Feature ReleaseAutomated WhatsApp Lead Captures & AI Bots Are Now Live — Discover Capabilities →
Processor Terms

Data Processing Agreement

When you route your customers' data through our platform, you are the Data Fiduciary and we are your Processor. These are the terms that govern that.

Effective: August 7, 2026 Version: 1.0

1. STATUS AND INCORPORATION

1.1. This Data Processing Agreement ("DPA") forms part of the Terms of Service between UrbanXPixels Creative Studio ("Processor", "we") and the account holder ("Controller", "you"). Accepting the Terms at registration accepts this DPA.

1.2. Roles. You are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDPA") and the controller under the GDPR where it applies, in respect of the personal data you route through our platform. We are your Data Processor. You determine the purposes; we act on your instructions.

1.3. For our own account, billing, and support records about you, we act as Data Fiduciary in our own right. That processing is governed by our Privacy Policy, not by this DPA.

1.4. Conflict. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.

2. SCOPE OF PROCESSING

2.1. Subject matter: provision of the website, WhatsApp automation, broadcast, inbox, and lead-capture services described in your Statement of Work or plan.

2.2. Duration: for the term of the Agreement, plus the deletion window in Section 8.

2.3. Categories of Data Principal: your customers, prospects, leads, enquirers, and message recipients; and your own staff who hold dashboard logins.

2.4. Categories of personal data we process on your behalf:

  • Names and WhatsApp/mobile numbers in your contact lists
  • Email addresses submitted through forms we build for you
  • Message content, chat transcripts, and attachments exchanged with your contacts
  • Delivery, read, and failure metadata for each message
  • Lead form submissions and any custom fields you configure
  • Contact tags, notes, and segmentation labels your team applies

2.5. Special or sensitive categories. Our platform is not designed for health data, financial account data, biometric data, or data about children. You must not route such data through it without a separate written agreement. If you do so anyway, you accept sole responsibility for the resulting compliance exposure.

2.6. Instructions. Your documented instructions comprise this DPA, your Statement of Work, and the configuration choices you make in the dashboard. We will tell you if, in our view, an instruction appears to breach applicable data protection law, and may pause that processing until it is resolved.

3. OUR OBLIGATIONS AS PROCESSOR

3.1. We shall process personal data only on your documented instructions and only for the purposes in Section 2 — never for our own marketing, never sold, and never used to build profiles unrelated to your service.

3.2. Personnel. Access is limited to personnel who need it to deliver or support the Services. Everyone with access is bound by written confidentiality obligations that survive their engagement.

3.3. Assistance with rights requests. Where a Data Principal contacts us directly about data we hold for you, we will refer them to you and notify you within 3 Working Days. We will give you reasonable technical assistance — export, correction, deletion — to help you meet your own response deadlines under DPDPA s.11–13 or GDPR Art. 15–22.

3.4. Records and audit. We maintain records of the processing we carry out for you. On not less than 30 days' written notice, no more than once in any twelve-month period, and subject to confidentiality, we will provide a written response to a reasonable security questionnaire or make relevant documentation available. On-site audits require separate written agreement and are at your cost.

3.5. DPIA support. We will provide the information reasonably available to us to help you complete a data protection impact assessment for processing carried out on our platform.

4. SECURITY MEASURES

4.1. We apply the following technical and organisational measures, and will not materially reduce them during the term:

  • Encryption in transit — TLS on all public endpoints, with HTTP redirected to HTTPS
  • Credential protection — passwords stored as PBKDF2-SHA512 hashes with a per-user salt; never reversible, never logged
  • Access-token secrecy — third-party API tokens encrypted at rest with authenticated encryption
  • Session integrity — signed, HttpOnly, SameSite session cookies with server-side revocation on password change or ban
  • Tenant isolation — every data query is scoped to the owning account, enforced in the data layer rather than the interface
  • Least privilege — role-based access control separating client, staff, and administrator capability
  • Rate limiting — throttling on authentication and messaging endpoints to blunt credential-stuffing and abuse
  • Webhook verification — inbound platform webhooks validated by signature before processing
  • Audit logging — administrative and consent actions written to append-only logs
  • Backups — regular database backups, with restoration tested periodically

4.2. These measures are reviewed as the platform changes. Where a measure is superseded, it is replaced by one offering equivalent or better protection.

