Skip to main content
Waaru
Legal

Data Processing Agreement

Effective date: 17 May 2025 · Last updated: 10 August 2026

1. Parties and scope

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Narayana Nexus (“Waaru”, “Processor”), and the business or individual (“Customer”, “Controller”) accessing the Waaru platform at waaru.app.

This DPA covers the processing of personal data performed by Waaru on behalf of the Customer in connection with the provision of the Waaru WhatsApp automation platform. By accepting Waaru’s Terms of Service, the Customer accepts this DPA.

2. Nature and purpose of processing

Waaru processes personal data to provide the following services on behalf of the Customer:

  • Receiving, storing, and routing WhatsApp messages between the Customer’s WhatsApp Business number and their contacts
  • Running automation flows triggered by incoming or outgoing messages
  • Storing contact records, conversation history, and form submissions in the Customer’s workspace
  • Delivering outbound messages (broadcasts, notifications) to opted-in contacts
  • Running customer, order, fulfilment, product, inventory, and location actions against a Shopify store that the Customer explicitly connects
  • Matching a WhatsApp contact to a Shopify customer by customer ID, exact email or phone, or bounded name search, and returning address details when the Customer's configured support workflow requests them

3. Categories of personal data processed

Depending on the Customer’s use of the platform, Waaru may process the following categories of data belonging to the Customer’s end contacts:

  • WhatsApp phone number
  • Display name as provided to or by WhatsApp
  • Message content (text, media, documents)
  • Structured form responses submitted via WhatsApp Flows
  • Message timestamps and delivery status
  • Connected-store customer identifiers, name, email address, phone number, and bounded address details
  • Connected-store order, fulfilment, product, inventory, and location data returned by an action the Customer invokes

Waaru does not knowingly process special category data (health, financial, biometric) unless the Customer explicitly configures workflows to collect such data. In that case, the Customer remains the Controller and is solely responsible for maintaining a lawful basis for that processing.

Waaru exposes reviewed connected-service actions rather than an unrestricted provider API proxy. It refuses ambiguous customer matches and limits customer search results to the default address; an explicit profile action can return up to ten addresses for the selected customer.

4. Data processing obligations

Waaru agrees to:

  • Process personal data only on documented instructions from the Customer, as configured in the Waaru platform
  • Ensure that personnel with access to personal data are bound by confidentiality obligations
  • Implement and maintain appropriate technical and organisational security measures as described in Section 5
  • Assist the Customer in responding to data subject access, correction, and erasure requests to the extent technically feasible
  • Delete personal data in accordance with the retention periods in Section 8
  • Notify the Customer without undue delay upon becoming aware of a personal data breach that affects the Customer’s data

5. Security measures

Waaru implements the following technical and organisational security measures:

  • Encryption of data in transit using TLS 1.2 or higher on all connections
  • Encryption of data at rest via AES-256 encryption on the underlying database
  • Row-level workspace isolation — no Customer’s data is accessible to another Customer’s workspace
  • Webhook signature verification using timing-safe comparison on all incoming events
  • Role-based access control with principle of least privilege
  • Short-lived authenticated sessions with JWT token expiry

6. Sub-processors

Waaru uses the following sub-processors to deliver the service. By accepting the Terms of Service, the Customer provides general authorisation for these sub-processors:

Sub-processorRoleData processed
Meta Platforms Ireland LimitedWhatsApp Cloud API — message delivery and receiptMessage content, phone numbers, media
Amazon Web Services (AWS)Environment-isolated cloud infrastructure, PostgreSQL, and storageCustomer workspace data
Vercel Inc.Public website hosting and deploymentWebsite request metadata and lead submissions
Google LLCGoogle OAuth authentication, where selectedCustomer name and email for authentication
Resend Inc.Transactional and authentication email deliveryCustomer email addresses
Cloudflare Inc.DNS proxy, DDoS protection, and security filtering, where applicableIP addresses, request metadata

Waaru will notify Customers via email at [email protected] at least 14 days before any new sub-processor begins processing Customer data.

7. International data transfers

Waaru isolates its AWS environments. Staging currently runs in the United States (us-east-1); production is designed for the Mumbai, India Region (ap-south-1) before production customer data is accepted. Some sub-processors listed above operate outside India and may process data internationally as part of delivering their services. Waaru ensures that such transfers are subject to appropriate contractual safeguards in accordance with the Digital Personal Data Protection Act, 2023.

No claims are made regarding processing within any specific jurisdiction outside India.

8. Data retention and deletion

Waaru retains Customer data while the account is active. After a verified account closure or termination, data is retained for 30 days, then permanently deleted, subject to applicable legal obligations.

Customers can submit a scoped deletion request at waaru.app/data-deletion. Waaru verifies the submitted email and reviews workspace authority, other users' data, and legal-retention duties before deleting data. Requests may also be submitted to [email protected].

Any payment records are retained as required by applicable tax and accounting law, regardless of account status.

Terminal connected-service action records and provider event receipts are retained for up to 90 days. Retired credential versions and expired OAuth authorisation sessions are removed after 7 days. Active provider credentials remain encrypted and are used only while the connection is active.

9. Changes to this DPA

Material changes to this DPA will be communicated by email at least 14 days before they take effect, consistent with Waaru’s Terms of Service.

10. Contact

For questions about this DPA, data subject requests, or to report a security incident:

Email: [email protected]

Narayana Nexus, Gondia, Maharashtra, India