Data Processing Agreement

Last updated: 12 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between VGraple ("Processor", "we", "us") and the business that has registered for a VGraple CRM account ("Customer", "Controller", "you") for the use of the VGraple CRM platform (the "Service"). It governs the processing of personal data that we carry out on your behalf when you use the Service to manage WhatsApp and related communications with your customers.

This DPA is designed to reflect the requirements of Article 28 of the EU/UK General Data Protection Regulation ("GDPR") and India’s Digital Personal Data Protection Act, 2023 ("DPDP Act"). Where you are subject to those laws, this DPA applies to the extent we process personal data as your processor (or, under the DPDP Act, as a Data Processor acting for you as Data Fiduciary). It is read together with our Privacy Policy and Terms of Service.

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person that we process on your behalf under the Service.
  • Processing: Any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
  • Controller / Data Fiduciary: You, the Customer, who determines the purposes and means of the Processing.
  • Processor / Data Processor: VGraple, which processes Personal Data on your documented instructions.
  • Sub-processor: A third party engaged by us to process Personal Data in connection with the Service.
  • Data Subject / Data Principal: The individual to whom the Personal Data relates, including your end-customers who message your WhatsApp Business number.

2. Roles of the Parties

You are the Controller of the Personal Data you upload to or generate within the Service, including your contacts’ details and the content of your conversations with them. We are the Processor acting on your behalf. You are responsible for establishing a lawful basis for the Processing (including obtaining any required consent or opt-in from your contacts) and for your instructions being lawful. We process Personal Data only as needed to provide the Service.

3. Scope and Instructions

We process Personal Data only on your documented instructions, given through this DPA and the Terms of Service, your use and configuration of the Service, and any additional lawful written instructions you provide.

We will inform you if, in our opinion, an instruction infringes applicable data protection law, unless legally prohibited from doing so. The details of the Processing are set out in Annex 1.

4. Confidentiality

We ensure that any person authorised to process the Personal Data is bound by an appropriate duty of confidentiality and processes the data only on our instructions. Access to production data is limited to personnel who need it to operate and support the Service.

5. Security Measures

Taking into account the state of the art and the nature of the Processing, we implement appropriate technical and organisational measures to protect Personal Data, as described in Annex 2. These include encryption of sensitive fields at rest, encryption in transit (TLS), access controls, a web application firewall, off-site encrypted backups, audit logging, and rate limiting.

6. Sub-processors

You provide general authorisation for us to engage the Sub-processors listed in Annex 3 to process Personal Data in connection with the Service. Each Sub-processor is bound by contractual obligations that provide a comparable level of data protection to this DPA. We remain responsible to you for the performance of our Sub-processors’ obligations.

If we add or replace a Sub-processor, we will update Annex 3 and, where required, give you notice so that you may object on reasonable data-protection grounds. The WhatsApp Business Cloud API operated by Meta is a core Sub-processor that cannot be removed without discontinuing the Service.

7. Assistance with Data Subject Rights

Taking into account the nature of the Processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (such as access, correction, deletion, and objection). The Service provides self-service tools to search, edit, export, and delete contact and conversation data, and to honour opt-out (STOP) requests automatically.

8. Personal Data Breach

We maintain monitoring and alerting to detect security incidents. In the event of a Personal Data Breach affecting your data, we will notify you without undue delay after becoming aware of it, and provide the information reasonably available to us to help you meet your own breach notification obligations. Notifications are sent to the email address associated with your account, so please keep it current.

9. Deletion and Return of Data

You may export your data at any time through the Service. On termination of your account, or on your written request, we will delete or return the Personal Data we process on your behalf, unless we are required by law to retain it. Contacts and conversations deleted in the app are removed from active systems, and residual copies in encrypted backups are purged on the backup rotation cycle.

10. Audits

We make available to you the information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, and no more than once per year (or following a Personal Data Breach), you may request additional information or an audit limited to our processing of your Personal Data, subject to confidentiality obligations and conducted in a way that does not compromise the security of other customers.

11. International Transfers

The Service and its Sub-processors may process Personal Data in countries other than your own, including India and the United States. Where a transfer is subject to GDPR, we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, or a Sub-processor’s own approved transfer framework. Where the DPDP Act applies, transfers are made in accordance with its cross-border provisions.

12. Liability and Term

This DPA is effective for as long as we process Personal Data on your behalf. Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails.

Annex 1 - Details of Processing

  • Subject matter: Provision of the VGraple CRM WhatsApp Business messaging and CRM platform.
  • Duration: For the term of your account, plus the retention periods described in the Privacy Policy.
  • Nature and purpose: Sending and receiving WhatsApp messages, storing conversation history, managing contacts and leads, running broadcasts and automations, scheduling appointments, taking in-chat payments, and generating analytics on your behalf.
  • Categories of Data Subjects: Your business users (agents) and your end-customers who communicate with your WhatsApp Business number or submit your forms.
  • Types of Personal Data: Names, phone numbers, email addresses, WhatsApp profile names, message and media content, form responses, appointment details, payment references, and usage or device identifiers.
  • Special categories: We do not require special category data. You should avoid sending sensitive personal data through the Service unless you have a lawful basis and appropriate safeguards.

Annex 2 - Technical and Organisational Measures

  • Encryption at rest: Sensitive fields (such as contact identifiers and credentials) are encrypted in the database; provider access tokens are encrypted before storage.
  • Encryption in transit: All connections use TLS. Public traffic passes through a web application firewall.
  • Access control: Role-based access within each account, two-factor authentication for user logins, and least-privilege access to production systems.
  • Tenant isolation: Every data query is scoped to the owning organisation to prevent cross-account access.
  • Backups: Automated encrypted backups stored off the primary server, with tested restore procedures.
  • Logging and monitoring: Audit logging of account changes, error monitoring, and uptime and health monitoring with alerting.
  • Rate limiting and abuse prevention: Rate limits and signature verification on public and webhook endpoints; a common-password blocklist on sign-up.
  • Secure development: Changes go through a continuous integration pipeline with type checks, linting, and automated tests before deployment.

Annex 3 - Sub-processors

We engage the following Sub-processors to provide the Service. The set that applies to your account depends on the features you use (for example, payment and AI providers are used only if you enable them).

Sub-processorPurpose
Meta Platforms (WhatsApp Business Cloud API)Sending and receiving WhatsApp messages and media on your behalf. Core to the Service.
Oracle Cloud InfrastructureApplication hosting and compute.
NeonManaged PostgreSQL database hosting.
CloudflareCDN, DNS, TLS, and web application firewall.
StripeSubscription billing and, if enabled, in-chat card payments.
Cashfree PaymentsSubscription billing and, if enabled, in-chat UPI/card payments (India).
AnthropicAI assistant and chatbot responses, if you enable AI features and provide a key.
OpenAIAI assistant, embeddings, and chatbot responses, if you enable AI features and provide a key.
Google (Firebase Cloud Messaging)Mobile push notifications to your team’s devices.
Google (Sign-In / OAuth)Optional Google single sign-on for account login.
CalendlyAppointment booking sync, if you connect a Calendly account.
SentryApplication error monitoring and diagnostics.
Better Stack (Logtail)Operational log management and uptime monitoring.

Contact

For any questions about this DPA or to exercise data protection rights on behalf of your organisation, contact us at [email protected]. This DPA is provided by VGraple as the operator of VGraple CRM.