01Parties and scope
This Data Processing Addendum (“DPA”) is part of the Terms of Service between YS Digital Studio Private Limited (“Jawab”, the data processor) and the business using Jawab (“you”, the data fiduciary). It applies automatically when you accept the Terms; no separate signature is needed. If you need a countersigned copy, email [email protected].
Words like “personal data”, “data principal”, “data fiduciary”, “data processor” and “personal data breach” have the meanings given in the Digital Personal Data Protection Act, 2023 (“DPDP Act”). If this DPA and the Terms conflict on data protection, this DPA wins.
02What we process and why
Subject matter and duration
Processing your customers' personal data to provide Jawab, for as long as your account is active plus the 30-day read-only period after it ends.
Nature and purpose
Receiving, storing, organising, displaying and sending WhatsApp messages; running automated replies, flows, reminders and broadcasts you set up; managing contacts, leads and bookings; producing reports; and supporting you.
Data principals
Your customers, leads and enquirers (for example patients, clients, students, buyers and their parents or guardians), and anyone else who messages your WhatsApp Business number.
Categories of personal data
- names, WhatsApp numbers and WhatsApp profile names;
- message content, photos, documents and voice notes;
- tags, notes, lead stage and staff assignment;
- booking, reminder and payment-status records;
- opt-in and opt-out records;
- any other data you choose to collect, which may include health or financial details — you decide whether to collect these.
03Our obligations
Jawab will:
- Follow your instructions. Process the data only to provide the service and on your documented instructions — the Terms, this DPA and how you configure Jawab — unless Indian law requires otherwise, in which case we will tell you first where the law allows. We will tell you if we believe an instruction breaks the DPDP Act.
- Keep it confidential. Allow access only to staff who need it, who are bound by confidentiality. Support access is read-only, requires a recorded reason, lasts 15 to 60 minutes and is written to your audit log.
- Protect it. Maintain reasonable security safeguards, including encryption in transit and at rest, separation between businesses, role-based access, backups and monitoring.
- Report breaches. Notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data — with what happened, the data and people likely affected, what we have done and what you may need to do. We will help you meet your own duty to inform the Data Protection Board of India and affected data principals, and we will report to CERT-In as the law requires.
- Help with requests. Help you respond to data principals exercising their rights (access, correction, erasure, grievance, nomination), mostly through tools in the app such as contact export, edit and delete. If a data principal contacts us directly, we will pass the request to you and not answer it ourselves unless you ask us to.
- Honour opt-outs. Record STOP replies and stop automated and promotional messages to that number.
- Return or delete at the end. Give you 30 days of read-only access to export your data after your account ends, then delete it, with backups overwritten within a further 35 days — except where the law requires us to keep something.
- Allow audits. Give you the information reasonably needed to show we meet this DPA, and allow an audit by you or an independent auditor bound by confidentiality, on at least 30 days' written notice, no more than once a year (unless after a breach or at a regulator's request), during business hours and at your cost.
04Your obligations
As the data fiduciary, you are responsible for having a lawful basis — usually consent — for the data you collect and the messages you send; giving your customers a privacy notice; getting verifiable parental consent for children; meeting WhatsApp's opt-in rules; and answering data principal requests.
05Subprocessors
You authorise us to use the subprocessors listed in our Privacy Policy — currently Amazon Web Services (hosting, India), Meta Platforms (WhatsApp Cloud API), Razorpay (payments), Resend or Amazon SES (email) and Google (sign-in and optional calendar sync).
- Each subprocessor is bound by written data protection terms at least as protective as these.
- We remain responsible to you for our subprocessors' work.
- We will give you at least 15 days' notice by email before adding or replacing a subprocessor. If you object on reasonable data protection grounds and we can't resolve it, you may end the affected service and receive a refund of prepaid fees for the unused period.
06Where data is stored
Your data is stored in India, on Amazon Web Services in Mumbai (ap-south-1). Messages pass through Meta's infrastructure as part of WhatsApp delivery, and some subprocessors may process limited data outside India to provide their service, always subject to any restrictions notified under section 16 of the DPDP Act.
07Liability and term
The limitation of liability in the Terms applies to this DPA. This DPA lasts as long as we process your data and ends when it has been deleted. Questions: [email protected].