logo
Legal Hub

DATA PROCESSING AGREEMENT

This Data Processing Agreement (the “DPA”) constitutes a legally binding agreement between the customer identified in the Terms (the “Customer”, “You”, “Your”) and the relevant Whatfix entity identified in the Terms (“Whatfix”, “Us”, “We”, “Our”). Each of You and Us is individually referred to as a “party” and collectively, the “parties”.

 

You are required to read this DPA carefully as this DPA forms an integral part of the software as a services agreement, or any other agreement between You and Us that references this DPA, as applicable (the “Terms”) and is applicable where We are the Processors of Your Personal Data. In the event of a conflict between this DPA and the Terms, this DPA shall prevail. 

 

  1. Definitions

    In this DPA, the following terms shall have the following meanings:

    CCPA” shall mean the California Consumer Privacy Act of 2018, and any related regulations or guidance provided by the California Attorney General;

    1. Customer Content” means all data and materials created or provided by the Customer to Whatfix for use in connection with the services, including, without limitation, flows, text snippets, images, and videos;

    2. Controller”, “Data Subject”, “Personal Data Breach”, “Processor” and “Process” shall have the meaning given to them in the GDPR and, as applicable, the CCPA and/ or other applicable Data Protection Laws;

    Data Protection Laws” shall mean the data protection laws of the country in which You are established, including the GDPR, the CCPA, and any data protection laws applicable to You in connection with the Terms (including without limitation, the UK GDPR and Data Protection Act 2018 if You are established in the United Kingdom);

    GDPR” shall mean the Regulation (EU) 2016/679 of the European Parliament and of the Council 11of 27 April 2016 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), as amended and updated from time to time; 

    "Model Clauses" means the European Commission Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914, together with any applicable United Kingdom International Data Transfer Addendum and Swiss adaptations, each as amended, replaced, or superseded from time to time.

    Personal Data” shall mean any information relating to an identified or identifiable natural person as defined by applicable Data Protection Laws that is Processed by Processor as part of providing the services to You as described in an Appendix; and

    UK GDPR” means the GDPR as adopted and made applicable in the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.

  1. Scope and Responsibilities

  • This DPA applies to Processing of Personal Data forming part of Customer Content.

  • Whatfix shall process Personal Data only on Your behalf and at all times only in accordance with this DPA and Appendices attached hereto. For the avoidance of doubt, Whatfix shall be the Processor and You shall be the Controller of the Personal Data.

  • Within the scope of the Terms, each party shall be responsible for complying with its respective obligations as Controller and Processor under Data Protection Laws.

  1. Term and Termination

  • This DPA becomes effective upon signature. It shall continue to be in full force and effect as long as Whatfix is Processing Personal Data pursuant to the Terms and shall terminate automatically thereafter.

  • Save and except for as expressly provided Clause 16 below, where amendments are required to ensure compliance of this DPA or an Appendix with Data Protection Laws, the parties shall make reasonable efforts to agree on such amendments upon your request. Where the parties are unable to agree upon such amendments, either party may terminate this DPA with 90 days written notice to the other party.

  1. Processing Instructions

  • Whatfix will Process Personal Data in accordance with Your instructions. This DPA contains Your initial instructions to Whatfix. The parties agree that You may communicate any change in its initial instructions to Whatfix by way of amendment to this DPA.

  • For the avoidance of doubt, any instructions that would lead to Processing outside the scope of this DPA (e.g. because a new Processing purpose is introduced) will require a prior written agreement between the parties.

  • Whatfix shall without undue delay inform You in writing if, in Whatfix’s reasonable opinion, an instruction infringes Data Protection Laws, and provide a detailed explanation of the reasons for its opinion in writing.

  1. Processor Personnel

  • Whatfix will restrict its personnel from Processing Personal Data without authorisation.

  • Whatfix will impose appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection and data security.

