Data Processing Addendum
Version 2026-08-10Document v1.0Effective 10 August 2026Updated 10 August 2026
- Product
- Calanai Connect
- Between
- CALANAI HQ LLP (Processor) and the customer identified in the Agreement (Controller)
Data Processing Addendum
1. Scope, structure, and precedence
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement between the parties governing use of Calanai Connect (the "Agreement"). It applies where, and to the extent that, we process Customer Personal Data on your behalf.
In the event of conflict, the following order of precedence applies: (a) any transfer mechanism agreed in writing between the parties under Section 10.2; (b) this DPA; (c) the Agreement.
Capitalised terms not defined in this DPA have the meanings given in the Agreement.
This DPA takes effect on the effective date of the Agreement and remains in force for as long as we process Customer Personal Data.
2. Definitions
| Term | Meaning |
|---|---|
| Data Protection Law | All laws applicable to the processing of personal data under the Agreement, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and rules made under it; the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into UK law ("UK GDPR") together with the Data Protection Act 2018; and the Swiss Federal Act on Data Protection. |
| Customer Personal Data | Personal data contained within Customer Data that we process on your behalf under the Agreement. |
| Data Subject | An identified or identifiable natural person to whom Customer Personal Data relates. Includes a "Data Principal" under the DPDP Act. |
| Controller, Processor, Processing, Personal Data Breach | As defined in the GDPR. "Controller" includes "Data Fiduciary" and "Processor" includes "Data Processor" under the DPDP Act, as context requires. |
| Sub-processor | Any third party engaged by us to process Customer Personal Data. |
| SCCs | The Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914. |
| UK Addendum | The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner. |
3. Roles of the parties
You are the Controller and we are the Processor in respect of Customer Personal Data. Where you are yourself a processor acting on behalf of a third-party controller, you warrant that you have the authority of that controller to enter into this DPA and to give the instructions it contains, and we act as sub-processor.
Each party is independently responsible for its own compliance with Data Protection Law applicable to it.
We act as an independent Controller in respect of personal data we process for our own purposes — including account administration, billing, security, service improvement, and our own legal compliance. That processing is described in our Privacy Policy and is not governed by this DPA.
4. Your obligations as Controller
You represent, warrant, and undertake that:
- you have provided all notices and obtained all consents, authorisations, and other lawful bases required for the collection, processing, and transfer of Customer Personal Data as contemplated by the Agreement, including the consents required by messaging platforms before contacting Data Subjects;
- your instructions to us comply with Data Protection Law, and processing in accordance with them will not cause either party to breach Data Protection Law;
- you are solely responsible for the accuracy, quality, and legality of Customer Personal Data and of the means by which you acquired it;
- you will not submit sensitive or special categories of personal data, or personal data relating to children, to the Service except as expressly agreed in writing with us and with an appropriate lawful basis; and
- you will configure the Service, manage the access rights of your users, and use the security features made available to you in a manner appropriate to the risk of your processing.
5. Our obligations as Processor
5.1 Processing on documented instructions
We will process Customer Personal Data only on your documented instructions, including as to international transfers, except where required by law to which we are subject. In that event we will inform you of the legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
Your instructions are constituted by the Agreement, this DPA, the documented functionality and configuration of the Service as you use it, and any further written instructions you give that we agree to.
We will inform you if, in our opinion, an instruction infringes Data Protection Law. We may suspend performance of the affected instruction until it is amended or confirmed.
5.2 Purpose limitation
We will not sell Customer Personal Data, will not process it for our own independent commercial purposes, will not disclose it for advertising purposes, and will not use it for any purpose other than providing and supporting the Service as instructed — save that we may create and use aggregated, statistical, and de-identified data as described in Section 5.7.
5.3 Confidentiality
We will ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, are informed of the confidential nature of the data, and receive appropriate training. Access is granted on a least-privilege basis and only to personnel who require it to perform their duties.
5.4 Security
We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.
Our measures as at the effective date are described in Annex B. We may update them from time to time provided the level of protection is not materially reduced.
5.5 Sub-processors
General authorisation. You give general written authorisation for us to engage Sub-processors to process Customer Personal Data.
We will:
- maintain a current list of Sub-processors at https://connect.calanaihq.com/sub-processors, including each Sub-processor's name, function, and location, and a means for you to subscribe to notifications of changes;
- impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA;
- carry out appropriate due diligence before engaging a Sub-processor; and
- remain fully liable to you for the acts and omissions of our Sub-processors as if they were our own.
