cosend Legal
Draft — pending legal review. This page states what Cosend does and is accurate to our specification. It has not yet been reviewed by counsel and is not a final agreement.

Data Processing Addendum

Last updated · v0.1

This Data Processing Addendum forms part of the Terms of Service between you ("Controller") and True North Tech Group LLC, Wyoming, USA ("Processor", "Cosend"). It applies automatically to every customer and needs no signature to be in force. §12 covers the case where your procurement team needs a countersigned copy.

Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.

1. Scope and roles

You are the controller of the personal data Cosend processes on your behalf. We are the processor. We process that data only to provide the service and only on your instructions.

For our own account and billing data we are the controller, and our Privacy Policy governs it. That data is outside this DPA.

2. Subject matter, duration, nature and purpose

ItemDetail
Subject matter Provision of WhatsApp coexistence, messaging, inbox, automation and connector services
Duration For as long as your account is active, plus the 30-day post-termination window in §11
Nature and purpose Receiving, sending, storing, routing, displaying and processing messages and related records so that you can communicate with your own customers and automate that communication
Categories of data subject Your customers and contacts who message you or whom you message; your own staff who use the Cosend dashboard
Categories of personal data Phone numbers, WhatsApp profile names, message content and media, message and conversation identifiers, delivery statuses, timestamps, contact records and custom fields you create, and whatever your own automations pass through a connector
Special categories Not requested and not required by the service. If your own use sends them through Cosend, you remain responsible for the lawful basis and for any Art. 9 condition

3. Instructions

We process personal data only on your documented instructions, which are: these terms, your configuration of the service, and any further written instruction you give us. We tell you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law.

If we are required by EU or member-state law to process beyond your instructions, we inform you of that requirement before processing, unless the law forbids it.

4. Confidentiality

Everyone we authorise to process your personal data is bound by a duty of confidentiality, and access is limited to those who need it to operate or support the service.

5. Technical and organisational measures

We implement measures appropriate to the risk, under Art. 32. The full description is at /security and this DPA incorporates it by reference — one description of our security that can drift is better than two. In summary:

We may change these measures, provided the level of protection is not reduced.

6. Sub-processing

You give general authorisation for us to engage sub-processors. The current list is published at /subprocessors with each sub-processor's purpose, the categories of data it can access and where it processes them. That page is generated from the same source the service is configured from, and the same list is available as JSON at /subprocessors.json.

We give at least 30 days' notice before adding or replacing a sub-processor, by email to your account's administrative contact. If you reasonably object on data-protection grounds within that period, tell us; if we cannot offer an alternative, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any prepaid fees.

We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

7. International transfers

Your database, API hosting and automation execution are in Germany. Sub-processors outside the EEA are marked as such at /subprocessors.

Where personal data is transferred out of the EEA or the UK, the European Commission's Standard Contractual Clauses (Decision 2021/914) apply and are incorporated into this DPA, with Module Two (controller to processor) for transfers from you to us and Module Three (processor to processor) for onward transfers to our sub-processors. For UK transfers, the UK International Data Transfer Addendum applies. The optional docking clause applies; the governing law and forum are those of the Republic of Ireland unless the exporter's member state requires otherwise; and the annexes to those clauses are populated by §2, §5 and §6 of this DPA.

8. Assistance and data subject requests

Taking into account the nature of the processing, we assist you with:

9. Breach notification

We notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting data we process for you. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we provide it in phases as it becomes available.

10. Audit

We make available the information necessary to demonstrate compliance with this DPA, and we allow and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice: for most requests, /security and this DPA are the answer. Where they are not, we will complete a reasonable security questionnaire. An on-site or remote inspection may be requested once in any 12-month period, on 30 days' notice, at your cost, subject to confidentiality, and scheduled so as not to disrupt the service — and immediately, without those limits, after a breach affecting your data.

11. Deletion and return

You can export your data at any time while your account is active. After termination we retain your data for 30 days so that you can export it, and then delete it. Deletion is hard deletion of the database row and the stored object, not a flag, and it propagates to backups as they age out under their own retention.

We retain what applicable law requires us to retain — billing and tax records in particular — and nothing else. Those records are listed in the retention table in our Privacy Policy.

12. Signature

This DPA is in force without a signature. Accepting the Terms of Service accepts it.

To keep a copy, print this page or save it as a PDF — it is laid out for it, and the version and date at the top identify exactly which text you accepted. You do not need to ask us for a file and you do not need to wait for one.

If your procurement process requires a countersigned copy, or a copy on your own paper, email privacy@cosend.app and we will sign and return it. That is a convenience, not a precondition — do not wait on it to start using Cosend.