Data Processing Agreement
This Data Processing Agreement governs the processing of personal data by Logiqal Space on behalf of customers of the Beacon platform.
Last updated: 6 August 2026
1. Parties and purpose
This Data Processing Agreement ("DPA") forms part of the agreement between Logiqal Space ("Processor") and the customer ("Controller") for the use of the Beacon WhatsApp Business API platform ("Service").
The Processor will process personal data on behalf of the Controller in order to provide the Service. This DPA sets out the terms that apply when personal data is processed under the Service agreement.
The parties agree that this DPA is entered into in compliance with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any national implementing legislation, to the extent applicable to the processing of personal data under this DPA.
This DPA supplements and forms part of the Service agreement between the parties. In the event of a conflict between this DPA and the Service agreement with respect to the processing of personal data, this DPA shall prevail.
2. Definitions
In this DPA, unless the context requires otherwise, the following definitions apply:
"Personal data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller in connection with the Service.
"Data subject" means the identified or identifiable natural person to whom personal data relates.
"Processing" means any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; this is the customer using the Beacon platform.
"Processor" means the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller; this is Logiqal Space.
"Subprocessor" means any third party engaged by the Processor (or by any subsequent Subprocessor) to process personal data on behalf of the Controller.
"Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
"Supervisory authority" means an independent public authority established by a Member State of the European Union under the GDPR.
3. Scope of processing
The Processor processes personal data to provide the Service as agreed in the Service agreement between the parties. The Processor shall not process personal data for any purpose other than as necessary to provide the Service, unless required to do so by applicable law.
Types of personal data processed include: contact phone numbers, message content and media files, consent records with opt-in source and timestamp, delivery and read events, API key metadata, workspace and account details, authentication data, and analytics derived from the Controller's use of the Service.
Categories of data subjects include: end users and customers of the Controller whose data is submitted to the Service through the Controller's use of the platform, and the Controller's Users who access the Service under the Controller's Account.
Processing continues for the duration of the Service agreement between the parties. The Processor shall cease processing personal data upon termination of the Service agreement, subject to the data return and deletion obligations set out in this DPA.
4. Processor obligations
The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by applicable law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Processor shall ensure that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
The Processor shall implement and maintain appropriate technical and organisational security measures as set out in Section 8 of this DPA, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
The Processor shall assist the Controller in ensuring compliance with the Controller's obligations under applicable data protection law, taking into account the nature of processing and the information available to the Processor, including: (a) obligations relating to security of processing under Article 32 of the GDPR; (b) obligations relating to data breach notification under Articles 33 and 34 of the GDPR; (c) obligations relating to data protection impact assessments under Article 35 of the GDPR; and (d) obligations relating to prior consultation under Article 36 of the GDPR.
The Processor shall assist the Controller in responding to data subject rights requests, including requests for access, rectification, erasure, portability, restriction of processing, and objection. The Processor shall promptly notify the Controller if the Processor receives a request directly from a data subject in relation to the Controller's personal data.
The Processor shall delete or return all personal data to the Controller at the Controller's choice at the end of the Service relationship, and shall delete existing copies unless applicable law requires storage of the personal data.
The Processor shall make available all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits and inspections, including on-site inspections, conducted by the Controller or another auditor mandated by the Controller.
5. Controller obligations
The Controller warrants that it has a lawful basis for processing personal data through the Service, including obtaining valid, informed, and freely given consent from data subjects where consent is the appropriate legal basis.
The Controller shall ensure that it has provided all necessary notices to data subjects regarding the processing of their personal data, including the identity of the Controller, the purposes of processing, and the rights of data subjects.
The Controller shall provide documented instructions to the Processor regarding the processing of personal data and shall ensure those instructions comply with applicable data protection law. The Controller shall be responsible for the lawfulness of its instructions.
The Controller is responsible for responding to data subject requests relating to personal data processed through the Service and shall do so in a timely manner. The Controller shall notify the Processor of any data subject request that requires the Processor's assistance.
The Controller shall promptly notify the Processor if it believes that any instruction from the Processor would violate applicable data protection law. The Processor shall not be in breach of this DPA if it suspends or declines to process personal data where it reasonably believes that the Controller's instructions would violate applicable law.
The Controller shall be responsible for complying with all applicable data protection law, including laws relating to the collection, use, and disclosure of personal data, and shall ensure that it has all necessary consents and authorisations for the processing of personal data under this DPA.
6. Subprocessing
The Controller provides general authorisation for the Processor to engage Subprocessors to support the delivery of the Service, including cloud hosting and infrastructure providers, payment processors, analytics services, and communication tools.
A current list of Subprocessors is available to the Controller on request. The Processor shall maintain a list of all Subprocessors and shall update it when Subprocessors are added or removed.