Notice and objection. We will give at least 15 days' notice before a new Sub-processor begins processing Customer Personal Data. You may object on reasonable, documented grounds relating to data protection within that period. The parties will discuss the objection in good faith. If we cannot provide a reasonable alternative or accommodation, you may terminate the affected part of the Service, as your sole remedy, and receive a pro-rata refund of prepaid unused fees.
Existing Sub-processors. Those listed at the effective date are deemed authorised.
Platform providers. You acknowledge that delivering the Service necessarily requires transmitting Customer Personal Data through the messaging platforms on which the Service operates, including Meta's WhatsApp Business Platform, and that this is an inherent and non-substitutable element of the Service that you instruct us to use.
5.6 Assistance to you
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you in relation to:
- Data Subject requests — see Section 6;
- Security of processing, in accordance with Section 5.4;
- Personal Data Breach notification and communication, in accordance with Section 7;
- Data protection impact assessments and prior consultation with a supervisory authority, where required in respect of processing under the Agreement.
We may charge a reasonable fee for assistance that is materially beyond the standard functionality of the Service or that is required as a result of your act or omission, having notified you in advance.
5.7 Aggregated and de-identified data
We may create aggregated, statistical, or de-identified data from Customer Personal Data, and may retain and use such data for any lawful purpose, including operating, securing, analysing, and improving the Service. Such data will not identify you or any Data Subject, and we will not attempt to re-identify it. Where such data no longer constitutes personal data, this DPA does not apply to it.
5.8 Model training
We will not use Customer Personal Data to train or improve generally available machine learning models operated by third parties, and we will contract with Sub-processors providing such technologies on terms intended to prevent them from doing so.
6. Data Subject requests
The Service provides functionality enabling you to access, correct, export, and delete Customer Personal Data within your account, so that you can respond to Data Subject requests yourself.
Where a Data Subject makes a request directly to us in respect of Customer Personal Data, we will not respond to it substantively unless legally required. We will promptly inform you of the request and, where we can identify the relevant account, forward it to you. We will provide reasonable assistance to enable you to respond, taking into account the nature of the processing.
You are responsible for responding to Data Subject requests within the time limits applicable to you under Data Protection Law.
7. Personal Data Breach
We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known and as it becomes available: the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where we cannot provide all information at once, we will provide it in phases without further undue delay.
We will take reasonable steps to contain, investigate, and remediate the breach, and will cooperate with you and provide the information you reasonably require to meet your own notification obligations to supervisory authorities and Data Subjects.
Our notification is not, and will not be construed as, an acknowledgement of fault or liability.
You are responsible for notifying supervisory authorities and affected Data Subjects where required, unless we are separately required to do so.
8. Deletion and return
On termination or expiry of the Agreement, and on your written request made within 30 days of that date, we will make Customer Personal Data available to you for export in a commonly used machine-readable format.
Following the export window, we will delete or de-identify Customer Personal Data in accordance with our retention practices as described in the Privacy Policy, and will procure that our Sub-processors do the same.
We may retain Customer Personal Data to the extent, and for as long as, required by law to which we are subject, or where it is reasonably necessary for the establishment, exercise, or defence of legal claims. Any data so retained remains subject to this DPA and will be processed only for the purpose of, and for the duration of, that requirement. Data residing in routine backups is deleted in the ordinary course of the backup cycle and is not restored to live systems in the interim.
On request, we will certify in writing that deletion has been carried out.
9. Audit and information
We will make available to you the information reasonably necessary to demonstrate compliance with this DPA.
We will satisfy this obligation, in the first instance, by providing our then-current security documentation, responses to reasonable written security questionnaires, and — where available — copies of relevant third-party audit reports or certifications.
Where that information is insufficient to demonstrate compliance, or following a Personal Data Breach, you (or an independent auditor appointed by you and not a competitor of ours, bound by confidentiality) may conduct an audit, subject to the following: audits take place no more than once in any twelve-month period, unless required by a supervisory authority or following a Personal Data Breach; you give at least thirty (30) days' prior written notice; audits are conducted during normal business hours, in a manner that does not unreasonably disrupt our operations, and in accordance with our on-site security and confidentiality requirements; the scope is limited to systems and information relevant to Customer Personal Data, and excludes information relating to other customers, and our internal pricing, personnel, and commercial data; and each party bears its own costs, save that you will reimburse our reasonable costs where an audit exceeds one business day or is repeated within a twelve-month period.
Audit findings are the Confidential Information of both parties.
10. International transfers
You authorise us and our Sub-processors to transfer Customer Personal Data internationally as necessary to provide the Service, subject to appropriate safeguards.
