DATA PROCESSING AGREEMENT
This Data Processing Agreement (the “DPA”) constitutes a legally binding agreement between the customer identified in the Terms (the “Customer”, “You”, “Your”) and the relevant Whatfix entity identified in the Terms (“Whatfix”, “Us”, “We”, “Our”). Each of You and Us is individually referred to as a “party” and collectively, the “parties”.
You are required to read this DPA carefully as this DPA forms an integral part of the software as a services agreement, or any other agreement between You and Us that references this DPA, as applicable (the “Terms”) and is applicable where We are the Processors of Your Personal Data. In the event of a conflict between this DPA and the Terms, this DPA shall prevail.
Definitions
In this DPA, the following terms shall have the following meanings:
“CCPA” shall mean the California Consumer Privacy Act of 2018, and any related regulations or guidance provided by the California Attorney General;
“Customer Content” means all data and materials created or provided by the Customer to Whatfix for use in connection with the services, including, without limitation, flows, text snippets, images, and videos;
“Controller”, “Data Subject”, “Personal Data Breach”, “Processor” and “Process” shall have the meaning given to them in the GDPR and, as applicable, the CCPA and/ or other applicable Data Protection Laws;
“Data Protection Laws” shall mean the data protection laws of the country in which You are established, including the GDPR, the CCPA, and any data protection laws applicable to You in connection with the Terms (including without limitation, the UK GDPR and Data Protection Act 2018 if You are established in the United Kingdom);
“GDPR” shall mean the Regulation (EU) 2016/679 of the European Parliament and of the Council 11of 27 April 2016 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), as amended and updated from time to time;
"Model Clauses" means the European Commission Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914, together with any applicable United Kingdom International Data Transfer Addendum and Swiss adaptations, each as amended, replaced, or superseded from time to time.
“Personal Data” shall mean any information relating to an identified or identifiable natural person as defined by applicable Data Protection Laws that is Processed by Processor as part of providing the services to You as described in an Appendix; and
“UK GDPR” means the GDPR as adopted and made applicable in the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.
Scope and Responsibilities
This DPA applies to Processing of Personal Data forming part of Customer Content.
Whatfix shall process Personal Data only on Your behalf and at all times only in accordance with this DPA and Appendices attached hereto. For the avoidance of doubt, Whatfix shall be the Processor and You shall be the Controller of the Personal Data.
Within the scope of the Terms, each party shall be responsible for complying with its respective obligations as Controller and Processor under Data Protection Laws.
Term and Termination
This DPA becomes effective upon signature. It shall continue to be in full force and effect as long as Whatfix is Processing Personal Data pursuant to the Terms and shall terminate automatically thereafter.
Save and except for as expressly provided Clause 16 below, where amendments are required to ensure compliance of this DPA or an Appendix with Data Protection Laws, the parties shall make reasonable efforts to agree on such amendments upon your request. Where the parties are unable to agree upon such amendments, either party may terminate this DPA with 90 days written notice to the other party.
Processing Instructions
Whatfix will Process Personal Data in accordance with Your instructions. This DPA contains Your initial instructions to Whatfix. The parties agree that You may communicate any change in its initial instructions to Whatfix by way of amendment to this DPA.
For the avoidance of doubt, any instructions that would lead to Processing outside the scope of this DPA (e.g. because a new Processing purpose is introduced) will require a prior written agreement between the parties.
Whatfix shall without undue delay inform You in writing if, in Whatfix’s reasonable opinion, an instruction infringes Data Protection Laws, and provide a detailed explanation of the reasons for its opinion in writing.
Processor Personnel
Whatfix will restrict its personnel from Processing Personal Data without authorisation.
Whatfix will impose appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection and data security.
