This data processing agreement (“Data Processing Agreement”) forms an integral part of the agreement between KobiTech B.V. and the Customer for the use of KobiChat. It governs the processing of personal data that the Customer has processed on its behalf through KobiChat, in accordance with Article 28 GDPR. In the event of any conflict with the general terms and conditions, this Data Processing Agreement takes precedence with regard to data protection.
Processor: KobiTech B.V., Klompenmakerstraat 24, 4871 EM Etten-Leur, Chamber of Commerce (KvK) 42005593 (“we”).
Controller: the Customer that subscribes to KobiChat and connects a WhatsApp Business account (“the Customer”).
1. Roles and subject matter
1.1 The Customer is the controller of the personal data it processes through KobiChat (in particular WhatsApp conversations, contact details and messages of its own customers). KobiTech is the processor of that data and processes it solely on behalf of the Customer.
1.2 For the Customer’s own account, billing and usage data, KobiTech is itself the controller; our privacy policy applies to that data.
2. Instructions
2.1 We process the personal data solely on the basis of the Customer’s documented instructions, including normal use of the service as described in the agreement and documentation, unless a legal obligation requires us to do otherwise (in which case we will notify the Customer in advance, unless the law prohibits this).
2.2 We will inform the Customer if, in our opinion, an instruction infringes the GDPR or other data protection rules.
3. Nature, purpose and duration
3.1 Nature and purpose: the provision of a team inbox for business WhatsApp communication (sending/receiving messages, managing contacts and conversations, and - where activated by the Customer - AI pre-qualification, broadcasts, calendar and CRM integrations). The processing details are set out in Annex A.
3.2 Duration: this Data Processing Agreement applies for as long as we process personal data for the Customer, and therefore for the duration of the agreement.
4. Confidentiality
Persons who have access to the personal data on our behalf are bound by a duty of confidentiality. KobiTech platform administrators have no access to the content of customers’ conversations in the course of ordinary administration.
5. Security
We take appropriate technical and organisational measures in accordance with Article 32 GDPR to secure the personal data. These measures are set out in Annex B. We evaluate and update them periodically.
6. Sub-processors
6.1 The Customer grants general authorisation for the engagement of sub-processors. The current list is set out in Annex C and in our privacy policy.
6.2 We impose on each sub-processor at least the same obligations as those in this Data Processing Agreement. In the event of an intended change (a new or replacement sub-processor), we will inform the Customer in advance; the Customer may object, stating reasons, within 14 days, after which the parties will seek a solution through reasonable consultation.
7. Assistance to the Customer
7.1 Data subject rights: we provide the Customer with reasonable assistance with requests from data subjects (access, rectification, erasure, restriction, portability, objection). If we receive such a request directly, we refer the data subject to the Customer.
7.2 DPIA and consultation: we provide reasonable assistance with a data protection impact assessment (DPIA) and with prior consultation of the supervisory authority, insofar as this relates to our processing.
8. Data breaches
We will inform the Customer without undue delay - and where feasible within 48 hours - after becoming aware of a personal data breach affecting the Customer’s data, providing the information referred to in Article 33 GDPR insofar as it is known to us. The Customer remains responsible for any notification to the supervisory authority and/or data subjects.
9. Return and deletion
After termination of the agreement, we will, at the Customer’s choice, delete the personal data or return it (export), and erase existing copies within a reasonable period, unless statutory retention obligations (e.g. the tax retention obligation for billing data) require longer retention. In addition, the Customer can export conversations and contacts itself, or have them deleted, at any time.
10. Audits
We make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allow audits to be carried out. Audits take place no more than once a year, following reasonable notice, during office hours and without unnecessarily disrupting business operations; the Customer bears its own costs of such audits.
11. Transfers outside the EEA
Processing takes place within the European Economic Area, except where a sub-processor (see Annex C) processes data outside the EEA. In that case, we base the transfer on an appropriate mechanism, such as the EU Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework.
Annex A - Processing details
| Subject matter | The provision of the KobiChat team inbox for business WhatsApp communication. |
|---|---|
| Nature of the processing | Collecting, storing, consulting, sending/receiving, structuring and - on request - erasing messages and contact details. |
| Purpose | Customer communication via WhatsApp, lead pre-qualification (AI, optional), broadcasts, calendar and CRM integration (optional). |
| Categories of data subjects | The Customer’s (end) customers and contacts who communicate with the Customer via WhatsApp; the Customer’s employees. |
| Types of personal data | Name, phone number, message content, any media/attachments, attributes and notes recorded by the Customer, email address (if provided). |
| Special categories | Not intended. The Customer must prevent special categories of personal data from being processed unnecessarily via WhatsApp. |
| Duration | For the duration of the agreement; thereafter in accordance with clause 9. |
Annex B - Security measures
- Encrypted connections (TLS/HTTPS) for all data traffic.
- Passwords stored as a strong hash (bcrypt); optional two-factor authentication (TOTP).
- Logical separation between customer environments (multi-tenant isolation on every data path).
- Signed/verified webhooks (HMAC) for incoming WhatsApp traffic.
- Role-based access within an environment (owner/administrator/team member/read-only).
- Hosting within the EU (Microsoft Azure, West Europe); daily backups.
- Limited, traceable access; platform administration without access to conversation content during regular administration.
- Procedures for detecting, handling and reporting data breaches.
Annex C - Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Meta Platforms Ireland Ltd. | WhatsApp Business Platform | EU/US (SCC/DPF) |
| Microsoft Azure | Hosting and database | EU (West Europe) |
| Mollie B.V. | Payment processing | EU (Netherlands) |
| Apple Inc. | Push notifications (APNs) | US (DPF) |
| Anthropic / OpenAI (optional) | AI replies (customer’s own key) | US (SCC/DPF) |
| Google Ireland Ltd. (optional) | Calendar integration | EU/US (DPF) |
| Teamleader NV (optional) | CRM connection | EU (Belgium) |
| Email provider (SMTP) | System/reminder emails | EU |