Skip to main content

Legal

Data Processing Addendum (DPA)

Version 1.0 — effective 24 July 2026. This Addendum forms part of the WASync Terms & Conditions.

1. Introduction and incorporation

This Data Processing Addendum ("DPA") is entered into between the customer accepting the WASync Terms & Conditions ("Customer") and TDACRM Solutions SRL (Romania, VAT RO45930062, Str. Ion Câmpineanu nr. 23, Sector 1, București), the company operating the WASync service ("WASync"). It is incorporated into and forms part of the agreement between Customer and WASync governing the use of the service (the "Agreement"). It reflects the parties' obligations under Article 28 of Regulation (EU) 2016/679 ("GDPR"). By using the service, Customer agrees to this DPA.

2. Roles of the parties

For Customer Data — WhatsApp messages and media, contact details of Customer's end users, and CRM field values processed through the service — Customer is the controller and WASync is the processor, processing such data only on Customer's behalf and documented instructions.

WASync acts as an independent controller for its own account, billing, and support data (as described in the Privacy Policy). Payment processors act as independent controllers for card payment data and are not sub-processors under this DPA.

3. Details of processing

  • Subject matter: provision of the WASync WhatsApp-to-CRM integration service.
  • Duration: the term of the Agreement, plus the deletion period in Section 9.
  • Nature and purpose: receiving, transmitting, storing and displaying WhatsApp conversations inside Customer's CRM; executing Customer-configured automations (including AI-generated messages); synchronising contacts and conversation history.
  • Categories of data subjects: Customer's staff and CRM users; Customer's customers, leads and other WhatsApp contacts.
  • Categories of personal data: phone numbers, names and WhatsApp profile information, message content including media files, delivery metadata, and CRM field values Customer chooses to process in automations.
  • Special categories: the service is not designed to process special categories of data. Customer is responsible for the content its end users transmit.

4. Processor obligations

WASync shall:

  • process Customer Data only on documented instructions from Customer (including the Agreement and Customer's configuration of the service), unless required otherwise by EU or Member State law — in which case WASync will inform Customer unless legally prohibited;
  • ensure that persons authorised to process Customer Data are bound by confidentiality obligations;
  • implement the technical and organisational measures described in Section 8 (Article 32 GDPR);
  • assist Customer, taking into account the nature of processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection);
  • notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information reasonably required for Customer's own notification obligations;
  • assist Customer with data protection impact assessments and prior consultations, insofar as they relate to processing under this DPA;
  • delete or return Customer Data at the end of the engagement (Section 9);
  • make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow audits as set out in Section 10; and
  • immediately inform Customer if, in WASync's opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions; WASync may suspend execution of that instruction until it is confirmed or modified.

5. Sub-processors

Customer provides a general written authorisation for the engagement of the sub-processors listed below. WASync will impose data protection obligations on each sub-processor that are no less protective than those in this DPA and remains liable for their performance. WASync maintains the current sub-processor list on this page and will update it at least 30 days before a new or replacement sub-processor first processes Customer Data; Customer may subscribe to change notifications by emailing [email protected] with the subject "Subscribe: sub-processor updates". Publication of the update, plus notice to subscribed customers, constitutes notice under this Section. Customer may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, Customer may terminate the affected subscription with a pro-rata refund of prepaid, unused fees.

Sub-processorPurposeLocationTransfer safeguard
Hetzner Online GmbHServer infrastructure and data storage (dedicated servers)Germany (EU)Processing within the EU
Cloudflare, Inc.Network security, DNS, TLS and content deliveryUSA / global edgeSCCs (2021/914); DPF-certified
Meta Platforms Ireland Ltd.WhatsApp Business Platform (Cloud API) message transmission for WhatsApp Business API connectionsIreland (EU) / globalMeta's GDPR terms; SCCs within the Meta group
Resend, Inc.Transactional email delivery (order confirmations, service notices)USASCCs (2021/914)
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsUSASCCs (2021/914); DPF-certified
Upstash, Inc.Caching and rate limitingUSA / EU regionsSCCs (2021/914)

For QR-linked (Linked Devices) connections, messages are transmitted through the consumer WhatsApp service operated by the Meta group as an independent service under WhatsApp's own terms and privacy policy; for that service Meta is not a sub-processor of WASync and WASync cannot impose processing obligations on it. WhatsApp applies end-to-end encryption in transit; WASync processes the messages as a linked device on Customer's instruction.