Disclosure to Third Parties; Data Subjects Rights
Whatfix shall not disclose Personal Data to any government agency, court, or law enforcement except with Your written consent or as necessary to comply with applicable mandatory laws. If Whatfix is obliged to disclose Personal Data to a law enforcement agency, Whatfix agrees to give You reasonable notice of the access request prior to granting such access, to allow You to seek a protective order or other appropriate remedy (provided that You seek any such order or remedy within the relevant time frame set out in the notice given by Whatfix to You). If such notice is legally prohibited, Whatfix will take reasonable measures to protect the Personal Data from undue disclosure as if it were Whatfix’s own confidential information being requested and shall inform You promptly as soon as possible if and when such legal prohibition ceases to apply.
In case You receive any request or communication from Data Subjects which relates to the Processing of Personal Data ("Request"), Whatfix shall reasonably provide You with full cooperation, information and assistance ("Assistance") in relation to any such Request where instructed by You.
Where Whatfix receives a Request, Whatfix shall (i) not directly respond to such Request, (ii) forward the Request to You within five (5) business days of identifying the Request as being related to You and (iii) provide Assistance according to further instructions from You.
Technical and Organizational Measures
Whatfix shall implement and maintain appropriate technical and organizational security (“TOMs”) measures to ensure that Personal Data is Processed according to this DPA, to provide Assistance and to protect Personal Data against a Personal Data Breach. Such measures shall include the measures outlined in Annex II (of the Annex to the Appendix 2).
Assistance with Data Protection Impact Assessment
Where a Data Protection Impact Assessment ("DPIA") is required under applicable Data Protection Laws for the Processing of Personal Data, Whatfix shall, upon your request, provide you with any information and assistance reasonably required for the DPIA and assistance for any communication with data protection authorities, where required, unless the requested information or assistance is not pertaining to Whatfix’s obligations under this DPA.
Information Rights and Audit
Whatfix shall, in accordance with Data Protection Laws, make available to You on request in a timely manner such information as is necessary to demonstrate compliance by Whatfix with its obligations under Data Protection Laws.
Whatfix shall, upon reasonable notice, allow for and contribute to audits of Whatfix’s Processing of Personal Data, as well as the TOMs (including data processing systems, policies, procedures and records), during regular business hours and with minimal interruption to Whatfix’s business operations. Such audits shall be conducted by You, Your affiliates or an independent third party on Your behalf (which will not be a competitor of Whatfix) that is subject to reasonable confidentiality obligations.
You shall pay Whatfix reasonable costs for allowing or contributing to audits or inspections in accordance with this Clause 9 where You wish to conduct more than one audit or inspection every 12 months. Whatfix will immediately refer to You any requests received from national data protection authorities that relate to Whatfix’s Processing of Personal Data, unless explicitly prohibited.
Whatfix undertakes to cooperate with You in its dealings with national data protection authorities and with any audit requests received from national data protection authorities.
Personal Data Breach Notification
In respect of any Personal Data Breach (actual or reasonably suspected), Whatfix shall:
notify You of a Personal Data Breach involving Whatfix or a subcontractor without undue delay and it shall be Your responsibility to inform the concerned supervisory authority of such breach within 48 hours of notice by Whatfix. The obligations of Whatfix under this sub-clause shall not apply to any Personal Data Breach caused by You or users of Our services (“Users”);
provide reasonable information, cooperation and assistance to You in relation to any action to be taken in response to a Personal Data Breach under Data Protection Laws, including regarding any communication of the Personal Data Breach to Data Subjects and national data protection authorities.
Except where prohibited by applicable Data Protection Laws or where doing so would unreasonably delay the Customer's compliance with its legal obligations, if the Customer determines that notification of a Personal Data Breach to a supervisory authority, Data Subjects, or the public is required, the Customer should use reasonable efforts to provide Whatfix with advance notice of such communication and consider in good faith any factual clarifications reasonably provided by Whatfix relating to the Personal Data Breach.