The Processor shall notify the Controller in writing at least 30 days before engaging any new Subprocessor or making any material change to the engagement of an existing Subprocessor. The notification shall include the identity and location of the Subprocessor, the nature of the processing to be undertaken, and the safeguards in place.
The Controller may object to the engagement of a new Subprocessor on reasonable data protection grounds within 30 days of receiving notification. If the Controller objects, the parties shall discuss the objection in good faith. If the parties are unable to reach a mutually agreeable resolution within 30 days of the objection, the Controller may terminate the affected Service (but not the entire Service agreement) upon written notice.
The Processor shall impose data processing obligations on each Subprocessor that are no less protective than the obligations set out in this DPA. The Processor shall remain fully liable to the Controller for the performance of each Subprocessor's obligations.
Where the Processor engages a Subprocessor, the Processor shall: (a) carry out adequate due diligence to ensure that the Subprocessor is able to provide the level of protection for personal data required by this DPA; (b) ensure that the arrangement with the Subprocessor is governed by a written contract with terms substantially the same as those set out in this DPA; and (c) remain responsible for the acts and omissions of the Subprocessor.
7. International data transfers
Personal data may be transferred to and processed in countries other than the country in which the Controller is established. The Controller acknowledges that cross-border processing of personal data is necessary for the delivery of the Service.
Where personal data is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country outside those jurisdictions, the Processor shall ensure that appropriate safeguards are in place for the transfer, in accordance with applicable data protection law.
Where required, the Processor shall rely on standard contractual clauses approved by the European Commission or the relevant supervisory authority, or other recognised transfer mechanisms, to ensure an adequate level of protection for transferred personal data.
The Processor shall conduct a transfer impact assessment where required by applicable law, and shall implement supplementary measures where necessary to ensure that the level of protection of personal data is not undermined by the transfer.
The Controller authorises the Processor to transfer personal data to Subprocessors in countries outside the EEA, the United Kingdom, and Switzerland, provided that the Processor complies with the transfer requirements set out in this section.
8. Security measures
The Processor implements and maintains appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
Encryption: the Processor encrypts all personal data in transit using TLS 1.2 or higher and at rest using AES-256 encryption. HMAC-SHA256 signed webhooks with timestamp tolerance ensure webhook integrity and protect against tampering.
Access control: the Processor implements role-based access control (RBAC) across workspaces, with per-session permission scoping and multi-factor authentication support. Where enabled, single sign-on with SAML adds further protection. Access to personal data is limited to authorised personnel who require it to perform their duties.
Monitoring and audit: the Processor maintains immutable activity audit trails for all platform actions, session health monitoring over WebSocket, and webhook delivery logs with retry tracking. The Processor conducts regular security reviews and assessments.
Environment separation: production and testing environments are separated, with sandbox sessions available for safe development. Personal data is not used in testing environments without the Controller's explicit consent.
Incident response: the Processor maintains an incident response plan and shall notify the Controller without undue delay after becoming aware of a personal data incident, as set out in Section 12 of this DPA.
The Processor shall regularly review and update its security measures to address evolving threats and vulnerabilities. The Processor shall document all material changes to its security measures and make this information available to the Controller on request.
9. Data subject rights
The Processor shall assist the Controller in fulfilling the Controller's obligations to respond to data subject rights requests under applicable data protection law. The following rights may be exercised by data subjects: (a) right of access; (b) right to rectification; (c) right to erasure; (d) right to restriction of processing; (e) right to data portability; and (f) right to object.
Right of access: the data subject has the right to obtain confirmation as to whether personal data is being processed, and where that is the case, to access the personal data and information about the processing, including the purposes, categories of data, recipients, and retention periods.
Right to rectification: the data subject has the right to have inaccurate personal data corrected and incomplete personal data completed without undue delay.
Right to erasure: the data subject has the right to have personal data deleted without undue delay where: (a) the data is no longer necessary for the purpose for which it was collected; (b) consent is withdrawn; (c) the data subject objects to processing; (d) the data has been unlawfully processed; or (e) erasure is required by applicable law.
Right to restriction: the data subject has the right to restrict processing where: (a) the accuracy of the data is contested; (b) processing is unlawful; (c) the Controller no longer needs the data but the data subject requires it for legal claims; or (d) the data subject has objected to processing pending verification.
Right to data portability: the data subject has the right to receive personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, where technically feasible.
Right to object: the data subject has the right to object to the processing of personal data based on legitimate interests, including profiling, unless the Controller demonstrates compelling legitimate grounds for the processing.
The Processor shall promptly notify the Controller (and in any event within 5 business days) if the Processor receives a request directly from a data subject in relation to the Controller's personal data. The Processor shall not respond to such a request directly unless authorised by the Controller or required by applicable law.
10. Data Protection Impact Assessments
The Processor shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities where required by applicable data protection law.
