Legal
Data processing addendum
This addendum forms part of our terms of service and applies whenever you process personal data through WAFollow. Enterprise customers can request a countersigned copy.
1. Roles of the parties
- Controller
- The customer, who decides which contacts to message and why.
- Processor
- WAFollow, which processes contact and message data only on the customer's documented instructions.
- Sub-processor
- A vendor engaged by WAFollow to help deliver the service, listed on the compliance page.
- Personal data
- WhatsApp numbers, names, message content, delivery events and consent records.
2. Subject matter and duration
We process personal data for as long as your subscription is active, plus up to 30 days for backup expiry. Processing is limited to sending and receiving WhatsApp messages, storing the contacts you upload, running the automations you configure and producing your analytics.
3. Customer obligations
You are the controller. You confirm that you have a lawful basis and documented opt-in for every contact you message, that you honour opt-out requests, and that your use complies with Meta's WhatsApp Business Messaging Policy. WAFollow records consent state on every contact and automatically suppresses contacts who reply STOP.
4. Sub-processors
Our current sub-processors and their locations are published on the compliance page. We give notice before adding a new sub-processor, and you may object on reasonable data-protection grounds.
5. International transfers
Where personal data leaves its region of origin, transfers rely on the EU Standard Contractual Clauses or an equivalent lawful transfer mechanism, together with the technical measures below.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for all customer data.
- Row-level database isolation so a workspace can only ever read its own records.
- Access tokens for connected WhatsApp accounts stored in a service-role-only table, never readable by the browser.
- Least-privilege staff access with audit logging on every administrative action.
- Signed and verified inbound webhooks; unsigned payloads are rejected.
- Backups retained for 30 days with restore testing, then permanently deleted.
7. Personal data breach
We notify affected customers without undue delay and, in any case, within 72 hours of becoming aware of a personal data breach, with the facts known at that time and our remediation steps. Reports and questions: security@wafollow.in.
8. Data subject rights
You can export your workspace data and raise a deletion request at any time from Settings → Privacy, or follow data deletion. We assist with access, rectification, erasure, restriction, portability and objection requests you receive from your own contacts.
9. Audit and assistance
On reasonable notice and no more than once a year, we provide the information needed to demonstrate compliance with this addendum. Enterprise plans include a security questionnaire response and a signed DPA.
10. Deletion on termination
On termination we delete or return personal data within 30 days, except where retention is required by law. Financial records are retained for statutory accounting periods.
11. Contact
Data protection contact: privacy@wafollow.in. Postal: WAFollow, Jaipur, Rajasthan, India.