Data Processing Addendum (DPA)

Data protection terms governing personal data processed via Digital Bridge Apps.

Last Updated: March 26, 2026

1. Scope & Purpose

This Data Processing Addendum (“DPA”) forms part of the agreement between Digital Bridge Apps (“Processor”) and the customer (“Controller”) where personal data is processed in connection with the services.

2. Roles & Responsibilities
  • Customer acts as Data Controller
  • Digital Bridge Apps acts as Data Processor
  • Processing occurs solely on documented customer instructions
3. Categories of Data
  • Phone numbers
  • Message content and metadata
  • WhatsApp identifiers and timestamps
  • End-user provided data via messaging channels
4. Security Measures
  • Encrypted communication (TLS / HTTPS)
  • Role-based access control
  • System monitoring and audit logging
  • Restricted internal access on a need-to-know basis
5. Sub-Processors

Digital Bridge Apps may engage subprocessors (e.g., cloud hosting, payment processors) under contractual confidentiality and security obligations.

A list of subprocessors may be provided upon reasonable request.

6. Data Retention & Deletion

Personal data will be retained only as long as necessary to provide services or as required by law. Upon termination, data may be deleted or returned upon request, subject to legal obligations.

7. Governing Law

This DPA is governed by the laws of the United Arab Emirates (UAE).