1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Junkies Coder ("Processor", "we", "us") and you ("Controller", "Customer") for the use of the Replai platform ("Service").
This DPA governs the processing of personal data by Replai on behalf of the Customer in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and India's Digital Personal Data Protection Act, 2023 ("DPDPA").
2. Definitions
- Personal Data — Any information relating to an identified or identifiable individual, as defined by applicable data protection law
- Controller — The Customer who determines the purposes and means of processing personal data (you)
- Processor — Junkies Coder / Replai, which processes personal data on behalf of the Controller
- Sub-processor — A third party engaged by the Processor to process personal data
- Data Subject — An identified or identifiable individual whose personal data is processed
3. Scope of Processing
3.1 Nature and Purpose
We process personal data solely to provide the Replai Service, including:
- Facilitating WhatsApp Business API messaging
- Storing and managing contacts, conversations, and message history
- Powering AI-assisted features and automation workflows
- Providing team collaboration and CRM features
- Generating analytics and reporting
3.2 Types of Personal Data
- Contact information (names, phone numbers, email addresses)
- WhatsApp message content and metadata
- Customer interaction history and preferences
- Account and team member information
3.3 Categories of Data Subjects
- End users / customers of the Controller (WhatsApp contacts)
- Team members and employees of the Controller
3.4 Duration
Processing continues for the duration of the service agreement. Upon termination, data will be deleted within 30 days unless retention is required by law.
4. Obligations of the Processor
We shall:
- Process personal data only on documented instructions from the Controller
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in fulfilling data subject rights requests
- Assist the Controller with data protection impact assessments where required
- Delete or return all personal data upon termination of the agreement
- Make available all information necessary to demonstrate compliance
- Allow for and contribute to audits conducted by the Controller or an authorized auditor
5. Sub-processors
The Controller provides general authorization for the Processor to engage sub-processors. Current sub-processors include:
| Sub-processor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business API messaging | United States / Global |
| Supabase, Inc. | Database, authentication, and storage | United States (AWS) |
| Vercel, Inc. | Application hosting and edge delivery | United States / Global |
| OpenAI / AI Provider | AI-powered features (message drafting, automation) | United States |
We will notify the Controller of any intended changes to sub-processors at least 30 days in advance, providing the Controller the opportunity to object.
6. Security Measures
We implement and maintain the following technical and organizational measures:
Technical Measures
- TLS/SSL encryption for data in transit
- AES-256 encryption for data at rest
- End-to-end encryption for WhatsApp messages (provided by Meta)
- Row-level security (RLS) ensuring strict data isolation between tenants
- Automated backups with point-in-time recovery
- Vulnerability scanning and dependency monitoring
Organizational Measures
- Access limited to authorized personnel on a need-to-know basis
- Role-based access controls with granular permissions
- Regular security training for team members
- Incident response procedures and breach notification protocols
- Secure development practices including code review
7. Data Subject Rights
We will assist the Controller in responding to requests from data subjects exercising their rights under applicable law, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to restriction of processing
- Right to object to processing
We will promptly notify the Controller of any data subject request received directly and will not respond independently unless authorized.
8. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach
- Provide sufficient information for the Controller to meet its own notification obligations
- Cooperate with the Controller to investigate, mitigate, and remediate the breach
- Document all breaches including facts, effects, and remedial actions taken
9. International Data Transfers
Where personal data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-U.S. Data Privacy Framework certification (where applicable)
- Adequacy decisions recognized by relevant data protection authorities
10. Audit Rights
The Controller has the right to audit our compliance with this DPA. Audits may be conducted:
- No more than once per calendar year (unless a data breach has occurred)
- With at least 30 days' written notice
- During normal business hours
- Subject to reasonable confidentiality obligations
11. Term and Termination
This DPA is effective as long as the Processor processes personal data on behalf of the Controller. Upon termination of the Service:
- All personal data will be deleted within 30 days
- The Controller may request a data export prior to deletion
- Certain data may be retained if required by applicable law
12. Contact
For DPA-related inquiries:
- Email: privacy@junkiescoder.com
- Company: Junkies Coder
- Website: https://junkiescoder.com