10.1 India
Transfers of personal data out of India are made in accordance with the DPDP Act, and we will not transfer personal data to any territory notified as restricted by the Central Government.
Our primary data store is located in India. Certain Sub-processors identified in the list referenced in Section 5.5 process Customer Personal Data outside India, as recorded in that list.
10.2 Territorial scope of the Service
The Service is offered to customers established in India. We do not currently offer the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent European transfer mechanism, and we have not appointed a representative under Article 27 of the GDPR.
If you are established in the European Economic Area, the United Kingdom, or Switzerland, or if your use of the Service involves personal data subject to the GDPR, the UK GDPR, or Swiss data protection law, you must tell us before entering into the Agreement so that the parties can agree an appropriate transfer mechanism in writing. Absent such written agreement, the Service is not offered for that processing.
10.3 Alternative mechanisms
If a transfer mechanism relied upon here is invalidated, superseded, or replaced, the parties will cooperate in good faith to implement a valid alternative mechanism without undue delay, and such mechanism will apply automatically in place of the affected one to the extent permitted by law.
11. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement.
Nothing in this DPA limits either party's liability to a Data Subject under the third-party beneficiary provisions of any transfer mechanism agreed under Section 10.2, or any liability that cannot be limited or excluded under Data Protection Law.
12. General
This DPA may be updated by us where required to reflect a change in Data Protection Law, a decision of a supervisory authority, the adoption of a new transfer mechanism, or a change in our Sub-processors or security measures, provided that no update materially reduces the protections afforded to Customer Personal Data. We will give reasonable notice of material updates.
If any provision of this DPA is held invalid or unenforceable, it will be modified to the minimum extent necessary or severed, and the remainder continues in force.
Except as amended by this DPA, the Agreement remains in full force and effect.
Annex A — Description of processing
(Describes the processing. Would populate Annex I to the SCCs if a transfer mechanism is agreed in writing under Section 10.2.)
A.1 Parties
Data exporter (Controller): the Customer identified in the Agreement. Contact details and activities relevant to the transfer are as recorded in the Customer's account and Order Form. Role: Controller (or processor, where Module Three applies).
Data importer (Processor): CALANAI HQ LLP, No.11/41, Narasinghapuram Street, Anna Road, Chennai - 600002, Tamil Nadu, India. Contact: privacy@calanaihq.com. Activities relevant to the transfer: provision of the Calanai Connect business messaging and customer engagement platform. Role: Processor.
A.2 Categories of Data Subjects
- The Customer's customers, prospective customers, and other individuals who communicate with the Customer through the Service ("End Customers").
- The Customer's personnel who are authorised to use the Service ("Authorised Users").
- Other individuals whose personal data the Customer chooses to process through the Service.
A.3 Categories of Personal Data
- Identity and contact data — telephone number, messaging profile name, name, email address, and similar identifiers.
- Profile data — such as city or location indication, language preference, company, job title, and customer-defined attributes.
- Communications data — the content and metadata of messages exchanged through the Service, including text, structured and interactive content, references to attachments and media, message identifiers, delivery and read status, and timestamps.
- Conversation and service records — conversation state and history, assignment and handling records, internal notes, and records of automated processing.
- Enquiry and commercial data — enquiries, requirements, preferences, interests, indications of value, and, where the Customer enables the relevant features, transactional information such as order, delivery, invoice, payment, return, and product or service history.
- Preference data — consent and opt-out status and related records.
- Technical data — identifiers, log and diagnostic data associated with use of the Service.
- Any other personal data the Customer chooses to submit to the Service or that a Data Subject volunteers in the course of a communication.
A.4 Sensitive data
The Service is not intended for sensitive or special categories of personal data, and the Customer is restricted from submitting such data without our prior written agreement. Where, exceptionally, such data is agreed or is volunteered by a Data Subject in free-text content, the restrictions and safeguards in Annex B apply, including encryption in transit and at rest, strict access limitation on a need-to-know basis, and confidentiality obligations on personnel.
A.5 Frequency of transfer
Continuous, for the duration of the Agreement.
A.6 Nature and purpose of processing
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, disclosure by transmission, alignment, combination, erasure, and destruction of Customer Personal Data, as necessary to provide, maintain, secure, support, and improve the Service — including message delivery and receipt, automated and assisted response generation, conversation management and routing, contact and enquiry record management, integration with systems connected by the Customer, analytics and reporting, and technical support.
A.7 Duration of processing
For the duration of the Agreement, plus the retention and deletion periods described in Section 8 of this DPA and in the Privacy Policy.
