Data Processing Agreement
Terms governing how MacropageConnect processes Personal Data on your behalf.
Table of Contents
- 1. Introduction
- 2. Definitions
- 3. Scope
- 4. Roles of the Parties
- 5. Nature of Processing
- 6. Categories of Personal Data
- 7. Categories of Data Subjects
- 8. Processor Obligations
- 9. Confidentiality
- 10. Security Measures
- 11. Sub-Processors
- 12. International Data Transfers
- 13. Data Breach Notification
- 14. Assistance to Customers
- 15. Data Retention and Deletion
- 16. Audit Rights
- 17. Limitation of Liability
- 18. Changes to this Agreement
- 19. Contact Information
- 20. Version History
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between MacropageConnect, A Brand of MR TECH SOLUTIONS PRIVATE LIMITED ("Processor", "we", "our", or "us"), and the Customer ("Controller", "you", or "your").
This DPA governs the processing of Personal Data by MacropageConnect on behalf of its customers while providing the Services.
This Agreement is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Definitions
For the purposes of this DPA:
Controller means the entity that determines the purposes and means of processing Personal Data. Processor means MacropageConnect, which processes Personal Data on behalf of the Controller. Personal Data means any information relating to an identified or identifiable natural person. Processing includes collecting, recording, storing, organizing, using, transmitting, deleting, or otherwise handling Personal Data. Sub-Processor means any third party engaged by MacropageConnect to process Personal Data on behalf of the Customer.
3. Scope
This DPA applies whenever MacropageConnect processes Personal Data on behalf of customers through:
- WhatsApp Business API
- Chatbot Services
- CRM Integrations
- API Services
- Shared Inbox
- Broadcast Messaging
- Customer Support
- Cloud Infrastructure
4. Roles of the Parties
Customer (Controller) The Customer determines:
- The purpose of processing.
- The categories of Personal Data collected.
- The recipients of communications.
- The legal basis for processing.
MacropageConnect (Processor) MacropageConnect processes Personal Data solely in accordance with the Customer's documented instructions and applicable law.
5. Nature of Processing
Processing activities may include:
- Collection
- Storage
- Organization
- Retrieval
- Transmission
- Hosting
- Encryption
- Backup
- Deletion
- Analytics required to provide the Services
Processing is limited to what is necessary for delivering the subscribed Services.
6. Categories of Personal Data
Depending on the Services used, Personal Data may include:
- Name
- Mobile Number
- Email Address
- Company Information
- WhatsApp Number
- IP Address
- Device Information
- Message Templates
- Customer Communications
- API Logs
- Billing Information
Customers remain responsible for ensuring that they lawfully collect and provide such information.
7. Categories of Data Subjects
Personal Data may relate to:
- Customers
- Prospective Customers
- Employees
- Business Contacts
- Vendors
- Suppliers
- Website Visitors
- End Users
8. Processor Obligations
MacropageConnect agrees to:
- Process Personal Data only on documented instructions.
- Maintain confidentiality.
- Implement appropriate security measures.
- Restrict access to authorized personnel.
- Assist customers in complying with applicable privacy laws.
- Notify customers of verified Personal Data breaches where legally required.
- Delete or return Personal Data upon termination where applicable.
9. Confidentiality
All personnel authorized to process Personal Data are subject to confidentiality obligations.
Access to Personal Data is limited to individuals who require such access to perform their job responsibilities.
10. Security Measures
MacropageConnect maintains reasonable technical and organizational safeguards, including:
- SSL/TLS Encryption
- Secure Cloud Infrastructure
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (where applicable)
- Secure Password Storage
- System Monitoring
- Backup Procedures
- Vulnerability Management
- Logging and Audit Trails
While we implement commercially reasonable security practices, no system can be guaranteed to be completely secure.
11. Sub-Processors
MacropageConnect may engage trusted third-party service providers to support the Services, including providers of:
- Cloud Hosting
- Payment Processing
- Email Delivery
- Analytics
- Customer Support
- Security Monitoring
- Infrastructure Services
We remain responsible for ensuring that such Sub-Processors are contractually obligated to provide appropriate data protection measures.
12. International Data Transfers
Where Personal Data is transferred outside the country of origin, MacropageConnect will implement appropriate safeguards as required by applicable data protection laws.
Customers acknowledge that certain cloud service providers may process data in multiple jurisdictions.
13. Data Breach Notification
If MacropageConnect becomes aware of a confirmed Personal Data breach affecting Customer Data, we will:
- Investigate the incident.
- Take appropriate corrective action.
- Notify affected customers without undue delay where required by law.
- Cooperate in responding to regulatory requirements where applicable.
14. Assistance to Customers
Upon reasonable request, MacropageConnect will provide appropriate assistance to enable Customers to comply with applicable data protection obligations, including requests relating to:
- Access
- Correction
- Deletion
- Data Portability
- Security Measures
Such assistance may be subject to reasonable administrative charges where permitted.
15. Data Retention and Deletion
Upon termination of the Services, Personal Data will be retained only as necessary to:
- Comply with legal obligations.
- Resolve disputes.
- Enforce agreements.
- Meet regulatory requirements.
After applicable retention periods, data will be securely deleted or anonymized unless otherwise required by law.
16. Audit Rights
Where required by applicable law or contractual obligation, Customers may request reasonable information regarding MacropageConnect's security and privacy practices.
Audit requests must:
- Be made in writing.
- Be reasonable in scope.
- Avoid disruption to normal business operations.
- Respect the confidentiality of other customers.
17. Limitation of Liability
The liability of each party under this DPA shall be governed by the liability provisions contained in the MacropageConnect Terms of Service unless otherwise agreed in writing.
18. Changes to this Agreement
MacropageConnect may update this DPA from time to time to reflect changes in legal requirements, operational practices, or the Services.
Material updates will be published on our website or communicated through the Platform.
19. Contact Information
MacropageConnect A Brand of MR TECH SOLUTIONS PRIVATE LIMITED Email: contact@macropageconnect.com Website: https://macropageconnect.com Registered Office: Krishna Vatika Colony, Near Shalini School, Sadar Bazar, Raigarh, Chhattisgarh, India
20. Version History
Version: 1.0 Effective Date: 03 July 2026 Description: Initial Release.
Request a Signed DPA
Processing personal data on behalf of your customers? Get our DPA signed.
contact@macropageconnect.com