Back to WaAutoflow
Legal · Compliance

GDPR Compliance

WaAutoflow's commitment to the General Data Protection Regulation (EU) 2016/679 and UK GDPR.

Regulation: GDPR (EU) 2016/679·Last Updated: January 2026

Overview

The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union (EU) and European Economic Area (EEA). The UK GDPR applies similar requirements in Great Britain following Brexit.

WaAutoflow is committed to full compliance with GDPR and UK GDPR in all aspects of our operations. This page explains how GDPR applies to WaAutoflow, the roles we play in data processing, and how you can exercise your rights.

🔐

Data Minimisation

We only collect data strictly necessary for app functionality

📋

Lawful Basis

Every processing activity has a documented legal basis under GDPR

Rights Response

All data subject requests acknowledged within 30 days

Our Role in Data Processing

Data ControllerMerchant

You (the Merchant) are the Data Controller for your customers' personal data. You determine the purposes and means of processing customer data through WaAutoflow.

As Controller, you are responsible for ensuring you have a lawful basis for processing, obtaining necessary consents, and providing customers with privacy information.

Data ProcessorWaAutoflow

WaAutoflow acts as a Data Processor when processing your customers' data on your behalf to deliver the automation services.

As Processor, WaAutoflow processes data only on your documented instructions, maintains appropriate security measures, and assists you in fulfilling data subject rights.

Data Processing Agreement (DPA): GDPR Article 28 requires a written contract between controllers and processors. By using WaAutoflow, you enter into a Data Processing Agreement with us. The full DPA terms are incorporated into our Terms of Service. If you require a standalone signed DPA document, contact us at hello.waflows@gmail.com.

Data We Process

The following categories of personal data are processed by WaAutoflow:

CategoryExamplesPurposeRetention
Merchant Account DataStore name, URL, owner name, email address, phone number, app configuration settingsAccount management, service provision, supportDuration of app installation + 30 days post-uninstall
Customer Order DataCustomer name, phone number, order ID, order items, amounts, shipping address, order statusSending WhatsApp automation messages configured by the merchantUp to 12 months for operational records
WhatsApp Session DataLinked-device session tokens, connection statusMaintaining WhatsApp connection for automationRevoked immediately on disconnection or uninstall
Technical & Log DataIP address, browser type, error logs, API call logs, performance metricsSecurity, fraud prevention, service stabilityUp to 90 days
Usage AnalyticsFeature usage frequency, automation trigger counts (anonymised)Product improvement, aggregated reportingIndefinitely in anonymised/aggregated form
Support CommunicationsEmails, chat messages exchanged during customer supportResolving support requests, training, quality assuranceUp to 2 years

WaAutoflow does not process special categories of personal data (sensitive data) as defined under GDPR Article 9.

Your Rights Under GDPR

Data subjects (individuals whose data is processed) have the following rights under GDPR. Merchants can also exercise these rights in relation to their own data as a merchant/account holder.

1

Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data, and to receive a copy of that data along with information about how it is used.

Submit a Subject Access Request (SAR) to hello.waflows@gmail.com with subject: 'GDPR - Access Request'. We will respond within 30 days.

2

Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data we hold about you, and to have incomplete data completed.

Contact us at hello.waflows@gmail.com with subject: 'GDPR - Rectification Request', specifying what data needs correction.

3

Right to Erasure / Right to be Forgotten (Article 17)

You have the right to request deletion of your personal data where there is no compelling reason for its continued processing.

Submit a deletion request to hello.waflows@gmail.com with subject: 'GDPR - Erasure Request'. We will process and confirm within 30 days.

4

Right to Restrict Processing (Article 18)

You have the right to request that we restrict processing of your personal data in certain circumstances - for example, while accuracy is contested or while an objection is being considered.

Contact us at hello.waflows@gmail.com with subject: 'GDPR - Restriction Request'.

5

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Submit a portability request to hello.waflows@gmail.com with subject: 'GDPR - Portability Request'. Data will be provided in JSON or CSV format.

6

Right to Object (Article 21)

You have the right to object to processing of your personal data where processing is based on legitimate interests or for direct marketing purposes.

Contact us at hello.waflows@gmail.com with subject: 'GDPR - Objection'. Processing will cease unless we demonstrate compelling legitimate grounds.

7

Right to Withdraw Consent (Article 7)

Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing.

Withdrawal requests can be sent to hello.waflows@gmail.com with subject: 'GDPR - Withdraw Consent'.