Subcontracting
You consent to Whatfix engaging third party sub-processors as indicated in Appendix 1 to Process Personal Data in the provision of services provided that, Whatfix will provide at least thirty (30) days’ notice to You prior to the appointment or replacement of any sub-processor. You may object to Whatfix’s appointment or replacement of a sub-processor prior to its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such an event, Whatfix will either not appoint or replace the sub-processor or, if this is not possible, You may suspend or terminate the service(s) (without prejudice to any fees incurred by You prior to such suspension or termination). In the event You do not object within thirty (30) days from the date of such notice intimating the appointment or replacement of any sub-processor, then the new sub-processor shall be deemed accepted.
Where Whatfix subcontracts its obligations and rights under this DPA it shall do so only by way of a binding written contract with the sub-processor which imposes essentially the same obligations according to Art. 28 GDPR especially with regard to instructions and TOMs on the sub-processor as are imposed on Whatfix under this DPA.
Where the sub-processor fails to fulfil its data protection obligations under the subcontracting agreement, Whatfix shall remain fully liable to You for the fulfilment of its obligations under this DPA and for the performance of the sub-processor’s obligations.
International Data Transfers
Whatfix shall provide an adequate level of protection for Personal Data in accordance with applicable Data Protection Laws.
Where Whatfix processes Personal Data originating from the European Economic Area ("EEA"), the United Kingdom, or Switzerland and such processing involves a restricted transfer under applicable Data Protection Laws, the parties agree that the applicable Model Clauses are hereby incorporated by reference and form part of this DPA as if fully set forth herein.
For the purposes of the Model Clauses:
where the Customer acts as a Controller and Whatfix acts as a Processor, Module Two (Controller-to-Processor) shall apply;
where Whatfix engages sub-processors to process Personal Data on behalf of the Customer, Module Three (Processor-to-Processor) shall apply to any onward transfers, as applicable.
Clause 7 (Docking Clause) shall apply;
in Clause 9 (Use of Sub-processors), Option 2 (General Written Authorisation) shall apply, and the notice period for the appointment or replacement of sub-processors shall be thirty (30) days, as set out in this DPA;
in Clause 11 (Redress), the optional independent dispute resolution provision shall not apply;
in Clause 17 (Governing Law), the laws of the Republic of Ireland shall govern the Model Clauses;
in Clause 18(b) (Choice of Forum and Jurisdiction), the courts of the Republic of Ireland shall have jurisdiction;
the Customer shall act as the data exporter and Whatfix shall act as the data importer; and
the information required for the completion of the applicable annexes to the Model Clauses is set out in Appendix 1 to this DPA.
Deletion or Return of Personal Data
Upon termination or expiry of the Terms, Whatfix may retain Customer Content, including Personal Data, for up to two (2) years to enable Customer access, export, and account recovery. During this retention period, Customer may request export of its Customer Content by contacting Whatfix at privacy@whatfix.com.
Upon Customer's written request at any time during the retention period, Whatfix shall permanently delete the Customer Content, including Personal Data, within thirty (30) days of receipt of such request. Where the Customer requests export of its Customer Content prior to deletion, Whatfix shall make such Customer Content available for export before completing the deletion process.
Notwithstanding the foregoing, where Whatfix is required by applicable law to retain some or all Customer Content or Personal Data, Whatfix shall retain such information only for the period and purposes required by applicable law and shall protect it from further processing except to the extent necessary to comply with such legal obligation.
Your Obligations
You shall:
implement and maintain appropriate technical and organisational measures within your systems and environments to protect Personal Data and ensure compliance with applicable Data Protection Laws.
provide clear and comprehensible written instructions to Whatfix for the Processing of Personal Data to be carried out under this DPA;
ensure that you have all the necessary licences, permissions, consents and notices in place to enable lawful transfer of Personal Data to Whatfix for the duration and purposes of this DPA.
as part of using Whatfix’s platform, You shall obtain Users' consent and required approvals as may be necessary, in compliance with Data Protection Laws; and
be responsible for determining the categories of Personal Data made available to the services and use reasonable efforts to avoid providing Special Category Data (as defined under Article 9 of the GDPR), Personal Data relating to criminal convictions and offences (as defined under Article 10 of the GDPR), or other sensitive Personal Data under applicable Data Protection Laws, unless the Customer has established an appropriate legal basis and implemented sufficient safeguards required under applicable Data Protection Laws.
