Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller", "you") and Activated Digital Ltd ("Processor", "WAGate"). It applies where WAGate processes Personal Data on your behalf — primarily the WhatsApp conversation data of your end-customers — and reflects the requirements of Article 28 of the GDPR and comparable laws.
1. Roles & scope
For Personal Data you submit to or generate through the Service about your own end-customers, you are the Controller and WAGate is the Processor. WAGate processes such data only to provide the Service and only on your documented instructions, including those in the Terms, this DPA, and your use of the Service's settings. For your own account data, WAGate acts as a controller under the Privacy Policy.
2. Processing details (Annex I)
- Subject matter: provision of the WAGate WhatsApp messaging platform.
- Duration: for the term of your subscription, plus the deletion period in §9.
- Nature & purpose: sending, routing, automating, storing, and analysing WhatsApp messages; optional AI-assisted responses.
- Types of Personal Data: end-customer phone numbers, WhatsApp profile names, message content and media, delivery/read events, and any data you choose to include in messages, contacts, or notes.
- Categories of data subjects: your end-customers and other recipients you message; your team members/agents.
3. Processor obligations
WAGate will:
- Process Personal Data only on your documented instructions, including for international transfers, unless required by law (in which case we will inform you unless legally prohibited).
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Annex III).
- Assist you, taking into account the nature of processing, with data-subject requests and with your obligations on security, breach notification, and data-protection impact assessments.
- Make available information necessary to demonstrate compliance and allow for audits as described in §8.
4. Confidentiality & security (Annex III)
WAGate maintains measures including: encryption of access tokens at rest (AES-256-GCM) and TLS in transit; hashed credentials; access controls and least-privilege; CSRF and session protections; prepared statements against injection; logging and monitoring; and segregation of customer workspaces. We do not access the content of your customers' messages except as needed to provide and support the Service or as you instruct.
5. Subprocessors
You authorise WAGate to engage the subprocessors below to process Personal Data to provide the Service. Each is bound by data-protection obligations no less protective than this DPA. We will give notice of any intended changes (addition/replacement) so you can object on reasonable data-protection grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd (WhatsApp) | Message delivery via the WhatsApp Cloud API | Ireland / USA |
| Amazon Web Services (Amazon SES) | Transactional email delivery | EU / USA |
| Google LLC (Gemini API) | Optional AI chatbot & AI-assist features | USA |
| Sumit (via pay.activated.digital) | Subscription billing & payments | Israel |
| Amazon Web Services (AWS) | Application & database hosting | Israel (il-central-1) |
6. Data-subject requests
Taking into account the nature of the processing, WAGate will assist you by appropriate measures, insofar as possible, to respond to requests from data subjects exercising their rights. If we receive such a request directly, we will refer it to you (the Controller).
7. Personal-data breach
WAGate will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, and will provide information reasonably available to help you meet your notification obligations.
8. Audits
WAGate will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not disrupt the Service.
9. Return & deletion
On termination of the Service, and at your choice, WAGate will delete or return the Personal Data and delete existing copies, except to the extent retention is required by law. See the Data Deletion page for timelines.
10. International transfers
Where WAGate or a subprocessor transfers Personal Data outside the EEA/UK, such transfers are made under an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, which are incorporated by reference.
11. General
This DPA is governed by the law and jurisdiction stated in the Terms. If any conflict arises between this DPA and the Terms regarding the processing of Personal Data, this DPA prevails. Questions: info@activated.digital.