VAT number 09856651212
Registro delle Imprese di Napoli – REA NA-1063019
Data protection contact: info@everysoft.me
Subject and scope
1.1 This agreement (the "Agreement") governs, under Article 28 of Regulation (EU) 2016/679 ("GDPR"), the processing of personal data that the Provider carries out on behalf of the Customer when providing the SendApp Agent platform (the "Service"). The Agreement forms an integral part of the Service's Terms and Conditions (the "Terms").
1.2 The Agreement applies to every feature of the Service that processes data on behalf of the Customer: the messaging channels (WhatsApp, Instagram, Messenger, Telegram, e-mail, SMS, website chat), the AI assistant, campaigns and automations, the contact book, the calendar and booking pages, the WhatsApp Commerce websites and catalogue, telephony and the voice assistant, integrations with external services, the mobile app and SendApp Pixel. Annex 1 describes the processing.
1.3 The Agreement does not cover the data the Provider processes as an independent controller about the Customer itself (account data, billing, use of the Service): that is covered by the privacy policy.
1.4 If the Agreement and the Terms conflict on a matter of personal data protection, the Agreement prevails.
Definitions
2.1 "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and the other terms defined in the GDPR have the meaning given in Article 4 GDPR.
2.2 "Customer Data": the personal data the Provider processes on behalf of the Customer as part of the Service. "Sub-processor": another processor the Provider engages for specific processing activities on behalf of the Customer. "Applicable Law": the GDPR, Italian Legislative Decree 196/2003 (the "Privacy Code") and the other personal data protection rules that apply to the processing.
Roles and the Customer's duties
3.1 For Customer Data the Customer is the controller and the Provider is the processor. Where the Customer itself processes the data on behalf of a third party (for example an agency handling another business's customers), the Provider acts as a sub-processor and the Customer warrants that its own controller has authorised it to engage the Provider on the terms of the Agreement.
3.2 The Customer decides which data to enter or collect with the Service, for which purposes and by which means, and is responsible for it. In particular the Customer:
- has a valid legal basis for every processing operation, including sending promotional messages, for which it collects and keeps consent where the law requires it (the Service provides the tools to record and prove it);
- gives data subjects the information required by Articles 13 and 14 GDPR;
- does not enter special categories of data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) unless this is necessary and permitted, for example when it enables, under its own responsibility, the integration with a healthcare practice-management system;
- complies with the terms of the services it connects to the Service, including Meta's terms for the WhatsApp Business Platform;
- gives instructions that comply with Applicable Law.
Instructions
4.1 The Provider processes Customer Data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which the Provider is subject. In that case the Provider informs the Customer before processing, unless that law prohibits it on important grounds of public interest.
4.2 Documented instructions are: the Agreement; the Terms; the configuration and use of the Service's features by the Customer and by the people the Customer authorises (settings, campaigns, automations, integrations, AI assistant); the Customer's written requests to the Provider's support.
4.3 The Provider immediately informs the Customer if, in its opinion, an instruction infringes Applicable Law.
4.4 The Provider does not sell Customer Data or process it for its own purposes, except to the extent strictly necessary to secure the Service, prevent abuse, calculate billable usage and comply with legal obligations. It does not use Customer Data to train artificial intelligence models and, with sub-processors providing such models, uses terms that exclude its use for training.
Confidentiality
5.1 The Provider ensures that the persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access it only to the extent their tasks require.
5.2 The Provider's staff enter the Customer's account from the admin panel only for support requested by the Customer, security or legal compliance. Every such access is recorded (who, which account, when, with the reason given), ends automatically after 120 minutes, and the record is kept for 24 months.
Security
6.1 Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing and the risks to the rights and freedoms of data subjects, the Provider implements appropriate technical and organisational measures under Article 32 GDPR. The measures in place are described in Annex 2.
6.2 The Provider may update the measures, provided the overall level of protection is not reduced.
6.3 The Customer is responsible for the security of what is under its control: its login credentials, enabling two-factor authentication, the permissions it gives operators, and the devices and services it connects.
Sub-processors
7.1 The Customer gives the Provider general authorisation to engage the sub-processors listed in Annex 3, each for the activities indicated. The complete, current list is supplied to the Customer on request using the contact details in the privacy policy, including before accepting the Agreement. The list forms an integral part of the Agreement; Annex 3 explains how to obtain it and does not publish the provider table.
