Legal

Data Processing Agreement

Last updated: 11 July 2026

This DPA forms part of the agreement between the customer (“Controller”) and Pleisys (“Processor”) and governs the processing of personal data on the Controller's behalf when using Pleisys Engage.

1. Definitions

“Personal data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given in applicable data-protection law, including India's DPDP Act 2023 and the GDPR.

2. Scope & nature of processing

Detail
Subject-matterProcessing of personal data to provide the Pleisys Engage platform.
DurationFor the term of the customer's subscription.
NatureStorage, transmission, segmentation, and conversation delivery.
PurposeEnabling the customer to engage its contacts across messaging channels.
Data typesContact identifiers, message content, consent records, usage metadata.
Data subjectsThe customer's contacts and end users.

3. Controller obligations

The Controller is responsible for establishing a lawful basis and obtaining any required consent for the personal data it processes through the platform, and for issuing lawful processing instructions.

4. Processor obligations

  • Process personal data only on the Controller's documented instructions.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organizational security measures.
  • Assist the Controller with data subject requests and breach notifications.
  • Delete or return personal data at the end of the engagement.

5. Sub-processors

The Controller authorizes the use of the sub-processors below. We will give notice before adding or replacing a sub-processor.

Sub-processorPurposeRegion
Meta PlatformsWhatsApp Cloud APIUSA / EU
TwilioWhatsApp & SMS deliveryUSA
Amazon Web Services (SES)Email deliveryIndia / USA
Amazon Web Services (S3)Object & file storageIndia / USA
RazorpayPayments (INR)India
Hostinger (VPS)HostingIndia

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access control and least-privilege access.
  • Password hashing with a memory-hard function (scrypt).
  • Tenant isolation via row-level security.
  • Audit logging and monitoring.
  • Vulnerability management and incident response (breach notification within 72 hours).

7. Data subject rights

We provide tooling and assistance to help the Controller fulfil data subject requests, including access, correction, deletion (via crypto-shred erasure), and export. End users may also use our DSAR portal.

8. International data transfers

Primary data is stored in India, which is not the subject of an EU adequacy decision under Art. 45 GDPR. Accordingly, the Standard Contractual Clauses are the transfer mechanism for personal data of individuals in the EU/EEA.

Where the Processor transfers Controller personal data across borders, the parties incorporate the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) by reference — Module Two (controller-to-processor) where the Controller is the exporter, and Module Three (processor-to-processor) where a Pleisys sub-processor is the onward importer, as applicable. For transfers of UK personal data, the parties incorporate the UK International Data Transfer Addendum to the SCCs. These are supported by a transfer impact assessment and the technical and organizational measures described in this DPA.

9. Personal data breach notification

On becoming aware of a personal data breach affecting Controller personal data, the Processor will notify the Controller without undue delay and in any event within 72 hours. The notification will provide the information the Controller reasonably needs to meet its own obligations under Arts. 33 and 34 GDPR — including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it — supplemented as further details become available. The Processor will assist the Controller in notifying its supervisory authority and affected data subjects where required.

10. Audit rights

On reasonable notice, the Controller may request information necessary to demonstrate compliance with this DPA, subject to confidentiality and not more than once per year except where required by a supervisory authority.

11. Term & termination

This DPA remains in effect for as long as we process personal data on the Controller's behalf. On termination, we delete or return personal data per the Controller's instruction and our retention policy.

12. Contact & governing law

For DPA matters, contact privacy@pleisys.com. This DPA is governed by the laws of India.