Data processing agreement
Last updated: 31 August 2026
This data processing agreement governs our handling of the personal data contained in the conversations that pass through your workspace. It forms part of the terms of service and applies automatically to every customer. There is nothing to sign, but we will countersign a copy on request.
1. Who is who
You are the controller. The conversations between your business and your customers are yours. You decide why they are collected and what happens to them.
We are the processor. DIGICORE IT LTD (company number 15984126) processes that personal data only on your documented instructions.
Your use of the product is itself an instruction to process the data as needed to provide it. Any other instruction must be in writing, and we may charge for work that goes materially beyond providing the service.
This agreement is made under Article 28 of the UK GDPR. Where we handle personal data as a controller in our own right, for example the account details of your staff, our privacy policy governs that instead.
2. What we process
| Subject matter | Providing the Digicore messaging product. |
|---|---|
| Duration | For as long as your workspace is open, plus the deletion period in section 8. |
| Nature and purpose | Receiving, storing, displaying, organising, searching and sending WhatsApp messages on your behalf, and the automated follow-ups and flows you configure. |
| Types of personal data | Phone numbers, WhatsApp profile names, message content including any text, images, documents and audio your customers send, delivery and read receipts, and any notes your staff add to a conversation. |
| Categories of data subject | Your customers and enquirers, and the staff you invite to your workspace. |
| Special category data | Not requested and not required. If your customers volunteer it in a message, for example in a clinic setting, we will hold it under the same terms; you remain responsible for having an Article 9 condition for it. |
3. Our obligations
- We process personal data only on your documented instructions, including on transfers abroad, unless the law requires otherwise. If it does, we will tell you first unless the law forbids that.
- Everyone we authorise to access the data is bound by a duty of confidence.
- We keep the security measures set out in section 6.
- We engage sub-processors only as set out in section 4.
- Taking account of what we can see, we assist you in responding to requests from data subjects exercising their rights.
- We assist you with your obligations on security, breach notification, impact assessments and prior consultation, taking account of the nature of the processing and what we know.
- At the end of the agreement we delete or return the data as set out in section 8.
- We make available the information needed to show we have met these obligations, and allow for audits as set out in section 9.
- We will tell you if, in our opinion, an instruction of yours infringes data protection law.
4. Sub-processors
You give us general authorisation to engage the sub-processors listed in our privacy policy, which is kept current. Each is bound by written terms that impose obligations no less protective than these, and we remain fully liable to you for their performance.
We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith to find an alternative. If we cannot, you may end the affected part of the service without penalty.
Meta is different in kind: the WhatsApp Business Platform is the service itself, not a supplier we chose on your behalf, and it cannot be substituted.
5. International transfers
Workspace and conversation data is stored in the United Kingdom. Where a sub-processor operates outside the UK, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment and any supplementary measures it identifies.
6. Security measures
We maintain appropriate technical and organisational measures under Article 32, including:
- Encryption of personal data in transit and at rest.
- Database-level isolation so one workspace cannot read another’s data.
- Sign-in by one-time email code, with no reusable password stored.
- Access to production systems limited to those who need it, and reviewed.
- An audit log of significant actions taken in a workspace.
- Managed, encrypted backups with a defined retention period.
- Segregated development and production environments.
We keep these measures under review and may improve them, but will not materially reduce the level of protection during the agreement.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. We will tell you what we know, what we are doing about it, and what we recommend. Notifying the ICO and affected individuals is your decision as controller; we will give you what you need to make it.
8. Deletion and return
You can export or delete your data yourself at any time while the workspace is open.
When the agreement ends we will, at your choice, delete or return your data within 30 days. If you ask for neither, we delete it. We delete it sooner on request. Copies held in encrypted backups are overwritten within a further 30 days, so nothing survives more than 120 days past deletion. We keep data beyond that only where the law requires, and only for as long as it does.
9. Audit
We will make available the information reasonably needed to demonstrate compliance with this agreement, and will respond to a reasonable security questionnaire once in any twelve months. Where that is genuinely insufficient, you may audit us, or appoint an independent auditor who is not a competitor of ours, on 30 days’ notice, no more than once a year unless a breach or a regulator requires otherwise. Audits happen in business hours, must not disrupt the service, and are subject to confidentiality. You bear your own costs, and ours if the audit goes beyond what the law requires.
10. General
If this agreement conflicts with the terms of service on the handling of personal data, this agreement wins. Liability under this agreement is subject to the limits in the terms of service, except where the law does not allow that. It is governed by the laws of England and Wales.
11. Contact
Data protection questions, requests for a countersigned copy, and sub-processor objections go to info@digicore.uk, or to DIGICORE IT LTD, 124 City Road, London, England, EC1V 2NX.
Digicore