Data Processing Addendum

Version 2026-09-21 · Part of the Terms of Service

This Data Processing Addendum (the "DPA") forms part of the agreement between anfigo LLC ("Anfigo", the "Processor") and the Customer (the "Customer", the "Controller") under the Terms of Service. It applies whenever Anfigo processes personal data on the Customer's behalf. It is accepted together with the Terms; no separate signature is needed. A Customer that wants a countersigned copy can ask at legal@anfigo.com.

1. Definitions

"Data Protection Laws" means every law on personal data that applies to the processing, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws. "Customer Personal Data" means the personal data Anfigo processes on the Customer's behalf to provide the Service, described in Annex I. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings in the GDPR, or the nearest equivalent in the applicable law. Other capitalised words have the meaning in the Terms.

2. Roles and instructions

2.1 The Customer is the controller and Anfigo is the processor of Customer Personal Data. Where the Customer acts as processor for another controller, Anfigo is its sub-processor and the Customer passes on to that controller what this DPA requires.

2.2 Anfigo processes Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, the Customer's settings in the Service and its written requests, unless a law requires otherwise (in which case Anfigo informs the Customer first, unless the law forbids it). Anfigo tells the Customer if, in its opinion, an instruction breaches Data Protection Laws.

2.3 Anfigo does not sell Customer Personal Data, does not share it for cross-context behavioural advertising, does not use it to train AI models, and does not use it for any purpose of its own other than those the Terms allow (providing, supporting and securing the Service, including finding and fixing errors). Data Anfigo receives from Meta's platforms is processed only for the Customer that connected them, and disclosed only to the Customer and to the sub-processors in Annex III.

2.4 The Customer is responsible for the lawfulness of its instructions and of the processing it asks for, including having a legal basis and the notices and permissions its guests need (Terms §6.3).

2.5 PMS data. Where a PMS provider's terms make Anfigo responsible for data read through its API, Anfigo also complies with those terms (including their security and deletion rules). As between the Customer and Anfigo, that data is Customer Personal Data and is used only to provide the Service to the Customer.

3. People

Anfigo ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality and has access only as far as their work needs.

4. Security

Anfigo implements and maintains the technical and organisational measures in Annex II, appropriate to the risk. Anfigo may update them as long as the overall level of protection does not decrease.

5. Sub-processors

5.1 The Customer gives Anfigo general authorisation to engage sub-processors. The current list is in Annex III.

5.2 Anfigo gives the Customer at least 30 days' notice (by e-mail to the account address, and by updating Annex III) before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for it. In an emergency (for example to keep the Service running when a provider fails) the notice may be shorter, with the reason given.

5.3 Anfigo binds each sub-processor by a written contract with data-protection obligations no less protective than this DPA, and remains responsible to the Customer for its sub-processors' performance, subject to the Terms.

5.4 Platforms the Customer chooses to connect under its own account — its messaging channels, its PMS, its payment provider — process data under their own terms with the Customer; Anfigo sends data to them on the Customer's instructions.

6. Helping the Customer

6.1 Data subject requests. Taking into account the nature of the processing, Anfigo helps the Customer answer requests from data subjects to exercise their rights. If a data subject writes to Anfigo directly about Customer Personal Data, Anfigo tells the Customer and, where the Customer agrees or the law requires, acts on it (for example deletion under our data deletion process).

6.2 Assessments. Anfigo gives the Customer the information it reasonably needs for data-protection impact assessments and prior consultations with authorities about the Service.

7. Personal data breaches

Anfigo notifies the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes, as far as known, the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. Anfigo takes reasonable steps to contain the breach and gives updates as it learns more. Notifying is not an admission of fault.

8. Deletion and return

When the Service ends, Anfigo makes Customer Personal Data available for export for 30 days (Terms §13.1), then deletes it from its live systems within 30 days. Data read from the Customer's PMS is deleted within 10 days of the end. Backup copies are never restored into the Service and expire on their fixed schedule, at most 12 weeks after they were made; until then they stay protected under this DPA. Anfigo may keep data a law requires it to keep, only for that purpose and period. On request, Anfigo confirms the deletion in writing.

