This agreement forms part of our terms. You do not have to sign it separately: accepting the terms puts it in force. It sets out what we may do with the personal data of your customers.
1. Parties and scope
This data processing agreement forms part of the terms of service and applies from the moment you create an account, for as long as that account exists. Where the terms and this agreement conflict on personal data, this agreement prevails.
You, the business holding a Tobachat account, are the controller. Ciro Byte Solutions (Dutch Chamber of Commerce 81089058), trading as Tobachat, is the processor. You enter into this agreement electronically, which counts as the written form the GDPR requires.
2. Subject matter, nature, purpose and duration
- Subject matter: the personal data you put into Tobachat and the personal data that reaches you over WhatsApp.
- Nature: storing, organising, retrieving, forwarding, processing automatically and erasing.
- Purpose: delivering Tobachat: receiving and sending messages, keeping contacts and labels, running campaigns, running automations, and showing you what happened.
- Duration: for as long as you hold an account. Section 11 covers what happens afterwards.
3. Data and data subjects
These categories of personal data are involved:
- contact details: phone number, name, email address, labels and custom fields, as far as you record them
- the content of messages in both directions, including photos, documents and voice notes
- traffic data: timestamps, delivery status, who replied on your behalf, and whether someone opted out
- data from an integration you switch on yourself, such as a booking or an order number
- data about your own staff: name, email address, role, and what they do in the dashboard
The data subjects are your customers and anyone else you talk to through Tobachat, plus your own staff. You decide what goes into the service. The service is not built for special categories of personal data, health data for example. If you process them anyway, tell us, so that we can judge whether additional measures are needed.
4. What you are responsible for
As the controller you determine the purposes and the means. That means:
- You make sure you are allowed to process the data and have a lawful basis, including the opt-in WhatsApp requires.
- You inform your own customers about what happens to their data. There is wording you can use on the sub-processor page.
- You instruct us through the settings in the product, and in writing where the product offers no setting. What you configure counts as an instruction.
- You decide how long data stays, as far as the product gives you that choice, and you remove what you no longer need.
- You handle requests from your own customers. We help you, see section 8.
- You make sure your own staff only keep access for as long as they need it.
5. What we do, and what we will not do
As the processor we act only on your instructions. Specifically:
- We process the data only on your instructions and for the purposes in section 2, never for ourselves.
- We never use one organisation's conversations to improve anything for another, and we do not train models on them.
- Everyone at our end with access is under a duty of confidentiality and only gets access where the work requires it.
- We take appropriate technical and organisational measures: encryption in transit and at rest, separation per organisation enforced by the database itself, a record of changes, and encrypted backups.
- If we believe an instruction of yours breaches the law, we say so and we do not carry it out.
6. Other parties we engage
We engage other companies to deliver the service. Each of them is under an agreement that binds them to the same obligations that bind us here. We remain liable to you for what they do.
By this agreement you give us prior general authorisation for the parties on the sub-processor list. That list is the current version. This agreement does not repeat it, so that two lists can never drift apart.
If we add or replace a party, we tell you at least 30 days beforehand, by email to the administrators of your organisation. If you object within those 30 days and we cannot resolve it together, you may terminate as of the date the change takes effect, at no cost for the remaining period.
7. Processing outside the EU
Where a party processes outside the European Economic Area, it does so on a basis the GDPR allows: an adequacy decision of the European Commission, or its standard contractual clauses. The sub-processor list states which basis applies to which party. If an adequacy decision falls away, the standard contractual clauses apply from that moment on their own, with nothing to renegotiate.
8. Requests from your customers
If one of your customers asks for access, correction, erasure, restriction or portability, you handle it. We help you with the functions in the product and, where those are not enough, by hand. If such a request reaches us by mistake, we forward it to you and do not answer it ourselves.
9. Security incidents
If we discover a security breach affecting your data, we notify you without undue delay and within 48 hours of becoming aware of it. We tell you what happened, which data is involved, what the likely consequences are and what we are doing about it, and we keep you informed while the investigation runs. Reporting to the supervisory authority and to your own customers is yours to do: that duty sits with the controller. If you have to carry out a data protection impact assessment, or consult the supervisory authority beforehand, we supply the information we hold.
10. Audits
You may check that we keep to this agreement. On request we provide the information needed for that within 30 days. If you want an audit by an independent expert under a duty of confidentiality, we cooperate, at most once a year and more often if a supervisory authority asks for it. You bear the cost, unless the audit turns up something we have to put right.
11. End of the agreement
You can export your data for as long as the account exists. When the account ends, you tell us whether you want the data returned or erased. If we hear nothing, we erase it from the live systems within 60 days; it leaves the backups as those expire, within 90 days at the latest. Where the law requires us to keep something longer, invoicing data for example, we keep only that and only for as long as we must.
12. Changes and governing law
We may amend this agreement where the law or the service requires it. We announce substantive changes at least 30 days in advance, in the same way as a change to the sub-processor list. If you do not agree, you may terminate as of the date the change takes effect.
This agreement is governed by Dutch law. Disputes go to the competent Dutch court.