This Data Processing Agreement ("DPA") describes how SnopDesk AI ("SnopDesk", "processor") processes personal data on behalf of a merchant ("you", "controller") using the SnopDesk Service, to the extent applicable data-protection law (such as the GDPR) treats SnopDesk as your processor for that data. It supplements the Terms of Service and the Privacy Policy.
This document is a practical, product-grounded DPA template. It has not yet been reviewed by qualified legal counsel and should not be treated as final for enterprise contracting purposes until that review is complete — see docs/legal-review-required.md.
1. Scope and precedence
This DPA applies only to personal data SnopDesk processes as your processor — principally, your end customers' WhatsApp, order, and support-conversation data (see the Privacy Policy §3 for how we distinguish our controller and processor roles). Where SnopDesk acts as an independent controller (for example, for merchant account and billing data), this DPA does not apply — the Privacy Policy governs that processing directly. If this DPA conflicts with the Terms on data-protection matters, this DPA controls.
2. Roles
You are the controller of your end-customer data. SnopDesk is your processor for that data.
3. Subject matter and duration
The subject matter is SnopDesk's provision of the Service to you. Processing lasts for the duration of your subscription, plus any retention period described in §14 and the Privacy Policy §16.
4. Nature and purpose of processing
SnopDesk processes your end-customer data to operate the shared inbox, send and receive WhatsApp messages on your behalf, confirm orders, provide AI-assisted and (where you enable it) automated replies, and support human handoff — all as configured by you.
5. Categories of data subjects
Your end customers who message your connected WhatsApp number or place orders processed through the Service.
6. Categories of personal data
Name, phone number, WhatsApp message content and metadata (including voice notes and transcriptions where enabled), order and shipping details, and customer-support communications — see the Privacy Policy §4 for the full breakdown.
7. Merchant documented instructions
SnopDesk processes your end-customer data only on your documented instructions — which include your workspace configuration (for example, enabling AI auto-reply, connecting a store, or configuring delivery carriers) and your use of the Service's features — except where we are required to process it differently by law. If we believe an instruction violates applicable data-protection law, we will tell you.
8. Confidentiality
SnopDesk ensures personnel authorized to process your end-customer data are subject to confidentiality obligations.
9. Security measures
SnopDesk implements technical and organizational measures appropriate to the risk, described in the Annex below.
10. Subprocessors
You authorize SnopDesk to engage the subprocessors listed at /subprocessors, which is incorporated into this DPA by reference. SnopDesk imposes data-protection obligations on subprocessors that are consistent with this DPA. See that page for how we handle updates to the list.
11. Assistance with rights requests
Taking into account the nature of the processing, SnopDesk will provide reasonable assistance to help you respond to data-subject requests concerning your end-customer data, through the Service's available features and, where those are insufficient, by request to contact@snopdesk.com.
12. Security incidents
SnopDesk will notify you without undue delay after becoming aware of a security incident affecting your end-customer data, with information reasonably available at the time, and will provide reasonable cooperation as the situation develops.
13. DPIAs and regulatory cooperation
SnopDesk will provide reasonably available information to help you carry out a data protection impact assessment or consult with a supervisory authority where applicable law requires it in connection with your use of the Service.
14. Deletion or return at termination
At the end of the Service relationship, SnopDesk will delete your end-customer data in accordance with the retention terms in the Privacy Policy §16, subject to legal, security, fraud-prevention, and accounting retention requirements that may require limited continued retention. A dedicated self-service "export all data before deletion" feature is not yet available — see the Terms §25 and docs/legal-review-required.md; in the interim, contact contact@snopdesk.com to request an export before deletion.
15. Audits and information rights
SnopDesk will make available information reasonably necessary to demonstrate compliance with this DPA upon reasonable written request, and will allow for and contribute to audits conducted by you or an auditor you mandate, subject to reasonable scope, confidentiality, and scheduling terms to be agreed in writing. SnopDesk does not currently hold ISO 27001, SOC 2, PCI DSS, or another independent security certification — do not rely on any implication otherwise. Where Stripe processes your payment data directly, that does not make SnopDesk itself PCI-DSS compliant.
16. International transfers
SnopDesk and its subprocessors may process data outside your country, including in Morocco, the European Union, and the United States. See the Subprocessor list for verified processing locations.
17. Standard Contractual Clauses
Where a transfer of personal data subject to the GDPR or UK GDPR requires the EU Standard Contractual Clauses (or the UK International Data Transfer Addendum) as a transfer mechanism, the parties intend for the applicable clauses to apply to that transfer. SnopDesk has not yet formally executed or published a standalone SCC module annex — this is flagged in docs/legal-review-required.md as an item for counsel to finalize before this DPA is relied on for EU/UK enterprise contracting.
18. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
19. How this DPA is accepted
This DPA is incorporated by reference into the Terms of Service (§18), which you accept when you create a SnopDesk account. SnopDesk does not currently offer a separate click-to-accept or countersignature flow specifically for this DPA. If your organization requires a separately executed DPA (for example, for enterprise procurement or a specific regulator's requirements), contact contact@snopdesk.com.
20. Contact
Data-protection questions about this DPA: contact@snopdesk.com.
Annex: technical and organizational measures
Based only on controls actually implemented in the Service as of this document's effective date:
- Encryption in transit (TLS) for the web application and APIs.
- Authenticated encryption for stored Meta WhatsApp access tokens, never exposed to the browser.
- Workspace-level data isolation, enforced at the data-access layer.
- Role-based access control for team members (owner/admin/agent).
- Signature verification on inbound WhatsApp and billing webhooks before processing.
- Secrets (API keys, app secrets, encryption keys) kept out of source control, in server-only environment configuration.
- Structured, redacted logging practices that avoid storing full message bodies in aggregate logs.
- Database backups, with periodic restore testing.
- An internal process for responding to and communicating about security incidents.
This list reflects implemented controls, not a certified or externally audited security program — see §15.