Gchat
CapabilitiesAI workspaceWorkflowChannels
DocsAsk AI
Log inStart free trial

Data Processing Agreement (DPA)

DATA PROCESSING AGREEMENT (DPA) (in accordance with Regulation (EU) 2016/679 – GDPR) This Data Processing Agreement (“DPA”) forms an integral part of the Terms of Service and/or any Master Service Agreement (“Agreement”) concluded between: GChat Technologies GmbH Boriñaur enparantza 86 07500, Balearic Islands Spain (hereinafter – the “Processor”) and The legal entity or individual using the GChatFlow Platform (hereinafter – the “Controller”). The Controller and the Processor are hereinafter referred to individually as a “Party” and collectively as the “Parties”. 1. PURPOSE AND SCOPE 1.1. This DPA governs the processing of Personal Data by the Processor on behalf of the Controller in connection with the use of the GChatFlow Platform. 1.2. The Parties agree that for the purposes of GDPR: The Controller determines the purposes and means of processing Personal Data. The Processor processes Personal Data solely on documented instructions from the Controller. 1.3. This DPA applies whenever the Processor processes Personal Data subject to Regulation (EU) 2016/679 (GDPR). 2. DEFINITIONS For purposes of this DPA: Personal Data – any information relating to an identified or identifiable natural person. Processing – any operation performed on Personal Data (collection, storage, use, transmission, deletion, etc.). Data Subject – an identified or identifiable natural person. Subprocessor – a third party engaged by the Processor to process Personal Data on behalf of the Controller. Supervisory Authority – an independent public authority established under GDPR. 3. SUBJECT MATTER OF PROCESSING 3.1. Nature and Purpose of Processing: Provision of messaging automation, customer communication management, API integrations, analytics, storage and related SaaS functionality. 3.2. Duration of Processing: Processing shall continue for the duration of the Agreement and until deletion or return of Personal Data in accordance with Section 10 of this DPA. 3.3. Categories of Data Subjects may include: Customers of the Controller Prospects and leads Employees and contractors of the Controller Website visitors Messaging platform users 3.4. Categories of Personal Data may include: Names Email addresses Phone numbers Messaging identifiers IP addresses Communication content Metadata related to messages Technical and usage data The exact categories depend on how the Controller uses the Platform. 4. PROCESSOR OBLIGATIONS The Processor shall: 4.1. Process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries. 4.2. Ensure that persons authorized to process Personal Data are bound by confidentiality obligations. 4.3. Implement appropriate technical and organizational measures (TOMs) in accordance with Article 32 GDPR, including: Encryption in transit (TLS/HTTPS) Access control and role-based permissions Two-factor authentication Logging and monitoring Secure hosting infrastructure Regular security updates 4.4. Assist the Controller in responding to Data Subject requests under Articles 15–22 GDPR. 4.5. Assist the Controller in ensuring compliance with obligations under Articles 32–36 GDPR (security, breach notification, DPIA, prior consultation). 4.6. Notify the Controller without undue delay after becoming aware of a Personal Data breach. 5. CONTROLLER OBLIGATIONS The Controller shall: 5.1. Ensure that it has a valid legal basis for processing Personal Data. 5.2. Provide legally required notices to Data Subjects. 5.3. Ensure that instructions to the Processor comply with GDPR. 5.4. Not use the Platform for unlawful processing activities. 5.5. Remain solely responsible for the legality of collected communication data and messaging campaigns. 6. SUBPROCESSORS 6.1. The Controller authorizes the Processor to engage Subprocessors necessary for service provision. 6.2. The Processor shall ensure that Subprocessors are bound by data protection obligations equivalent to those in this DPA. 6.3. The Processor remains fully liable for Subprocessors’ performance of their obligations. 6.4. A current list of Subprocessors shall be made available upon request. 7. INTERNATIONAL DATA TRANSFERS 7.1. Personal Data may be processed within the European Union. 7.2. If Personal Data is transferred outside the EEA, the Processor shall ensure appropriate safeguards, including: European Commission Standard Contractual Clauses (SCCs) Adequacy decisions Other lawful transfer mechanisms under GDPR 8. DATA SUBJECT RIGHTS 8.1. The Processor shall assist the Controller, taking into account the nature of processing, in responding to requests for: Access Rectification Erasure Restriction Data portability Objection 8.2. The Processor shall not respond directly to Data Subject requests unless legally required. 9. PERSONAL DATA BREACH 9.1. In the event of a Personal Data breach, the Processor shall: Notify the Controller without undue delay Provide information necessary to meet reporting obligations Take reasonable steps to mitigate the breach 9.2. The Controller is responsible for notifying Supervisory Authorities and Data Subjects where required. 10. RETURN AND DELETION OF DATA 10.1. Upon termination of the Agreement, the Processor shall, at the Controller’s choice: Return Personal Data; or Securely delete Personal Data unless EU or Member State law requires retention. 10.2. Backup retention may continue for a limited period in accordance with security policies. 11. AUDIT RIGHTS 11.1. The Processor shall make available information necessary to demonstrate compliance. 11.2. Audits shall be: Reasonable in scope Conducted during normal business hours Subject to confidentiality At Controller’s expense Third-party certifications may satisfy audit requirements. 12. LIABILITY 12.1. Each Party shall be liable in accordance with GDPR and the underlying Agreement. 12.2. Liability limitations in the main Agreement apply unless prohibited by law. 13. GOVERNING LAW 13.1. This DPA is governed by the laws of Spain and applicable European Union legislation. 13.2. Disputes shall be resolved in competent courts of Spain unless otherwise agreed. 14. ORDER OF PRECEDENCE In case of conflict between this DPA and the main Agreement, this DPA shall prevail regarding data protection matters. 15. CONTACT For data protection matters: GChat Technologies GmbH Boriñaur enparantza 86 07500, Balearic Islands Spain Email: [email protected] Website: https://gchatflow.com/
Gchat

One operating view for Facebook Messenger and Telegram conversations, ownership, customer context, automation, and reporting.

Product

  • Capabilities
  • AI workspace
  • Workflow
  • Channels
  • FAQ

Resources

  • Documentation
  • Ask AI

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA

Company

[email protected]

GIBBI, LLC, Burlingame, CA, United States

Copyright 2026 Gchat. All rights reserved.

GDPR compliant. Security-first.