7.2 The Provider informs the Customer of any intended addition or replacement of a sub-processor at least 15 days before it takes place, by e-mail to the account holder's address, and updates Annex 3. Within the same period the Customer may object on reasonable data protection grounds. If the parties do not find a solution, the Customer may terminate the Service before the change applies and receive a refund of the unused part of any period already paid for. Where a replacement is urgent for the security or continuity of the Service, the Provider may proceed with shorter notice, giving it as soon as possible with the reason for the urgency; the periods to object and terminate run from that notice.
7.3 The Provider imposes on each sub-processor, by contract, data protection obligations substantially equivalent to those of the Agreement, and remains liable to the Customer for their performance.
7.4 The following are not the Provider's sub-processors: (a) the messaging networks the Customer chooses to use (Meta for WhatsApp, Instagram and Messenger; Telegram), with which the Customer has a direct relationship under their own terms, including, for WhatsApp, the data processing terms Meta applies to businesses; the Provider transmits data to them on the Customer's instructions; (b) the services the Customer chooses to connect (for example its own online shop, calendar or management software), with which the Service exchanges data on the Customer's instructions.
Transfers outside the EEA
8.1 The servers that run the Service and its database are located in Italy.
8.2 Some sub-processors are established or process data outside the European Economic Area, mainly in the United States. The main case is the AI assistant: to generate a reply, the content of the conversation is sent to the model provider. These transfers rely on the standard contractual clauses adopted by the European Commission or, for certified recipients, on the EU-US Data Privacy Framework, as indicated in Annex 3. The Customer authorises these transfers and may ask for a copy of the safeguards in place.
8.3 If the Customer cannot accept transfers outside the EEA, it contacts the Provider before enabling the AI features: some of them can be switched off for its account.
Data subjects' rights
9.1 Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures so that it can respond to requests to exercise the rights in Articles 15–22 GDPR. The Service lets the Customer view, correct, export and permanently erase a contact with its whole history, record consents and withdrawals, and manage unsubscribes.
9.2 If a data subject contacts the Provider directly about Customer Data, the Provider forwards the request to the Customer without undue delay and does not respond on the merits without the Customer's instructions, except to tell the data subject to contact the Customer.
Personal data breaches
10.1 The Provider notifies the Customer of any personal data breach affecting Customer Data without undue delay after becoming aware of it, by e-mail to the account holder's address and, where useful, by a notice in the platform.
10.2 The notification contains, to the extent available, the information in Article 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a contact point at the Provider. Information not yet available is provided in phases, without further undue delay.
10.3 The Provider takes, without delay, reasonable measures to contain the breach and mitigate its effects, and cooperates with the Customer so that it can meet its own obligations to notify the supervisory authority and communicate with data subjects.
Further assistance
11.1 Taking into account the nature of the processing and the information available to it, the Provider assists the Customer in ensuring compliance with the obligations in Articles 32–36 GDPR, including data protection impact assessments and any prior consultation, by providing the information about the Service that the Customer reasonably requests.
11.2 Where the law allows, the Provider informs the Customer of requests from public authorities concerning Customer Data.
SendApp Pixel
12.1 With SendApp Pixel the Customer installs a script of the Provider on its own website. The Provider processes, on behalf of the Customer, the browsing data of the website's visitors described in Annex 1, part B. The Customer is the controller of this data too.
12.2 Before publishing the Pixel on its website, the Customer:
- obtains visitors' consent where the law requires it for storing or reading information on their device (Article 5(3) of Directive 2002/58/EC, in Italy Article 122 of the Privacy Code and the Garante's cookie guidelines of 10 June 2021), setting up the cookie banner so that the Pixel waits for the visitor's choice. Cookieless measurement (see below) is the Customer's choice;
- updates the website's cookie policy and privacy notice (the Service provides a starting text);
- collects marketing consent where it uses browsing data to send messages;
- excludes pages with special data (for example customer area, payments, health) or enables the settings provided for sensitive sectors.
12.3 Cookieless measurement. If the Customer enables it, when the visitor has not made a choice within a few seconds the Pixel still sends the page's events, without setting cookies or persistent identifiers. To count the day's unique visitors the Provider computes a fingerprint of the truncated IP address, browser type and device type with a key that changes every day. Events collected this way are pseudonymous, not anonymous, and purchases keep their amount and order number. The Provider does not warrant that this mode is exempt from consent: choosing it and assessing its compliance is the Customer's decision.
