Data Processing Agreement
Updated May 2026
This Data Processing Agreement (DPA) is entered into between Amargi Creative (the Processor) and the customer subscribing to Amargi Reach or any other Amargi product (the Controller), and forms part of the Terms of Service. This page is the standard template. The executed version is signed alongside the commercial contract; a countersigned copy is available on request to contracts@amargicreative.com.
Definitions
Capitalised terms not defined here have the meaning given in the General Data Protection Regulation (EU) 2016/679 (GDPR) or the Terms of Service. Personal Data means information relating to an identified or identifiable natural person processed by Amargi Creative on behalf of the Customer, including contact names, phone numbers, email addresses, and message contents. Sub-processor means a third party engaged by Amargi Creative to process Personal Data on behalf of the Customer.
Scope and roles
The Customer is the Controller of Personal Data uploaded to or generated through Amargi Reach. Amargi Creative is the Processor and processes Personal Data only on documented instructions from the Customer, as defined in the Terms of Service and any usage of the API or admin panel.
Categories of data subjects and data
Data subjects include the Customer's end users and the Customer's own employees who use the admin panel. Contact identifiers include name, phone number, email address, WhatsApp ID, and Instagram handle. Communication content includes message bodies (text, media, locations, and contacts shared in messages), template names, and response timestamps. Operational metadata includes delivery status, read receipts, conversation state, quality ratings, and opt-in and opt-out records. Authentication data includes hashed passwords (Argon2id), TOTP secrets (AES-encrypted at rest), and session identifiers. Amargi Creative does not ask the Customer to upload, and does not knowingly process, any GDPR Article 9 special-category data (health, biometrics, political opinions, etc.). The Customer is responsible for ensuring it does not transmit such data through the products.
Duration
Personal Data is processed for the duration of the Customer's subscription. Upon termination, Personal Data is deleted within 30 days from primary storage and within 90 days from backups.
Processor obligations
Amargi Creative will: (1) Process Personal Data only on the Customer's documented instructions, and notify the Customer if any instruction violates applicable law. (2) Ensure personnel authorised to process Personal Data have committed to confidentiality. (3) Implement appropriate technical and organisational measures as detailed in Section 8. (4) Assist the Customer in fulfilling data subject rights as detailed in Section 7. (5) Notify the Customer within 48 hours of becoming aware of a Personal Data breach affecting their data. (6) On termination, delete or return all Personal Data, at the Customer's choice.
Sub-processors
The Customer authorises Amargi Creative to engage the sub-processors listed at https://amargicreative.com/legal/subprocessors. That page is the single canonical list; no other copy of it is maintained anywhere, so that the list a Customer reads is always the current one. Amargi Creative will notify the Customer at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds; if unresolved, the Customer may terminate the affected service with a pro-rata refund of pre-paid fees.
Data subject rights
Amargi Reach provides programmatic endpoints that allow the Customer to fulfil data subject requests directly. Access and portability is available via POST /api/v1/privacy/export, which returns a machine-readable archive of the requested contact's conversations, messages, and metadata. A contact is withdrawn via DELETE /api/v1/contacts/{contact_id}, which removes that contact and its history from every view in the account immediately. The underlying message rows are retained rather than erased, and media attachments expire separately on the Customer's own media retention schedule, 90 days by default. Where a data subject requires erasure rather than withdrawal, the Customer should send the request to contact@amargicreative.com; Amargi Creative carries out the erasure within 30 days and confirms it in writing. Rectification, restriction, and objection are surfaced in the admin panel under the contact's profile. If a data subject contacts Amargi Creative directly, we forward the request to the Customer within 5 business days and assist without independent action as directed.
Technical and organisational measures
Full details are in the Privacy Posture document. Summary of measures: TLS 1.2+ for all public endpoints with automatic Let's Encrypt certificate rotation and HSTS preload-eligible headers. High-sensitivity fields (Meta access tokens, TOTP secrets, OAuth refresh tokens) are encrypted at the application layer through a secret resolver whose key ring is held outside the database, so a database dump on its own does not yield usable credentials. Tenant isolation via row-level partner_id filters, RBAC, and least privilege for operator accounts. Argon2id password hashing with server-side pepper, TOTP 2FA available, and short-lived access tokens plus rotating refresh tokens. Audit logging of every administrative action with 12-month minimum retention. X-Hub-Signature-256 verification on every inbound provider webhook. Nightly database backups at 02:30 UTC, 14 daily and 8 weekly sets retained inside the same EU region, every run verified by reading the archive back in full, and restores rehearsed against a written runbook.
Audits
Once per calendar year with 30 days' notice, the Customer may request a security audit. Amargi Creative will satisfy this by providing the most recent SOC 2 or ISO 27001 report under NDA (if available), completing a documented questionnaire (CAIQ, VSA-Full) within 30 days, or permitting a remote audit at the Customer's expense by a mutually-agreed independent auditor.
International transfers
Personal Data of EU and UK data subjects transferred outside the EU and UK is governed by the EU Standard Contractual Clauses (Module 2, Controller to Processor, June 2021 version), incorporated by reference. Sub-processors in third countries are bound by equivalent SCCs.
Requests from public authorities
Amargi Creative has never received a request from a public authority for Personal Data processed under this DPA. If one is received, Amargi Creative will: (1) Review the legality of the request before any Personal Data is accessed, and refuse any request that does not identify a valid legal instrument compelling disclosure. (2) Challenge any request it considers unlawful or wider than the power relied on, including by refusing and requiring the authority to enforce the request through a court. (3) Disclose only the minimum Personal Data that answers the order, never bulk data, and never direct or standing access to its systems. (4) Record the request, its legal reasoning, every person involved, and exactly what was disclosed. (5) Direct the authority to the Customer as Controller wherever the request is properly addressed to the Customer, and notify the Customer without undue delay unless legally prohibited from doing so.
The full procedure, including who inside Amargi Creative is accountable and what is entered in the register, is published at https://amargicreative.com/legal/authority-requests and forms part of this DPA.
Liability
Liability for breaches of this DPA is capped at the limits in the underlying Terms of Service, except as permitted by applicable law.
Governing law
This DPA is governed by the laws of the Hashemite Kingdom of Jordan. For EU and UK data subjects, GDPR (or UK GDPR) applies as the substantive data-protection regime regardless of governing law.
Order of precedence
In the event of conflict between this DPA and the Terms of Service, this DPA prevails with respect to Personal Data processing. In the event of conflict between this DPA and the EU Standard Contractual Clauses, the SCCs prevail.
Contact
Data protection inquiries, breach notifications, and DPA execution requests should be sent to contact@amargicreative.com. Commercial contract questions should be sent to contracts@amargicreative.com.