Legal

Data Processing Agreement

For business and reseller customers handling personal data via WhatsMark.

This DPA is incorporated into your agreement with WhatsMark and applies automatically when you use the Service to process personal data. If your organisation needs a countersigned copy on file, email [email protected] and we will return one.

Effective date: 15 July 2026 · Processor: Corbital Technologies LLP, 406, 4th Floor, Aditya One - A Corporate Park, Kalavad Rd, opp. ISKCON Temple, Rajkot, Gujarat 360005, India (GST 24AARFC0936A1ZU) ("WhatsMark", "we", "us").

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer", the data controller) and WhatsMark (the data processor) for your use of the WhatsMark platform (the "Service"). It governs our processing of personal data on your behalf and is designed to meet the requirements of the EU GDPR, the UK GDPR, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Where this DPA conflicts with the main terms, this DPA controls for matters of data protection.

1. Roles

You are the controller of the personal data you upload to or generate through the Service (your contacts, their phone numbers, message content, and related metadata). We act as your processor and process that personal data only on your documented instructions — which include your configuration and use of the Service — except where law requires otherwise, in which case we will tell you unless that law prohibits it.

2. Scope of processing

  • Subject matter & duration: provision of the Service for the term of your subscription and any wind-down period.
  • Nature & purpose: storing, transmitting, and displaying WhatsApp/Messenger messages and contact data so you can run marketing, sales, and support conversations.
  • Categories of data subjects: your customers and contacts.
  • Categories of personal data: names, phone numbers, message content and media, contact attributes/tags you define, and technical metadata (timestamps, delivery status). You are responsible for not sending special-category data you have no lawful basis to process.

3. Our obligations

  • Process personal data only on your instructions and for the purposes above.
  • Ensure personnel with access are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (Article 32 GDPR) — see §5.
  • Assist you, taking into account the nature of processing, with data-subject requests and with your obligations around security, breach notification, and impact assessments.
  • On termination, delete or return personal data as described in §7.

4. Sub-processors

You authorise us to engage the sub-processors listed below to deliver the Service. Each is bound by data protection terms no less protective than this DPA. We will give reasonable notice of any intended addition or replacement so you can object on reasonable data protection grounds.

Sub-processor Purpose Location
Meta Platforms (WhatsApp / Messenger Cloud API)Message delivery and receipt over the official Meta Cloud APIUSA / EU
Razorpay Software Pvt. Ltd.Payment processing for WhatsMark subscription billing (INR)India
Dodo PaymentsPayment processing for WhatsMark subscription billing (USD, Merchant of Record)USA
Cloudflare, Inc.CDN, DNS, DDoS protection and Turnstile bot verificationGlobal (EU edge available)
OpenAIAI features (flow generation, message improve/translate) when the tenant uses them — the relevant message text is sent to generate the responseUSA
Anthropic (Claude)AI features (flow generation, message improve/translate) when the tenant uses them — the relevant message text is sent to generate the responseUSA
PostHogProduct analytics (EU-hosted instance; consent-gated)EU (eu.i.posthog.com)
Google (Google Analytics 4)Website analytics on the public marketing site (consent-gated)USA / EU
Cloud hosting / infrastructure providerApplication hosting, database and file storageIndia
Outbound email (SMTP) providerTransactional and notification email deliveryIndia

5. Security measures

We maintain encryption of data in transit (TLS), access controls and least-privilege permissions, tenant data isolation, encrypted storage of channel credentials, audit logging, and regular backups. Measures are reviewed and may be updated provided the level of protection is not materially reduced.

6. Data location & international transfers

Your data is hosted and primarily processed in India. Some sub-processors listed in §4 operate outside India (for example the Meta Cloud API, and the AI providers, which process the relevant message text in the United States when you use those features). Where a transfer of personal data crosses borders, it is made under an appropriate transfer mechanism — such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision — as applicable to that sub-processor, together with the safeguards described in §5.

7. Breach notification, return & deletion

  • We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification duties.
  • On termination, and at your choice, we delete or return the personal data and delete existing copies within a reasonable period, unless retention is required by law.

8. Audit & contact

We make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits on reasonable prior notice, subject to confidentiality. For data protection queries or to request a countersigned copy, contact [email protected].

Last updated 15 July 2026. The binding version is the one executed between you and Corbital Technologies LLP.