Wesend Data Processing Addendum (DPA)
Last Updated: July 2026
Contents
- Scope and precedence
- Roles of the parties
- Customer instructions
- Confidentiality and personnel
- Subprocessors
- Security measures
- Security incidents and breach notification
- Assistance
- International transfers
- Return and deletion
- Audit information
- Annex 1 – Details of processing
- Annex 2 – Baseline security measures
- Annex 3 – International Transfers
1. Scope and precedence
This DPA forms part of the agreement between Wesend and the customer for the Service where Wesend processes Customer Personal Data on the customer’s behalf.
If there is a conflict between this DPA and the main commercial terms in relation to data protection, this DPA controls to the extent of that conflict.
2. Roles of the parties
For Customer Personal Data processed through the Service on behalf of the customer, the customer acts as controller or business and Wesend acts as processor or service provider. Customer remains responsible for the lawfulness of collection, transparency, lawful basis, instructions and the rights and relationships with its end users or contacts.
3. Customer instructions
Wesend will process Customer Personal Data only on documented instructions from the customer, including instructions in the agreement, in-product settings, support requests and authorised administrator actions, unless otherwise required by law.
Wesend will inform the customer if, in its opinion, an instruction infringes applicable data protection law, unless prohibited by law.
4. Confidentiality and personnel
Wesend will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
5. Subprocessors
Customer authorises Wesend to use trusted third-party Subprocessors (such as cloud infrastructure and AI service providers like OpenAI) to provide the Service. Wesend will impose data protection obligations on Subprocessors that are substantially similar to the obligations in this DPA and remain responsible for the performance of those obligations to the extent required by law.
Wesend will publish or otherwise make available notice of new Subprocessors before they begin processing Customer Personal Data, with a target notice period of at least 10 calendar days where practicable.
6. Security measures
Wesend will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. A current summary of baseline security measures appears in Annex 2.
7. Security incidents and breach notification
If Wesend becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, Wesend will notify the customer without undue delay and provide available information reasonably necessary for the customer to meet any legal notification obligations.
Wesend may provide information in phases as it becomes available and will take reasonable steps to mitigate and remediate the incident.
8. Assistance
Taking into account the nature of the processing and information available to Wesend, Wesend will provide reasonable assistance with data subject requests, DPIAs, prior consultation requests and compliance inquiries to the extent required by applicable law and proportionate to the Service.
9. International transfers
Where Customer Personal Data is transferred internationally in a manner that requires a transfer mechanism, the parties will rely on an adequacy decision, standard contractual clauses, the UK addendum or another lawful mechanism as set out in Annex 3.
10. Return and deletion
Upon termination or expiry of the Service, Wesend will delete or return Customer Personal Data in accordance with the agreement, the customer’s documented instructions and applicable law, unless retention is required by law or necessary for security, dispute or backup purposes for a limited period.
11. Audit information
On reasonable written request, Wesend will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, questionnaires, third-party audit reports or certifications where available.
If additional audits are required by law and cannot reasonably be satisfied by existing materials, the parties will agree a proportionate process that protects the security and confidentiality of other customers and Wesend systems.
Annex 1 – Details of processing
| Field | Description |
|---|---|
| Subject matter | Provision of the Wesend chat automation, inbox, integration, AI features, and support service. |
| Duration | For the term of the agreement plus limited retention / backup periods. |
| Nature of processing | Hosting, storage, transmission, organisation, retrieval, AI-assisted generation of responses, analysis, support, security, deletion and other operations needed to provide the Service. |
| Categories of data subjects | Customer administrators, team members, leads, prospects, subscribers, end users and support contacts. |
| Categories of personal data | Names, contact details, account IDs, message content, Meta Platform Data (e.g., Instagram Direct Messages, comments, and public profile info), message metadata, automation settings, device/IP data, and billing data. |
| AI & Platform Data Restriction | Platform Data received from Meta Products and APIs is processed solely to provide the Service requested by the Customer and is not used to train or improve Wesend's own AI models or those of third parties. |
Annex 2 – Baseline security measures
| Control area | Security measure |
|---|---|
| Access control | Role-based access, password policy, MFA for admin accounts where supported, least-privilege approach. |
| Encryption | Encryption in transit (TLS/HTTPS) and, where appropriate, encryption at rest for sensitive data. |
| Logging and monitoring | System logging, error tracking, security monitoring and incident response workflows. |
| Business continuity | Backups, change management and disaster recovery processes appropriate to service scale. |
| Vendor management | Review and contractual controls for relevant Subprocessors. |
Annex 3 – International Transfers
Where the processing of Customer Personal Data by Wesend involves a transfer outside the United Kingdom or the European Economic Area (EEA) to a jurisdiction that is not recognized as providing an adequate level of protection, the parties will rely on an appropriate transfer mechanism as required by applicable data protection laws.
Depending on the circumstances of the transfer, such mechanisms may include:
| Region / route | Transfer mechanism |
|---|---|
| UK outbound transfers | The UK International Data Transfer Addendum (UK Addendum) to the EU Standard Contractual Clauses (SCCs), or another valid transfer mechanism recognized under UK data protection law. |
| EEA outbound transfers | The Standard Contractual Clauses (SCCs) adopted by the European Commission, or another valid transfer mechanism recognized under applicable EU data protection law. |