Data Processing Agreement
Last updated: 3 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between you (the “Customer”, acting as data controller) and us (the “Processor”) for your use of the Service. It applies where we process personal data on your behalf.
1. Roles
The Customer is the controller and we are the processor of the personal data the Customer uploads or generates through the Service (“Customer Data”). Each party will comply with applicable data-protection law, including the GDPR where applicable and Indonesia’s Personal Data Protection Law (UU PDP).
2. Scope + purpose of processing
We process Customer Data only to provide and support the Service and on the Customer’s documented instructions (including via the app’s configuration), unless required otherwise by law. The subject matter is the operation of a marketing/sales CRM; the data subjects are the Customer’s contacts, leads, and users; the categories are contact details, communication content + events, and usage data.
3. Confidentiality
We ensure personnel authorized to process Customer Data are bound by confidentiality and access it only as needed to provide the Service.
4. Security
We implement appropriate technical and organizational measures, including encryption in transit and at rest, per-tenant isolation, role-based access control, audit logging, and regular backups. Customers can export or erase their organization’s data from within the app (Settings → Data & Privacy).
5. Data subject rights
Taking into account the nature of the processing, we assist the Customer with responding to data-subject requests (access, rectification, erasure, portability, restriction). The Customer can fulfil most requests directly using the app’s export + erase tools.
6. Sub-processing
The Customer authorizes us to engage the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We will give notice of any intended change so the Customer may object.
7. International transfers
Where Customer Data is transferred across borders, we rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or an equivalent) as required by applicable law.
8. Retention + deletion
We retain Customer Data for the periods below, then delete or anonymize it, unless a longer period is required by law. On termination, the Customer may export its data; we delete it within the periods stated after account/organization deletion.
| Data category | Retention period |
|---|---|
| Contacts, lists, campaigns, forms, and landing pages | For the life of the account; deleted or anonymized within 30 days of account/org deletion. |
| Email + WhatsApp send logs and delivery events | Up to 24 months, then aggregated or deleted. |
| Audit log (who did what) | Up to 12 months rolling. |
| Billing invoices + payment records | Retained as required by tax/accounting law (typically up to 10 years). |
| Backups | Rolling backups retained up to 35 days, then overwritten. |
| Account + authentication data | For the life of the account; deleted within 30 days of deletion (except where law requires longer). |
9. Personal data breach
We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information reasonably available to help the Customer meet its own notification obligations.
10. Audits
On reasonable request and subject to confidentiality, we make available information necessary to demonstrate compliance with this DPA.
This DPA is a template and not legal advice. Have counsel review and adapt it — including governing law, entity names, the transfer mechanism, and liability — before relying on it. See also our Terms of Service and Privacy Policy.