Data Processing Agreement
Version 2026-10-08 · in effect from 8 October 2026
The short version
When your business keeps personal data in Teamline (your contacts, chats, leads and emails), you decide what happens to it and you are responsible for having the right to use it. We only process it to run Teamline for you, keep it secure and confidential, use only the providers listed on our sub-processor page, tell you about breaches, help you answer people's requests, and delete it when the contract ends.
This Data Processing Agreement (“DPA”) is part of the Terms of Service between Andybot (“Processor”, “we”) and the Customer (“you”). It applies whenever we process personal data in Customer Data on your behalf. Words with a capital letter have the meaning given in the Terms.
1. Definitions
- “Data Protection Law” means every law on personal data that applies to the processing, which may include UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, DIFC Data Protection Law No. 5 of 2020, ADGM Data Protection Regulations 2021, the Saudi Personal Data Protection Law and the California Consumer Privacy Act (“CCPA”).
- “Personal Data”, “controller”, “processor”, “data subject”, “processing” and “personal data breach” have the meanings given in Data Protection Law (or the closest equivalent terms).
- “Sub-processor” means a provider we engage that processes Personal Data in Customer Data for us.
2. Roles
- You are the controller of the Personal Data in Customer Data (or, where you act for another controller, a processor; we are then your sub-processor and you confirm you have that controller's authorisation). We are your processor.
- You are responsible for: having a lawful basis (for example consent) for the data you put into, collect through or send with Teamline; giving data subjects any notice the law requires; the accuracy of the data; and making sure your instructions comply with Data Protection Law.
- Details of the processing are in Annex 1.
3. Your instructions
- We process Personal Data only on your documented instructions, unless a law we are subject to requires otherwise (in which case we will tell you first, unless the law forbids that). Your instructions are: the Terms and this DPA; your configuration and use of Teamline (including the WhatsApp numbers, mailboxes and AI settings you connect and turn on); and any other written instructions we agree.
- We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not required to check your instructions for legal compliance.
- We do not sell Personal Data, share it for cross-context behavioural advertising, or use it for our own purposes, except to create anonymous aggregate statistics as allowed in the Terms.
4. Confidentiality
We make sure everyone we authorise to process Personal Data is bound by confidentiality, and give access only to those who need it to provide, support or secure the service.
5. Security
We take appropriate technical and organisational measures to protect Personal Data, described in Annex 2. We may update them as long as the overall level of protection does not go down. You are responsible for the security of your own devices, passwords and accounts, for the access you give your Users, and for the WhatsApp numbers and mailboxes you connect.
6. Sub-processors
- You give us general authorisation to use the Sub-processors listed on our sub-processor page (Annex 3).
- We will give at least 30 days' notice before adding or replacing a Sub-processor, by updating that page and emailing the account owner. You may object on reasonable data protection grounds within 14 days of the notice. We will then try to find a reasonable solution. If we cannot, you may end the affected part of the service and we will refund any prepaid fees for the period after it ends; that is your only remedy for the objection.
- If a Sub-processor must be replaced urgently (for example for security or because it stops its service), we may do so straight away and will notify you as soon as possible.
- We impose data protection obligations on each Sub-processor that are no less protective than this DPA (to the extent applicable to its service), and we remain responsible for its performance as Data Protection Law requires.
- Services you choose are not our Sub-processors. When you connect WhatsApp (Meta), an email provider or any other Third-Party Service, data flows between that service and Teamline at your direction, under your own agreement with that provider. Those providers process data as independent parties, not on our behalf, and we are not responsible for them.
7. Helping you
- Requests from people. Teamline lets you find, export, correct and delete data. If we receive a request from a data subject about Customer Data, we will pass it to you (without answering it ourselves, unless you ask) where we can identify you. Where you cannot answer using the service, we will give reasonable help; we may charge for substantial effort.
- Assessments and regulators. We will give reasonable help with data protection impact assessments and consultations with regulators, as far as they relate to our processing and taking into account the information available to us.
8. Personal data breaches
- We will notify you without undue delay, and in any event within 48 hours, after we become aware of a personal data breach affecting Customer Data.
- We will tell you what we know (the nature of the breach, the data and people likely affected, likely consequences, and what we are doing), add details as we learn them, and take reasonable steps to contain it and reduce harm.
- You are responsible for deciding whether to notify regulators and data subjects, and for doing so, unless the law places that duty on us. Our notice is not an admission of fault.
9. Deletion at the end
During the contract you can delete Customer Data in Teamline at any time. When the contract ends, you may ask for an export within 30 days. After that we delete Customer Data within 30 days, unless the law requires us to keep some of it (in which case we keep it protected and only for that purpose). Backup copies, if any, are deleted on their normal schedule. On request we will confirm deletion in writing.
10. Information and audits
- We will make available the information reasonably needed to show compliance with this DPA, including this DPA's annexes and written answers to reasonable security questionnaires (up to once a year).
