Version 2.0 — July 1, 2026

Notice: This DPA applies to White Dot's business and enterprise customers who are subject to the GDPR, UK GDPR, or equivalent data protection laws. If you are an individual user, our Privacy Policy governs how we process your data.

1. Definitions

Capitalized terms used in this DPA have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679) where applicable.

2. Scope and Purpose

This Data Processing Agreement ("DPA") forms part of the Terms of Service between White Dot ("Processor") and the Customer ("Controller") when the Customer uses White Dot's services in a business or enterprise capacity. It sets out the terms governing the Processing of Personal Data by the Processor on behalf of the Controller.

3. Roles of the Parties

The Customer is the Controller of Personal Data processed under this DPA. White Dot is the Processor. White Dot processes Personal Data only on documented instructions from the Controller, unless required to do otherwise by applicable law.

4. Description of Processing

Categories of data subjects: End users of the Customer who use White Dot messaging services.

Categories of personal data: Phone numbers, display names, profile pictures, device identifiers, and encrypted message metadata.

Special categories of data: None. White Dot's architecture prevents processing of special category data as all message content is end-to-end encrypted and inaccessible.

Processing operations: Collection, storage, transmission, and deletion of the above data for the purpose of providing messaging services.

5. Processor Obligations

White Dot shall:

6. Data Subject Rights

White Dot shall assist the Controller in fulfilling its obligations to respond to data subject requests under Chapter III of the GDPR. Because of White Dot's zero-knowledge architecture:

7. Subprocessing

The Controller provides general authorization for White Dot to engage Subprocessors. A current list of Subprocessors is maintained at whitedot.chat/subprocessors. White Dot shall notify the Controller at least 30 days before adding or replacing any Subprocessor.

8. Technical and Organizational Measures

White Dot maintains the following security measures:

9. Security Breach Notification

White Dot shall notify the Controller within 48 hours of becoming aware of a Personal Data breach. The notification shall include:

10. Data Retention and Deletion

Upon termination of the Service, White Dot shall delete all Personal Data within 30 days, unless retention is required by applicable law. Encrypted messages that have been delivered may be deleted from servers within 7 days of delivery.

11. Governing Law

This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising under this DPA shall be resolved in the courts of Kota, Rajasthan.

12. Contact

For DPA requests or questions:

Email: dpo@whitedot.chat