ملحق معالجة البيانات (DPA) الخاص بـ

DATA PROCESSING AGREEMENT (DPA) 

Last updated: 26 August 2026 · Version: 5.0 

This Data Processing Agreement (“DPA”) forms an integral part of the Terms of Use, the Subscription Agreement or any other written or electronic agreement (the “Agreement”) entered into between the Customer (as defined in the Agreement, the “Customer”) and 3S CONVERSATIONAL PLATFORM, S.L. (hereinafter, “the Processor”), with registered office at Av. Cortes Valencianas 10, 1º Izq., 46015 Valencia (Spain), Spanish tax ID B75461509, under which the Processor provides the Customer with the omnichannel messaging platform and conversational agents services (the “Services”). 

By accepting the Terms of Use, the Customer accepts this DPA. In the event of any conflict between the Agreement and this DPA, this DPA prevails with respect to the matters it governs. 

 

1. Definitions 

GDPR: Regulation (EU) 2016/679. LOPDGDD: Spanish Organic Law 3/2018. Applicable Data Protection Law: the GDPR, the LOPDGDD and any equivalent laws. Personal Data: any information relating to an identified or identifiable natural person entered into, uploaded, transmitted, generated or otherwise processed in or through the Services. Processing: any operation performed on Personal Data, whether or not by automated means. Controller: the entity that determines the purposes and means of processing. Processor: the entity that processes Personal Data on behalf of the Controller. Sub-processor: any third party engaged by the Processor to carry out specific processing activities on behalf of the Controller. Personal Data Breach: any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. Portal: the web interface and APIs through which the Customer configures, administers and uses the Services. Data Subject: the natural person to whom the Personal Data relates. 

 

2. Roles of the parties 

The Customer acts as Controller and the Processor acts as Data Processor in respect of Personal Data processed in the provision of the Services. 

The Processor acts as an independent Controller in respect of administrator account data, billing data, platform operational and security logs, aggregated and anonymised usage metrics and business contacts. Such processing is governed by the Processor’s Privacy Policy and not by this DPA. 

 

3. Subject matter, nature, purpose and duration 

3.1 Subject matter and purpose. The Processor shall process Personal Data solely to provide the Services to the Customer under the Agreement, including the receipt, sending, storage, routing, transformation and rendering of messages on messaging channels (WhatsApp Business Cloud API, Facebook Messenger, Instagram, Line, WeChat, WebChat and other channels enabled by the Processor) and the operation of conversational agents, integrations and connectors configured by the Customer. 

3.2 Nature of processing. Collection, recording, structuring, storage, retrieval, consultation, use, disclosure by transmission, access and interconnection, restriction, erasure and destruction, as necessary to provide the Services. 

3.3 Duration. This DPA shall be in force for the entire term of the Agreement and, in respect of obligations that by their nature survive, until Personal Data has been effectively returned or deleted. 

4. Categories of Personal Data and Data Subjects 

4.1 The processing is carried out on personal data owned by the Controller, in connection with the provision of the Services described in Clause 3. The Processor shall exercise the utmost diligence in complying with the GDPR, national laws and any other regulations affecting personal data processing under the Agreement. 

4.2 Categories of Personal Data. Identifying data; phone numbers; data included in chats or other communication channels integrated into the platform; content of conversations; associated technical metadata (timestamps, session and conversation IDs, channel, message status). 

4.3 Categories of Data Subjects. Personal data of the Customers and of third parties with whom the Customers contact through the service. 

 

5. General-purpose platform 

The Processor provides a general-purpose communication platform on a self-service basis. The Processor does not provide specific infrastructure for regulated sectors. The Customer is solely responsible for determining whether the Services are appropriate for its use case, taking into account its regulatory obligations, and for configuring the Services accordingly. The Processor does not independently assess the lawfulness, accuracy, minimisation, adequacy or relevance of the Personal Data that the Customer enters into the Platform or requests from Data Subjects through the conversational agents configured by the Customer. Nothing in this DPA excludes or limits the Processor’s own obligations under the GDPR and the LOPDGDD. 

