Data Processing Agreement (DPA)
Last Updated: February 27, 2026
Effective Date: February 27, 2026
Company: GoWap (A Product of GoUp Digital Marketing Agency)
Website: https://gowap.in
Contact Email: info@gowap.in
1. PURPOSE
This Data Processing Agreement (“DPA”) governs the processing of personal data by GoUp Digital Marketing Agency (“Processor”) on behalf of the subscribing user or business (“Controller”) in connection with the GoWap SaaS platform. This DPA forms an integral part of the GoWap Terms of Service.
2. ROLES OF THE PARTIES
- Controller: The user, freelancer, or agency utilizing GoWap to generate and deliver Meta Ads performance reports to their clients. The Controller determines the purpose and means of processing the client contact data.
- Processor: GoWap (GoUp Digital Marketing Agency), which processes data strictly to provide the automated reporting services. GoWap does not determine the purpose of processing client contact data; it processes such data solely on the documented instructions of the Controller.
3. NATURE AND PURPOSE OF PROCESSING
The Processor processes data exclusively for the following purposes:
- Connecting securely to Meta Ads accounts via official OAuth.
- Fetching advertising performance metrics from the Meta Marketing API.
- Generating KPI-based performance reports based on user settings.
- Delivering reports directly to clients via the WhatsApp Cloud API.
- Logging delivery status (e.g., sent, delivered, read) to maintain system reliability.
Processing is strictly limited to the core reporting functionality of the GoWap platform.
4. TYPES OF DATA PROCESSED
To provide the service, the Processor handles the following categories of data:
4.1 Account Data
- Full Name
- Email address (used strictly for account authentication and service notices)
4.2 Advertising Performance Data
- Meta Ad Account IDs
- Campaign and Ad Set names
- Advertising performance metrics
- KPIs selected by the Controller (e.g., Impressions, Leads, ROAS, Spend)
4.3 Client Contact Data
- Client name
- WhatsApp phone number
- Time zone
- Consent timestamp
Note: The Processor does not intentionally process sensitive personal data (e.g., health, financial, or biometric data), and the Controller agrees not to upload such data to the platform.
5. DURATION OF PROCESSING
Data is processed strictly for the duration of the Controller's active subscription, until deletion is explicitly requested by the Controller, or until account termination. Upon termination, data is securely deleted according to the Data Deletion procedures outlined in Section 11.
6. PROCESSOR OBLIGATIONS
The Processor agrees to:
- Process data only on the documented instructions of the Controller (which includes the configurations set by the Controller within the GoWap dashboard).
- Implement appropriate technical and organizational safeguards to protect the data.
- Ensure that any personnel authorized to process the data have committed themselves to confidentiality.
- Restrict access to authorized staff only, strictly on a need-to-know basis.
- Maintain secure infrastructure and proactively monitor for vulnerabilities.
- Notify the Controller of any data breach without undue delay.
7. SECURITY MEASURES
The Processor implements modern, industry-standard security measures, including but not limited to:
- Secure Data Transmission: HTTPS encryption for all data in transit.
- Authentication: JSON Web Tokens (JWT) for secure, stateless user sessions.
- Password Security: Bcrypt hashing for all user passwords.
- Encryption at Rest: Secure storage for Meta OAuth access tokens and client WhatsApp numbers.
- Access Control: Strict Role-Based Access Controls (RBAC) for internal infrastructure.
- Data Isolation: Account-level data separation to prevent cross-account leakage.
- Routine logging and monitoring of system access.
8. SUBPROCESSORS
The Controller provides general authorization for the Processor to engage third-party Subprocessors to deliver the service. The Processor currently uses:
- Meta Marketing API: To fetch advertising data.
- WhatsApp Cloud API: To deliver the automated reports.
- Secure Cloud Hosting Providers: To host the GoWap application and databases.
- Email Delivery Providers: For essential account authentication and password resets.
- Google Analytics / Tracking Technologies: Limited strictly to GoWap website analytics and marketing measurement (as detailed in the Cookie Policy), never applied to the Controller's client data or ad reports.
The Processor ensures that all Subprocessors are bound by written agreements requiring them to maintain appropriate security and data protection standards.
9. DATA SUBJECT RIGHTS
As the data owner, the Controller is solely responsible for receiving and handling data subject requests (such as a client asking to be removed from the WhatsApp reporting list).
The Processor shall assist the Controller, where technically feasible and through the platform's standard UI features, in fulfilling obligations to respond to:
- Access requests
- Correction requests
- Deletion requests
- Consent withdrawals
10. DATA BREACH NOTIFICATION
In the event of a confirmed data breach affecting the Controller's personal data, the Processor shall:
- Notify the Controller without undue delay after becoming aware of the breach.
- Provide relevant information regarding the nature of the breach, the data affected, and the mitigation steps taken.
- Cooperate fully with the Controller in mitigation efforts and required regulatory reporting.
11. DATA DELETION
Upon account termination or written request from the Controller, the Processor will execute the following:
- OAuth Tokens: Meta OAuth tokens are immediately revoked and deleted.
- Client Data: Client WhatsApp numbers and contact details are permanently deleted.
- Logs: Delivery logs are purged according to the standard 90-day retention policy.
- Account Data: Complete and permanent removal of the organization’s data from active databases within 7 business days of a verified request.
12. INTERNATIONAL TRANSFERS
Data is processed on secure cloud infrastructure that may operate across multiple global regions. The Processor ensures that reasonable, industry-standard safeguards are in place for any cross-border data transfers necessary to operate the service.
13. GOVERNING LAW
This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts in Chennai, Tamil Nadu, India.
14. CONTACT
For any inquiries related to this Data Processing Agreement, please contact our team at:
Email: info@gowap.in
Website: https://gowap.in