  1. Disclosure to Third Parties; Data Subjects Rights

  • Whatfix shall not disclose Personal Data to any government agency, court, or law enforcement except with Your written consent or as necessary to comply with applicable mandatory laws. If Whatfix is obliged to disclose Personal Data to a law enforcement agency, Whatfix agrees to give You reasonable notice of the access request prior to granting such access, to allow You to seek a protective order or other appropriate remedy (provided that You seek any such order or remedy within the relevant time frame set out in the notice given by Whatfix to You). If such notice is legally prohibited, Whatfix will take reasonable measures to protect the Personal Data from undue disclosure as if it were Whatfix’s own confidential information being requested and shall inform You promptly as soon as possible if and when such legal prohibition ceases to apply.

  • In case You receive any request or communication from Data Subjects which relates to the Processing of Personal Data ("Request"), Whatfix shall reasonably provide You with full cooperation, information and assistance ("Assistance") in relation to any such Request where instructed by You.

  • Where Whatfix receives a Request, Whatfix shall (i) not directly respond to such Request, (ii) forward the Request to You within five (5) business days of identifying the Request as being related to You and (iii) provide Assistance according to further instructions from You.

  1. Technical and Organizational Measures

  • Whatfix shall implement and maintain appropriate technical and organizational security (“TOMs”) measures to ensure that Personal Data is Processed according to this DPA, to provide Assistance and to protect Personal Data against a Personal Data Breach. Such measures shall include the measures outlined in Annex II (of the Annex to the Appendix 2).

  1. Assistance with Data Protection Impact Assessment

  • Where a Data Protection Impact Assessment ("DPIA") is required under applicable Data Protection Laws for the Processing of Personal Data, Whatfix shall, upon your request, provide you with any information and assistance reasonably required for the DPIA and assistance for any communication with data protection authorities, where required, unless the requested information or assistance is not pertaining to Whatfix’s obligations under this DPA.

  1. Information Rights and Audit

  • Whatfix shall, in accordance with Data Protection Laws, make available to You on request in a timely manner such information as is necessary to demonstrate compliance by Whatfix with its obligations under Data Protection Laws.

  • Whatfix shall, upon reasonable notice, allow for and contribute to audits of Whatfix’s Processing of Personal Data, as well as the TOMs (including data processing systems, policies, procedures and records), during regular business hours and with minimal interruption to Whatfix’s business operations. Such audits shall be conducted by You, Your affiliates or an independent third party on Your behalf (which will not be a competitor of Whatfix) that is subject to reasonable confidentiality obligations.

  • You shall pay Whatfix reasonable costs for allowing or contributing to audits or inspections in accordance with this Clause 9 where You wish to conduct more than one audit or inspection every 12 months. Whatfix will immediately refer to You any requests received from national data protection authorities that relate to Whatfix’s Processing of Personal Data, unless explicitly prohibited.

  • Whatfix undertakes to cooperate with You in its dealings with national data protection authorities and with any audit requests received from national data protection authorities.

  1. Personal Data Breach Notification

  • In respect of any Personal Data Breach (actual or reasonably suspected), Whatfix shall:

  • notify You of a Personal Data Breach involving Whatfix or a subcontractor without undue delay and it shall be Your responsibility to inform the concerned supervisory authority of such breach within 48 hours of notice by Whatfix. The obligations of Whatfix under this sub-clause shall not apply to any Personal Data Breach caused by You or users of Our services (“Users”);

  • provide reasonable information, cooperation and assistance to You in relation to any action to be taken in response to a Personal Data Breach under Data Protection Laws, including regarding any communication of the Personal Data Breach to Data Subjects and national data protection authorities.

Except where prohibited by applicable Data Protection Laws or where doing so would unreasonably delay the Customer's compliance with its legal obligations, if the Customer determines that notification of a Personal Data Breach to a supervisory authority, Data Subjects, or the public is required, the Customer should use reasonable efforts to provide Whatfix with advance notice of such communication and consider in good faith any factual clarifications reasonably provided by Whatfix relating to the Personal Data Breach.