 

6. Purpose limitation and Controller’s instructions 

6.1 The processing that the Processor undertakes to carry out shall be limited to the actions necessary to provide the Customer with the contracted Services, and shall be performed in accordance with the Controller’s documented instructions, unless the Processor is required to do so by Union or Member State law to which it is subject, in which case the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. For the purposes of Article 28(3)(a) GDPR, the actions and configurations adopted by the Customer through the Portal —including feature activations, conversation flow definitions, connectors, integrations, templates, fields and retention settings— constitute the Controller’s documented instructions to the Processor. Any additional instruction outside the Portal shall be communicated in writing. 

6.2 The Processor shall immediately inform the Controller if, in its opinion, an instruction of the Customer infringes the GDPR or other Union or Member State data protection provisions, without prejudice to the fact that the Processor is not obliged to verify the substantive lawfulness of the processing decided by the Customer. 

 

7. Customer obligations (Controller) 

The Customer represents, warrants and undertakes to: (i) determine the purpose, aims, legal basis and categories of Personal Data processed through the Services; (ii) have a valid legal basis (Article 6 GDPR and, where applicable, Article 9) for all processing that it instructs the Processor to carry out, including providing the Processor with the Data Subjects’ WhatsApp phone numbers; (iii) obtain and maintain the necessary consents from Data Subjects and keep records of them; (iv) provide Data Subjects with the information required by Articles 13 and 14 GDPR, including reference to the Processor, to WhatsApp Ireland Limited / Meta Platforms Ireland Limited and, where applicable, to the other Sub-processors; (v) configure the Portal consistently with its regulatory obligations, including retention, minimisation and access controls; (vi) determine whether the Services are appropriate for the intended use; (vii) comply with the applicable terms of use and policies of the integrated messaging channels, including those of WhatsApp Business and Meta; (viii) promptly notify the Processor of any withdrawal of consent, binding Data Subject request, regulatory demand or incident affecting the Personal Data processed through the Services; (ix) not enter Personal Data that is not necessary for the configured purpose. 

 

8. Confidentiality 

The Processor shall inform its employees of the obligation of secrecy and confidentiality and of the consequences of non-compliance; guarantee the necessary training in personal data protection for persons authorised to process personal data; and grant access to such data only to those employees who need to know it for the proper performance of their duties under the Agreement. 

 

9. Sub-processors 

9.1 General authorisation and flow-down. The Customer grants a general written authorisation to the Processor for the engagement of third-party Sub-processors to provide ancillary services necessary for the usual operation of the Services. The Processor shall enter into an agreement with its Sub-processors imposing on them data protection obligations no less protective than those set out in this DPA (the “flow-down” clause), and shall remain liable to the Customer for the performance of such obligations. This flow-down clause equally applies where the Customer itself acts as Processor vis-à-vis an ultimate third-party Controller and the Processor acts as Sub-processor in such chain. 

9.2 Public list, notification and objection. The public and up-to-date list of Sub-processors is available at https://woztell.com/dpa/#sub-processors; an abbreviated extract is included in Annex II to this DPA. The Processor shall notify the Customer of any intended addition or replacement of Sub-processors with a minimum of fifteen (15) calendar days’ prior notice. The Customer shall have a period of ten (10) calendar days from receipt of such notice to raise objections on legitimate data-protection grounds. Upon expiry of that period without objection, the new Sub-processor shall be deemed accepted. In case of justified objection, the Processor shall use reasonable efforts to offer an alternative; if not possible, the Customer may terminate this DPA without penalty. 

