Data processing agreement
Version 2026-09, September 2026
This agreement is concluded between the customer (controller) and EINSZWEIDREI SOLUTIONS UG, Hochstraße 2, 56242 Ellenhausen, Germany (processor). It becomes part of the contract as soon as the customer uses Whazzup and can additionally be accepted in the account under Settings → Data processing.
1. Subject, duration and purpose
The processor operates a support platform with a shared inbox for chat and email, a knowledge base, a website widget, contact management and consent-based screen sharing. Personal data is processed exclusively to provide these services. The agreement runs for as long as the main contract and ends with it.
2. Categories of data and data subjects
- Data subjects: website visitors of the customer, the customer's end customers, employees and team members of the customer.
- Contact data: name, email address, company, phone number where provided, custom attributes supplied by the customer.
- Communication content: chat and email messages, attachments, internal notes, ticket metadata.
- Usage data: IP address, browser and device information, pages visited, events, session and log data.
- Account data of the customer's team: name, email address, role, alias, signature.
No special categories of data under Art. 9 GDPR are intended. The customer must not deliberately transmit such data through the platform.
3. Instructions
The processor processes personal data only on documented instructions from the controller. The use of the platform's functions and settings constitutes such an instruction. Additional instructions are given in text form to the contact address below. The processor informs the controller without delay if an instruction appears to infringe data protection law.
4. Confidentiality
All persons authorised to process the data are bound to confidentiality and are trained in the relevant data protection requirements. Access is granted strictly on a need-to-know basis.
5. Security of processing
The processor implements the technical and organisational measures set out in Annex 1 in accordance with Art. 32 GDPR and keeps them up to date with the state of the art.
6. Subprocessors
The controller grants general authorisation for the subprocessors listed in Annex 2. The processor imposes the same data protection obligations on every subprocessor and remains fully liable towards the controller. New subprocessors are announced at least 30 days in advance on the subprocessor page; the controller may object for good cause.
7. Data subject rights
The processor supports the controller with suitable technical and organisational measures in answering requests for access, rectification, erasure, restriction, objection and data portability. Requests received directly by the processor are forwarded to the controller without undue delay and are not answered independently.
8. Personal data breaches
The processor notifies the controller of any personal data breach without undue delay, at the latest within 24 hours of becoming aware of it, describing the nature of the incident, the categories and approximate number of records affected, likely consequences and the measures taken. The processor supports the controller with notifications under Art. 33 and 34 GDPR.
9. Deletion and return
On termination of the contract the processor deletes all personal data within 30 days or, at the controller's choice, returns it in a machine-readable format beforehand. Statutory retention obligations remain unaffected. Backups are overwritten within the regular backup cycle. During the contract, retention periods for logs, sessions and technical records apply as described in Annex 1.
10. Audits
The controller may verify compliance with this agreement. As a rule this is done through documentation, self-assessments and provider certificates. On-site inspections are possible with reasonable notice during business hours, without disrupting operations and at most once a year, unless there is a concrete cause.
11. International transfers
Processing takes place in the European Union wherever possible. Where data reaches a third country, this is based on an adequacy decision or the EU standard contractual clauses together with supplementary measures such as encryption and access controls.
12. Liability and final provisions
Liability follows Art. 82 GDPR and the liability provisions of the main contract. German law applies. If individual provisions are invalid, the remainder stays in force. In case of conflict, this agreement prevails over the main contract in matters of data protection.
Annex 1 — Technical and organisational measures
- Access control: passwords stored only as salted hashes, optional two-factor authentication, role-based permissions (owner, agent, viewer), session tokens with expiry.
- Tenant separation: every record carries an organisation reference and is protected by row-level security rules in the database, so one workspace can never read another's data.
- Encryption: TLS for all transport, encryption at rest for database and file storage, signed identity tokens (HMAC) for verified widget users.
- Widget security: origin allow-list per workspace, rate limits, replay protection for identity tokens, logging of security events.
- Screen sharing: starts only after explicit consent in the moment, transmits peer-to-peer, is never recorded, is time limited and can be stopped by the visitor at any time.
- Deletion concept: an hourly automated job removes expired sessions, nonces, rate-limit records, typing signals, security events and stale anonymous visitor records; empty anonymous contacts are not created at all.
- Availability: managed database with automatic daily backups and point-in-time recovery, distributed hosting, monitoring of errors and runtime problems.
- Organisational measures: need-to-know access for the small team, confidentiality commitments, separation of development and production data, review of measures at least once a year and whenever the product changes significantly.
Annex 2 — Subprocessors
The current list is published at whazzup.io/subprocessors and forms part of this agreement.
Contact
Data protection contact: hello@whazzup.io
