Data Processing Agreement
Last updated: 25 August 2026
This Agreement forms part of the Terms of Service and applies whenever Labeeq processes personal data on your behalf. You are the controller, we are the processor, and this sets out what that obliges us to do. If your organisation needs it signed, write to [email protected].
1. What we process, and for whom
Subject matter: providing the platform. Duration: as long as your workspace is open, plus the retention window in the Privacy Policy. Nature and purpose: receiving, storing, displaying and sending your customers' messages and records so your team can work on them.
- Categories of data subject: your customers and prospects, and your own teammates.
- Categories of personal data: names, phone numbers, email addresses, profile identifiers from connected channels, message content and attachments, and anything else your team chooses to record.
- Special-category data: not requested and not required. If your business records it anyway, you are responsible for having a lawful basis to do so.
2. We act on your instructions
We process personal data only to provide the service, to follow your documented instructions, and where a law we are subject to requires otherwise — in which case we tell you first unless that law forbids it.
3. Confidentiality
Everyone with access to your data is bound by confidentiality obligations, and access is limited to the people who need it to run or support the service.
4. Security
We keep technical and organisational measures appropriate to the risk; the Security page describes the current ones. Measures evolve, and we will not weaken them below the level described there without telling you.
5. Sub-processors
You give general authorisation for the sub-processors listed on the sub-processors page. We impose data-protection terms on each of them no less protective than these, and we remain responsible to you for what they do. The page is updated before a new sub-processor begins processing, so you can object.
6. Helping you answer your customers
The platform lets you find, export, correct and delete a contact and their conversation yourself. Where a request needs more than that, we help you within a reasonable time, and we pass on any request that reaches us directly rather than answering it for you.
7. Personal data breaches
If we become aware of a breach affecting your data, we tell you without undue delay and in any case within 72 hours of becoming aware, with what we know, what we are doing, and what we advise you to do.
8. Deletion and return
You can export your data at any time while the workspace is open. When it closes, we delete your data within 90 days unless a law requires us to keep some of it — billing records being the usual case.
9. Audits
We answer reasonable questions about how we process your data, and provide the documentation we hold. Where a formal audit is required by law, we agree scope and timing in advance so it does not disturb other customers.
10. International transfers
Where personal data covered by European rules leaves the region — because a messaging or AI provider is elsewhere — the transfer relies on standard contractual clauses or another lawful mechanism.
Questions about any of this? Write to [email protected].
Prefer WhatsApp? Message us on +20 109 056 6135.