  1. Subcontracting

  • You consent to Whatfix engaging third party sub-processors as indicated in Appendix 1 to Process Personal Data in the provision of services provided that, Whatfix will provide at least thirty (30) days’ notice to You prior to the appointment or replacement of any sub-processor. You may object to Whatfix’s appointment or replacement of a sub-processor prior to its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such an event, Whatfix will either not appoint or replace the sub-processor or, if this is not possible, You may suspend or terminate the service(s) (without prejudice to any fees incurred by You prior to such suspension or termination). In the event You do not object within thirty (30) days from the date of such notice intimating the appointment or replacement of any sub-processor, then the new sub-processor shall be deemed accepted.

  • Where Whatfix subcontracts its obligations and rights under this DPA it shall do so only by way of a binding written contract with the sub-processor which imposes essentially the same obligations according to Art. 28 GDPR especially with regard to instructions and TOMs on the sub-processor as are imposed on Whatfix under this DPA.

  • Where the sub-processor fails to fulfil its data protection obligations under the subcontracting agreement, Whatfix shall remain fully liable to You for the fulfilment of its obligations under this DPA and for the performance of the sub-processor’s obligations.

  1. International Data Transfers

  • Whatfix shall provide an adequate level of protection for Personal Data in accordance with applicable Data Protection Laws. 

  • Where Whatfix processes Personal Data originating from the European Economic Area ("EEA"), the United Kingdom, or Switzerland and such processing involves a restricted transfer under applicable Data Protection Laws, the parties agree that the applicable Model Clauses are hereby incorporated by reference and form part of this DPA as if fully set forth herein.

  • For the purposes of the Model Clauses:

  1. where the Customer acts as a Controller and Whatfix acts as a Processor, Module Two (Controller-to-Processor) shall apply;

    1. where Whatfix engages sub-processors to process Personal Data on behalf of the Customer, Module Three (Processor-to-Processor) shall apply to any onward transfers, as applicable. 

    2. Clause 7 (Docking Clause) shall apply;

    3. in Clause 9 (Use of Sub-processors), Option 2 (General Written Authorisation) shall apply, and the notice period for the appointment or replacement of sub-processors shall be thirty (30) days, as set out in this DPA;

    4. in Clause 11 (Redress), the optional independent dispute resolution provision shall not apply;

    5. in Clause 17 (Governing Law), the laws of the Republic of Ireland shall govern the Model Clauses;

    6. in Clause 18(b) (Choice of Forum and Jurisdiction), the courts of the Republic of Ireland shall have jurisdiction;

    7. the Customer shall act as the data exporter and Whatfix shall act as the data importer; and

    8. the information required for the completion of the applicable annexes to the Model Clauses is set out in Appendix 1 to this DPA.

  1. Deletion or Return of Personal Data

  • Upon termination or expiry of the Terms, Whatfix may retain Customer Content, including Personal Data, for up to two (2) years to enable Customer access, export, and account recovery. During this retention period, Customer may request export of its Customer Content by contacting Whatfix at privacy@whatfix.com.

  • Upon Customer's written request at any time during the retention period, Whatfix shall permanently delete the Customer Content, including Personal Data, within thirty (30) days of receipt of such request. Where the Customer requests export of its Customer Content prior to deletion, Whatfix shall make such Customer Content available for export before completing the deletion process.

  • Notwithstanding the foregoing, where Whatfix is required by applicable law to retain some or all Customer Content or Personal Data, Whatfix shall retain such information only for the period and purposes required by applicable law and shall protect it from further processing except to the extent necessary to comply with such legal obligation.

  1. Your Obligations 

You shall: 

  1. implement and maintain appropriate technical and organisational measures within your systems and environments to protect Personal Data and ensure compliance with applicable Data Protection Laws.

  2. provide clear and comprehensible written instructions to Whatfix for the Processing of Personal Data to be carried out under this DPA;

  3. ensure that you have all the necessary licences, permissions, consents and notices in place to enable lawful transfer of Personal Data to Whatfix for the duration and purposes of this DPA.

