Data Processing Agreement (DPA)
Effective: April 25, 2026 — Version 2.0
1. Definitions
- "Controller" or "Data Controller": the Client who determines the purposes and means of processing End Customers' personal data through the Platform
- "Processor" or "Data Processor": Wappi Holding LLC, which processes personal data exclusively on behalf of and under the documented instructions of the Controller
- "Personal Data": any information relating to an identified or identifiable natural person, as defined in Art. 4(1) GDPR, Section 1798.140(v) CCPA, and applicable data protection law
- "Sub-processor": any third party engaged by Wappi that has access to or processes Personal Data on behalf of the Controller
- "Security Breach" or "Data Breach": any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data
- "Applicable Data Protection Law": the set of laws and regulations applicable to personal data processing, including the GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), POPIA (South Africa), and any other applicable regulation based on the Controller's jurisdiction
- "DSAR" (Data Subject Access Request): a request to exercise rights submitted by a data subject under Applicable Data Protection Law
2. Scope, Roles, and Subject Matter of Processing
This DPA applies to the processing of Personal Data that the Controller enters, generates, or stores on the Platform. Wappi acts exclusively as Processor under the Controller's documented instructions. The subject matter of processing comprises: (a) End Customer identification data (name, phone, email); (b) message and conversation content; (c) order and commercial transaction data; (d) multimedia files processed in conversations; (e) voice call recordings and transcriptions; (f) appointment and scheduling data; and (g) any other personal data the Controller enters into the Platform.
3. Processor Obligations
- Process Personal Data only in accordance with the Controller's documented instructions, unless required by law to process otherwise, in which case Wappi will inform the Controller in advance (unless legally prohibited)
- Ensure that authorized personnel with access to Personal Data have committed in writing to confidentiality or are subject to a legal obligation of confidentiality of equivalent nature
- Implement and maintain the technical and organizational measures described in Annex II of this DPA, ensuring an appropriate level of security for the processing risk
- Not engage another processor (sub-processor) without the Controller's prior general written authorization, as described in Section 4
- Assist the Controller, taking into account the nature of processing, through appropriate technical and organizational measures for the fulfillment of DSARs within legally established timeframes
- Assist the Controller in carrying out Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities when required
- At the Controller's choice, delete or return all Personal Data upon termination of the service, and destroy existing copies unless legally required to retain
- Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and Applicable Data Protection Law
- Allow and contribute to audits and inspections carried out by the Controller or an authorized auditor, with 30 days' reasonable notice during business hours
4. Authorized Sub-processors
The Controller generally authorizes the use of the following sub-processors for Personal Data processing. Wappi ensures that all sub-processors are subject to contractual obligations equivalent to those set out in this DPA:
4. Authorized Sub-processors
- Meta Platforms Inc. — WhatsApp Cloud API — Sending and receiving messages, template delivery — US/Global
- Twilio Inc. — Voice calls (IVR), phone verification, SMS — US
- Twilio SendGrid — Transactional email (optional, per Controller configuration) — US
- Mailgun Technologies Inc. (Sinch) — Transactional email (optional, per Controller configuration) — US
- Stripe Inc. — Payment processing, subscriptions, and billing — US
- Supabase Inc. — PostgreSQL database, authentication, file storage, vector embeddings — US/EU (AWS)
- OpenAI LLC — Language models (GPT-4o, GPT-4o-mini), embedding generation — US
- Anthropic PBC — Language models (Claude Sonnet) — US
- Google LLC — Language models (Gemini), text-to-speech (Cloud TTS), calendar (Calendar API) — US
- Groq Inc. — Accelerated inference of open-source models (Llama, Gemma, Mistral) — US
- OpenRouter Inc. — Multi-model AI routing and access — US
- Deepgram Inc. — Real-time voice transcription (STT, Nova-3 model) — US
- ElevenLabs Inc. — High-fidelity voice synthesis (TTS, optional) — US
- Cartesia AI — Streaming voice synthesis (TTS, optional) — US
- Calendly LLC — Appointment scheduling and availability management (optional) — US
- Cloudflare Inc. — Web security, bot protection (Turnstile), CDN — US/Global
- Mastershop — Product, order, and customer synchronization (e-commerce) — Colombia
- n8n GmbH — Workflow automation and event processing — Germany
- Telegram FZ-LLC — Bot messaging (optional, per Controller configuration) — United Arab Emirates
Change notification: Wappi will notify the Controller at least 30 calendar days in advance before adding, replacing, or materially modifying a sub-processor. The Controller may reasonably object to the change within 15 days of notification. In the event of a legitimate unresolved objection, the Controller shall have the right to terminate the agreement without penalty.
5. International Data Transfers
As Wappi operates from the United States and uses sub-processors in multiple jurisdictions, Personal Data may be transferred outside the Controller's or their End Customers' country of residence. All international transfers are carried out with the following safeguards: (a) Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914), included as Annex III to this DPA; (b) Transfer Impact Assessments (TIAs) conducted in accordance with EDPB Recommendations 01/2020; (c) supplementary technical measures (end-to-end encryption, pseudonymization, data segmentation) when the assessment of the destination country requires it; (d) commitment to notify the Controller of government access requests, unless legally prohibited.
6. Security Measures (Annex II — Technical and Organizational Measures)
- Encryption at rest: AES-256-GCM for credentials, tokens, and sensitive data stored in the database
- Encryption in transit: TLS 1.2 or higher for all communications, including internal and external APIs
- Per-tenant data isolation: Row Level Security (RLS) in PostgreSQL ensuring complete isolation between organizations
- Access control: JWT-based token authentication, RBAC (Role-Based Access Control), principle of least privilege
- Integrity verification: incoming webhook validation via HMAC-SHA256 with rotating secrets
- Monitoring and detection: real-time alerting system for anomalous access, intrusion attempts, and suspicious usage patterns
- Backups: automated daily backups with 30-day retention and encryption at rest
- Incident response plan: documented procedure for detection, containment, eradication, recovery, and notification
- Vulnerability management: periodic security assessments, continuous dependency updates, and security patches
- Personnel training: security awareness and data protection training program for all personnel with access to Personal Data
7. Security Breach Notification
In the event of a Security Breach affecting the Controller's Personal Data, Wappi will notify the Controller without undue delay and in any case within 72 hours of becoming effectively aware of the breach, pursuant to Article 33 GDPR. The notification will include: (a) description of the nature of the breach; (b) categories and approximate number of affected data subjects; (c) likely consequences; (d) measures taken or proposed to mitigate the effects; and (e) DPO or point of contact details. Wappi will cooperate with the Controller and provide all necessary information and assistance for the Controller to fulfill their own notification obligations to authorities and data subjects.
8. Assistance with Impact Assessments (DPIA)
Wappi will assist the Controller in carrying out Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities when processing through the Platform may pose a high risk to the rights and freedoms of data subjects. This assistance will include providing information about implemented security measures, data flows, and sub-processors involved.
9. Duration and Termination
This DPA takes effect on the date of the Controller's registration on the Platform and remains in force as long as Wappi processes Personal Data on behalf of the Controller. Upon termination of the service, Wappi will delete or return all Personal Data within 30 days and destroy existing backup copies within 90 days, unless legally required to retain.
10. DPA Contact
For requests, inquiries, or notifications related to this Data Processing Agreement: [email protected]