Skip to main content
HQ HandleHQ
How it works Your dashboard Pricing Use cases About
Log in Get early access
Legal

Data Processing Agreement

Last updated: July 2, 2026

Draft pending legal review. This document is a first draft prepared without legal counsel, modeled on GDPR Article 28 requirements. It has not been reviewed by a lawyer and should not be relied upon as legally vetted until this notice is removed.

1. Parties and purpose

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Saifullah Khan, doing business as HandleHQ (sole proprietor, New York, USA) (“HandleHQ”, the “Processor”) and the business customer (the “Customer”, the “Controller”). It governs HandleHQ's processing of personal data belonging to the Customer's end-customers on the Customer's behalf. It applies whenever the Customer routes end-customer messages through the HandleHQ service.

2. Definitions

  • Personal data, processing, controller, processor, data subject, and supervisory authority have the meanings given in the GDPR (Regulation (EU) 2016/679), applied by analogy where other data protection laws govern.
  • Sub-processor means a third party engaged by HandleHQ to process personal data on the Customer's behalf.
  • End-customer means a person who communicates with the Customer through channels connected to the service.
  • Applicable data protection law means the data protection laws that apply to the personal data processed under this DPA, which may include the GDPR, the UK GDPR, Singapore's PDPA, and similar frameworks.

3. Scope and details of processing

  • Subject matter: customer-support and sales messages sent to the Customer by its end-customers via WhatsApp and email.
  • Duration: the term of the Customer's subscription, plus the deletion period in Section 10.
  • Nature of processing: receipt, storage, AI-assisted analysis and extraction of structured information, generation of draft responses, and display in the Customer's dashboard.
  • Purpose: providing the HandleHQ service to the Customer, as instructed through the Customer's configuration and use of the service.
  • Categories of data subjects: the Customer's end-customers and, incidentally, the Customer's staff who appear in conversations.
  • Categories of personal data: names, phone numbers, email addresses, message content, conversation metadata, and any structured information the AI extracts from messages (for example request types or budgets).
  • Special categories: the service is not intended for special-category data. The Customer must not deliberately route special-category data through the service; incidental appearance in free-text messages is handled under the security measures in Section 5.

4. Instructions

HandleHQ processes personal data only on the Customer's documented instructions, including as set out in the Terms of Service, this DPA, and the Customer's configuration of the service, unless required to do otherwise by law (in which case HandleHQ informs the Customer before processing, unless the law prohibits it). HandleHQ will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

5. Confidentiality and security

  • Persons authorized to process personal data are bound by confidentiality obligations.
  • HandleHQ implements appropriate technical and organizational measures, including encryption of data in transit (TLS) and at rest, access controls limiting access to authorized personnel, and logging and monitoring of production systems.
  • HandleHQ does not use personal data processed under this DPA to train AI models without the Customer's explicit consent, and its AI sub-processor is configured not to use API data for model training.

6. Sub-processors

The Customer gives general authorization for the sub-processors listed below. HandleHQ imposes data protection obligations on each sub-processor that are materially equivalent to this DPA and remains liable for their performance.

  • OpenAI (OpenAI, L.L.C., USA) - AI processing of message content (extraction and response generation).
  • Twilio Inc. / SendGrid (USA) - inbound and outbound email routing.
  • Meta Platforms (WhatsApp Cloud API; USA / Ireland) - receipt and delivery of WhatsApp messages.
  • DigitalOcean, LLC (USA) - cloud infrastructure hosting the application and database; data is hosted in DigitalOcean's Singapore (SGP1) data center region.

HandleHQ will notify the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the remaining period.

7. International transfers

Personal data is hosted in Singapore and may also be processed in the United States and other countries where HandleHQ or its sub-processors operate. Where personal data protected by the GDPR, UK GDPR, or Swiss data protection law is transferred to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two: controller to processor), which are incorporated into this DPA by reference, supplemented by the UK International Data Transfer Addendum or Swiss adaptations where applicable. Where a sub-processor performs the transfer, HandleHQ ensures an equivalent transfer mechanism is in place.

8. Assistance and breach notification

  • HandleHQ will assist the Customer, taking into account the nature of the processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Requests received directly from end-customers are forwarded to the Customer promptly and are not answered directly except to direct the person to the Customer.
  • HandleHQ will assist the Customer with data protection impact assessments and consultations with supervisory authorities where required, considering the information available to HandleHQ.
  • HandleHQ will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's data, and will provide information reasonably needed for the Customer to meet its own notification obligations.

9. Audits

HandleHQ will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to written security questionnaires and summaries of relevant policies, at most once per 12-month period unless a supervisory authority requires otherwise or a breach has occurred. On-site audits are available where required by applicable data protection law, on at least 30 days written notice, during business hours, at the Customer's expense, and subject to confidentiality obligations.

10. Deletion and return of data

On termination or expiry of the Customer's subscription, HandleHQ will, at the Customer's choice, return or delete all personal data processed under this DPA within 30 days, unless law requires longer storage. Residual copies in encrypted backups are deleted in the normal backup rotation cycle and remain protected until deletion. On request, HandleHQ will confirm deletion in writing.

11. Liability and order of precedence

Liability under this DPA is subject to the limitations of liability in the Terms of Service. If this DPA conflicts with the Terms of Service, this DPA prevails with respect to the processing of personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.

12. Governing law and contact

This DPA is governed by the same law as the Terms of Service, except where the Standard Contractual Clauses or applicable data protection law require otherwise. Data protection contact: hello@handlehq.net. Formal legal notices: saifullah4khan@gmail.com.

© 2026 HandleHQ. All rights reserved.
Use cases About Contact Early access Dashboard Privacy Terms DPA Accessibility