Data Processing Agreement
Last updated: 11 July 2026
1. Definitions
“Personal data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given in applicable data-protection law, including India's DPDP Act 2023 and the GDPR.
2. Scope & nature of processing
| Detail | |
|---|---|
| Subject-matter | Processing of personal data to provide the Pleisys Engage platform. |
| Duration | For the term of the customer's subscription. |
| Nature | Storage, transmission, segmentation, and conversation delivery. |
| Purpose | Enabling the customer to engage its contacts across messaging channels. |
| Data types | Contact identifiers, message content, consent records, usage metadata. |
| Data subjects | The customer's contacts and end users. |
3. Controller obligations
The Controller is responsible for establishing a lawful basis and obtaining any required consent for the personal data it processes through the platform, and for issuing lawful processing instructions.
4. Processor obligations
- Process personal data only on the Controller's documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Assist the Controller with data subject requests and breach notifications.
- Delete or return personal data at the end of the engagement.
5. Sub-processors
The Controller authorizes the use of the sub-processors below. We will give notice before adding or replacing a sub-processor.
| Sub-processor | Purpose | Region |
|---|---|---|
| Meta Platforms | WhatsApp Cloud API | USA / EU |
| Twilio | WhatsApp & SMS delivery | USA |
| Amazon Web Services (SES) | Email delivery | India / USA |
| Amazon Web Services (S3) | Object & file storage | India / USA |
| Razorpay | Payments (INR) | India |
| Hostinger (VPS) | Hosting | India |
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control and least-privilege access.
- Password hashing with a memory-hard function (scrypt).
- Tenant isolation via row-level security.
- Audit logging and monitoring.
- Vulnerability management and incident response (breach notification within 72 hours).
7. Data subject rights
We provide tooling and assistance to help the Controller fulfil data subject requests, including access, correction, deletion (via crypto-shred erasure), and export. End users may also use our DSAR portal.
8. International data transfers
Primary data is stored in India, which is not the subject of an EU adequacy decision under Art. 45 GDPR. Accordingly, the Standard Contractual Clauses are the transfer mechanism for personal data of individuals in the EU/EEA.
Where the Processor transfers Controller personal data across borders, the parties incorporate the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) by reference — Module Two (controller-to-processor) where the Controller is the exporter, and Module Three (processor-to-processor) where a Pleisys sub-processor is the onward importer, as applicable. For transfers of UK personal data, the parties incorporate the UK International Data Transfer Addendum to the SCCs. These are supported by a transfer impact assessment and the technical and organizational measures described in this DPA.
9. Personal data breach notification
On becoming aware of a personal data breach affecting Controller personal data, the Processor will notify the Controller without undue delay and in any event within 72 hours. The notification will provide the information the Controller reasonably needs to meet its own obligations under Arts. 33 and 34 GDPR — including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it — supplemented as further details become available. The Processor will assist the Controller in notifying its supervisory authority and affected data subjects where required.
10. Audit rights
On reasonable notice, the Controller may request information necessary to demonstrate compliance with this DPA, subject to confidentiality and not more than once per year except where required by a supervisory authority.
11. Term & termination
This DPA remains in effect for as long as we process personal data on the Controller's behalf. On termination, we delete or return personal data per the Controller's instruction and our retention policy.
12. Contact & governing law
For DPA matters, contact privacy@pleisys.com. This DPA is governed by the laws of India.