Data processing agreement

Last updated: 31 August 2026

This data processing agreement governs our handling of the personal data contained in the conversations that pass through your workspace. It forms part of the terms of service and applies automatically to every customer. There is nothing to sign, but we will countersign a copy on request.

1. Who is who

You are the controller. The conversations between your business and your customers are yours. You decide why they are collected and what happens to them.

We are the processor. DIGICORE IT LTD (company number 15984126) processes that personal data only on your documented instructions.

Your use of the product is itself an instruction to process the data as needed to provide it. Any other instruction must be in writing, and we may charge for work that goes materially beyond providing the service.

This agreement is made under Article 28 of the UK GDPR. Where we handle personal data as a controller in our own right, for example the account details of your staff, our privacy policy governs that instead.

2. What we process

Subject matterProviding the Digicore messaging product.
DurationFor as long as your workspace is open, plus the deletion period in section 8.
Nature and purposeReceiving, storing, displaying, organising, searching and sending WhatsApp messages on your behalf, and the automated follow-ups and flows you configure.
Types of personal dataPhone numbers, WhatsApp profile names, message content including any text, images, documents and audio your customers send, delivery and read receipts, and any notes your staff add to a conversation.
Categories of data subjectYour customers and enquirers, and the staff you invite to your workspace.
Special category dataNot requested and not required. If your customers volunteer it in a message, for example in a clinic setting, we will hold it under the same terms; you remain responsible for having an Article 9 condition for it.

3. Our obligations

4. Sub-processors

You give us general authorisation to engage the sub-processors listed in our privacy policy, which is kept current. Each is bound by written terms that impose obligations no less protective than these, and we remain fully liable to you for their performance.

We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith to find an alternative. If we cannot, you may end the affected part of the service without penalty.

Meta is different in kind: the WhatsApp Business Platform is the service itself, not a supplier we chose on your behalf, and it cannot be substituted.

5. International transfers

Workspace and conversation data is stored in the United Kingdom. Where a sub-processor operates outside the UK, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment and any supplementary measures it identifies.

6. Security measures

We maintain appropriate technical and organisational measures under Article 32, including:

We keep these measures under review and may improve them, but will not materially reduce the level of protection during the agreement.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. We will tell you what we know, what we are doing about it, and what we recommend. Notifying the ICO and affected individuals is your decision as controller; we will give you what you need to make it.

8. Deletion and return

You can export or delete your data yourself at any time while the workspace is open.

When the agreement ends we will, at your choice, delete or return your data within 30 days. If you ask for neither, we delete it. We delete it sooner on request. Copies held in encrypted backups are overwritten within a further 30 days, so nothing survives more than 120 days past deletion. We keep data beyond that only where the law requires, and only for as long as it does.

9. Audit

We will make available the information reasonably needed to demonstrate compliance with this agreement, and will respond to a reasonable security questionnaire once in any twelve months. Where that is genuinely insufficient, you may audit us, or appoint an independent auditor who is not a competitor of ours, on 30 days’ notice, no more than once a year unless a breach or a regulator requires otherwise. Audits happen in business hours, must not disrupt the service, and are subject to confidentiality. You bear your own costs, and ours if the audit goes beyond what the law requires.

10. General

If this agreement conflicts with the terms of service on the handling of personal data, this agreement wins. Liability under this agreement is subject to the limits in the terms of service, except where the law does not allow that. It is governed by the laws of England and Wales.

11. Contact

Data protection questions, requests for a countersigned copy, and sub-processor objections go to info@digicore.uk, or to DIGICORE IT LTD, 124 City Road, London, England, EC1V 2NX.