  4. as part of using Whatfix’s platform, You shall obtain Users' consent and required approvals as may be necessary, in compliance with Data Protection Laws; and

  5. be responsible for determining the categories of Personal Data made available to the services and use reasonable efforts to avoid providing Special Category Data (as defined under Article 9 of the GDPR), Personal Data relating to criminal convictions and offences (as defined under Article 10 of the GDPR), or other sensitive Personal Data under applicable Data Protection Laws, unless the Customer has established an appropriate legal basis and implemented sufficient safeguards required under applicable Data Protection Laws.

 

  1. Undertaking

  • Whatfix shall not sell, retain, use, or disclose Personal Data of the Users that Whatfix processes on Your behalf when providing the services under the Terms for any purpose other than for the specific purpose of providing the services in accordance with the Terms and as part of the direct relationship between Whatfix and the Customer. Whatfix certifies that it understands the restrictions in this Clause 15 and will comply with such restrictions.

 

  1. Miscellaneous

  • Whatfix may modify this DPA where (a) such modification is required to comply with applicable law; or (b) such modification is commercially reasonable, does not reduce the security of the services, does not materially change the scope of Processing of Personal Data, and does not have a material adverse impact on the Customer's rights under this DPA. Whatfix shall provide Customers with at least thirty (30) days' prior notice of any such modification by email, through the services, or by other reasonable means. Where a modification is required to comply with applicable law and advance notice is not reasonably practicable, Whatfix shall provide notice as soon as reasonably practicable following implementation of the modification.

  • To support, operate, and improve the product, Whatfix may track and analyze system-level data regarding user interactions with the services. For the avoidance of doubt, this analysis is strictly limited to understanding product usage patterns and software functionality, and shall not involve the monitoring or exploitation of the underlying Customer Content itself.

  • In case of any conflict, the provisions of this DPA shall take precedence over the provisions of any other agreement (including the Terms) with Whatfix.

  • No party shall receive any remuneration for performing its obligations under this DPA except as explicitly set out herein or in another agreement.

  • Where this DPA requires a “written notice” such notice can also be communicated per email to the other party. Notices shall be sent to the contact persons set out in Appendix 1.

  • Should individual provisions of this DPA become void, invalid or non-viable, this shall not affect the validity of the remaining conditions of this DPA.

  • Limitation of Liability. Each Party’s liability taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitation of liability provisions of the Terms.

 

The following Appendices form an integral part of this DPA:

 

APPENDIX 1

DETAILS OF THE PROCESSING OF PERSONAL DATA

  • Data subjects

Data Subjects include individuals whose Personal Data is processed by Whatfix on behalf of the Customer in connection with the services.

  • Categories of Personal Data

  • User identifiers, including name, username, employee ID, email address, and account identifiers.

    • Technical and usage data, including IP address, device information and session identifiers.

    • Any Personal Data contained within Customer Content submitted to or processed by the services, such as text, images, documents, forms, videos, screenshots, session recordings, page renderings, application content, DOM data, and other information provided to the services by the Customer or its users.

    • To the extent the Customer elects to use AI-enabled features made available under the Terms, information processed through such features, including prompts, contextual information, retrieved content, and AI-generated outputs.

    • The categories of Personal Data processed will vary based on Customer's configuration and use of the services.

Incidental Personal Data

  • Customer acknowledges that certain Services may capture or process content displayed within Customer applications, websites, documents, forms, workflows, screenshots, recordings, application interfaces, or other Customer Content. Such content may contain Personal Data that is not specifically requested, required, or intentionally collected by Whatfix, but may be incidentally included within information processed on Customer's behalf in connection with providing the Services. Except as necessary to provide the Services, Whatfix does not use such Personal Data for its own independent business purposes and does not seek to identify, extract, or profile individuals from such content.

  • Customer remains responsible for determining the categories of Personal Data made available to the Services and for implementing appropriate masking, filtering, redaction, or configuration settings where necessary.

  • Where the Customer elects to use AI-enabled features made available under the Terms, Whatfix may, as necessary to provide the requested functionality, securely transmit customer content, including incidental personal data, to authorized AI model providers acting as sub-processors. Whatfix shall use AI model providers that are contractually prohibited from using customer content to train or improve their general-purpose AI models.

