Data Processing Agreement
Last updated: 2026-07-21
⚠️ This policy is currently being drafted and reviewed by legal counsel. It will be published here once approved. For questions, contact legal@shinygt360.com.
1Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between [Shiny Global Technologies] (“Processor,” “Shiny GT 360”) and the customer (“Controller”) for the processing of Personal Data through the Shiny GT 360 platform. [Important: a DPA is a contract, not marketing copy — this draft gives you the standard structure, but the specific sub-processor list, security certifications, and international transfer mechanism need to be accurate to your actual infrastructure. Do not publish claims about certifications (SOC 2, ISO 27001, etc.) unless you genuinely hold them.]
21. Definitions
Terms like “Personal Data,” “Processing,” “Data Subject,” “Controller,” and “Processor” have the meanings given in the applicable data protection law (GDPR, UAE PDPL, or India’s DPDPA, depending on which governs your relationship with this specific customer).
32. Roles of the Parties
The Customer is the Data Controller for the personal data of their end customers/contacts uploaded to Shiny GT 360 (names, phone numbers, message content, etc.). Shiny GT 360 acts as the Data Processor, processing that data solely on the Customer’s documented instructions, to provide the Service.
43. Processing Details
• Subject matter: Provision of the Shiny GT 360 WhatsApp CRM platform • Duration: For the term of the Customer’s subscription, plus any post-termination retention described in the Privacy Policy • Nature and purpose: Chat management, broadcast delivery, contact segmentation, analytics, and related CRM functions • Categories of data subjects: The Customer’s end customers/contacts • Categories of personal data: Names, phone numbers, message content, and any custom fields the Customer configures
54. Sub-processors
Shiny GT 360 may engage sub-processors to support the Service. [supabase, railway — e.g. cloud hosting provider, Meta/WhatsApp Cloud API, OpenAI for the AI Bot, payment processor. Each of these needs its own data processing agreement with you, which then flows through to this document.] We will notify Customers of material changes to this list.
65. Security Measures
Shiny GT 360 implements technical and organizational measures appropriate to the risk, including [insert your actual measures — encryption in transit/at rest, access controls, employee confidentiality agreements — don’t list measures you haven’t implemented].
76. Data Subject Requests
Shiny GT 360 will assist the Customer in responding to data subject requests (access, deletion, portability) to the extent the Customer cannot fulfill them directly through the platform’s own tools.
87. International Transfers
[If you host data outside the customer’s region, this section needs a real transfer mechanism — Standard Contractual Clauses for GDPR, or the UAE PDPL’s equivalent adequacy/consent requirements. This is not optional boilerplate; get legal input specific to your hosting setup.]
98. Data Breach Notification
Shiny GT 360 will notify the Customer without undue delay upon becoming aware of a personal data breach affecting the Customer’s data, providing available details to support the Customer’s own regulatory notification obligations.
109. Deletion or Return of Data
Upon termination of the Customer’s subscription, Shiny GT 360 will delete or return the Customer’s data within [insert your actual retention/deletion timeline], except where retention is required by law.
1110. Audit Rights
[Enterprise customers often expect an audit clause. Insert your actual policy — e.g. “Shiny GT 360 will provide audit reports/documentation on reasonable request, up to once per year” — rather than promising unlimited audit access you’re not set up to support.]
12Contact Us
For DPA execution or data protection inquiries: info@shinygt360.com
Questions about this policy?
Contact us →