 

10. Meta / WhatsApp 

In providing the Services that use the WhatsApp Business Cloud API: in respect of the content of messagesWhatsApp Ireland Limited acts as a Sub-processor under the WhatsApp Business Data Processing Terms, incorporated by reference into the WhatsApp Business Terms of Service accepted by the Customer when registering its number; in respect of certain platform metadata (security, integrity, anti-fraud, telemetry), Meta Platforms Ireland Limited acts as an independent Controller under the terms Meta publishes and that the Customer accepts directly with Meta. It is not necessary to enter into a separate DPA with Meta for the use of WhatsApp Business Cloud API. The Customer shall include in its information to Data Subjects a reference to the Processor, to WhatsApp Ireland Limited and to Meta Platforms Ireland Limited. 

 

11. Security measures 

The Processor, as well as any third parties necessary to provide the Services, shall ensure, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, compliance with appropriate technical and organisational measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, with processes for regular verification, evaluation and assessment. The specific measures are set out in Annex I. 

 

12. Personal Data Breach notification 

12.1 The Processor shall notify the Customer, without undue delay and in any case within a period that allows the Controller to comply with its obligation to notify the competent Supervisory Authority within the 72 hours of Article 33 GDPR, of any personal data breaches of which it becomes aware. Such notification shall include, at a minimum and to the extent the information is available: (i) the nature of the breach; (ii) the categories and approximate number of Data Subjects and records affected; (iii) the possible consequences; and (iv) the measures taken or proposed. The Processor shall provide reasonable support to the Controller in the notification to the competent Supervisory Authority. 

12.2 The Processor shall not be responsible for carrying out the procedure for notifying the personal data breach to the competent supervisory authority, nor for any communication to the Data Subjects, where applicable. 

 

13. Exercise of Data Subject rights 

The Processor shall notify the Customer, without undue delay, of any requests to exercise Data Subject rights that it may receive, and shall provide reasonable assistance to enable the Customer to comply with its obligation to respond. The Processor shall not respond directly to the Data Subject except upon documented instruction of the Customer or applicable legal requirement. 

 

14. Return or deletion of data 

The Processor shall delete or return the personal data covered by this DPA in accordance with the Customer’s orders, upon completion of the provision of the Services, unless it is required to retain the data under applicable data protection regulations. 

 

15. International data transfers 

Data shall as a general rule be processed within the territory of the European Union or the European Economic Area (EEA). Notwithstanding the foregoing, the Processor acknowledges that, for the provision of the Services, it may carry out international data transfers to countries outside the EEA by entering into the applicable Standard Contractual Clauses approved by the European Commission or other valid mechanisms provided for in Chapter V GDPR, including any supplementary measures that may be necessary. 

 

16. Cooperation with the Supervisory Authority and contact 

The Processor shall cooperate with the relevant Supervisory Authority, at its request, in the performance of its duties. General contact: support@woztell.com. 

 

17. Audit and verification 

The Processor shall make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and shall allow and contribute to the performance of audits, including inspections, subject to: (a) written notice of thirty (30) calendar days with intended scope and duration; (b) a maximum of one (1) audit per calendar year, unless required by a competent supervisory authority; (c) NDA subscription by the auditor, who may not be a direct competitor of the Processor; (d) audit costs borne by the Controller, unless a material non-compliance by the Processor is revealed; (e) the Processor may satisfy this obligation by providing an audit report or certification from a qualified independent third party (SOC 2 Type II, ISO 27001, ENS or equivalent) no older than 36 months. 

18. Governing law and jurisdiction 

This DPA shall be governed by Spanish law and any dispute between the parties shall be settled under the exclusive jurisdiction of the Courts of Valencia (Spain), without prejudice to the mandatory competence of the supervisory authority and to the mandatory rights of Data Subjects. 

 

19. Miscellaneous 

Precedence: in case of conflict between this DPA and the Agreement, this DPA prevails in respect of the matters it governs. Amendments: the Processor may update this DPA to reflect regulatory changes, incorporate best practices or update Sub-processors, provided that the overall level of protection does not decrease. Severability: if any clause is declared void, the remaining clauses shall retain their validity. Languages: this DPA is published in Spanish and English. In case of discrepancy, the Spanish version prevails. 