8

Right Not to be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

WaAutoflow does not engage in automated decision-making that produces legal effects on individuals.

Response Timelines

Within 72 hours

Acknowledgement

Within 30 days

Full Response

Up to 90 days (with notice)

Extension (complex)

International Data Transfers

WaAutoflow is operated from India. When we process data of EEA/UK individuals, we ensure appropriate safeguards are in place per GDPR Chapter V:

1

Standard Contractual Clauses (SCCs)

Where applicable, we use EU Commission-approved SCCs to ensure adequate protection for data transferred to non-EEA countries.

2

Adequacy Decisions

Transfers to countries with an EU adequacy decision are made without additional safeguards.

3

Processor Agreements

All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security measures.

India is currently working towards an EU adequacy decision. In the meantime, we rely on Standard Contractual Clauses for transfers from the EEA to India. For details of the SCCs in use, contact hello.waflows@gmail.com.

Technical & Organisational Security Measures

Per GDPR Article 32, WaAutoflow implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk:

Encryption in Transit

All data transmitted between users, Shopify, and our servers uses TLS 1.2+ encryption

Encryption at Rest

Sensitive stored data is encrypted using industry-standard encryption algorithms

Access Controls

Role-based access controls ensure staff access only the minimum data necessary

Authentication

Multi-factor authentication required for all internal system access

Security Monitoring

Continuous monitoring for suspicious activity, intrusion attempts, and anomalies

Vulnerability Management

Regular security assessments, penetration testing, and prompt patching of vulnerabilities

Sub-processor Controls

All sub-processors are vetted and bound by Data Processing Agreements

Staff Training

Regular GDPR and security awareness training for all staff with data access

Incident Response

Documented incident response procedures for rapid containment and notification

Data Minimisation

Systems designed to collect and retain only the minimum data necessary for service delivery

Data Breach Notification

In compliance with GDPR Articles 33 and 34, WaAutoflow has documented procedures for detecting, reporting, and investigating data breaches:

1
0–24 hrs

Detection & Containment

Security team identifies and contains the breach. Initial assessment of scope, type, and risk to individuals.

2
24–48 hrs

Internal Assessment

Full investigation of cause, data affected, number of individuals impacted, and potential consequences.

3
Within 72 hrs

Supervisory Authority Notification

Where required, notify the competent Lead Supervisory Authority (per GDPR Article 33). Notification includes nature of breach, categories of data, approximate numbers affected, and measures taken.

4
Without undue delay

Merchant Notification

Notify affected merchants where the breach is likely to result in a risk to their customers' rights and freedoms, including sufficient detail to allow them to meet their own notification obligations.

5
Without undue delay (high risk)

Individual Notification

Where the breach is likely to result in a high risk to individuals' rights and freedoms, those individuals are notified directly with clear information about what happened and recommended protective steps.

Sub-Processors

Per GDPR Article 28(3)(d), we disclose all sub-processors used in delivering the Service. All sub-processors are bound by GDPR-compliant Data Processing Agreements:

Sub-processorPurposeLocationSafeguard
Shopify Inc.App distribution, billing, store APICanada (Adequate)EU Adequacy Decision
Cloud Hosting ProviderServer infrastructure, data storageIndia / GlobalStandard Contractual Clauses
Meta / WhatsAppWhatsApp message deliveryUSASCCs + Meta DPA
Error Monitoring ServiceBug tracking, error loggingUSA / EUSCCs or EU hosting

We will notify merchants of any intended changes to sub-processors (additions or replacements) with sufficient advance notice.

Contact, DPA & Supervisory Authority

Data Protection Contact

For all GDPR-related enquiries and data subject requests

Subject Lines

GDPR - Access Request

GDPR - Erasure Request

GDPR - DPA Request

GDPR - Complaint

Address

18 Kadamb Bungalow, Ahmedabad, GJ 380015, India

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority

EEA - Lead Supervisory Authority

Contact your local EU data protection authority. Find yours at: edpb.europa.eu

UK - Information Commissioner's Office (ICO)

ico.org.uk · 0303 123 1113

India - Data Protection Board

Under the Digital Personal Data Protection Act, 2023

Requesting a Data Processing Agreement (DPA)

If your organisation requires a standalone signed Data Processing Agreement (for example, for your own GDPR compliance documentation), please email hello.waflows@gmail.com with subject “GDPR - DPA Request”. We will provide a signed DPA document within 10 business days.

© 2026 WaAutoflow · Developed by NCS Global · Ahmedabad, India

Last updated January 2026