Data Processing Agreement (DPA)

Between Filova LTD ("Processor") and the Tenant ("Controller")

Last updated: 5 August 2026

Tenant accepts this DPA when creating an account, together with the Terms of Service. No separate signature is required.

1. Definitions

  • "Controller": the Tenant who determines the purposes and means of processing Personal Data of their end-users.
  • "Processor": Filova LTD, which processes Personal Data on behalf of the Controller.
  • "Personal Data": any information relating to an identified or identifiable natural person.
  • "Processing": any operation performed on Personal Data (collection, storage, use, disclosure, deletion, etc.).
  • "Data Subject": the natural person to whom Personal Data relates (i.e., the end-user messaging via WhatsApp).
  • "Sub-processor": a third party engaged by the Processor to carry out specific Processing activities on behalf of the Controller.
  • "Supervisory Authority": the Information Commissioner's Office (ICO) for UK personal data; the relevant EU data protection authority for EU personal data.

2. Scope and Duration

This DPA applies to all Personal Data processed by Filova LTD on behalf of the Tenant in connection with the Wava service. Duration: co-terminus with the Wava Terms of Service. Upon termination of the Terms of Service, this DPA also terminates, subject to the data deletion obligations in Section 11.

3. Nature and Purpose of Processing

Processor processes Personal Data solely to provide the Wava WhatsApp customer support service, including: receiving and processing end-user WhatsApp messages, generating AI-powered responses via Anthropic Claude, storing conversation history, and providing analytics via the dashboard.

4. Categories of Personal Data and Data Subjects

CategoryDetails
Data subjectsEnd-users of Tenant's WhatsApp channel
Personal data categoriesWhatsApp phone number in full (E.164 format), message content, conversation metadata (timestamps, state), a 1–5 satisfaction rating where the end-user sends one, consent records keyed to a salted hash of the phone number, and — where an end-user supplies them during a conversation — lead details: email and phone held encrypted, name and free-text note as provided
Special category dataNone intentionally processed. Tenant must not send special category data (Art. 9 GDPR / Art. 6 UK GDPR) via the Wava service.

5. Controller's Instructions

Processor shall process Personal Data only on documented instructions from Controller (these Terms and this DPA). Controller instructs Processor to: (a) process data to provide the Service; (b) delete data per retention schedules; (c) assist with data subject rights requests. If Processor is required by law to process Personal Data beyond these instructions, Processor will inform Controller before such processing, unless prohibited by law.

6. Processor Obligations (GDPR Art. 28(3))

  • Process Personal Data only on Controller's documented instructions.
  • Ensure that persons authorised to process Personal Data are under appropriate confidentiality obligations.
  • Implement appropriate technical and organisational security measures in accordance with Art. 32 GDPR / UK GDPR.
  • Respect the conditions for engaging Sub-processors (Art. 28(2) GDPR / UK GDPR).
  • Assist Controller in responding to Data Subject rights requests under Arts. 15–22 GDPR / UK GDPR.
  • Assist Controller with obligations under Arts. 32–36 GDPR / UK GDPR (security, DPIA, prior consultation).
  • Delete or return all Personal Data at the end of the service, and delete existing copies unless retention is required by law.
  • Make available all information necessary to demonstrate compliance and allow for audits (Art. 28(3)(h)).

7. Sub-processors

Controller provides general authorisation for Processor to engage Sub-processors listed at wavaapp.com/en/subprocessors. Processor will notify Controller of any intended changes (additions or replacements) with 30 days' notice. Controller may object in writing within 14 days of such notice. Current Sub-processors:

  • WhatsApp Ireland Limited (Meta)WhatsApp message delivery. Ireland (EU) — onward transfer to WhatsApp LLC (US) relies on the EU-US Data Privacy Framework.
  • Anthropic, Inc.AI-powered response generation. United States.
  • Supabase Pte. Ltd.Database and authentication. Singapore (contracting entity) — database hosting: EU (eu-central-1, Frankfurt).
  • Vercel Inc.Application hosting. United States (global CDN).
  • Sentry (Functional Software, Inc.)Error tracking and application monitoring. United States.
  • Upstash, Inc.Idempotency (duplicate message-processing guard). United States (contracting entity; provisioned through Vercel Marketplace) — data hosting: EU (AWS eu-central-1, Frankfurt).

This authorisation covers only the Sub-processors above, meaning those that process Personal Data on Controller's behalf. Providers that Processor engages for its own purposes — billing, account notifications and bot protection, where Processor acts as a controller in its own right rather than on Controller's instructions — are not Sub-processors under this Agreement and are not subject to this clause. They are disclosed for transparency in the second table at wavaapp.com/en/subprocessors.

