
2.1.2 In respect of personal data of the Client's own Users, billing contacts and support requesters, and of Wapzio Operational Data, Wapzio is the Data Fiduciary and its Privacy Policy applies.
2.1.3 The Client acknowledges that section 8(1) of the DPDP Act places responsibility for compliance on the Data Fiduciary, including for processing undertaken by a processor on its behalf, and that the Client bears that responsibility in respect of Client Data.
2.1.4 Wapzio does not determine the purpose or means of processing Client Data. If Wapzio ever does so for a particular processing operation, it becomes a Data Fiduciary for that operation and will say so expressly.
2.2 Instructions
2.2.1 Wapzio processes Client Data only on the Client's documented instructions, which comprise: this DPA, the Terms, the Order Form, the Documentation, and configurations and actions taken by the Client in the Services.
2.2.2 Wapzio may process Client Data without instruction where required by Applicable Law or a lawful order, and where necessary for security, fraud prevention, abuse detection, service integrity, metering and billing.
2.2.3 If Wapzio considers an instruction to infringe Applicable Law, it will notify the Client and may suspend performance of that instruction. Notification is not legal advice and does not transfer responsibility to Wapzio.
2.3 Client obligations
The Client shall, in respect of all Client Data: establish and maintain a valid lawful basis and, where required, valid consent; issue s.5 notices to data principals; maintain consent evidence and produce it on request within 48 hours; honour withdrawal and rights requests; not submit special categories of data, financial account data, health data, biometric data, government identifiers (including Aadhaar) or children's data to the Services unless expressly agreed in writing in Annex A; and not instruct any processing that would cause Wapzio to breach Applicable Law or the Meta Terms.
The Client indemnifies Wapzio against all claims, penalties and losses arising from breach of this clause 2.3, without limitation of liability.
2.4 Confidentiality and personnel
Wapzio limits access to Client Data to personnel who need it, who are bound by written confidentiality obligations surviving termination, and who receive periodic data-protection and security training. Access is role-based, logged, and reviewed at least quarterly.
2.5 Security
Wapzio implements the technical and organisational measures set out in Annex B, which are designed to meet the "reasonable security safeguards" standard under section 8(5) of the DPDP Act and the DPDP Rules, including encryption or equivalent protection, access control, logging and monitoring, backup, and contractual controls over processors.
Wapzio may update measures provided the overall level of protection is not reduced.
2.6 Sub-processors
2.6.1 The Client grants general written authorisation for Wapzio to engage sub-processors, subject to this clause.
2.6.2 The current list is at https://www.wapzio.com/legal/subprocessors and reproduced at Annex C. Clients may subscribe to change notifications at that URL.
2.6.3 Wapzio gives at least 30 days' notice before adding or replacing a sub-processor that processes Client Data. The Client may object on reasonable, documented data-protection grounds within 15 days. The parties will discuss in good faith. If no resolution is reached, the Client may terminate the affected Services on written notice and receive a pro-rata refund of pre-paid unused Fees. This is the Client's sole remedy for an objection. Absence of objection within the period is deemed approval.
2.6.4 Wapzio imposes on each sub-processor data-protection obligations no less protective than this DPA and remains responsible to the Client for the sub-processor's performance of those obligations.
2.6.5 Meta Platforms, Inc. and its affiliates are not sub-processors of Wapzio. The Client contracts with Meta directly under the Meta Terms and Meta acts in its own right in respect of WhatsApp message data.
2.7 Assistance with data principal rights
Wapzio provides self-service tools enabling the Client to access, correct, export and delete Client Data. Where a request cannot be fulfilled through those tools, Wapzio will provide reasonable assistance within 10 business days, at the Client's cost where the assistance is not covered by self-service functionality.
Where Wapzio receives a request directly from a data principal relating to Client Data, Wapzio will not respond substantively. It will confirm receipt, direct the person to the Client, and forward the request to the Client within 5 business days, recording the forwarding event.
2.8 Personal data breach
2.8.1 Wapzio notifies the Client without undue delay and in any event within 48 hours of confirming a personal data breach affecting Client Data.
2.8.2 The notification includes, so far as known: nature of the breach; categories and approximate volume of data and data principals affected; likely consequences; measures taken and proposed; and a contact point. Information may be supplied in phases as the investigation progresses.
