Legal

Data processing addendum

This addendum forms part of our terms of service and applies whenever you process personal data through WAFollow. Enterprise customers can request a countersigned copy.

1. Roles of the parties

Controller
The customer, who decides which contacts to message and why.
Processor
WAFollow, which processes contact and message data only on the customer's documented instructions.
Sub-processor
A vendor engaged by WAFollow to help deliver the service, listed on the compliance page.
Personal data
WhatsApp numbers, names, message content, delivery events and consent records.

2. Subject matter and duration

We process personal data for as long as your subscription is active, plus up to 30 days for backup expiry. Processing is limited to sending and receiving WhatsApp messages, storing the contacts you upload, running the automations you configure and producing your analytics.

3. Customer obligations

You are the controller. You confirm that you have a lawful basis and documented opt-in for every contact you message, that you honour opt-out requests, and that your use complies with Meta's WhatsApp Business Messaging Policy. WAFollow records consent state on every contact and automatically suppresses contacts who reply STOP.

4. Sub-processors

Our current sub-processors and their locations are published on the compliance page. We give notice before adding a new sub-processor, and you may object on reasonable data-protection grounds.

5. International transfers

Where personal data leaves its region of origin, transfers rely on the EU Standard Contractual Clauses or an equivalent lawful transfer mechanism, together with the technical measures below.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for all customer data.
  • Row-level database isolation so a workspace can only ever read its own records.
  • Access tokens for connected WhatsApp accounts stored in a service-role-only table, never readable by the browser.
  • Least-privilege staff access with audit logging on every administrative action.
  • Signed and verified inbound webhooks; unsigned payloads are rejected.
  • Backups retained for 30 days with restore testing, then permanently deleted.

7. Personal data breach

We notify affected customers without undue delay and, in any case, within 72 hours of becoming aware of a personal data breach, with the facts known at that time and our remediation steps. Reports and questions: security@wafollow.in.

8. Data subject rights

You can export your workspace data and raise a deletion request at any time from Settings → Privacy, or follow data deletion. We assist with access, rectification, erasure, restriction, portability and objection requests you receive from your own contacts.

9. Audit and assistance

On reasonable notice and no more than once a year, we provide the information needed to demonstrate compliance with this addendum. Enterprise plans include a security questionnaire response and a signed DPA.

10. Deletion on termination

On termination we delete or return personal data within 30 days, except where retention is required by law. Financial records are retained for statutory accounting periods.

11. Contact

Data protection contact: privacy@wafollow.in. Postal: WAFollow, Jaipur, Rajasthan, India.