5. SUB-PROCESSORS

5.1. You give general written authorisation for us to engage the sub-processors below. Each is bound by written terms no less protective than this DPA, and we remain liable to you for their performance.

Sub-processorPurposeProcessing location
Meta Platforms (WhatsApp Business API)Delivering and receiving WhatsApp messagesUnited States / global
Cloud hosting provider (AWS, ap-south-1)Application servers, database, and object storageMumbai, India
Turso / libSQLManaged database for account and messaging recordsRegion-configurable; India where available
Payment gatewayProcessing subscription and invoice paymentsIndia
Transactional email providerAccount, billing, and password-reset emailsUnited States / global

5.2. Changes. We will give you at least 30 days' notice before adding or replacing a sub-processor that handles your Data Principals' personal data. If you reasonably object on data protection grounds within that period, we will work with you on an alternative; if none is workable, you may terminate the affected Service without penalty for the unexpired term.

5.3. This page is the authoritative sub-processor list. Check the version stamp above to confirm you are reading the current edition.

6. INTERNATIONAL TRANSFERS

6.1. Primary application and database infrastructure is hosted in Mumbai, India (ap-south-1).

6.2. Some sub-processors in Section 5 — notably Meta and our email provider — process data outside India as an inherent part of their service. Routing a message through WhatsApp necessarily involves Meta's global infrastructure.

6.3. DPDPA s.16. We will not transfer personal data to any territory that the Central Government restricts by notification, and will reconfigure or replace an affected sub-processor if a notification requires it.

6.4. GDPR. Where the GDPR applies to your processing, transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with the measures in Section 4 as supplementary safeguards.

7. PERSONAL DATA BREACH

7.1. Notification to you. We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting personal data we process on your behalf.

7.2. Contents. The notification will describe, so far as then known: the nature of the breach; the categories and approximate number of Data Principals and records affected; the likely consequences; and the measures taken or proposed to address it and mitigate harm. Where full detail is not yet available we will provide it in phases without further undue delay.

7.3. Your reporting duties. As Data Fiduciary, you are responsible for notifying the Data Protection Board of India and affected Data Principals where the law requires it. We will give you the information you reasonably need to do so within your own deadline.

7.4. Remediation. We will take reasonable steps to contain the breach, preserve evidence, and prevent recurrence, and will keep you informed of material developments.

7.5. Notification is not an admission of fault by either party. Our aim is to get you accurate information fast enough for you to meet your own obligations.

8. RETURN AND DELETION

8.1. Export on request. During the term and for 30 days after termination, you may request an export of the personal data we hold for you in a structured, machine-readable format at no charge.

8.2. Deletion. Within 30 days of termination, or of your earlier written instruction, we will delete the personal data we process on your behalf from live systems, and from backups within the ordinary backup rotation cycle.

8.3. Permitted retention. We may retain data where storage is required by Indian law — including financial and tax records, and the consent records described in clause 8.4. Retained data stays subject to this DPA's confidentiality and security obligations for as long as we hold it.

8.4. Consent records. Records of legal-document acceptance — account identifier, email, document version and effective date, UTC timestamp, IP address, and user-agent — are retained for seven (7) years as evidence of consent under DPDPA s.6 and GDPR Art. 7(1). These records are append-only, survive account deletion, and are excluded from erasure requests, because their whole purpose is to prove what was agreed and when.

9. LIABILITY AND CONTACT

9.1. Liability under this DPA is subject to the limitations and the aggregate cap in Section 12 of the Terms of Service, except where a mandatory provision of applicable data protection law prevents that limitation.

9.2. Nothing in this DPA relieves either party of a duty imposed directly on it by the DPDPA or the GDPR.

9.3. Data protection contact: privacy@urbanxpixels.com

9.4. Grievance Officer (DPDPA s.13): grievances@urbanxpixels.com

9.5. A countersigned copy of this DPA for your compliance file is available on request to privacy@urbanxpixels.com.