2.8.3 Wapzio separately reports to CERT-In within 6 hours of noticing a reportable cyber incident, and to the Data Protection Board as required, in respect of incidents affecting its own systems.
2.8.4 Notification to affected data principals and to the Data Protection Board in respect of Client Data is the Client's obligation as Data Fiduciary. Wapzio will provide reasonable information to enable it.
2.8.5 Wapzio's notification is not an admission of fault or liability.
2.9 Audit
2.9.1 Wapzio will make available on request: this DPA, Annex B, its security policy summary, its sub-processor list, penetration-test summary reports, and any certifications held (No third-party certification currently held. The controls described in this Annex are implemented but have not been independently certified.).
2.9.2 Where the above is insufficient to demonstrate compliance, the Client may, not more than once in any 12-month period, on 30 days' written notice, conduct an audit limited to Wapzio's processing of that Client's data, at the Client's cost, during business hours, subject to confidentiality, without access to other customers' data or to Wapzio's source code or security-sensitive infrastructure detail, and by an independent auditor reasonably acceptable to Wapzio who is not a competitor of Wapzio.
2.9.3 Additional audits are permitted where required by a regulator or following a confirmed breach affecting the Client.
2.10 Cross-border processing
Wapzio may process Client Data outside India only in accordance with section 16 of the DPDP Act, only with sub-processors listed in Annex C, and never in a country notified as restricted by the Central Government. Logs subject to the CERT-In 180-day retention direction are maintained within India. Annex C states each sub-processor's processing location.
2.11 Deletion and return
2.11.1 On termination, the Client may export Client Data for 30 days.
2.11.2 Thereafter Wapzio deletes or de-identifies Client Data within 60 days, except: (a) data under legal hold; (b) data required by Applicable Law, including logs under the CERT-In Directions and records under the IT Rules, 2021; (c) data reasonably required to defend a legal claim; (d) billing and tax records; and (e) data in encrypted backups, which is deleted on the ordinary backup expiry cycle of 35 days and is not restored except for disaster recovery.
2.11.3 Retained data remains subject to this DPA. Wapzio provides a deletion certificate on written request, recording scope, method, date and exceptions.
2.12 Liability
The limitations in clause 1.17 of the Terms apply to this DPA, subject to the data-protection super-cap in clause 1.17.3 where purchased. This DPA does not create liability for Wapzio in respect of the Client's own failure to obtain consent or to comply with its obligations as Data Fiduciary.
2.13 Precedence and term
This DPA prevails over the Terms in respect of the processing of personal data. It takes effect on the Effective Date of the Order Form and continues until deletion or return of all Client Data.
ANNEX A — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Wapzio SaaS messaging platform |
| Duration | For the Subscription Term plus the retention periods in Annex D |
| Nature | Collection, recording, structuring, storage, retrieval, transmission, display, deletion |
| Purpose | Enabling the Client to manage contacts and send, receive and analyse business communications |
| Categories of data principals | The Client's Users; the Client's customers, prospects and message Recipients |
| Categories of personal data | Name, phone number (E.164), email, contact attributes and custom fields defined by the Client, message content and media, conversation metadata, delivery and read status, opt-in/opt-out records, IP and device data where the Client collects it |
| Special / sensitive categories | None permitted unless expressly listed here and agreed in writing: ______________ |
| Prohibited without written agreement | Aadhaar or other government ID numbers; payment card data; health records; biometric data; children's data |
| Frequency | Continuous |
| Retention | Per Annex D and the Client's configured settings |
ANNEX B — Technical and organisational measures
| Domain | Measures |
|---|---|
| Encryption | TLS 1.2+ in transit; AES-256 at rest for databases, object storage and backups; secrets in a managed vault (KMS / Secrets Manager); tokenisation of identifiers where practicable |
| Access control | RBAC with least privilege; MFA mandatory for all administrative and production access; SSO where offered; unique named accounts (no shared credentials); JIT/break-glass access with approval and full session logging; quarterly access review; deprovisioning within 24 hours of exit |
