← Back

Data Processing Agreement

Last updated: 3 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between you (the “Customer”, acting as data controller) and us (the “Processor”) for your use of the Service. It applies where we process personal data on your behalf.

1. Roles

The Customer is the controller and we are the processor of the personal data the Customer uploads or generates through the Service (“Customer Data”). Each party will comply with applicable data-protection law, including the GDPR where applicable and Indonesia’s Personal Data Protection Law (UU PDP).

2. Scope + purpose of processing

We process Customer Data only to provide and support the Service and on the Customer’s documented instructions (including via the app’s configuration), unless required otherwise by law. The subject matter is the operation of a marketing/sales CRM; the data subjects are the Customer’s contacts, leads, and users; the categories are contact details, communication content + events, and usage data.

3. Confidentiality

We ensure personnel authorized to process Customer Data are bound by confidentiality and access it only as needed to provide the Service.

4. Security

We implement appropriate technical and organizational measures, including encryption in transit and at rest, per-tenant isolation, role-based access control, audit logging, and regular backups. Customers can export or erase their organization’s data from within the app (Settings → Data & Privacy).

5. Data subject rights

Taking into account the nature of the processing, we assist the Customer with responding to data-subject requests (access, rectification, erasure, portability, restriction). The Customer can fulfil most requests directly using the app’s export + erase tools.

6. Sub-processing

The Customer authorizes us to engage the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We will give notice of any intended change so the Customer may object.

7. International transfers

Where Customer Data is transferred across borders, we rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or an equivalent) as required by applicable law.

8. Retention + deletion

We retain Customer Data for the periods below, then delete or anonymize it, unless a longer period is required by law. On termination, the Customer may export its data; we delete it within the periods stated after account/organization deletion.

Data categoryRetention period
Contacts, lists, campaigns, forms, and landing pagesFor the life of the account; deleted or anonymized within 30 days of account/org deletion.
Email + WhatsApp send logs and delivery eventsUp to 24 months, then aggregated or deleted.
Audit log (who did what)Up to 12 months rolling.
Billing invoices + payment recordsRetained as required by tax/accounting law (typically up to 10 years).
BackupsRolling backups retained up to 35 days, then overwritten.
Account + authentication dataFor the life of the account; deleted within 30 days of deletion (except where law requires longer).

9. Personal data breach

We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information reasonably available to help the Customer meet its own notification obligations.

10. Audits

On reasonable request and subject to confidentiality, we make available information necessary to demonstrate compliance with this DPA.

This DPA is a template and not legal advice. Have counsel review and adapt it — including governing law, entity names, the transfer mechanism, and liability — before relying on it. See also our Terms of Service and Privacy Policy.