12.4 Otherwise the Pixel works as follows:
- it sets the first-party cookie
_sa_vid(6 months), which recognises the browser from one visit to the next, only after the visitor's consent to statistics or marketing; on refusal or withdrawal the cookie and any pending events are deleted; - it does not store the full IP address or the raw browser string: the IP address is used in memory and kept only, truncated, as a cryptographic fingerprint computed with a key that changes every day and is deleted after just over 24 hours; of the browser only the device type and the browser family remain;
- it removes e-mail addresses, phone numbers and other identifying parameters from page addresses before storing them, and keeps only the name of the referring site;
- it links browsing to one of the Customer's contacts only if the visitor has given marketing consent and has identified themselves, for example by opening a personal link received from the Customer, sending a form the Customer measures or completing an order;
- it respects the visitor's objection, recorded with the
_sa_optoutcookie (12 months) where the Customer's website offers it, and deletes the data of that browser; - it does not pass data to advertising networks, does not build advertising audiences and does not link visitors across different customers' websites.
12.5 Browsing data is kept for the period the Customer chooses for each website (3, 6 or 13 months; 13 months if no choice is made) and then deleted automatically. After that period attributed orders lose their link to the browser and the visit and are deleted at 25 months, like the aggregated statistics; clicks on message links are deleted at 13 months. Removing a website deletes all its data. What the Pixel adds to a contact's record (last visit, number of visits, events in the timeline) follows the retention of the contact.
Return and deletion
13.1 When the Service ends, the Provider, at the Customer's choice, returns Customer Data and deletes it. While the Service is provided, the Customer can delete contacts and conversations at any time and export contacts and individual conversations; on a written request received before deletion, the Provider supplies an export of the other Customer Data in a structured, commonly used format.
13.2 The Customer can request the deletion of its account from Settings → Account. After 30 days, during which it can cancel the request, the Provider deletes Customer Data from its live systems, except what it must keep by law.
13.3 Backups are encrypted and follow their own rotation cycle: deleted data disappears from them within 13 months. Until then backups are used only to restore the Service after faults or incidents and for periodic restore tests.
13.4 If the Service ends without a deletion request (for example when the plan expires), the account and Customer Data are kept so that it can be renewed, and in any case no longer than two years after the last renewal expires. The Provider carries out deletion within that period; plan expiry alone is not an account deletion request. The Customer can ask at any time for their deletion or export.
Information and audits
14.1 The Provider makes available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 GDPR: the Agreement, the current list of sub-processors, the description of the security measures and answers to reasonable questionnaires.
14.2 The Provider allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor it appoints who is bound by confidentiality: with at least 30 days' written notice, no more than once a year except after a personal data breach or at the request of a supervisory authority, during normal business hours, without access to other customers' data and without compromising the security of the Service. The costs of the audit are borne by the Customer.
Term, liability, changes
15.1 The Agreement lasts as long as the Terms and, after they end, remains in force for as long as the Provider processes Customer Data.
15.2 Each party is liable to data subjects under Article 82 GDPR; nothing in the Agreement limits data subjects' rights. Between the parties, including recourse under Article 82(5) GDPR, the Provider's liability under the Agreement and the Terms is subject, in aggregate, to the limitation in the Terms, which does not apply to wilful misconduct or gross negligence or where the law does not allow liability to be limited.
15.3 The Provider may update the Agreement to reflect Applicable Law, guidance from the authorities or the evolution of the Service, without reducing the protection of Customer Data. It announces the new version at least 30 days before it applies, by e-mail or in the platform; a Customer who does not accept it may terminate before that date. The version and the effective date are shown at the top of the Agreement.
15.4 The Agreement is governed by Italian law. Disputes are handled as provided in the Terms. If a clause is held invalid, the others remain in force.
Acceptance
16.1 The Agreement forms part of the Terms. For accounts opened from the effective date it applies from acceptance of the Terms. For existing accounts it applies from the date the Provider notifies it by e-mail to the account holder: from then on the Provider's obligations as processor apply; the other clauses apply 30 days after the notice unless the Customer terminates earlier, or from the Customer's express acceptance if earlier.