| Network | Private subnets for data stores; security groups default-deny; WAF; DDoS protection; no public DB endpoints; bastion or SSM-only production access |
| Application | Input validation; parameterised queries; output encoding; CSRF and rate limiting; dependency scanning in CI; SAST; secrets scanning; mandatory peer code review; segregated dev/stage/prod |
| Logging & monitoring | Centralised, append-only logs; hash-chained audit trail (Part 4 §8); NTP synchronised to NIC/NPL per CERT-In; alerting on privileged access, failed auth, bulk export, config change; ≥180-day log retention within India |
| Backup & recovery | Daily encrypted backups; PITR where supported; 35-day retention; cross-AZ replication; restoration tested at least quarterly with a written test record |
| Vulnerability management | Critical patched within 7 days, High 30 days, Medium 90 days; annual third-party VAPT; documented remediation tracking |
| Incident response | Documented IR plan; on-call rota; severity matrix; CERT-In 6-hour reporting runbook; annual tabletop exercise |
| People | Background verification for privileged roles; signed confidentiality and IP deed; onboarding and annual security training; documented disciplinary process |
| Vendors | Risk-based due diligence pre-onboarding; executed DPA; annual review; register maintained |
| Physical | Cloud data centres operated by Amazon Web Services under their certified physical controls; no customer data on employee endpoints without full-disk encryption and MDM |
ANNEX C — Sub-processors
| # | Vendor | Service | Data categories | Purpose | Location | DPA on file | Added |
|---|---|---|---|---|---|---|---|
| 1 | Amazon Web Services, Inc. | Object storage (S3) | Media and documents, which may contain any personal data a client chooses to send | Storage of media, documents and attachments uploaded by clients and sent to recipients | India — AWS ap-south-1 | No | 2026-09-03 |
| 2 | Hostinger International Ltd. | Application server hosting | Everything in transit, plus system and application logs | Runs the application, the job queues, and holds the system logs | India — Mumbai, Maharashtra | No | 2026-09-03 |
| 3 | Meta Platforms, Inc. | WhatsApp Business Platform, Facebook and Instagram APIs | Recipient phone numbers, message content and media, social profile identifiers | Transmission of messages, template approval, lead forms, and social channel integration | United States and Meta global infrastructure | No | 2026-09-03 |
| 4 | Google LLC (Maps Platform) | Geocoding and map rendering | Search terms and coordinates entered by a client. No recipient data. | Location targeting for click-to-WhatsApp ad campaigns | United States and Google global infrastructure | No | 2026-09-03 |
| 5 | Google LLC (Workspace APIs) | Calendar, Sheets and Forms integration | Whatever the connected sheet, calendar or form contains, which is chosen by the client | Syncing appointments, contacts and form submissions where a client connects their account | United States and Google global infrastructure | No | 2026-09-03 |
| 6 | Razorpay Software Private Limited | Payment gateway | Billing contact, amount, transaction identifiers. Card data does not touch this platform. | Collection of subscription fees and payment links raised by clients | India | No | 2026-09-03 |
| 7 | MongoDB, Inc. (Atlas) | Managed database hosting | All client data, all message content, all account and billing data | Primary datastore for every collection on the platform | India — MongoDB Atlas on AWS ap-south-1 (Mumbai) | No | 2026-09-03 |
7 of 7 sub-processors do not yet have an executed data processing agreement on file. Section 8(2) of the DPDP Act, 2023 requires a valid contract with every processor engaged, and this Annex records the position as it actually stands.
Change log: v2.0 date — initial published list.
ANNEX D — Retention schedule
| Data | Retention | Legal basis |
|---|---|---|
| Active Client Data | Subscription Term + 30 days export window | Contract |
| Deleted contacts / messages | Purged within 60 days of deletion trigger | DPDP s.8(7) |
| Backups | 35-day rolling expiry | Business continuity |
| Consent & opt-out records | Relationship + 8 years | Defence of claims; limitation period |
| Campaign & send logs | 24 months (longer under hold) | Dispute defence; abuse investigation |
| ICT / system logs | ≥ 180 days, within India | CERT-In Direction (iv) |
| Content-removal records | 180 days from removal | IT Rules 2021 Rule 3(1)(g) |
| Legal acceptance records | Account life + 8 years | Evidence of contract |
| Billing, invoices, tax | 8 years | Companies Act s.128(5); CGST |
| Support tickets | 24 months | Service and dispute |
| Incident records | 5 years | Regulatory and defence |
| Enforcement / complaint cases | 5 years | Defence of claims |
| Anything under legal hold | Until released in writing | Evidence preservation |