Where the Controller requires assistance with a DPIA, the Controller shall notify the Processor in writing and provide reasonable information about the proposed processing operation. The Processor shall provide relevant information about the technical and organisational measures in place, the nature and scope of processing, and the risks to data subjects.
The Processor shall assist the Controller in identifying and mitigating risks to the rights and freedoms of data subjects, including by implementing additional technical and organisational measures where necessary.
The Processor shall maintain a record of processing activities under its responsibility, including the categories of processing carried out on behalf of the Controller, transfers to third countries, and a general description of the technical and organisational security measures implemented.
11. Audit rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and with applicable data protection law, including maintaining records of processing activities, security measures, and Subprocessor arrangements.
The Controller (or a third-party auditor mandated by the Controller) may conduct audits and inspections of the Processor's compliance with this DPA, including on-site inspections of the Processor's facilities and systems, upon reasonable written notice of at least 30 days.
Audits shall be conducted during normal business hours and shall not unreasonably interfere with the Processor's operations. The Controller shall ensure that its auditors are bound by appropriate confidentiality obligations.
The Processor shall cooperate fully with audits and shall provide the Controller (or its auditor) with reasonable access to information, personnel, and facilities necessary for the conduct of the audit. The Processor shall promptly address any non-compliance identified during an audit and shall implement corrective measures within a reasonable timeframe.
The costs of audits shall be borne by the Controller, except where the audit reveals material non-compliance by the Processor, in which case the Processor shall bear the reasonable costs of the audit.
In lieu of an on-site audit, the Processor may provide the Controller with a recent third-party audit report (such as a SOC 2 Type II report) or other independent verification of compliance, provided that such report or verification is sufficient to address the Controller's reasonable concerns.
12. Incident notification
The Processor shall notify the Controller without undue delay and in any event within 72 hours after becoming aware of a personal data incident affecting personal data processed under this DPA.
The notification shall include, to the extent known at the time of notification: (a) a description of the nature of the incident, including the categories and approximate number of data subjects affected; (b) the categories and approximate number of personal data records affected; (c) the likely consequences of the incident; (d) the measures taken or proposed to address the incident and mitigate its effects; and (e) the contact point for further information.
Where the Processor is unable to provide all of the information referred to above at the time of the initial notification, the Processor shall provide the information in phases without further undue delay as it becomes available.
Notification will be sent through the Controller's account contact details or through the contact form on the Beacon website. The Processor shall maintain records of all incidents, including the facts relating to the incident, its effects, and the remedial action taken.
The Processor shall cooperate with the Controller and take such reasonable commercial steps as may be directed by the Controller to assist in the investigation, mitigation, and remediation of each incident.
13. Confidentiality
The Processor shall ensure that all personnel who have access to personal data are subject to appropriate confidentiality obligations. The Processor shall ensure that access to personal data is limited to those personnel who need access to perform their duties.
The Processor shall ensure that all personnel who process personal data on behalf of the Controller have received appropriate training on data protection and the handling of personal data.
The Processor shall not transfer or disclose personal data to any third party except as necessary for the provision of the Service or as required by applicable law. Where the Processor is required by applicable law to disclose personal data, the Processor shall, to the extent permitted by law, inform the Controller before such disclosure.
The confidentiality obligations in this section survive termination of this DPA for a period of three years.
14. Liability
The Processor's liability arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Service agreement between the parties.
Nothing in this DPA shall limit or exclude either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) any other liability that cannot be limited or excluded by applicable law.
The Processor shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or in connection with this DPA, regardless of the theory of liability.
The Processor's total aggregate liability arising out of or in connection with this DPA shall not exceed the amount of fees paid by the Controller to the Processor during the twelve (12) months immediately preceding the event giving rise to the liability, unless a higher limit is agreed in the Service agreement.
15. Term and termination
This DPA shall commence on the date the Service agreement takes effect and shall remain in effect for the duration of the Service agreement between the parties.
On termination of the Service agreement, the Processor shall, at the Controller's choice, return or delete all personal data within 30 days. Deletion shall be confirmed in writing upon request.
The Processor may retain personal data to the extent required by applicable law, provided that the Processor shall ensure that the data remains protected in accordance with this DPA and that the processing is limited to the purposes required by law.
The Processor shall certify in writing that all personal data has been returned or deleted, except as required by applicable law, within 60 days of termination of the Service agreement.
16. Governing law
This DPA is governed by the laws applicable to Logiqal Space, without regard to its conflict of law provisions.
Any dispute arising out of or relating to this DPA shall first be addressed through good-faith negotiations between the parties. If the parties are unable to resolve a dispute through good-faith negotiations within 30 days, either party may submit the dispute to the courts of competent jurisdiction.
Nothing in this DPA shall prevent either party from seeking injunctive or other equitable relief to prevent irreparable harm pending the resolution of a dispute.