Whappy

Data Processing Addendum

Last Updated: October 3, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you, the business using Whappy ("you" or the "Customer"), and Whappy Inc., a Delaware corporation ("Whappy", "we", "us"). It applies whenever Whappy processes personal data on your behalf while providing the Service, including personal data received from a store you connect, such as a Shopify store. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.

1. Roles

For the personal data of your leads and customers ("Customer Personal Data"), you are the controller and Whappy is your processor (or service provider under the CCPA). For your own account data, Whappy is the controller, as described in our Privacy Policy.

2. Details of the processing

Subject matterRunning your WhatsApp conversations: starting them, answering in them with the AI assistant, and handing results to the tools you connect
DurationFor as long as you use the Service, plus the deletion periods in section 7
Data subjectsYour leads and customers, including buyers of a connected store
Categories of dataName, phone number, email address, WhatsApp identifier, the messages exchanged with you, answers given in a conversation, appointments, consent and opt-out records, and, from a connected store, recent orders (order number, date, items, total, status and tracking) and abandoned checkouts (cart contents, total and recovery link)
Special categoriesNone are needed. Do not ask your customers for special-category data through Whappy
PurposeProviding the Service to you as configured by you; nothing else

3. Our obligations

  1. Your instructions. We process Customer Personal Data only to provide the Service and on your documented instructions, which are these Terms, this DPA and your configuration of the Service. We tell you if we believe an instruction breaks the law.
  2. No other use. We do not sell Customer Personal Data, share it for cross-context behavioural advertising, combine it with another customer's data, or use it to train AI models.
  3. Confidentiality. Only Whappy staff who need access to run or support the Service can reach Customer Personal Data, and they are bound by confidentiality.
  4. Security. We apply the measures in section 9 and keep them at least at that level for the life of this DPA.
  5. Assistance. We help you answer requests from your customers to access, correct, delete or export their data, and with data protection impact assessments where our processing is relevant. For connected Shopify stores, access and deletion requests are handled automatically (section 8).
  6. Breach notification. We notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your Customer Personal Data, with what we know about its nature, the data and people concerned, its likely consequences and the measures taken. We keep you updated as we learn more.
  7. Records and audits. We make available the information you reasonably need to show compliance with this DPA, and answer reasonable written audit questions once a year, or after a breach, at no charge.

4. Your obligations

You are responsible for having a lawful basis for the processing you instruct, including the opt-in that WhatsApp and the law require before a business messages a person, and for the accuracy of the data you bring into Whappy.

5. Sub-processors

You authorise us to use the sub-processors below. We hold each to data protection terms at least as protective as this DPA and remain responsible for their work. We give at least 30 days' notice of a new sub-processor by email to your account address; you may object on reasonable data protection grounds, and if we cannot address the objection you may end the affected part of the Service.

Sub-processorWhat it does for usWhere
Google LLC (Google Cloud, including Vertex AI and Firebase Authentication)Hosting, storage, queues, logging, sign-in, and the AI models that write repliesApplication hosting in the European Union (Belgium, Netherlands); AI requests may be served from other Google regions
MongoDB, Inc. (MongoDB Atlas)DatabaseCloud region of our Atlas cluster
Meta Platforms Ireland Ltd (WhatsApp Business Platform)Delivering messages to and from the people you messageMeta's infrastructure
Langfuse GmbHRecords of AI requests and replies, used to find and fix mistakesEuropean Union
Resend, Inc.Sending service emails, including data-export linksUnited States

6. International transfers

Where Customer Personal Data subject to the GDPR, UK GDPR or Swiss law is transferred to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission (Module 2, or Module 3 where you are yourself a processor), with the UK Addendum where relevant, are incorporated into this DPA by reference, with Whappy as data importer. The courts and law named in the Terms apply to the extent the clauses allow.

7. Retention and deletion

We keep Customer Personal Data for as long as you keep it in the Service. When you delete a lead, a campaign or your account, the related data is deleted from our production systems; backups roll off on their normal cycle and are not restored except to recover from an incident. Data from a connected store has shorter limits:

Data from a connected storeKept for
Abandoned checkouts30 days
Recent orders used for order answers90 days
Store webhook delivery records7 days
Records of a buyer's data request60 days
A buyer's data export file30 days after it is delivered
Everything from a store, after the app is uninstalledPurged when Shopify sends its shop deletion request, 48 hours after uninstall

8. Connected Shopify stores

When you connect a Shopify store:

  • What we receive. Only customers who agreed to SMS marketing in Shopify become leads or receive messages. We use their name, email and phone number; we do not use addresses. If a customer withdraws consent in Shopify, they stop receiving marketing messages from you through Whappy.
  • Buyer requests. When Shopify forwards a buyer's request for their data, we prepare an export of everything we hold about that buyer and email the store owner a download link valid for 7 days. When Shopify forwards a buyer's deletion request, we anonymise that buyer's leads, blank the text of their conversations and delete their appointments and order records.
  • Access tokens. The token that lets Whappy read your store is encrypted at rest and is never shown to you or to other customers.
  • Billing. Plans for Shopify stores are charged by Shopify; Shopify does not receive your customers' conversations from us.

9. Security measures

  • Encryption in transit (TLS) on every endpoint and at rest for databases, storage and backups; store access tokens additionally sealed with AES-256-GCM.
  • Tenant isolation: every request is scoped to the account it belongs to.
  • Secrets held in a managed secret store with access granted per service; storage buckets are private and reached only through short-lived signed links.
  • Staff access limited to those who need it, with unique strong passwords and two-step verification.
  • Logs of access to secrets and stored exports kept for 400 days; request logs for every API call.
  • Separate development and production environments; production data is not copied to development.
  • A written security incident response policy, including the 72-hour notice in section 3.

10. Contact

Questions about this DPA or a data protection request: team@whappy.ai, or Whappy Inc., 2045 Connecticut Ln, Sewickley, PA 15143, USA.