9. Information and audits

Anfigo makes available to the Customer the information necessary to demonstrate compliance with this DPA: this document, the Security page and written answers to a reasonable security questionnaire, once a year or after a personal data breach. Where Data Protection Laws require more and that information is not enough, the Customer (or an independent auditor bound by confidentiality) may carry out an audit on 30 days' notice, during business hours, at the Customer's cost, without access to other customers' data, and at most once in any 12 months.

10. International transfers

10.1 Customer Personal Data is stored in the United States. Anfigo may process it in the countries of the sub-processors in Annex III.

10.2 Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module Two (controller to processor), or Module Three where the Customer is itself a processor, which are incorporated by reference, with: clause 7 (docking) included; clause 9 option 2 (general authorisation, with the notice in §5.2); the optional wording in clause 11 omitted; clause 17 option 1, the law of Ireland; clause 18, the courts of Ireland; Annexes I to III of the SCCs completed by Annexes I to III of this DPA.

10.3 For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner applies, with the tables completed from this DPA. For transfers subject to Swiss law, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority and references to the GDPR read as references to Swiss law.

10.4 If the SCCs conflict with this DPA or the Terms, the SCCs prevail for the transfers they cover.

11. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Terms (§18), except where a law or the SCCs do not allow it. For data protection, this DPA prevails over the Terms. It lasts as long as Anfigo processes Customer Personal Data.

Annex I — Details of the processing

  • Subject matter and purpose: providing the Service — answering the Customer's guests on its behalf across its messaging channels, reading and writing its PMS and payment accounts within the rules it sets, handing chats to its team, and showing its team the inbox, guest profiles, bookings and reports.
  • Nature: collection, storage, retrieval, analysis by AI (including transcription of voice notes and description of images), transmission, and deletion.
  • Duration: the term of the agreement, plus the periods in §8.
  • Data subjects: the Customer's guests and prospective guests who message it; guests in its PMS; the Customer's team members.
  • Categories of data: identifiers (phone number, messaging-platform user IDs, name, profile picture), contact details (e-mail, country), message content and attachments (text, photos, documents, voice notes and their transcripts or descriptions), booking details (dates, room, guests, amounts, payment status), language, and notes by the Customer's team.
  • Special categories: none intended. Guests may volunteer such data in a message (for example about health or accessibility); the Customer's Acceptable Use obligations limit collection to what a stay needs.
  • Frequency: continuous.
  • Controller / data exporter: the Customer, contact at its account e-mail. Processor / data importer: anfigo LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA, privacy@anfigo.com.

Annex II — Technical and organisational measures

  • Encryption in transit (TLS) for every connection; encryption at rest by the cloud provider for the database, file storage and backups.
  • Per-property separation: every record is stored under its property, and every dashboard request is authorised for that property only.
  • Authentication: passwords and PINs stored only as salted one-way hashes; Google sign-in; signed session tokens; limits on wrong sign-in and PIN attempts; an optional manager / front-desk split with a manager PIN.
  • Credentials are never shown back in the dashboard; the service's own secrets are held in a secret manager.
  • Webhooks are authenticated (platform signatures, per-property tokens, shared secrets) and each delivery is processed once.
  • Access to production is limited to the people who operate the service.
  • Monitoring and alerting for errors, failed deliveries, rejected webhooks and uptime.
  • Resilience: point-in-time recovery (7 days) and daily and weekly backups, all expiring within 12 weeks; restore procedures are tested.
  • AI: only paid AI services that do not use the data to train models; the AI acts only within the property's rules and hands chats to people.
  • Data minimisation and deletion: short-lived traces (30 days), deletion on request and at the end of the Service as in §8.
  • Incident response: breach notification within 72 hours (§7).

Annex III — Sub-processors

Sub-processorWhat it doesLocation
Google LLC (Google Cloud, Firebase)Hosting, database, file storage, backups, task scheduling, sign-in, dashboard analyticsUnited States
Google LLC (Gemini API, paid)AI replies, voice-note transcription, image descriptionUnited States and other Google locations
WADA B.V. (Dualhook)Connects the Customer's WhatsApp number (coexistence)Netherlands / EU
ManyChat, Inc.Connects the Customer's WhatsApp number, for some accountsUnited States
E-mail providers for @anfigo.comAccount and support e-mailUnited States

Platforms the Customer connects under its own account (Meta — WhatsApp, Messenger, Instagram; Telegram; its PMS, such as Cloudbeds; its payment provider, such as Recurrente) process data under their own terms with the Customer (§5.4).