duhbi
  • How it works
  • Features
  • Pricing
  • Docs

Legal

Data Processing Agreement

Between Duhbi (Processor) and you, the seller (Controller). This forms part of the Terms of Service.

Last updated: 3 May 2026 · Effective: 3 May 2026 · Governs: all sellers using Duhbi to handle end-customer messages

1. Roles

You (the Seller) are the Data Controller for personal data sent by your end customers (your customers' messages, names, phone numbers, addresses, order details).

Duhbi is the Data Processor — we process that data only on your documented instructions, configured through the dashboard and the workflow you set up.

This DPA reflects Articles 28 and 32 of the GDPR and equivalent provisions in other applicable privacy laws (UK GDPR, Moroccan Law 09-08, Tunisia Law 63-2004, etc.).

2. Subject matter and duration

  • Subject matter: processing of personal data to operate a structured WhatsApp order-intake workflow.
  • Duration: for as long as you have an active Duhbi subscription, plus any post-termination period needed to return or delete data (max 30 days after termination).
  • Nature and purpose: automated message processing, AI-generated reply drafting, order recording, dashboard display, notifications.
  • Data subjects: end customers who message your WhatsApp Business number; your team members who use the dashboard.

3. Categories of data processed

CategoryExamples
IdentificationPhone number, WhatsApp display name, LID identifier
Communication contentInbound and outbound WhatsApp messages (text, audio, image)
Order dataCustomer name, address, city, items, quantities, price
Behavioural metadataConversation state, lead score, tags, ad referral source, timestamps
Operational logsMessage IDs, error logs, audit trails (for security)

We do not process special categories of data (Art. 9 GDPR). If your customers volunteer such information through their messages, we treat it as ordinary message content and will not single it out for special processing.

4. Duhbi's obligations as Processor

  • Process data only on your documented instructions (dashboard config + this DPA).
  • Ensure that personnel with access are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (Section 7).
  • Engage sub-processors only under written contracts that bind them to equivalent obligations (Section 5).
  • Assist you with data subject requests, DPIAs, and regulator inquiries to the extent reasonably possible.
  • Notify you of personal data breaches affecting your data without undue delay (Section 8).
  • On termination of services, delete or return your data within 30 days, except where retention is required by law.

5. Sub-processors

You authorise Duhbi to engage the following sub-processors:

Sub-processorPurposeRegionTransfer mechanism
Supabase, Inc.Database, authentication, file storageEU (Frankfurt)EU — n/a
Meta Platforms Ireland Ltd.WhatsApp Business Platform — message deliveryEU (Ireland)EU — n/a
Anthropic, PBCAI inference for reply generation (Claude)USAEU SCCs
Google LLCGoogle Sheets sync, Gemini AI inferenceEU / USAEU SCCs (where applicable)
OpenAI, L.L.C.Voice transcription (Whisper)USAEU SCCs
Hetzner Online GmbHApplication server hostingEU (Germany / Finland)EU — n/a

Duhbi will notify you of any new or replaced sub-processor at least 30 days in advance via email. You may object on reasonable grounds; if we can't accommodate the objection, you may terminate the affected service for your account.

6. International transfers

Where data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and supplementary measures as needed (encryption in transit and at rest, access logging, contractual restrictions).

7. Security measures (Art. 32)

Technical

  • TLS 1.2+ for all network traffic.
  • Encryption at rest for all databases and object storage.
  • AES-256-GCM for highly sensitive credentials (e.g., delivery carrier API keys).
  • Per-tenant authentication; cross-tenant access checks on every dashboard route.
  • Row-level isolation in the database; backend uses scoped service keys.
  • Rate limiting on inbound and outbound APIs.
  • Daily off-site database backups with point-in-time recovery (7-day window).

Organisational

  • Access to production data limited to engineers on a need-to-know basis.
  • Multi-factor authentication required for all admin and infrastructure accounts.
  • Audit logging of admin actions.
  • Vulnerability disclosure programme: security@duhbi.com.
  • Annual security review and policy update.

8. Personal data breach notification

If we become aware of a personal data breach that affects your data, we will notify you without undue delay — and in any case within 72 hours of becoming aware. The notification will include:

  • Nature of the breach and categories of data affected.
  • Approximate number of data subjects and records.
  • Likely consequences.
  • Measures taken or proposed to address the breach and mitigate harm.

Notifications are sent to the email on file for your account. You're responsible for keeping that address current.

9. Data subject rights

If an end customer contacts Duhbi to exercise their rights (access, rectification, erasure, portability, restriction, objection), we will refer them to you as the Controller. We'll also assist you in responding within statutory deadlines, including by providing technical means to:

  • Export an individual conversation and order history.
  • Delete a specific customer's data.
  • Restrict further processing of an individual.

10. Audits

You may audit Duhbi's compliance with this DPA once per year, with 30 days' written notice, during business hours, in a manner that does not disrupt operations. We may satisfy audit requests by providing recent third-party assessments (e.g., SOC 2, ISO 27001) when such reports become available.

11. Liability and termination

Liability under this DPA is governed by the limitations in our Terms of Service. This DPA terminates automatically when your subscription ends. Upon termination, we will delete your data within 30 days unless legal retention applies.

12. Conflicts and governing law

If there's a conflict between this DPA and the Terms of Service on a data-processing matter, this DPA prevails. Otherwise, the Terms of Service govern. Governing law: as set out in the Terms of Service.

13. Contact

Data protection questions: dpo@duhbi.com
Privacy: privacy@duhbi.com
Security incidents: security@duhbi.com

duhbi

A structured WhatsApp order-intake platform for e-commerce sellers. Built on Meta's official WhatsApp Business Platform.

Product

  • How it works
  • Features
  • Pricing
  • Docs

Resources

  • Documentation
  • Quickstart
  • Workflow
  • Meta compliance

Company

  • About
  • Contact
  • Blog
  • contact@duhbi.com
  • support@duhbi.com

Legal

  • Privacy
  • Terms
  • DPA
  • Acceptable use
  • Report abuse

© 2026 Duhbi. All rights reserved.

PrivacyTermsContact

Duhbi is an independent Meta Tech Provider. WhatsApp and the WhatsApp logo are trademarks of Meta Platforms, Inc.