Data Processing Agreement
Last updated: 29 September 2026. This Data Processing Agreement ("DPA") applies where we process personal data on your behalf, and forms part of our Terms of Service. It supplements our Privacy Policy.
Roles
For the personal data contained in the messages, contacts, and accounts you handle through the service, you are the controller and WhatsMCP is your processor: we process that data only to provide the service and only on your documented instructions, which your use of the service and these terms constitute. Where a data-protection law applies to this processing (including the EU GDPR, the UK GDPR, and the CCPA/CPRA), this DPA sets out how we do it. Nothing here makes us the controller of that data.
What we process, and why
The subject matter is our operation of a linked WhatsApp account on your behalf; the duration is for as long as the account stays linked and your account stays open; the nature and purpose is to send, receive, and serve back the data of that account through the API. The personal data and data subjects are as described in our Privacy Policy, in summary:
- Categories of personal data: message content and metadata; the linked account's phone number and session credentials; the synced address book; call history; group and channel membership; media attachments; and webhook destinations.
- Categories of data subjects: you, and the people you and your linked account communicate with or store as contacts.
Our obligations as processor
We will:
- Process personal data only on your instructions, including for transfers, unless required otherwise by law — in which case we'll tell you first, where the law permits.
- Ensure the people who process the data are bound by confidentiality.
- Not use the data for our own purposes, and never for advertising, and never sell it.
- Assist you, taking into account the nature of the processing, in meeting your own obligations (see "Helping you meet your obligations" below).
Security
We keep technical and organisational measures appropriate to the risk. These include per-workspace isolation (a request authenticated to one workspace cannot read another's data), API keys stored only as salted hashes, HMAC-SHA256-signed webhook deliveries, and encryption in transit. We review these measures as the service changes.
Sub-processors
You authorise us to engage sub-processors to provide the service. Each is bound by data-protection terms no less protective than this DPA, and we remain responsible for their performance. Our current sub-processors are:
- Cloudflare — hosting and content delivery.
- Brevo — account-related (transactional) email.
- A payment processor — billing, for paid plans only.
We'll give reasonable notice before adding or replacing a sub-processor so you can object on reasonable data-protection grounds.
International transfers
Where we or a sub-processor transfer personal data out of the UK or the EEA, we rely on an appropriate safeguard — such as the European Commission's Standard Contractual Clauses and the UK Addendum — so the data keeps an equivalent level of protection.
Helping you meet your obligations
Taking into account the nature of the processing and the information available to us, we will help you respond to requests from data subjects (access, correction, deletion, portability, objection), and help you with data-protection impact assessments and consultations with a supervisory authority. Much of this you can do yourself in the console — unpair an account or delete your data — as described in the Privacy Policy.
Personal-data breaches
If we become aware of a personal-data breach affecting data we process for you, we will notify you without undue delay and give you the information you reasonably need to meet your own notification duties.
Deletion or return
When an account is unpaired or you delete your WhatsMCP account, we delete the personal data tied to it, except where we are required by law to keep it. The exact timeline is stated in our Privacy Policy.
Audits
We will make available the information reasonably necessary to demonstrate our compliance with this DPA and will contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice and subject to confidentiality.
Your obligations as controller
You are responsible for having a lawful basis for the processing you instruct, including any consent the people you contact require, and for the accuracy and legality of the instructions you give us through the service.
Order of precedence and law
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. The operating entity and the governing law are as stated in the Terms of Service [NEEDS INPUT: confirm once the entity and jurisdiction there are filled in].
Contact
Questions about this DPA, or to request a countersigned copy: contact us.