Legal

Data Processing Addendum

Last updated 21 September 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Squidfy (“Processor”) and the business that uses the Service (“Customer”, the “Controller”). It applies to personal data that Squidfy processes on the Customer’s behalf, such as the WhatsApp conversations, names and phone numbers of the Customer’s own customers (“Customer Personal Data”).

1. Roles and instructions

The Customer is the controller and Squidfy is the processor. We process Customer Personal Data only to provide the Service and only on the Customer’s documented instructions, which are the Terms, this DPA and the Customer’s use of the Service’s features. We do not process it for our own purposes, do not sell or share it, and do not use it to train or improve AI models.

2. Details of processing

  • Subject matter and duration: providing the Service for as long as the Customer’s workspace exists, plus the deletion period in section 8.
  • Nature and purpose: receiving, storing, displaying and sending WhatsApp messages; generating AI-assisted replies from the Customer’s knowledge base; managing leads and campaigns.
  • Data subjects: the Customer’s customers, leads and contacts, and the Customer’s team members.
  • Types of data: names, phone numbers, message content (text, voice notes, images), timestamps, delivery status, and notes and tags the Customer adds.

3. Customer responsibilities

The Customer is responsible for having a lawful basis and any required consent (including WhatsApp opt-in) for the data it processes through the Service, for giving its customers the notices the law requires, and for not submitting special-category or payment-card data unless the law and WhatsApp’s policies allow it.

4. Confidentiality and security

Personnel with access to Customer Personal Data are bound by confidentiality. We maintain technical and organisational measures appropriate to the risk, including encryption in transit, encryption at rest for WhatsApp access tokens and PINs, verified webhook signatures, signed session cookies, and separation of workspaces.

5. Sub-processors

The Customer authorises the following sub-processors, which we bind to data-protection obligations no less protective than this DPA:

  • Meta Platforms — WhatsApp Business Platform (message transport).
  • OpenAI — AI reply generation and voice-note transcription (no training on this data).
  • Stripe — subscription payments (no message content is shared).
  • Hostinger — email delivery and hosting infrastructure.

We will notify Customers of new sub-processors before they process Customer Personal Data so the Customer can object on reasonable grounds.

6. Data subject requests

We will promptly tell the Customer if we receive a request from one of its data subjects, and will provide reasonable help, through the Service or on request, for the Customer to respond to access, correction, deletion and export requests.

7. Personal data breaches

We will notify the Customer without undue delay after becoming aware of a breach affecting Customer Personal Data, with the information we have to help the Customer meet its own notification duties.

8. Return and deletion

When the Customer deletes its workspace or the agreement ends, we delete or anonymise Customer Personal Data within 30 days, except where the law requires us to keep it. Raw webhook logs are deleted after 30 days in any case. See our data deletion instructions.

9. International transfers

Our sub-processors operate globally. Where Customer Personal Data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses, where required by applicable law.

10. Audits

On reasonable written request, and no more than once a year unless required by a regulator or after a breach, we will provide information needed to show compliance with this DPA.

11. Contact

Questions, or a signed copy of this DPA: info@squidfy.com.