We use a small number of other companies to deliver Tobachat. These are our sub-processors. For each one, you will find below what we use it for, which data it sees, where it processes that data, and on what basis data may leave the EU.
1. What this list is
For your customers' messages and contacts, you are the controller and we are the processor. We process that data only on your instructions. The parties below in turn act on our instructions and may not use the data for anything beyond what is stated here.
Accepting our terms gives us your prior authorization to engage these parties. How that works is set out in the data processing agreement. If the list changes, we will tell you in advance (see section 5).
2. The list
Current as of the date at the top of this page.
Supabase Pte. Ltd. (Singapore)
- What for: the database, login, media storage, and running our server functions.
- Which data: everything held in Tobachat: contacts, phone numbers, message content, media, accounts and settings.
- Where: the EU. Some supporting processing may take place outside the EU.
- Basis for transfer: the European Commission's 2021 standard contractual clauses.
WhatsApp Ireland Limited (Ireland)
- What for: sending and receiving WhatsApp messages and managing your WhatsApp Business account.
- Which data: phone numbers, message content, media, and your WhatsApp Business account details.
- Where: Ireland, with processing across Meta's global network, including the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which WhatsApp LLC is enrolled in, with the standard contractual clauses as a fallback.
Google Cloud EMEA Limited (Ireland), for the Gemini API
- What for: the AI features: proposing or sending a reply, classifying a message, extracting a detail from one, and drafting flows and templates.
- Which data: the messages in the conversation, including voice notes and photos, the contact's name along with the labels and fields you keep, and the business context you fill in yourself. We do not add the contact's phone number or email address. Google does not use this data to improve its products or train its models, but keeps it for a limited time to detect abuse.
- Where: Ireland as the contracting party, with processing in Google data centers, including some outside the EU.
- Basis for transfer: the EU-US Data Privacy Framework, which Google LLC is enrolled in, with the standard contractual clauses as a fallback.
Functional Software, Inc., trading as Sentry (United States)
- What for: tracking down technical faults in the software.
- Which data: error reports with technical detail, sometimes with a screen recording, and the signed-in staff member's account. Your customers' personal data is filtered out.
- Where: error reports in the EU, account data in the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which Sentry is enrolled in, with the standard contractual clauses as a fallback.
Cloudflare, Inc. (United States)
- What for: hosting the website and the dashboard, network traffic, and encrypted storage.
- Which data: IP addresses and requested pages, inbound webhooks, click data for campaign links, and encrypted backups.
- Where: Cloudflare's global network.
- Basis for transfer: the EU-US Data Privacy Framework, which Cloudflare is enrolled in, with the standard contractual clauses for anything it does not cover.
Stripe Payments Europe, Limited (Ireland)
- What for: handling payments, subscriptions and invoices.
- Which data: your company name, email address, billing details and payment details. None of your customers' data.
- Where: Ireland, with onward transfer to Stripe, LLC in the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which Stripe, LLC is enrolled in, with the standard contractual clauses as a fallback.
Plus Five Five, Inc., trading as Resend (United States)
- What for: sending email about your account: confirmations, invitations, notifications and password resets.
- Which data: the recipient's email address and name, and the content of that email.
- Where: the United States.
- Basis for transfer: the European Commission's 2021 standard contractual clauses, alongside the EU-US Data Privacy Framework.
GitHub, Inc. (United States)
- What for: running our build and maintenance jobs, including encrypted backups.
- Which data: a copy of the database, held briefly while a backup is made and before it is encrypted and stored.
- Where: outside the EU, by default in the United States.
- Basis for transfer: the EU-US Data Privacy Framework, which GitHub is enrolled in, with the 2021 standard contractual clauses as an alternative.
Nothing else leaves our systems. We do not sell data, and we never use one organization's conversations to improve anything for another.
3. Processing outside the EU
Data may leave the European Economic Area on one of two grounds. The first is an adequacy decision: the European Commission has determined that an arrangement offers enough protection. The EU-US Data Privacy Framework is such a decision; a US company enrolls in it and renews that enrollment every year. The second is the standard contractual clauses the Commission adopted in 2021: a fixed contract that binds the recipient to European rules.
The entry for each party above shows which of the two applies. Where a party relies on the Data Privacy Framework, its contract also includes the standard contractual clauses as a fallback, so a change to that decision does not interrupt the service.
4. Parties you engage yourself
When you switch on an integration, data goes to a party you chose. That party is not on the list above, because we did not choose it and have no agreement with it. This applies to:
- Zapier, if you switch on the Zapier integration. Contacts and inbound messages then go to the Zaps you build.
- a web address you fill in yourself in the HTTP step of a flow. Whatever you put in that step goes there.
- your booking system, such as FareHarbor or LetsBook, which sends bookings and contact details to Tobachat.
You are responsible for those parties and for arranging whatever they require. Switch the integration off and the data stops flowing.
5. Changes to the list
If we add or replace a party, we tell you at least 30 days beforehand. It works like this:
- We email your organization's administrators.
- The date at the top of this page changes with it.
- If you object, tell us within 30 days. We then look for a solution together.
- If we cannot find one, you may terminate as of the date the change takes effect, at no cost for the remaining period.
To object, or to ask a question, email info@tobachat.nl.
6. Wording for your own privacy statement
Telling your own customers what happens to their data is your duty, not ours. But you do not have to write the wording yourself: copy the text below into your privacy statement.
This is sample text. We do not know what else you process, so check it against your own situation and adjust anything that does not apply.
AI assistance in answering your message
We use Tobachat to receive and answer messages over WhatsApp. As part of that, an AI model may read your message, along with your name and what we have recorded about you, so that a good answer arrives sooner. Sometimes the model proposes an answer that a member of our staff checks and sends; sometimes the model sends the answer itself. In the second case the message says so.
The model only reads our own conversations and does not use your message to train itself. The provider of the model does keep your message for a limited time to detect abuse. Would you rather not deal with AI? Ask for a person, and one of us takes over.
Tobachat processes this data as a processor, on our instructions. The other parties involved are listed at tobachat.nl/subprocessors.
7. Visitors to our own website
This list covers the data you entrust to us. Who receives data about visitors to tobachat.nl, and which cookies we set for that, is in our privacy statement.