16.2 The account holder, who declares to have the authority to bind the Customer, can accept it expressly on this page, in the account settings or before publishing SendApp Pixel. The Service records the name and e-mail of the person accepting, the date and time, the version accepted and the network address from which it was accepted. Acceptance in electronic form meets the written-form requirement of Article 28(9) GDPR.
16.3 This page can be printed or saved as PDF at any time. The Agreement is drawn up in Italian and English; if they differ, the Italian text prevails.
Annex 1 · Description of the processing
A. The Service
- Nature and purpose — collection, recording, organisation, storage, consultation, transmission, generation of automatic replies and erasure, to provide the Customer with the Service as it configures it: communicating with customers and contacts on the connected channels, managing contacts, appointments, orders, campaigns and automations.
- Data subjects — the Customer's customers, prospects and contacts; people who write to or call the Customer's channels; visitors of the Customer's websites who use the chat, the booking pages or the shop; patients, where the Customer connects a healthcare practice-management system; the people the Customer authorises to use the Service (operators).
- Data — identification and contact data (name, phone number, e-mail, social media accounts); the content of conversations, including attachments, images, voice notes, call recordings and transcripts; tags, notes and custom fields; consents, withdrawals and unsubscribes; appointments, orders, carts and leads; data coming from the services the Customer connects; operators' activity in the Service. Payment card data does not pass through the Service: it is handled by the payment providers.
- Special categories — only if the Customer enters or collects them, for example health data through a connected practice-management system, or if data subjects write them spontaneously in messages.
- Duration — for the whole duration of the Service and until deletion under the article "Return and deletion".
B. SendApp Pixel
- Nature and purpose — measuring visits and actions on the Customer's website, attributing visits and orders to the Customer's campaigns and messages, calculating an interest score from actions on the website and, with the visitor's consent, linking browsing to the contact in order to send them relevant messages with the Service, including automatic ones where the Customer configures them (profiling, Article 4(4) GDPR).
- Data subjects — the visitors of the websites on which the Customer installs the Pixel.
- Data — pseudonymous browser identifier (
_sa_vidcookie); pages visited (address cleaned of identifying parameters and, if the Customer enables it, page title); actions on the website (measured clicks, form submissions, products viewed, cart, checkout, purchases with amount and order number); origin of the visit (name of the referring site, UTM parameters, the Customer's campaign or message); device type and browser family; reference code added to the website's WhatsApp links; clicks on links in the Customer's messages; cryptographic fingerprint of the truncated IP address; the data the visitor enters in the forms the Customer measures (phone, e-mail, name, consent), which go into the contact's record. - Duration — as set out in the article "SendApp Pixel", point 12.5.
Annex 2 · Security measures
- Transmission — encrypted HTTPS connections (TLS 1.2 and 1.3), mandatory redirect from HTTP and HSTS.
- Credentials — user passwords are stored only as hashes (bcrypt); API keys and app tokens are stored as hashes; the access credentials of channels and integrations and two-factor authentication secrets are stored encrypted in the account's configuration.
- Authentication — limits on login attempts; two-factor authentication available to account holders (authenticator app, code via WhatsApp, backup codes); protected session cookies (HttpOnly, Secure, SameSite).
- Access control — each account's data is kept separate from other accounts'; operators see only the areas and AI accounts the account holder assigns them; access by the Provider's staff is recorded and time-limited, as described in point 5.2; technical access to servers and databases is restricted to authorised staff and used only for maintenance, security and support.
- Infrastructure — dedicated servers in Italy; database and internal services not reachable from the Internet; web application firewall (WAF) and automatic blocking of addresses that attempt attacks.
- Backups — encrypted copies of the database (every 6 hours), conversations, files and configuration, kept on separate storage with dedicated, restricted credentials; integrity check and automatic restore test every week; rotation within 13 months.
- SendApp Pixel — the measures described in points 12.3 and 12.4.
- Incidents — a written procedure for handling personal data breaches, with an incident register.
- Minimisation — conversation content is not used to train AI models; each sub-processor receives only the data its activity requires (Annex 3).
Annex 3 · Sub-processors
The complete, current list of sub-processors, including their activities, the data processed, processing locations and safeguards for any transfers outside the EEA, is available on request using the contact details below, including before accepting the Agreement. The list is not published on this page.
To request a copy of the list and the safeguards in place, write to info@everysoft.me.