Delivering Tobachat takes a handful of other companies. They are called sub-processors. Below you will find, per party, what we use them for, which data they see, where they process it, and on what basis data may leave the EU.
1. What this list is
For the messages and contacts of your customers you are the controller and we are the processor. We process that data only on your instructions. The parties below work on our instructions in turn, and may do nothing with the data beyond what is stated here.
Accepting our terms gives us your prior authorisation to engage these parties. How that works is set out in the data processing agreement. If the list changes, you hear about it in advance. See section 5.
2. The list
Current as of the date at the top of this page.
Supabase Pte. Ltd. (Singapore)
- What for: the database, login, media storage, and running our server functions.
- Which data: everything held in Tobachat: contacts, phone numbers, message content, media, accounts and settings.
- Where: the database, login and storage sit in Ireland. Logs, backups and function execution may fall outside it.
- Basis for transfer: the European Commission's 2021 standard contractual clauses. Supabase is not enrolled in the Data Privacy Framework.
WhatsApp Ireland Limited (Ireland)
- What for: sending and receiving WhatsApp messages and managing your WhatsApp Business account.
- Which data: phone numbers, message content, media, and your WhatsApp Business account details.
- Where: Ireland, with processing across Meta's global network, including the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which WhatsApp LLC is enrolled in, with the standard contractual clauses as a fallback.
Google Cloud EMEA Limited (Ireland), for the Gemini API
- What for: the AI features: proposing or sending a reply, classifying a message, extracting a detail from one, and drafting flows and templates.
- Which data: the text of the customer's message and the business context you fill in yourself. No name, no phone number, no email address. For customers in the European Economic Area, Google does not use these prompts and responses to improve its products. It does keep them: every prompt and every response stays on file for 55 days for abuse detection, and within that period an authorised Google employee can review content that has been flagged as possible abuse.
- Where: Ireland as the contracting party, with processing in Google data centres that also sit outside the EU.
- Basis for transfer: the EU-US Data Privacy Framework, which Google LLC is enrolled in, with the standard contractual clauses as a fallback.
Functional Software, Inc., trading as Sentry (United States)
- What for: tracking down technical faults in the software.
- Which data: error reports with technical detail, the page where it went wrong, and the user id and email address of the signed-in staff member. For a fault in the dashboard, a recording of that screen as well. Phone numbers, email addresses and message content are filtered out beforehand.
- Where: error reports and screen recordings sit in the EU region in Frankfurt. Account details, settings and support traffic sit in the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which Sentry is enrolled in, with the standard contractual clauses as a fallback.
Cloudflare, Inc. (United States)
- What for: hosting the website and the dashboard, relaying inbound webhooks, measuring clicks on links in campaigns, and storing backups.
- Which data: the IP address and requested page of every visitor, the content of inbound webhooks, per-recipient click data, and the database backups. Those backups are encrypted before they are written.
- Where: Cloudflare's global network.
- Basis for transfer: the EU-US Data Privacy Framework, which Cloudflare is enrolled in, with the standard contractual clauses for anything it does not cover.
Stripe Payments Europe, Limited (Ireland)
- What for: handling payments, subscriptions and invoices.
- Which data: your company name, email address, billing details and payment details. None of your customers' data.
- Where: Ireland, with onward transfer to Stripe, LLC in the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which Stripe, LLC is enrolled in, with the standard contractual clauses as a fallback.
Plus Five Five, Inc., trading as Resend (United States)
- What for: sending email about your account: confirmations, invitations, notifications and password resets.
- Which data: the recipient's email address and name, and the content of that email.
- Where: the United States. Sending can happen from Ireland, but account data and logs sit in the United States.
- Basis for transfer: the European Commission's 2021 standard contractual clauses, alongside the EU-US Data Privacy Framework.
GitHub, Inc. (United States)
- What for: running our build and maintenance jobs, including the twice-weekly database backup.
- Which data: while a backup is made, a full copy of the database sits briefly on a GitHub machine before it is encrypted and written away.
- Where: virtual machines in Microsoft Azure. GitHub stores data for GitHub.com in the United States by default and offers no region choice for these machines.
- Basis for transfer: the EU-US Data Privacy Framework, which GitHub is enrolled in, with the 2021 standard contractual clauses as an alternative.
Nothing else leaves our systems. We do not sell data, and we never use one organisation's conversations to improve anything for another.
3. Processing outside the EU
Data may leave the European Economic Area for two reasons. The first is an adequacy decision: the European Commission has determined that an arrangement offers enough protection. The EU-US Data Privacy Framework is such a decision; a US company enrols in it and confirms that enrolment every year. The second is the set of standard contractual clauses the Commission adopted in 2021: a fixed contract that binds the recipient to European rules.
Each party above states which of the two applies. Where a party relies on the Data Privacy Framework, the standard contractual clauses sit in the contract as a fallback, so that a change to that decision does not bring the service down.
4. Parties you engage yourself
Switch on an integration and data goes to a party you picked. It is not on the list above, because we did not pick it and we hold no agreement with it. These are the cases:
- Zapier, if you switch on the Zapier integration. Contacts and inbound messages then go to the Zaps you build.
- a web address you fill in yourself in the HTTP step of a flow. Whatever you put in that step goes there.
- your booking system, FareHarbor or LetsBook for example, which sends bookings and contact details into Tobachat.
For those parties you are responsible yourself and arrange what is needed yourself. Switch the integration off and the flow stops.
5. Changes to the list
If we add or replace a party, we tell you at least 30 days beforehand. It works like this:
- You get an email at the address of your organisation's administrators.
- The date at the top of this page changes with it.
- If you object, tell us within 30 days. We then look for a solution together.
- If we cannot find one, you may terminate as of the date the change takes effect, at no cost for the remaining period.
To object, or to ask a question, email [email protected].
6. Wording for your own privacy statement
You inform your own customers about what happens to their data. That duty is yours, not ours, but you do not have to write the wording yourself. Take this and put it in your privacy statement.
It is sample wording. We do not know what else you process, so read it against your own situation and change whatever does not fit.
AI assistance in answering your message
We use Tobachat to receive and answer messages over WhatsApp. As part of that, an AI model may read the content of your message, so that a good answer arrives sooner. Sometimes the model proposes an answer that a member of our staff checks and sends; sometimes the model sends the answer itself. In the second case the message says so.
The model only reads our own conversations and does not use your message to train itself. The provider of the model does keep your message and the answer for 55 days to detect abuse, and during that period can review content flagged as possible abuse. Would you rather not deal with AI? Ask for a person, and one of us takes over.
Tobachat is supplied by Ciro Byte Solutions, which processes this data as a processor, on our instructions. The other parties involved are listed at tobachat.nl/subprocessors.
7. Visitors to our own website
This list covers the data you entrust to us. Who receives data about visitors to tobachat.nl, and which cookies we set for that, is in our privacy statement.