Legal

Data Processing Addendum

The terms on which ChatDaddy processes personal data on a tenant's behalf as their WhatsApp automation processor.

Last updated: 18 August 2026

Jump to a section

Summary

This page summarizes the terms on which ChatDaddy processes personal data on your behalf as a data processor. It is a summary for evaluation purposes — a countersigned DPA, incorporating Standard Contractual Clauses where relevant, is available on request and is the document that governs for customers who sign one.

Roles

For personal data in your workspace — your contacts and the messages they exchange with you — you are the controller and ChatDaddy is the processor. For your own account data (your users, billing details), we are the controller.

Scope of processing

  • Subject matter: providing the WhatsApp messaging, automation, AI agent, and analytics services.
  • Duration: for the term of your subscription, plus the retention period below.
  • Categories of data subject: your end customers who message you on WhatsApp, and your own workspace users.
  • Categories of data: phone numbers, profile names, message content and attachments, and any custom contact fields you choose to store.

Our obligations

  • Process personal data only on your documented instructions.
  • Ensure personnel with access are bound by confidentiality.
  • Apply appropriate technical and organizational measures — encryption in transit and at rest, per-tenant isolation at the application and database layers, and role-based access control (see Security).
  • Assist you with data subject requests and security notifications.
  • Delete or return personal data at the end of the engagement, per data deletion instructions.

Sub-processors

You give general authorization for the sub-processors listed at /sub-processors, including Meta Platforms, Inc. for message delivery, with at least 30 days’ notice of additions.

International transfers

Where personal data leaves the EEA or UK, transfers rely on the Standard Contractual Clauses, incorporated into the signed DPA, together with the UK Addendum where relevant.

Retention and deletion

Data is retained while your subscription is active. After termination it’s kept for 30 days to allow recovery, then deleted, unless we’re legally required to retain it. Earlier deletion can be requested any time — see data deletion instructions.

Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information needed for your own regulatory obligations.

Requesting a signed copy

Use the contact form and select “DPA request” as the topic. Include your workspace name and the signing entity.