8. Security Measures (Art. 32)

  • (a) Encryption in transit (TLS 1.2+) and at rest.
  • (b) Personal data is protected according to the role it plays in the Service:
    • Consent and audit records identify the end-user only by a salted SHA-256 hash of their phone number, which cannot be reversed to the number itself.
    • Lead contact details (email, phone) are encrypted at the column level with pgcrypto; the encryption key is held in the application environment and is never stored in the database.
    • The conversation record stores the WhatsApp phone number in full, because each inbound message is matched to its conversation by number. It is protected by row-level security (tenant isolation) and encryption at rest, and is masked wherever it appears in logs.
  • (c) Message content is not written to production logs.
  • (d) Access controls, role-based permissions, and multi-factor authentication for staff.
  • (e) Automated checks on every change before deployment (type checking, test suite, linting) and dependency vulnerability monitoring. Independent penetration testing is carried out before general availability and periodically thereafter.
  • (f) Documented incident response procedures.

9. Data Breach Notification

Processor shall notify Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Controller's data. Notification shall include: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences of the breach, and measures taken or proposed to address the breach and mitigate its possible adverse effects.

10. Data Subject Rights

Processor shall assist Controller in responding to Data Subject requests under GDPR / UK GDPR Arts. 15–22 (right of access, rectification, erasure, restriction of processing, data portability, and objection). Controller remains solely responsible for responding to Data Subjects. Processor will action verified instructions from Controller within 30 days of receipt.

11. Data Deletion / Return

Upon termination of the Wava service, Processor shall, at Controller's election: (a) delete all Personal Data within 30 days, or (b) provide a data export in JSON format within 30 days. Deletion from Processor's production systems is completed within that 30-day period. Residual copies held in Sub-processor backup snapshots are not accessible for ordinary use and expire on those providers' rolling retention cycles, in any event no later than 30 days after the production deletion. Error-diagnostic records held by our monitoring Sub-processor are deleted on that provider's own retention cycle. Processor does not deliberately send message content or contact details to that provider, but such data may appear incidentally within an error message or stack trace; those records are not used for any purpose other than diagnosing the fault. Processor shall provide written certification of deletion upon request.

12. International Transfers

Where Processor transfers Personal Data to third countries (directly US-based Sub-processors: Anthropic, Vercel, Sentry; Meta's WhatsApp Business Platform contracts through its Irish entity, WhatsApp Ireland Limited, with onward transfer to its US affiliates; the contracting entities of Supabase and Upstash are incorporated in Singapore and the United States respectively, though the data each holds is hosted in the EU), Processor relies on the following transfer mechanisms:

  • EU personal data: Standard Contractual Clauses (EU Commission Implementing Decision 2021/914).
  • UK personal data: UK Addendum to the EU SCCs (issued by the ICO, in force March 2022) and/or the UK–US Data Bridge where applicable.
  • Turkish personal data: where KVKK applies, Processor will put in place the appropriate safeguard required under KVKK Art. 9(4) — typically the Standard Contract (Standart Sözleşme) under Art. 9(4)(c) — before the transfer, and will notify the Personal Data Protection Board (KVKK Kurulu) within 5 business days of signature as required by KVKK Art. 9(5).
  • End users in other jurisdictions: Controller is established in Türkiye or the United Kingdom (see the Service's Terms of Service), but its own end users may be located anywhere. Where Data Subjects are located outside the EU, UK and Türkiye, Processor will apply safeguards no less protective than those described above (using the EU Standard Contractual Clauses as the general benchmark) and will provide details of the applicable mechanism to Controller upon request.

13. Audit Rights

Controller may, upon 30 days' prior written notice, conduct (or commission a qualified third-party auditor to conduct) an audit of Processor's compliance with this DPA, no more than once per calendar year and at Controller's own expense. Processor will cooperate fully and provide access to relevant documentation and personnel. Audit findings shall be treated as confidential.

14. Entire Agreement

This DPA supplements and forms part of the Wava Terms of Service. In the event of conflict between this DPA and the Terms of Service with respect to data protection matters, this DPA shall prevail.

15. Governing Law

This DPA is governed by the laws of England and Wales. Any dispute arising out of or in connection with this DPA shall be subject to the jurisdiction of the courts of England and Wales on a non-exclusive basis. Controllers established in Turkey may alternatively bring proceedings before the Istanbul Central (Çağlayan) Courts and Enforcement Offices, Türkiye.

16. Contact

For DPA-related enquiries, please contact: privacy@wavaapp.com
Filova LTD · 71-75 Shelton Street, London WC2H 9JQ, UK · Company No: 17263134 · Phone: +44 7441 427697