← Back to home

Data Processing Agreement

Last updated: April 30, 2026  ·  This DPA forms part of the Terms of Service

This Data Processing Agreement ("DPA") describes how Sevenoways Relay ("Processor") processes personal data on behalf of customers ("Controllers") in the course of providing the messaging platform service.

1. Definitions

2. Subject Matter & Nature of Processing

The Processor facilitates the transmission of WhatsApp messages on behalf of the Controller. Processing includes:

3. Data Categories Processed

CategoryPurposeRetention
Account credentials (email, password hash)AuthenticationUntil account deletion
WhatsApp session credentialsMaintaining WA connectionUntil instance deletion
Message content (preview only)Logging & audit90 days
Recipient identifiers (group/phone)Message delivery90 days
IP addressesSecurity, rate limiting30 days
Queue dataReliable deliveryPurged after send/fail

4. Controller Obligations

The Controller agrees to:

5. Processor Obligations

The Processor agrees to:

6. Sub-processors

The Processor uses the following sub-processors:

Sub-processorPurposeLocation
CloudflareCDN, DDoS protection, TLS terminationGlobal (US-based)
Amazon Web Services (SES)Transactional email deliveryUS East
VPS ProviderServer infrastructure, data storageAs configured

7. International Data Transfers

Where personal data is transferred outside the EEA, the Processor ensures appropriate safeguards are in place, including Standard Contractual Clauses where required by applicable law.

8. Security Measures

The Processor implements the following technical and organisational measures:

9. Data Breach Notification

In the event of a personal data breach, the Processor will notify the affected Controller within 72 hours of becoming aware of the breach, and will provide information about the nature of the breach, categories and approximate number of individuals affected, and recommended mitigation measures.

10. Term & Termination

This DPA is effective for the duration of the service agreement. Upon termination, all personal data processed on behalf of the Controller will be deleted within 30 days, except where retention is required by law.


This DPA is incorporated into and forms part of the Terms of Service. In case of conflict, the DPA shall prevail for matters relating to personal data processing.