This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between the Customer (the "Controller") and MetaGrad Labs Private Limited, trading as OptimReach (the "Processor"), under which OptimReach provides WhatsApp automation, CRM, and business communication services (the "Services").
The Standard Contractual Clauses referenced herein are those issued under EU Commission Implementing Decision 2021/914 of 4 June 2021 (Module 2: Controller to Processor), available at eur-lex.europa.eu. To execute signed SCCs, email privacy@optimreach.in.
1. Definitions
- "Personal Data" - any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws.
- "Processing" - any operation or set of operations performed on Personal Data.
- "Data Protection Laws" - EU GDPR, UK GDPR, India DPDP Act 2023, and any other applicable data protection legislation.
- "Sub-processor" - a third party engaged by OptimReach to process Personal Data to deliver the Services.
- "Standard Contractual Clauses (SCCs)" - EC Implementing Decision 2021/914 of 4 June 2021.
2. Scope and Purpose
This DPA governs OptimReach's processing of Personal Data provided by the Controller as part of the Services. OptimReach shall process Personal Data only on documented instructions from the Controller, for the purpose of providing the Services as described in the Agreement.
3. Categories of Personal Data and Data Subjects
| Category | Examples |
|---|---|
| Customer account holders | Name, email, phone, company, role |
| End users (Customer's WhatsApp contacts) | WhatsApp phone number, name, message content, order data, appointment details, opt-in status |
| Customer staff / agents | Name, email, role, conversation activity |
4. Duration of Processing
OptimReach will process Personal Data for the duration of the Agreement. Upon termination, OptimReach will, at the Controller's election, return or delete all Personal Data within 90 days, except where retention is required by applicable law.
5. Controller's Obligations
- The Controller warrants it has a valid lawful basis under applicable Data Protection Laws to provide Personal Data to OptimReach for processing.
- The Controller is responsible for providing appropriate privacy notices to its End Users.
- The Controller shall promptly notify OptimReach of any revocation of consent by a Data Subject.
- The Controller shall promptly notify OptimReach of any data subject rights requests, regulatory enquiries, or data breach notifications relating to data processed under this DPA.
6. Processor's Obligations
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
- Ensure personnel authorised to process Personal Data are bound by appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organisational security measures (see Section 9).
- Assist the Controller in responding to Data Subject rights requests to the extent reasonably possible.
- Notify the Controller within 72 hours upon becoming aware of a Personal Data Breach.
- Provide all information reasonably necessary to demonstrate compliance with this DPA and cooperate with audits.
- Delete or return Personal Data at the end of the Agreement as instructed by the Controller.
7. Sub-processors
The Controller grants general authorisation to OptimReach to engage Sub-processors. The current list is at optimreach.in/sub-processors. OptimReach will notify the Controller at least 14 days before adding a new Sub-processor. The Controller may object within that period by emailing privacy@optimreach.in. All Sub-processors are bound by data protection obligations no less protective than this DPA.
8. International Data Transfers
Where Personal Data is transferred outside the EEA or UK, such transfers are governed by the Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2: Controller to Processor) and/or the UK International Data Transfer Addendum (IDTA), as applicable, incorporated into this DPA by reference.
To request a signed copy of the SCCs: privacy@optimreach.in.
9. Technical and Organisational Measures (TOMs)
Encryption
- AES-256-GCM encryption for all sensitive credentials at rest (access tokens, app secrets, verify tokens)
- TLS 1.2 or higher for all data in transit
- SHA-256 one-way hashing for lookup tokens and API keys
Access Controls
- Role-based access control (RBAC) with least-privilege principles
- Multi-tenant data isolation - each workspace's data is logically and technically separated
- JWT-based authentication for all staff and admin sessions
- API key authentication with hashed key storage - plaintext keys never persisted
Operational Security
- Webhook HMAC-SHA256 signature verification for all inbound Meta API events
- Inbound message deduplication to prevent replay processing
- Rate limiting on all public endpoints
- All schema changes are managed through versioned Flyway migrations. No ad-hoc DDL is used in production.
Incident Response
- Personal Data Breaches notified to the Controller within 72 hours of discovery
- Breach notifications include: nature of breach, categories and approximate number of affected data subjects, likely consequences, and measures taken
10. Audit Rights
Upon 30 days' prior written notice, the Controller may conduct, or commission a third party to conduct, an audit of OptimReach's processing activities. OptimReach will provide reasonable cooperation. The Controller bears the cost of the audit. Any audit must not disrupt OptimReach's operations.
11. Personal Data Breach Notification
OptimReach shall notify the Controller without undue delay, and where feasible within 72 hours, upon becoming aware of a Personal Data Breach. Notification will be sent to the email address on the Customer account.
To report a security issue: security@optimreach.in
12. Return and Deletion
Within 90 days following termination or expiry of the Agreement, OptimReach will, at the Controller's election: (a) return all Personal Data in a commonly used format; or (b) securely delete all Personal Data and certify deletion in writing. Copies held in automated backups will be deleted within 30 days of the scheduled backup deletion cycle.
13. Governing Law
This DPA is governed by the laws of India, except where applicable Data Protection Laws (including EU GDPR / UK GDPR) require the application of other law, in which case those requirements prevail.
Contact: privacy@optimreach.in · MetaGrad Labs Private Limited, #9 MetaGrad Labs Pvt Ltd, Akilandeshwari Templedeva, Budigere, Bangalore Rural, Hoskote, Karnataka, India, 562129
