Legal

Data Processing Addendum

Last updated July 21, 2026

Placeholder — pending legal review

This document uses templated language adapted from a standard SaaS legal template. It is provided for transparency and product-review purposes and is not final or binding legal text. A lawyer-reviewed version will replace it before it takes effect.

1. Parties and roles

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Controller”) and Relay (“Processor”) for the provision of the Service. It applies where Relay processes personal data relating to the Controller’s end-customers on the Controller’s behalf. To the extent of any conflict with the Terms of Service on the subject of end-customer data processing, this DPA prevails.

2. Subject-matter, duration and scope

Subject-matter: processing of personal data as necessary to provide the Service. Duration: for the term of the agreement plus any period required for deletion or return. Nature and purpose: hosting, transmitting, storing and processing WhatsApp messages and related CRM data. Types of data: contact phone numbers, WhatsApp profile names, message content and media, delivery/read status, and any custom fields the Controller configures. Categories of data subjects: the Controller’s customers and contacts.

Relay processes personal data only on the Controller’s documented instructions, including with regard to international transfers, unless required to do otherwise by law.

3. Sub-processors and change notice

The Controller authorizes Relay to engage the sub-processors listed below to process end-customer data. Relay imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for their performance.

  • Supabase — Managed Postgres database, authentication and file storage — the primary system of record. (United States / EU).
  • Meta Platforms (WhatsApp Business Cloud API) — Sending and receiving WhatsApp messages on your behalf via the official WhatsApp Business Platform. (United States / global).
  • Stripe — Subscription billing and payment processing. (United States).
  • Email delivery provider — Transactional email (invitations, notifications, password resets). (United States / EU).
  • AI model providers (bring-your-own — e.g. OpenAI, Anthropic) — Generating reply drafts and running the optional AI assistant, using an API key you supply. Only engaged when you enable AI features. (United States).

Relay will give the Controller reasonable prior notice of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data-protection grounds.

4. Security measures

Relay implements appropriate technical and organizational measures, including: encryption in transit (TLS); encryption of WhatsApp access tokens at rest using AES-256-GCM; database row-level security enforcing per-account tenant isolation; role-based access control; verified/signed webhooks; and access limited to authorized personnel on a need-to-know basis.

5. Assistance with data-subject requests

Taking into account the nature of the processing, Relay will assist the Controller by appropriate technical and organizational measures, insofar as possible, in responding to data-subject requests (access, rectification, erasure, restriction, portability and objection), including through the in-product export and deletion tools.

6. Personal-data breach notification

Relay will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, and will provide information reasonably available to help the Controller meet its own notification obligations.

7. Return and deletion on termination

On termination or expiry of the agreement, Relay will, at the Controller’s choice, delete or return the end-customer personal data and delete existing copies, unless retention is required by law. The Controller may also export data before termination using the in-product tools.

8. International transfers

Where processing involves transferring personal data outside its country of origin, the parties rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference. [SCCs / transfer mechanism — to be confirmed on legal review.]

9. Requesting a signed copy

The enterprise DPA signing workflow is handled manually at this time. To request a countersigned copy of this DPA for your organization, contact legal@relay.app and we will arrange execution.