Data Processing Agreement (DPA)
Last updated: 2 September 2026
This Agreement is entered into between the Customer (the business using the WeHub service), acting as Controller, and [full registered company name], company number [ח.פ.], of [address], Israel ("WeHub", the "Processor"). It forms an integral part of the Terms of Service and applies automatically to every customer of the Service without separate signature. A customer requiring a signed counterpart may write to [[email protected]].
The Agreement is intended to satisfy the Israeli Protection of Privacy Law, 5741-1981 and Amendment No. 13 to it, the Protection of Privacy Regulations (Data Security), 5777-2017, and Article 28 of the GDPR with respect to data subjects in the European Union.
1. Subject matter and nature of the processing
WeHub processes personal data on the Customer's behalf in order to provide an omnichannel customer-communication service: receiving, storing, routing and displaying messages and conversations from WhatsApp, Instagram, Messenger, email and telephony; contact management; automation and routing rules; AI features the Customer has enabled; reporting; and notifications to the Customer's team.
2. Duration
For the term of the engagement, plus 30 days thereafter as an export window, and thereafter until deletion is completed under Section 9.
3. Categories of personal data
- Identifiers: phone number (E.164), email address, Messenger PSID, Instagram IGSID, name and profile picture from the channel.
- Communication content: message bodies in both directions, media (images, video, documents, voice messages), template-based messages.
- Metadata: timestamps, delivery statuses, channel, agent assignment, labels, conversation status, close reason.
- Telephony: call logs, duration, direction, extension, and recordings and transcripts where the Customer has enabled them.
- Customer-defined fields: custom contact-card fields, internal notes, tags.
- Consents and preferences: marketing opt-in and opt-out per channel, blocks.
- Feedback: customer satisfaction (CSAT) responses.
- Customer staff data: name, email, phone, role, department, extension, usage data and audit records.
The Customer shall not enter special-category data (such as health, biometric, criminal, political or religious data) into the Service unless it has notified WeHub in advance and appropriate safeguards have been agreed.
4. Categories of data subjects
- The Customer's End Customers and anyone contacting it through the connected channels.
- Suppliers, applicants and any third party the Customer chooses to communicate with through the Service.
- The Customer's employees and agents who use the Service.
5. Customer instructions
5.1 WeHub shall process personal data solely on the Customer's documented instructions, which are: the Terms of Service, this Agreement, the settings the Customer configures in the system, and its ongoing use of the interfaces and the API.
5.2 WeHub shall notify the Customer if, in its view, an instruction infringes data protection law, and may suspend performance of that instruction.
5.3 Processing beyond the instructions will occur only where required by law; in that case WeHub shall notify the Customer in advance, unless the law prohibits it.
5.4 The Customer warrants that it has a lawful basis for collecting the data and transferring it for processing, that it has provided the required notices to data subjects, and that it has obtained messaging consents as required under s.30A of the Israeli Communications Law and channel policies.
6. Confidentiality
WeHub shall ensure that anyone authorised to process the data on its behalf is bound by confidentiality in contract or by law, has received privacy training, and is granted access strictly on a need-to-know basis. Access rights are reviewed periodically and revoked on role change or departure.
7. Security measures
WeHub shall implement appropriate technical and organisational measures, including:
- Tenant isolation: every business record carries a business identifier, and all access passes through a data-access layer that enforces it; automated tests prevent code from bypassing that layer.
- Encryption: TLS in transit; AES-256-GCM for secrets and credentials at rest, cryptographically bound to the business identifier and field, so that ciphertext cannot be moved between customers.
- Access control: roles and visibility scopes enforced on the server on every request; two-factor authentication; the option to enforce 2FA and IP allow-listing at the customer level.
- Secrets and passwords: passwords hashed (bcrypt), session tokens stored hashed, secrets displayed masked.
- Media: stored without public access, reachable only through short-lived signed links.
- Audit logging of sensitive actions, including WeHub support access.
- Support access: time-limited sessions, visibly indicated in the interface, read-only by default, with write access only on customer approval or under a documented emergency procedure.
- Rate limiting, webhook signature verification, and redaction of secrets and message content from system logs.
- Encrypted backups with periodic restore testing [to be completed: frequency].
- Vulnerability management: dependency updates, code review, and penetration testing [to be completed: frequency and tester].
Full detail in Annex B.
8. Sub-processors
8.1 The Customer gives general authorisation to the sub-processors listed in Annex A.
8.2 WeHub shall engage each sub-processor under an agreement imposing obligations no less protective than those in this Agreement, and remains liable to the Customer for its sub-processors' acts.
8.3 Before adding or replacing a sub-processor, WeHub shall give the Customer at least 30 days' notice (by email to account administrators and on a dedicated page). The Customer may object on reasonable, substantiated grounds within that period; absent a resolution, it may cancel the affected portion of the subscription without penalty.