    • Processing operations

    The processor must process the data collected from or for the Controller or in connection with its services provided to the Controller solely to provide the services specified in the Terms. The duration of processing will be as designated in the Terms.

    • Nature of the processing

      Processor shall process Personal Data on behalf of the Controller as necessary to provide and support the services in accordance with the Terms and the Controller's documented instructions. Processing may include the collection, storage, use, transmission, analysis, and deletion of Personal Data made available through the services.

 

  • Purpose(s) for which the personal data is processed on behalf of the controller

To provide, operate, maintain, support, secure, and improve the Whatfix services subscribed to by the Controller, and to perform related activities necessary to deliver such services in accordance with the Terms.

  • Duration of the processing

For the duration of the Terms and any applicable retention period specified therein.

The Processor may engage sub-processors to process Personal Data in connection with the provision of the services. The subject matter, nature, and duration of such processing shall be consistent with the services described in the Terms and this DPA. The current list of authorized sub-processors is set out in Appendix 1.

 

Privacy Contact:

Name: Achyuth Krishna

Email Address: privacy@whatfix.com


To facilitate effective communication regarding data processing activities, the Customer shall designate a Privacy Contact. We shall notify the Privacy Contact of any additions or changes to our sub-processors. This notification will be provided at least 30 days before the new sub-processor begins processing personal data. Any significant changes to our privacy policy or principles that could affect the processing of personal data under the Terms will be communicated to the Privacy Contact.

 

 

 

List of Sub-processors

 

Sub-processors engaged by Whatfix are listed below. For any update to the below list after the date of signing this DPA,  please check here: https://whatfix.com/support/whatfix-sub-processors/

 

Whatfix Core Sub-processors

Sub Processor Name

Purpose Of

Processing

Type Of Data Processed

Registered Office / Location

Transfer

Mechanism / Safeguards

Processing Location

Microsoft Azure

For Hosting Whatfix Platform

Name, Email id, Company Name, IP Address, Platform Activity Data

Redmond USA,

Dublin, Ireland

Adequacy

decision, DPA (with SCC),

Security and Privacy due diligence

Virginia, USA

Arizona, USA

 

Zurich, Switzerland

Dublin, Ireland

Zendesk

Support Ticketing services

Name, Email id, Company Name

San Francisco, USA

Adequacy

decision, DPA (with SCC),

Security and Privacy due diligence

San Francisco, USA

Datadog

Observability Platform

Application performance metrics

New York, USA

Adequacy

decision, DPA (with SCC), DPF Registration, Security and Privacy due diligence

New York, USA

Cloudflare

Content Delivery, WAF (web

application firewall) services

IP Address, HTTP request information

San Francisco, USA

Adequacy

decision,

DPA (with

SCC), DPF

registration, Security and Privacy due diligence

San Francisco, USA

Descope

Authentication, authorization, and identity

management

Name, Username, Email Address, Hashed Password, Whatfix Role (role of user wrt Whatfix content), and User Information, for all end users if end user authentication has been enabled by Customer.

Los Altos, USA

Adequacy

decision,

DPA (with

SCC), BAA, DPF Registration, Security and Privacy due diligence

Los Altos, California

Whatfix Private Limited

To provide support services

Name, Email id, Company Name, IP Address, Platform Activity Data

Bangalore, India

Transfer Impact Assessment, DPA (with SCC), Security and Privacy Due Diligence.

Bangalore, India

 

Whatfix Third-party Sub-processors

Sub Processor Name

Purpose Of

Processing

Type Of Data Processed

Registered Office / Location

Transfer

Mechanism / Safeguards

Processing Location

Salesforce

Customer Relation Management

Name, Email id, Company Name

San Francisco, USA

Adequacy decision, DPA (with SCC), Security and Privacy due diligence

San Francisco, USA

Infobeans

Digital Adoption

Assistant

/Professional

services

Platform activity data, customer name, user name, email address, and IP address of Whatfix users

(Only if DAA services are opted for)

Pune, India

DPA (with SCC), Transfer impact assessment, Security and Privacy due diligence

Pune, India

Mindtickle

Customer relation management and enablement

Name, username, and email address of the dashboard users.

