Data Processing Addendum

Version 1.0 · Effective 3 July 2026 · Forms part of the Terms of Service between the Customer and ALLWAYSLIVE PRIVATE LIMITED.

This Data Processing Addendum ("DPA") governs the Processing by ALLWAYSLIVE PRIVATE LIMITED ("Allways", "Processor") of Personal Data relating to End-Customers on behalf of the Customer ("Fiduciary", "you") in connection with the Service. It is incorporated into and subject to the Terms of Service. Terms not defined here have the meanings in the Terms and the Digital Personal Data Protection Act, 2023 ("DPDP Act").

1. Roles

With respect to End-Customer Personal Data processed through the Service, the Customer is the Data Fiduciary and Allways is the Data Processor acting on the Customer's behalf and instructions. Where Allways engages sub-processors (including Meta/WhatsApp for message transmission and the providers listed in Annex B), they act as further processors. Each party will comply with its obligations under the DPDP Act and other applicable data-protection law.

2. Scope and details of processing

The subject-matter, nature, purpose, duration, categories of Data Principals and types of Personal Data are described in Annex A.

3. Processor obligations

Allways will:

  1. Instructions. Process End-Customer Personal Data only on the Customer's documented instructions (including as given through use and configuration of the Service and this DPA), unless required by law, in which case Allways will inform the Customer unless legally prohibited.
  2. Purpose limitation. Not process such data for its own purposes, and not sell it or use it to serve advertising or to train third-party general-purpose AI models.
  3. Confidentiality. Ensure personnel authorised to process the data are subject to binding confidentiality obligations and access it on a need-to-know, least-privilege basis.
  4. Security. Implement and maintain the technical and organisational measures in Annex C, appropriate to the risk, as required by Section 8 of the DPDP Act.
  5. Sub-processors. Engage sub-processors only under written terms imposing data-protection obligations no less protective than this DPA, and remain responsible for their performance. The current list is in Annex B; Allways will provide a mechanism to notify the Customer of intended changes and a reasonable opportunity to object.
  6. Assistance. Taking into account the nature of processing, provide reasonable assistance to enable the Customer to (a) respond to Data Principal requests (access, correction, erasure, grievance, nomination); and (b) meet its security, breach-notification and, where applicable, impact-assessment obligations.
  7. Breach notification. Notify the Customer without undue delay after becoming aware of a Personal Data breach affecting End-Customer data, with information reasonably available to assist the Customer's own notification obligations to the Data Protection Board and affected Data Principals.
  8. Deletion/return. On termination or on the Customer's request, delete or return End-Customer Personal Data in accordance with the retention terms and the Data Deletion process, save for copies required to be retained by law.
  9. Records & audit. Maintain records of processing and, on reasonable prior notice and subject to confidentiality, make available information necessary to demonstrate compliance and allow for reasonable audits (no more than once per 12 months, on at least 30 days' written notice, during business hours), which may be satisfied by third-party reports where available.

4. Fiduciary obligations

The Customer will: (a) comply with its obligations as Data Fiduciary, including providing notices to and obtaining valid consent from End-Customers as required by the DPDP Act; (b) issue only lawful instructions; and (c) be responsible for the accuracy and lawfulness of the data and instructions it provides.

5. International transfers

The Customer authorises transfers of End-Customer Personal Data to sub-processors located outside India (Annex B) for the purpose of providing the Service, subject to the DPDP Act and appropriate safeguards, and to any restrictions notified by the Central Government.

6. Meta / WhatsApp terms

The parties acknowledge that processing over WhatsApp is additionally subject to Meta's WhatsApp Business Solution Terms, the WhatsApp Business Data Processing Terms, and the Business Terms for Service Providers. Allways processes End-Customer data solely to enable access to and use of the WhatsApp Business Solution on the Customer's behalf, consistent with those terms.

7. Liability and term

The liability provisions of the Terms apply to this DPA. This DPA remains in effect for the duration of the Service and until deletion/return of End-Customer Personal Data is complete.


Annex A — Details of processing

ElementDetail
Subject-matterProvision of AI customer-service, bookings and enquiry automation over WhatsApp
Nature & purposeReceiving, interpreting and responding to End-Customer messages; capturing bookings; generating analytics — on the Customer's behalf
DurationTerm of the Service plus retention/deletion period
Data PrincipalsThe Customer's End-Customers (individuals messaging the Customer's number)
Categories of dataWhatsApp profile name and number; message content; booking details (name, phone, date/time, notes); derived metadata
Special/child dataNot intentionally collected; Customer must not use the Service to solicit sensitive or children's data without lawful basis

Annex B — Sub-processors

Sub-processorLocationPurpose
Meta Platforms, Inc. / WhatsAppUSA / globalMessage transmission
Anthropic, PBCUSAAI response generation
Amazon Web Services (AWS)India (Mumbai, ap-south-1)Hosting & storage
RailwayUSAApplication hosting / deployment
ResendUSATransactional email

Annex C — Technical & organisational measures

  1. Encryption of data in transit (TLS); encryption at rest where applicable.
  2. Cryptographic verification of inbound WhatsApp webhooks (X-Hub-Signature-256).
  3. Tenant isolation and per-request authorisation preventing cross-account access.
  4. Role-based, least-privilege access controls; secrets management; audit logging of sensitive account actions.
  5. Secure SDLC practices, dependency management, and periodic review of controls.
  6. Access revocation on personnel change; confidentiality obligations for authorised personnel.
  7. Regular encrypted backups with defined recovery procedures.

ALLWAYSLIVE PRIVATE LIMITED · Unit No-518A, Tower-C, M3M Urbana, Sector-67, Gurugram, Haryana 122101, India · Data queries: privacy@allways.live.

allways.live
"always" · English