Undertaking
Whatfix shall not sell, retain, use, or disclose Personal Data of the Users that Whatfix processes on Your behalf when providing the services under the Terms for any purpose other than for the specific purpose of providing the services in accordance with the Terms and as part of the direct relationship between Whatfix and the Customer. Whatfix certifies that it understands the restrictions in this Clause 15 and will comply with such restrictions.
Miscellaneous
Whatfix may modify this DPA where (a) such modification is required to comply with applicable law; or (b) such modification is commercially reasonable, does not reduce the security of the services, does not materially change the scope of Processing of Personal Data, and does not have a material adverse impact on the Customer's rights under this DPA. Whatfix shall provide Customers with at least thirty (30) days' prior notice of any such modification by email, through the services, or by other reasonable means. Where a modification is required to comply with applicable law and advance notice is not reasonably practicable, Whatfix shall provide notice as soon as reasonably practicable following implementation of the modification.
To support, operate, and improve the product, Whatfix may track and analyze system-level data regarding user interactions with the services. For the avoidance of doubt, this analysis is strictly limited to understanding product usage patterns and software functionality, and shall not involve the monitoring or exploitation of the underlying Customer Content itself.
In case of any conflict, the provisions of this DPA shall take precedence over the provisions of any other agreement (including the Terms) with Whatfix.
No party shall receive any remuneration for performing its obligations under this DPA except as explicitly set out herein or in another agreement.
Where this DPA requires a “written notice” such notice can also be communicated per email to the other party. Notices shall be sent to the contact persons set out in Appendix 1.
Should individual provisions of this DPA become void, invalid or non-viable, this shall not affect the validity of the remaining conditions of this DPA.
Limitation of Liability. Each Party’s liability taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitation of liability provisions of the Terms.
The following Appendices form an integral part of this DPA:
APPENDIX 1
DETAILS OF THE PROCESSING OF PERSONAL DATA
Data subjects
Data Subjects include individuals whose Personal Data is processed by Whatfix on behalf of the Customer in connection with the services.
Categories of Personal Data
User identifiers, including name, username, employee ID, email address, and account identifiers.
Technical and usage data, including IP address, device information and session identifiers.
Any Personal Data contained within Customer Content submitted to or processed by the services, such as text, images, documents, forms, videos, screenshots, session recordings, page renderings, application content, DOM data, and other information provided to the services by the Customer or its users.
To the extent the Customer elects to use AI-enabled features made available under the Terms, information processed through such features, including prompts, contextual information, retrieved content, and AI-generated outputs.
The categories of Personal Data processed will vary based on Customer's configuration and use of the services.
Incidental Personal Data
Customer acknowledges that certain Services may capture or process content displayed within Customer applications, websites, documents, forms, workflows, screenshots, recordings, application interfaces, or other Customer Content. Such content may contain Personal Data that is not specifically requested, required, or intentionally collected by Whatfix, but may be incidentally included within information processed on Customer's behalf in connection with providing the Services. Except as necessary to provide the Services, Whatfix does not use such Personal Data for its own independent business purposes and does not seek to identify, extract, or profile individuals from such content.
Customer remains responsible for determining the categories of Personal Data made available to the Services and for implementing appropriate masking, filtering, redaction, or configuration settings where necessary.
Where the Customer elects to use AI-enabled features made available under the Terms, Whatfix may, as necessary to provide the requested functionality, securely transmit customer content, including incidental personal data, to authorized AI model providers acting as sub-processors. Whatfix shall use AI model providers that are contractually prohibited from using customer content to train or improve their general-purpose AI models.