Customer's own CRM provider (e.g. Bitrix24, or another CRM Customer connects) processes Customer Data under Customer's own agreement with that provider and is not a sub-processor of WASync.

6. AI providers (engaged only on Customer's instruction)

AI features are optional. When Customer enables an AI automation, Customer selects the AI provider (OpenAI, L.L.C. · Anthropic, PBC · Google Ireland Ltd. · DeepSeek (Hangzhou DeepSeek AI)) and supplies Customer's own API key. AI providers are engaged under Customer's own contract with the provider and are Customer's processors, not sub-processors of WASync; Sections 5 and 7 do not apply to them. Customer thereby instructs WASync to transmit the configured prompt and selected CRM field values to that provider. WASync transmits only the data configured by Customer, stores the provider's response only as the resulting WhatsApp message saved in conversation history, and encrypts Customer's API key at rest. Providers may process data outside the EU/EEA in countries without an EU adequacy decision — in particular, DeepSeek processes data in the People's Republic of China. Customer is solely responsible for ensuring a valid transfer mechanism under Chapter V GDPR before enabling such a provider.

7. International transfers

Customer Data is stored on servers in the European Union. Where a sub-processor processes personal data outside the EU/EEA, the transfer is protected by an adequacy decision or the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with supplementary measures where appropriate. Where a US sub-processor is certified under the EU-U.S. Data Privacy Framework, that certification applies in addition to, not instead of, contractual safeguards.

8. Security measures (Article 32)

  • Encryption in transit: HTTPS / TLS 1.2+ for all connections.
  • Encryption at rest for credentials and tokens (AES-256-GCM); API keys are never written to logs.
  • EU-located data storage with logical tenant isolation per customer portal.
  • Role-based access control; administrative functions restricted to authorised personnel; authentication required for all access.
  • Logging and monitoring of production systems; error tracking with data minimisation.
  • Regular encrypted backups and recovery procedures.
  • Incident response process with defined escalation paths.
  • Ongoing vulnerability and patch management for production systems.
  • Personnel bound by confidentiality and instructed in data protection practices.
  • Data minimisation and retention limits (Section 9).

9. Deletion and return

At the end of the engagement WASync will, at Customer's choice, delete or return Customer Data. Customer may export conversation data via the service or request an export at [email protected] before or within 30 days of cancellation or uninstallation; absent such a request, Customer Data is deleted within 30 days, except where EU or Member State law requires longer storage. Residual copies in encrypted backups are overwritten in the ordinary backup rotation cycle (no longer than 90 days) and are not restored except for disaster recovery. Disconnecting a WhatsApp Business Account immediately revokes the related access token and stops further ingestion; unpairing a QR-linked number ends the session and stops further ingestion. End-user deletion requests are honoured under Article 17 GDPR.

10. Audits

WASync will make available documentation reasonably necessary to demonstrate compliance with this DPA. No more than once per 12 months, and subject to reasonable notice and confidentiality undertakings, Customer may conduct (itself or through an independent auditor that is not a competitor of WASync) an audit limited to the processing of Customer Data, at Customer's expense. WASync may first satisfy the request with existing audit reports or documentation.

11. Liability, precedence and governing law

Each party's liability under this DPA is subject to the limitations of liability in the Agreement. In case of conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails. This DPA is governed by the laws of Romania, without prejudice to the directly applicable provisions of the GDPR, and the courts of Bucharest, Romania have jurisdiction over disputes arising from this DPA. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR.

12. Contact

Data protection enquiries: [email protected]. See also our Privacy Policy and Terms & Conditions.