A.8 Sub-processors
Subject matter, nature, and duration of processing by Sub-processors are as set out in this Annex and in the list maintained at https://connect.calanaihq.com/sub-processors.
A.9 Competent supervisory authority
The Data Protection Board of India. Where a transfer mechanism is agreed in writing under Section 10.2, the competent authority for the purposes of that mechanism will be identified in that agreement.
Annex B — Technical and organisational measures
(Describes our security measures. Would populate Annex II to the SCCs if a transfer mechanism is agreed in writing under Section 10.2.)
We maintain the following measures, appropriate to the nature, scope, and risk of the processing. Specific implementations may change provided the level of protection is not materially reduced.
Encryption. Data in transit is protected using current industry-standard transport encryption on all external connections, including connections to our database and to the messaging platforms on which the Service operates. Integration credentials, platform access tokens, and comparable sensitive values are encrypted at rest using AES-256-GCM authenticated encryption and are decrypted only in memory at the point of use. The primary data store is encrypted at rest by the hosting provider. Where we retain a record of an individual's opt-out beyond the deletion of their other data, we store only a keyed one-way cryptographic hash of their telephone number, from which the number cannot be recovered.
Access control. Dashboard access is authenticated through a dedicated identity provider supporting federated sign-in, with a single concurrent session enforced per user. Within a customer account, permissions are role-based, and the most consequential operations — including deletion of an individual's records — are restricted to the account owner. Platform administrative access is separately authenticated by a distinct credential compared in constant time. Access to production systems and data is limited to the Designated Partner. Secrets are held in environment configuration, are excluded from version control, and are not written to logs.
Tenant separation. Each customer's data is logically separated. Every application query path is scoped to a single customer account, and cache keys, job queues, and real-time messaging channels are namespaced per customer. Separation is enforced in the application layer; we do not currently rely on database-level row security as an additional control.
Authenticity and integrity. Inbound webhooks from messaging platforms are verified by HMAC signature before any processing occurs, and platform callbacks that use a different signing scheme are verified against that scheme rather than reusing the webhook path. Inbound payloads and API inputs are schema-validated at trust boundaries. Message identifiers are used to deduplicate repeated platform deliveries.
Availability and resilience. The primary data store is operated on a managed plan providing automated backups retained on a defined cycle. Circuit breakers isolate failing external dependencies, and rate limiting is applied at several independent layers — per customer, per contacting individual, per messaging-platform account, and per source address on public endpoints. Outbound delivery failures are retried on a staged backoff, and permanently rejected sends are recorded to a durable failure ledger rather than discarded.
Logging and monitoring. Security-relevant events and actions taken by customer personnel within the Service are recorded to an audit log retained with the customer's account. Application logs are structured, and credentials, tokens, and comparable secrets are redacted from them by configuration. Application errors are captured by an error-monitoring service and alerted to us.
Secure development. Changes are version-controlled and are covered by an automated test suite executed before deployment. Runtime environments are separated from local development environments, and configuration is supplied per environment rather than embedded in code. Database migrations are applied through a controlled forward-only path, with destructive migration commands blocked by tooling.
Personnel. Access to personal data is presently limited to the Designated Partner. Any additional personnel granted access will be bound by written confidentiality obligations before access is granted, and access will be revoked promptly on role change or departure.
Sub-processor management. Sub-processors are subject to due diligence before engagement and are bound by written data protection terms no less protective than those in this DPA. The current list is maintained at the address given in Section 5.5.
Incident management. We maintain a process for detecting, reporting, investigating, and responding to security incidents, including the notification obligations in Section 7.
Deletion. The Service provides deletion on request rather than automatic time-based expiry: Customer Personal Data is retained for the duration of the customer's account, as described in Section 8 and in the Privacy Policy, and is deleted when the customer or we act on a deletion request. Deletion of an individual's records is executed as a single ordered transaction covering their contact record, conversations, message history, notes, enquiry records, and consent history. Deletion of an entire customer account covers every customer-scoped record, executed in dependency-safe order and re-runnable if interrupted. Records that survive deletion by design are limited to those described in Section 8 and in our published data deletion instructions — audit records of the deletion itself, opt-out records held as an irreversible hash, and aggregated data containing no personal data.
Physical security. Production infrastructure is hosted with reputable providers operating facilities with physical access controls, environmental protections, and appropriate certifications. We do not operate our own data centres.
Assistance to the Controller. The Service provides functionality enabling the Customer to access, correct, export, and delete Customer Personal Data in order to meet its own obligations, including a self-serve export of the account's data in a machine-readable format.