 

ANNEX I — Security measures 

The Processor’s platform is hosted on Amazon Web Services cloud infrastructure, in regions located within the European Economic Area (EEA). The access controls to premises and environmental controls (CCTV, UPS, backup generators, temperature and humidity control) are inherited from the certified data centres of the cloud infrastructure provider, as the Processor does not operate its own data centres. 

  1. Access controls to premises and facilities.Technical and organisational measures for access control, authorisation checks and entry/exit logging.
  2. Access controls to systems.User identification and authentication through password procedures (special characters, minimum length, periodic change, complexity); prohibition of guest users and anonymous accounts; access to systems centrally managed and subject to approval by both personnel management and system owner.
  3. Access controls to data.Requirements-driven authorisation scheme and access rights, with monitoring and logging; differentiated access rights (profiles, roles, transactions, objects) defined according to duties and least-privilege and segregation-of-duty principles.
  4. Environmental security.Systems that monitor and control temperature and humidity for IT equipment, CCTV, UPS modules and backup generators against electrical failures.
  5. Data integrity.Policies and procedures to protect the confidentiality, integrity and availability of Customer Data from improper disclosure, alteration or destruction.
  6. Audit controls.Hardware, software and procedural mechanisms that record and examine activity in information systems, with appropriate logs and security reports.
  7. Secure disposal.Policies and procedures for the disposal of tangible property containing Customer Data.
  8. Testing.Regular testing of key controls, systems and procedures of the information security programme, including internal risk assessments.
  9. Monitoring.Monitoring of network and production systems (error logs on servers, disks and security events), including review of changes to authentication, authorisation and auditing systems; review of privileged access; and network vulnerability assessments.
  10. Security incident procedures.Incident response plan including: (a) formation of an internal incident response team with a response leader; (b) assessment of the incident’s risk and affected parties; (c) internal reporting and notification in case of unauthorised disclosure in accordance with the Agreement; (d) permanent record of actions and responsible parties; (e) documented root-cause analysis and remediation plan.

 

ANNEX II — List of Sub-processors 

The public, complete and up-to-date list of Sub-processors —with legal entity, address, processing location, transfer mechanism and link to each Sub-processor’s DPA— is available at https://woztell.com/dpa/#sub-processors. As of the date of this DPA, the Sub-processors in force are: 

  • Amazon Web Services EMEA SARL — Cloud infrastructure, database and managed services (EU / EEA). 
  • MongoDB, Inc. — Managed product database (MongoDB Atlas, EEA region). 
  • Functional Software, Inc. (Sentry) — Product error tracking (USA, 2021 SCCs). 
  • WhatsApp Ireland Limited — WhatsApp Business Cloud API messaging transport (message content). 
  • Meta Platforms Ireland Limited — WhatsApp platform metadata (independent Controller). 
  • Resend, Inc. — Outbound transactional email (USA, 2021 SCCs). 
  • Zoho Corporation B.V. — CRM, support and billing (EU). 
  • Atlassian Corporation — Collaboration tools Jira/Confluence (EU). 
  • Microsoft Ireland Operations Limited — Internal communication and support (Teams) (EU). 

Conditional Sub-processors activated by the Customer: additional messaging channels (Facebook Messenger, Instagram, Line, WeChat, Telegram, WebChat); AI / LLM model providers; CRM and business connectors; voice and transcription services. These are engaged in the processing only where the Customer expressly activates the corresponding functionality in the Portal, such activation constituting its specific authorisation to onboard that Sub-processor. 

Last review of Annex II: 26 August 2026. 

We provide the full text of the DPA below and you can download and sign it.
Here is a PDF copy of the DPA:

Woztell-DPA_ENG Download

You may contact us to support@woztell.com for further information.

المعالِجون الفرعيون