- If that is not enough to meet a legal requirement, or a regulator requires it, you (or an independent auditor bound by confidentiality who is not our competitor) may audit our compliance once a year, with at least 30 days' written notice, during business hours, without disrupting our operations or accessing other customers' data, and at your cost. Our Sub-processors' own certifications and audit reports may be used for their part.
11. Transfers outside your country
- You authorise us and our Sub-processors to process Personal Data in the locations listed in Annex 3, including outside the country where you or the data subjects are.
- Where a Data Protection Law restricts transfers abroad, we rely on a lawful transfer ground under that law and, if needed, will sign the additional clauses it requires.
12. Requests from authorities
If a public authority asks us for Customer Data, we will redirect it to you where possible, notify you unless the law forbids it, challenge requests we reasonably consider unlawful, and disclose no more than the minimum legally required.
13. California (CCPA)
Where the CCPA applies, we act as your “service provider”. We will not sell or share Personal Data; retain, use or disclose it for any purpose other than the business purposes in the Terms and this DPA, or outside our direct business relationship with you; or combine it with personal information we receive from others, except as the CCPA permits. We will comply with the CCPA's applicable obligations, provide the same level of protection it requires, let you take reasonable steps to stop and remedy unauthorised use, and tell you if we can no longer meet our obligations. We certify that we understand these restrictions.
14. Liability and duration
- Each party's liability under or in connection with this DPA is subject to the limitations and exclusions in the Terms, to the extent Data Protection Law allows. Nothing limits rights that data subjects have under Data Protection Law.
- This DPA lasts for as long as we process Personal Data in Customer Data. If it conflicts with the Terms, this DPA prevails on data protection matters.
Annex 1: Details of the processing
| Parties | Controller: the Customer (contact: the account owner). Processor: Andybot, Dubai, United Arab Emirates (contact: info@andybot.net). |
|---|---|
| Subject matter and duration | Providing Teamline under the Terms, for the duration of the contract and the deletion period after it. |
| Nature and purpose | Hosting and storing Customer Data; syncing and sending WhatsApp messages through the numbers the Customer links; reading, storing and sending email through mailboxes the Customer connects; running campaigns, broadcasts and lead management the Customer sets up; AI features the Customer uses (automatic replies, writing help, translation, summaries); notifications; support; security and abuse prevention. |
| Data subjects | The Customer's contacts, customers, leads and prospects; people who message the Customer's linked WhatsApp numbers or are in its WhatsApp chats and groups (including, if the Customer links a number used personally, that number's personal contacts); people the Customer emails or receives email from; the Customer's Users. |
| Categories of data | Names, phone numbers, WhatsApp profile names and photos, email addresses, message content (text, photos, videos, voice messages, documents, stickers, locations, contacts shared), call notices, group membership, email content and attachments, lead details, notes, labels and tags, campaign history, AI conversation content and settings, translation text. |
| Special categories | None intended. Message content may contain special-category or sensitive data if the Customer or its contacts include it; the Customer is responsible for having a lawful basis for that. Measures in Annex 2 apply. |
| Frequency | Continuous. |
| Retention | As decided by the Customer during the contract; deletion after the contract as in section 9. |
| Sub-processors | As listed in Annex 3, for the services described there. |
Annex 2: Security measures
- Separation of customers. Each company's data is stored under its own space. Database and file-storage security rules check, on every read and write, the company and the role of the signed-in user. Cross-company access is tested, including with attack simulations.
- Access control. Sign-in through Firebase Authentication with hashed passwords; role- and permission-based access set by the account owner; access removed immediately when the owner removes a User; administrative actions limited to designated staff accounts.
- Encryption. All traffic is encrypted in transit (HTTPS/TLS, with HSTS). Data is encrypted at rest by Google Cloud.
- Secrets. Service keys are kept in Google Secret Manager. Mailbox app passwords are kept in a separate store that no dashboard user can read and are never sent back to the browser. WhatsApp session keys are kept in a store only the connection server uses.
- Connection server. The WhatsApp connection runs on a dedicated server with no public IP address and its own restricted service account; its software updates are checked by fingerprint and digital signature before installation.
- Application security. Strict Content Security Policy and other browser security headers; input validation and output escaping; protections against malicious content in messages and emails; dependency updates; internal security testing, including attack simulations against the access rules and APIs.
- Abuse prevention. Rate limits on sign-up and other costly or sensitive operations (sign-in attempts are throttled by Firebase Authentication); daily limits on new contacts per WhatsApp number; AI usage caps per company.
- Resilience. Managed Google Cloud services that store data redundantly across zones; automatic restart of the connection server.
- Logging and monitoring. Server logs kept for about 30 days to investigate errors and incidents.
- People. Access to production systems limited to authorised staff under confidentiality obligations, on a need-to-know basis.
- Incidents. A process to contain, investigate and notify personal data breaches (section 8).
- Deletion. Tools to delete records with their files, and to erase a company's data at the end of the contract.
Annex 3: Sub-processors
See the current list on our sub-processor page, which forms part of this Annex.
Teamline