Processing operations
The processor must process the data collected from or for the Controller or in connection with its services provided to the Controller solely to provide the services specified in the Terms. The duration of processing will be as designated in the Terms.
Nature of the processing
Processor shall process Personal Data on behalf of the Controller as necessary to provide and support the services in accordance with the Terms and the Controller's documented instructions. Processing may include the collection, storage, use, transmission, analysis, and deletion of Personal Data made available through the services.
Purpose(s) for which the personal data is processed on behalf of the controller
To provide, operate, maintain, support, secure, and improve the Whatfix services subscribed to by the Controller, and to perform related activities necessary to deliver such services in accordance with the Terms.
Duration of the processing
For the duration of the Terms and any applicable retention period specified therein.
The Processor may engage sub-processors to process Personal Data in connection with the provision of the services. The subject matter, nature, and duration of such processing shall be consistent with the services described in the Terms and this DPA. The current list of authorized sub-processors is set out in Appendix 1.
Privacy Contact:
Name: Achyuth Krishna
Email Address: privacy@whatfix.com
To facilitate effective communication regarding data processing activities, the Customer shall designate a Privacy Contact. We shall notify the Privacy Contact of any additions or changes to our sub-processors. This notification will be provided at least 30 days before the new sub-processor begins processing personal data. Any significant changes to our privacy policy or principles that could affect the processing of personal data under the Terms will be communicated to the Privacy Contact.
List of Sub-processors
Sub-processors engaged by Whatfix are listed below. For any update to the below list after the date of signing this DPA, please check here: https://whatfix.com/support/whatfix-sub-processors/
Whatfix Core Sub-processors
Sub Processor Name | Purpose Of Processing | Type Of Data Processed | Registered Office / Location | Transfer Mechanism / Safeguards | Processing Location |
Microsoft Azure | For Hosting Whatfix Platform | Name, Email id, Company Name, IP Address, Platform Activity Data | Redmond USA, Dublin, Ireland | Adequacy decision, DPA (with SCC), Security and Privacy due diligence | Virginia, USA Arizona, USA
Zurich, Switzerland Dublin, Ireland |
Zendesk | Support Ticketing services | Name, Email id, Company Name | San Francisco, USA | Adequacy decision, DPA (with SCC), Security and Privacy due diligence | San Francisco, USA |
Datadog | Observability Platform | Application performance metrics | New York, USA | Adequacy decision, DPA (with SCC), DPF Registration, Security and Privacy due diligence | New York, USA |
Cloudflare | Content Delivery, WAF (web application firewall) services | IP Address, HTTP request information | San Francisco, USA | Adequacy decision, DPA (with SCC), DPF registration, Security and Privacy due diligence | San Francisco, USA |
Descope | Authentication, authorization, and identity management | Name, Username, Email Address, Hashed Password, Whatfix Role (role of user wrt Whatfix content), and User Information, for all end users if end user authentication has been enabled by Customer. | Los Altos, USA | Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence | Los Altos, California |
Whatfix Private Limited | To provide support services | Name, Email id, Company Name, IP Address, Platform Activity Data | Bangalore, India | Transfer Impact Assessment, DPA (with SCC), Security and Privacy Due Diligence. | Bangalore, India |
Whatfix Third-party Sub-processors
Sub Processor Name | Purpose Of Processing | Type Of Data Processed | Registered Office / Location | Transfer Mechanism / Safeguards | Processing Location |
Salesforce | Customer Relation Management | Name, Email id, Company Name | San Francisco, USA | Adequacy decision, DPA (with SCC), Security and Privacy due diligence | San Francisco, USA |
Infobeans | Digital Adoption Assistant /Professional services | Platform activity data, customer name, user name, email address, and IP address of Whatfix users (Only if DAA services are opted for) | Pune, India | DPA (with SCC), Transfer impact assessment, Security and Privacy due diligence | Pune, India |