San

Francisco,

USA

Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence

California, USA

 

Ireland (EU)

 

Singapore

 

 

 

Whatfix AI Sub-processors

Sub Processor Name

Purpose Of

Processing

Type Of Data Processed

Registered Office / Location

Transfer

Mechanism / Safeguards

Processing Location

Mindtickle

Mirror Roleplay services

Name, username, and email address of the dashboard users.

San Francisco, USA

Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence

California, USA

 

Ireland (EU)

 

Singapore

Google Cloud Platform (Vertex AI, Claude, Anthropic's Computer Use tool)

AI services for automating flow creation and improving task automation

User prompts, screenshots, and input documents

California, USA

Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence

California, USA

OpenAI

AI services for enhancing task automation

User prompts, screenshots, and input documents

California, USA

DPA (with SCC), Security and Privacy due diligence

California, USA

Anthropic (Computer Use tool)

AI services for enhancing task automation

User prompts, screenshots, and input documents

California, USA

DPA (with SCC), Security and Privacy due diligence

California, USA

Future AGI

AI observability platform

User prompts, Application screenshots, AI model-generated outputs

Delaware, USA

DPA (with SCC), Security and Privacy due diligence

North Virginia, USA

Oregon, USA

 

 

 

 

 

APPENDIX 2

International Transfers Mechanisms

Where the Processing of Personal Data under this DPA involves a restricted international transfer under applicable Data Protection Laws, the following transfer mechanisms shall apply, as applicable:

  1. European Economic Area (EEA)

  2. United Kingdom

  3. Switzerland

The European Commission Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914 (as amended, replaced, or superseded from time to time), available at:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

 

The International Data Transfer Addendum to the European Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office ("UK Addendum"), as amended, replaced, or superseded from time to time, available at:
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/

 

For transfers subject to the Swiss Federal Act on Data Protection ("FADP"), the EU Standard Contractual Clauses referenced above shall apply with the modifications required under applicable Swiss data protection laws and guidance issued by the Swiss Federal Data Protection and Information Commissioner ("FDPIC"), as amended or superseded from time to time.

 

 

 

ANNEX I (of ANNEX to APPENDIX 2 - STANDARD CONTRACTUAL ClAUSES)

 

  1. LIST OF PARTIES

MODULE TWO: Transfer controller to processor

MODULE THREE: Transfer processor to processor

 

Controller(s):    <customer entity name>

Name:                <controller name>

Position:             <position of the controller person>

Address:            <Customer Address>

Contact details: <contact details>

 

Processor(s):     <Whatfix entity name>

Name:                Achyuth Krishna

Position:            Data Protection Officer

Address:            <Whatfix entity address>

Contact Details: privacy@whatfix.com

 

  1. DESCRIPTION OF TRANSFER

MODULE TWO: Transfer controller to processor

MODULE THREE: Transfer processor to processor

  • Categories of data subjects whose personal data is processed

Refer to Appendix 1 of this DPA.

  • Categories of personal data processed

Refer to Appendix 1 of this DPA.

  • Nature of the processing

Refer to Appendix 1 of this DPA.

  • Purpose(s) for which the personal data is processed on behalf of the controller

Refer to Appendix 1 of this DPA.

  • Duration of the processing

Refer to Appendix 1 of this DPA.

  1. COMPETENT SUPERVISORY AUTHORITY 

MODULE TWO: Transfer controller to processor

MODULE THREE: Transfer processor to processor

EU Data Protection Authorities

Data Protection Commission, Ireland

 

 

 

ANNEX II (of ANNEX to APPENDIX 2 - STANDARD CONTRACTUAL ClAUSES)

 

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

 

MODULE TWO: Transfer controller to processor

MODULE THREE: Transfer processor to processor

 

Whatfix Security Policy (Technical and Organisational measures) can be accessed at https://whatfix.com/security-framework-policy/