Annex A: Sub-processor list
| Provider | Service | Data categories | Location | |---|---|---|---| | Meta Platforms Ireland / Inc. | WhatsApp Cloud API, Instagram, Messenger | Message content, sender identifiers, metadata | Ireland / US | | Twilio Inc. | Telephony, numbers, SendGrid for email | Numbers, CDRs, recordings, email content | US / Europe | | Voicenter Ltd. | Telephony, extensions, voice agent | Numbers, CDRs, voice streams | Israel | | Cloudflare Inc. | Media storage (R2), CDN, infrastructure protection | Media, files | [to be completed: region] | | Anthropic PBC | Drafting suggestions, summaries, knowledge agent | Conversation excerpts per task | US | | OpenAI, L.L.C. | Complementary AI features (where enabled) | Conversation excerpts per task | US | | ElevenLabs Inc. | Speech synthesis (where enabled) | Text and audio segments | US | | Google LLC (Firebase) | Push notifications | Device token, notification title | US / global | | HYP / Yaad Sarig | Card processing | Payment details, token, status | Israel | | iCount | Accounting document issuance | Billing details | Israel | | Stripe, Inc. (optional) | International card processing | Payment details, status | US / Europe | | [Hosting provider] | Running servers and database | All Service data | [to be completed] |
9. Deletion and return
9.1 On termination the Customer has a 30-day window to export its data (a JSON archive together with media files) through the interface.
9.2 At the end of that window WeHub shall delete the personal data from production systems within [30 days] and from backup systems within [90 days], except data it is legally required to retain (for example accounting records for 7 years) and audit records without content.
9.3 Deletion of an individual contact at the Customer's request removes that contact's identities, conversations, messages and media; only an audit record remains.
9.4 A written deletion statement will be provided on request.
10. Assistance to the Customer
WeHub shall assist the Customer, to a reasonable extent and by appropriate means:
- Data subject requests (access, rectification, erasure, portability, objection): through the interface tools, and where necessary with manual assistance. A request that reaches us directly will be forwarded to the Customer within [5 business days] and will not be answered by us beyond an acknowledgement.
- Data protection impact assessments (DPIA) and prior consultation with a supervisory authority: by providing the necessary technical information.
- Security and incidents: as set out in Section 11.
11. Security incidents
11.1 WeHub shall notify the Customer of a security incident affecting its data without undue delay and no later than 72 hours after becoming aware of it.
11.2 The notice will include, so far as known at the time: the nature of the incident, the categories and approximate volume of data, the likely consequences, the measures taken and planned, and contact details. Further detail will follow as it becomes available.
11.3 Reporting to the supervisory authority and to data subjects is the Customer's responsibility as Controller; WeHub will assist with the necessary information.
11.4 WeHub will not issue a public statement identifying the Customer without coordinating with it, save where required by law.
12. Audit and demonstrating compliance
12.1 On request, WeHub shall make available the information needed to demonstrate compliance with this Agreement: a description of the security measures, a completed vendor questionnaire, and a summary of penetration-test findings [to be completed: whether certifications or audit reports exist].
12.2 An audit at WeHub's premises may take place once every 12 months, on 30 days' notice, during business hours, of reasonable scope, without prejudice to other customers' privacy and to system security, and subject to auditors signing confidentiality undertakings. Reasonable costs of an audit beyond that will be borne by the Customer.
12.3 A further audit is permitted after a material security incident or at the demand of a supervisory authority.
13. International transfers
13.1 Some sub-processors process data outside Israel and the European Economic Area.
13.2 Such transfers rely on an adequacy decision, EU Standard Contractual Clauses together with supplementary measures, or another lawful mechanism. Copies of the mechanisms are available on request.
13.3 With respect to Israel, transfers rely on the European Commission's adequacy decision [for counsel: verify its status at the time of publication].
14. Liability and miscellaneous
14.1 Subject to applicable law, the limitations of liability in the Terms of Service apply to this Agreement.
14.2 In case of conflict between this Agreement and the Terms of Service on data protection matters, this Agreement prevails.
14.3 This Agreement is governed by the laws of the State of Israel, and the courts of [Tel Aviv-Yafo] have exclusive jurisdiction.
Annex B: Description of security measures
Full logical isolation between customers at the database and data-access layers · TLS 1.2 or higher in transit · AES-256-GCM encryption of secrets bound to the customer identifier · key management with rotation support · role-based access control with visibility scopes · two-factor authentication · rate limiting and abuse protection · audit logging · signature verification on inbound channels · media served only through signed links · separation of development and production environments · encrypted backups · incident response procedures · staff training · code review and automated isolation tests before release.
Annex C: Contacts
- For WeHub: privacy officer, [privacy officer name], [[email protected]], [phone].
- For the Customer: the privacy contact configured in the account settings.
---
> Note: draft pending review by a licensed Israeli attorney (לתשומת-לב: טיוטה לבדיקת עורך-דין). Verify the sub-processor list, the deletion periods and the international transfer mechanisms against the actual implementation, and have the text approved by counsel before publication.