Data Processing Agreement (DPA)

Last updated: 19 June 2026

This document is a working draft. The data controller's details and the bracketed references must be completed, and the whole text should be reviewed by a legal advisor before final use.

This Data Processing Agreement (the “Agreement” or “DPA”) supplements the Terms of Service and governs the processing of personal data carried out by Whaiz on the user's behalf under Art. 28 of Regulation (EU) 2016/679 (the “GDPR”).

It applies when, by using the Service, the user has Whaiz process the data of their WhatsApp contacts, groups and conversations. With respect to such data the user is the Controller and Whaiz is the Processor.

1. Definitions

The terms “personal data”, “processing”, “data subject”, “controller”, “processor”, “sub-processor” and “personal data breach” have the meaning given to them by the GDPR.

“Controller”: the user of the Service. “Processor”: [Legal entity] (“Whaiz”). “Data”: the personal data processed by Whaiz on the Controller's behalf within the Service.

2. Subject matter, roles and duration

Under this Agreement the Controller appoints Whaiz as Processor for the Data processed for the purpose of providing the Service. Whaiz processes the Data only on the Controller's documented instructions, save for legal obligations.

The Controller's instructions consist of the Terms, this DPA and the configurations and actions set through the Service (for example enabling the Bot on a contact or group). Processing lasts for the term of the contractual relationship.

3. Categories of data and data subjects

Categories of data subjects: the Controller's contacts and the participants in the groups and conversations the Controller chooses to handle through the Service.

Categories of Data: identification and contact data (e.g. phone number, display name) and the message content of the conversations the Controller chooses to import or have the Bot process. The Controller undertakes not to process special categories of data through the Service unless it has an appropriate legal basis.

4. Processor obligations

Whaiz shall: (a) process the Data only on the Controller's documented instructions; (b) ensure that persons authorised to process are bound by confidentiality; (c) implement the security measures under Art. 32 GDPR; (d) assist the Controller with appropriate measures to respond to data subject requests and to meet the obligations under Arts. 32-36 GDPR; (e) make available to the Controller the information needed to demonstrate compliance.

Whaiz shall inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

5. Security measures

Whaiz adopts technical and organisational measures appropriate to the risk, including: encryption of data in transit, access and authentication controls, environment segregation, access logging, infrastructure hosted on servers in the European Union and a data-minimisation principle (no data is imported automatically when WhatsApp is connected).

6. Sub-processors

The Controller authorises Whaiz to engage sub-processors to deliver the Service. Whaiz imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA and remains responsible for their performance.

Sub-processors currently engaged: Anthropic, PBC (provider of the “Claude” AI models); Stripe (payment processing); the hosting and infrastructure provider in the European Union; the transactional email-delivery service.

Whaiz will inform the Controller of any changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on legitimate grounds.

7. Assistance to the Controller and data subject rights

Taking into account the nature of the processing, Whaiz assists the Controller, by appropriate technical and organisational measures, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection).

If Whaiz receives a request directly from a data subject regarding Data processed on the Controller's behalf, it forwards it to the Controller without undue delay, the Controller being the primary point of contact.

8. Personal data breaches

Whaiz notifies the Controller, without undue delay after becoming aware, of any breach of the personal Data processed on its behalf, providing the information reasonably available to enable the Controller to meet its notification obligations under Arts. 33-34 GDPR.

The obligations to notify the supervisory authority and the data subjects remain with the Controller.

9. Transfers to third countries

The Data is processed, where possible, on servers in the European Union. Any transfers to third countries take place only with adequate safeguards under Chapter V of the GDPR, such as adequacy decisions or standard contractual clauses (SCCs), in particular regarding the AI-model provider.

10. Audit

Whaiz makes available to the Controller the information needed to demonstrate compliance with the obligations of this Agreement and allows for and contributes to, within the limits of proportionality and confidentiality, audits conducted by the Controller or an auditor mandated by it, with reasonable notice.

11. Termination: return and deletion

On termination of the Service, at the Controller's choice, Whaiz deletes or returns the Data processed on its behalf and deletes existing copies, unless retention is required by Union or national law.

Deleting a session or the account results in the removal or inaccessibility of the associated Data within the technically necessary timeframes.

12. Governing law and jurisdiction

This Agreement is governed by Italian law. Any dispute shall be subject to the courts of [jurisdiction]. For any request regarding data processing you can contact us at [contact email].