Legal
Data Processing Addendum
Last updated: 4 October 2026
This Data Processing Addendum ("DPA") forms part of our Terms of Service and applies whenever Vancely processes personal data on your behalf. It takes effect automatically when you accept the Terms; you do not need to sign anything.
These are our standard terms. If you need a countersigned copy for your records, email support@bytevancer.com.
1. Roles
For the personal data of the people you message or chat with through the service ("customer personal data"), you are the controller and we are your processor. We process customer personal data only on your documented instructions, which are the Terms, this DPA and the way you configure and use the service. If we believe an instruction breaks data protection law, we will tell you. For your own account and billing data we act as a controller, as described in our Privacy Policy.
2. Details of the processing
- Subject matter and purpose: providing the service: sending and receiving WhatsApp messages from your number, website chat, bot flows, webhooks, and preventing abuse.
- Duration: for as long as you use the service, plus the retention periods below.
- Data subjects: the people you message or who message you, website visitors who use your chat widget, and your own staff who use the dashboard.
- Types of data: phone numbers, names shown on WhatsApp, message type, status and timestamps; opt-in and opt-out (STOP) records; message content (text, captions, locations and files) only while in transit; and, only if you turn them on and the person agrees in the chat, saved flow responses and chat transcripts. We do not ask for special categories of data; do not send them through the service unless you have a lawful basis to do so.
- Retention: message content is erased once delivered (inbound files after their first download and within 24 hours at most); message metadata is deleted after 90 days and webhook delivery logs after 30 days; opt-in and opt-out records are kept so that opt-outs keep being respected; saved flow responses are kept for the period you set (at most 365 days) and chat transcripts for the period you set (at most what your plan allows).
3. Our obligations
- We process customer personal data only to provide the service and never for our own purposes, advertising or sale.
- Everyone we authorise to process customer personal data is bound by confidentiality.
- We keep appropriate technical and organisational security measures in place, described in our Security overview, including encryption of message content in transit, erasure on delivery, hashed API keys, signed webhooks and restricted access to production systems. We may improve these measures over time but will not lower the overall level of protection.
4. Sub-processors
You authorise us to use the sub-processors listed on our Sub-processors page, currently Hostinger (server hosting) and Cloudflare (DNS, delivery and security). We bind each sub-processor to data protection obligations no less protective than this DPA and remain responsible for their work. We will update that page before adding a new sub-processor; if you object on reasonable data protection grounds, we will work with you to find a solution, and if we cannot, you may stop using the affected part of the service.
5. International transfers
Customer personal data may be processed outside your country. Where data protection law requires safeguards for a transfer, such as transfers from the EEA, the UK or Switzerland to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Module 2, controller to processor) and, for the UK, the UK International Data Transfer Addendum are incorporated into this DPA by reference, with you as data exporter and us as data importer.
6. Assistance
- If we receive a request from a data subject about customer personal data, we will pass it to you and will not answer it ourselves unless you ask us to.
- We will help you, taking into account the nature of the processing, to respond to data subject requests, carry out data protection impact assessments and consult supervisory authorities where required.
- The service already helps: recipients can opt out by replying STOP, and you can delete saved flow responses and chat transcripts in the dashboard at any time.
7. Personal data breaches
If we become aware of a personal data breach affecting customer personal data, we will notify you without undue delay and give you the information we have that you need to meet your own obligations, updating it as we learn more. We will take reasonable steps to contain the breach and limit its effects.
8. Deletion and return
Most customer personal data is deleted automatically on the schedule in section 2. When your account is closed, we delete the remaining customer personal data and WhatsApp sessions within a reasonable period, unless the law requires us to keep it. Before closing, you can ask us for a copy of what the service keeps.
9. Information and audits
On request, we will make available the information reasonably needed to demonstrate our compliance with this DPA, such as answers to security questionnaires. If that is not enough, or a supervisory authority requires it, we will allow and contribute to an audit with reasonable notice, at a reasonable time, and subject to confidentiality.
10. General
If this DPA conflicts with the Terms of Service, this DPA wins for matters of data protection; if the Standard Contractual Clauses apply and conflict with this DPA, the Clauses win. Apart from the Standard Contractual Clauses, which are governed as they state, this DPA is governed by the same law as the Terms of Service.
Contact
Data protection questions or a countersigned copy: support@bytevancer.com.