Mindtickle | Customer relation management and enablement | Name, username, and email address of the dashboard users. | San Francisco, USA | Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence | California, USA
Ireland (EU)
Singapore |
Whatfix AI Sub-processors
Sub Processor Name | Purpose Of Processing | Type Of Data Processed | Registered Office / Location | Transfer Mechanism / Safeguards | Processing Location |
Mindtickle | Mirror Roleplay services | Name, username, and email address of the dashboard users. | San Francisco, USA | Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence | California, USA
Ireland (EU)
Singapore |
Google Cloud Platform (Vertex AI, Claude, Anthropic's Computer Use tool) | AI services for automating flow creation and improving task automation | User prompts, screenshots, and input documents | California, USA | Adequacy decision, DPA (with SCC), BAA, DPF Registration, Security and Privacy due diligence | California, USA |
OpenAI | AI services for enhancing task automation | User prompts, screenshots, and input documents | California, USA | DPA (with SCC), Security and Privacy due diligence | California, USA |
Anthropic (Computer Use tool) | AI services for enhancing task automation | User prompts, screenshots, and input documents | California, USA | DPA (with SCC), Security and Privacy due diligence | California, USA |
Future AGI | AI observability platform | User prompts, Application screenshots, AI model-generated outputs | Delaware, USA | DPA (with SCC), Security and Privacy due diligence | North Virginia, USA Oregon, USA |
APPENDIX 2
International Transfers Mechanisms
Where the Processing of Personal Data under this DPA involves a restricted international transfer under applicable Data Protection Laws, the following transfer mechanisms shall apply, as applicable:
European Economic Area (EEA)
United Kingdom
Switzerland
The European Commission Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914 (as amended, replaced, or superseded from time to time), available at:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
The International Data Transfer Addendum to the European Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office ("UK Addendum"), as amended, replaced, or superseded from time to time, available at:
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/
For transfers subject to the Swiss Federal Act on Data Protection ("FADP"), the EU Standard Contractual Clauses referenced above shall apply with the modifications required under applicable Swiss data protection laws and guidance issued by the Swiss Federal Data Protection and Information Commissioner ("FDPIC"), as amended or superseded from time to time.
ANNEX I (of ANNEX to APPENDIX 2 - STANDARD CONTRACTUAL ClAUSES)
LIST OF PARTIES
MODULE TWO: Transfer controller to processor
MODULE THREE: Transfer processor to processor
Controller(s): <customer entity name>
Name: <controller name>
Position: <position of the controller person>
Address: <Customer Address>
Contact details: <contact details>
Processor(s): <Whatfix entity name>
Name: Achyuth Krishna
Position: Data Protection Officer
Address: <Whatfix entity address>
Contact Details: privacy@whatfix.com
DESCRIPTION OF TRANSFER
MODULE TWO: Transfer controller to processor
MODULE THREE: Transfer processor to processor
Categories of data subjects whose personal data is processed
Refer to Appendix 1 of this DPA.
Categories of personal data processed
Refer to Appendix 1 of this DPA.
Nature of the processing
Refer to Appendix 1 of this DPA.
Purpose(s) for which the personal data is processed on behalf of the controller
Refer to Appendix 1 of this DPA.
Duration of the processing
Refer to Appendix 1 of this DPA.
COMPETENT SUPERVISORY AUTHORITY
MODULE TWO: Transfer controller to processor
MODULE THREE: Transfer processor to processor
EU Data Protection Authorities
Data Protection Commission, Ireland
ANNEX II (of ANNEX to APPENDIX 2 - STANDARD CONTRACTUAL ClAUSES)
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
MODULE TWO: Transfer controller to processor
MODULE THREE: Transfer processor to processor
Whatfix Security Policy (Technical and Organisational measures) can be accessed at https://whatfix.com/security-framework-policy/