This Data Processing Addendum (the "DPA") forms part of the agreement between anfigo LLC ("Anfigo", the "Processor") and the Customer (the "Customer", the "Controller") under the Terms of Service. It applies whenever Anfigo processes personal data on the Customer's behalf. It is accepted together with the Terms; no separate signature is needed. A Customer that wants a countersigned copy can ask at legal@anfigo.com.
"Data Protection Laws" means every law on personal data that applies to the processing, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws. "Customer Personal Data" means the personal data Anfigo processes on the Customer's behalf to provide the Service, described in Annex I. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings in the GDPR, or the nearest equivalent in the applicable law. Other capitalised words have the meaning in the Terms.
2.1 The Customer is the controller and Anfigo is the processor of Customer Personal Data. Where the Customer acts as processor for another controller, Anfigo is its sub-processor and the Customer passes on to that controller what this DPA requires.
2.2 Anfigo processes Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, the Customer's settings in the Service and its written requests, unless a law requires otherwise (in which case Anfigo informs the Customer first, unless the law forbids it). Anfigo tells the Customer if, in its opinion, an instruction breaches Data Protection Laws.
2.3 Anfigo does not sell Customer Personal Data, does not share it for cross-context behavioural advertising, does not use it to train AI models, and does not use it for any purpose of its own other than those the Terms allow (providing, supporting and securing the Service, including finding and fixing errors). Data Anfigo receives from Meta's platforms is processed only for the Customer that connected them, and disclosed only to the Customer and to the sub-processors in Annex III.
2.4 The Customer is responsible for the lawfulness of its instructions and of the processing it asks for, including having a legal basis and the notices and permissions its guests need (Terms §6.3).
2.5 PMS data. Where a PMS provider's terms make Anfigo responsible for data read through its API, Anfigo also complies with those terms (including their security and deletion rules). As between the Customer and Anfigo, that data is Customer Personal Data and is used only to provide the Service to the Customer.
Anfigo ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality and has access only as far as their work needs.
Anfigo implements and maintains the technical and organisational measures in Annex II, appropriate to the risk. Anfigo may update them as long as the overall level of protection does not decrease.
5.1 The Customer gives Anfigo general authorisation to engage sub-processors. The current list is in Annex III.
5.2 Anfigo gives the Customer at least 30 days' notice (by e-mail to the account address, and by updating Annex III) before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for it. In an emergency (for example to keep the Service running when a provider fails) the notice may be shorter, with the reason given.
5.3 Anfigo binds each sub-processor by a written contract with data-protection obligations no less protective than this DPA, and remains responsible to the Customer for its sub-processors' performance, subject to the Terms.
5.4 Platforms the Customer chooses to connect under its own account — its messaging channels, its PMS, its payment provider — process data under their own terms with the Customer; Anfigo sends data to them on the Customer's instructions.
6.1 Data subject requests. Taking into account the nature of the processing, Anfigo helps the Customer answer requests from data subjects to exercise their rights. If a data subject writes to Anfigo directly about Customer Personal Data, Anfigo tells the Customer and, where the Customer agrees or the law requires, acts on it (for example deletion under our data deletion process).
6.2 Assessments. Anfigo gives the Customer the information it reasonably needs for data-protection impact assessments and prior consultations with authorities about the Service.
Anfigo notifies the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes, as far as known, the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. Anfigo takes reasonable steps to contain the breach and gives updates as it learns more. Notifying is not an admission of fault.
When the Service ends, Anfigo makes Customer Personal Data available for export for 30 days (Terms §13.1), then deletes it from its live systems within 30 days. Data read from the Customer's PMS is deleted within 10 days of the end. Backup copies are never restored into the Service and expire on their fixed schedule, at most 12 weeks after they were made; until then they stay protected under this DPA. Anfigo may keep data a law requires it to keep, only for that purpose and period. On request, Anfigo confirms the deletion in writing.
Anfigo makes available to the Customer the information necessary to demonstrate compliance with this DPA: this document, the Security page and written answers to a reasonable security questionnaire, once a year or after a personal data breach. Where Data Protection Laws require more and that information is not enough, the Customer (or an independent auditor bound by confidentiality) may carry out an audit on 30 days' notice, during business hours, at the Customer's cost, without access to other customers' data, and at most once in any 12 months.
10.1 Customer Personal Data is stored in the United States. Anfigo may process it in the countries of the sub-processors in Annex III.
10.2 Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module Two (controller to processor), or Module Three where the Customer is itself a processor, which are incorporated by reference, with: clause 7 (docking) included; clause 9 option 2 (general authorisation, with the notice in §5.2); the optional wording in clause 11 omitted; clause 17 option 1, the law of Ireland; clause 18, the courts of Ireland; Annexes I to III of the SCCs completed by Annexes I to III of this DPA.
10.3 For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner applies, with the tables completed from this DPA. For transfers subject to Swiss law, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority and references to the GDPR read as references to Swiss law.
10.4 If the SCCs conflict with this DPA or the Terms, the SCCs prevail for the transfers they cover.
Each party's liability under this DPA is subject to the limits in the Terms (§18), except where a law or the SCCs do not allow it. For data protection, this DPA prevails over the Terms. It lasts as long as Anfigo processes Customer Personal Data.
| Sub-processor | What it does | Location |
|---|---|---|
| Google LLC (Google Cloud, Firebase) | Hosting, database, file storage, backups, task scheduling, sign-in, dashboard analytics | United States |
| Google LLC (Gemini API, paid) | AI replies, voice-note transcription, image description | United States and other Google locations |
| WADA B.V. (Dualhook) | Connects the Customer's WhatsApp number (coexistence) | Netherlands / EU |
| ManyChat, Inc. | Connects the Customer's WhatsApp number, for some accounts | United States |
| E-mail providers for @anfigo.com | Account and support e-mail | United States |
Platforms the Customer connects under its own account (Meta — WhatsApp, Messenger, Instagram; Telegram; its PMS, such as Cloudbeds; its payment provider, such as Recurrente) process data under their own terms with the Customer (§5.4).