Skip to content
SendInbox
ProductTrust centerSecurityContactSign in
Sign inStart free trial
Trust center/Customer data

Data Processing Addendum

The processing terms that apply when SendInbox handles contacts, messages, and other personal data for a workspace customer.

Status
Current
Effective
28 August 2026
Contents08 sections
  1. §01Application and definitions
  2. §02Roles and instructions
  3. §03Processing details
  4. §04Processor commitments
  5. §05Security and personal data breach
  6. §06Subprocessors and transfers
  7. §07Rights requests and review
  8. §08Return, deletion, and survival
All documents
§01

Application and definitions

This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer and the SendInbox operator defined in the Terms whenever we process personal data on Customer’s behalf. “Personal Data”, “processing”, “Data Principal”, “Data Fiduciary”, and “Data Processor” have the meanings in applicable data-protection law; “controller” and “processor” are used as equivalent international terms where applicable.

If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. It does not apply where we independently determine the purpose and means of processing account, billing, security, legal, or direct support data, which the Privacy Policy covers.

§02

Roles and instructions

Customer is the Data Fiduciary/controller and we are its Data Processor/processor for Customer Personal Data. Customer instructs us to process that data to provide and secure the service, comply with the agreement, perform documented product actions, and follow additional lawful written instructions we accept.

Customer is responsible for lawful collection, notices, permissions, consent and opt-out handling, accuracy, data-minimization, retention decisions, rights requests, and the legality of its instructions. We will notify Customer if we reasonably believe an instruction violates applicable data-protection law, unless prohibited from doing so.

§03

Processing details

  • Subject matter: providing a multi-tenant WhatsApp campaign, contact, template, analytics, and shared-inbox service.
  • Duration: the agreement plus the deletion and backup-expiry periods described below.
  • Activities: collection, import, organization, storage, selection, transmission to Meta, receipt from Meta, display, analytics, support, security, redaction, export, and deletion.
  • People: Customer’s contacts and prospects, message recipients and senders, workspace users, staff, representatives, and other people whose data Customer submits.
  • Data: identity and contact details, phone numbers, tags and attributes, consent evidence, templates, campaign membership, messages and attachments, delivery/read/reply events, and audit metadata.
  • Sensitive data: not intentionally required. Customer must not submit highly sensitive or regulated data unless expressly permitted by law, Meta policy, and the agreement.
§04

Processor commitments

We will:

  • process Customer Personal Data only on documented instructions and as required by law;
  • ensure people authorized to process it are bound by confidentiality;
  • maintain proportionate technical and organizational security measures;
  • assist Customer, taking into account the nature of processing, with rights requests, security, breach response, and legally required assessments;
  • make available information reasonably necessary to demonstrate these commitments; and
  • not sell Customer Personal Data or use it for third-party advertising.

Assistance beyond standard product functionality may be charged at a reasonable rate where it requires substantial bespoke effort and the need was not caused by our breach.

§05

Security and personal data breach

Current measures include encrypted network transport, password hashing, short and rotating sessions, role- and tenant-scoped authorization, optional TOTP MFA, application-layer encryption for Meta access tokens, signed raw-body provider webhooks, private object storage, structured log redaction, audit trails, retention workers, and tested backups. The Security page records limitations as well as controls.

We will notify Customer without undue delay after confirming a personal data breach affecting Customer Personal Data and provide information reasonably available for Customer’s response. Notification is not an admission of fault. Customer remains responsible for notices to Data Principals and authorities except where law places that duty directly on us.

§06

Subprocessors and transfers

Customer gives general authorization for the subprocessors described in our Subprocessor Disclosure. We will impose data-protection duties appropriate to their processing and remain responsible for our obligations under this DPA. Material changes will be posted before the new subprocessor begins routine processing where reasonably possible.

Customer may object on reasonable data-protection grounds by contacting us promptly. We will work in good faith on a reasonable alternative; if none is available, either party may discontinue the affected feature. International processing is subject to applicable legal restrictions and appropriate contractual or technical safeguards. No India-only residency commitment applies unless stated in a signed order.

§07

Rights requests and review

If we receive a request concerning Customer Personal Data, we will direct the person to Customer or notify Customer where legally permitted. Customer can use product controls to search, correct, export, suppress, and delete certain contact data. We will provide additional reasonable assistance after verifying scope and authority.

On reasonable written request no more than annually, we will provide relevant security and compliance information. If that is insufficient for a legal obligation, Customer may request a scoped review during business hours, subject to confidentiality, security of other customers, and reimbursement of reasonable costs. Reviews must not include penetration testing of production or access to another customer’s data.

§08

Return, deletion, and survival

During an active account, Customer may export supported data. At termination or on a verified lawful instruction, we will delete or anonymize Customer Personal Data unless law requires retention. Current operational defaults and live-data deletion behavior are described in the Privacy Policy. Backup copies expire on their normal cycle and are not restored except for disaster recovery.

We may retain minimal audit, consent, transaction, security, and dispute records where necessary, with access restricted and processing limited to that purpose. Confidentiality, deletion, liability, and other terms that by nature should survive continue after the main agreement ends.

Document clarificationQuestions, rights requests, and formal notices
Contact our team
SendInbox

A shared home for your WhatsApp campaigns, customers, and conversations.

support@sendinbox.co
ProductHomeCreate workspaceSign inSupport
TrustSecuritySubprocessorsData deletionContact
LegalPrivacyTermsAcceptable useCookiesData processingRefunds
Official WhatsApp Cloud APIBusiness-owned accountsMeta usage billed directly
© 2026 SendInboxWhatsApp is a trademark of Meta Platforms, Inc. SendInbox is not WhatsApp or Meta.