Data Processing Addendum (DPA)
Effective Date: September 1, 2026
Last Updated: September 1, 2026
This Data Processing Addendum ("DPA") supplements and forms an integral part of the Peach Terms of Service available at /legal/terms (the "Agreement") entered into by and between Peach AI ("Peach", "Processor", or "We") and the entity or individual customer agreeing to these terms ("Customer", "Controller", or "You").
This DPA governs the Processing of Personal Data in connection with the services provided by Peach (including Peach CoPilot, Peach Core, and related APIs, collectively the "Services").
1. Definitions
1.1. "Applicable Data Protection Law" means all worldwide privacy and data protection laws and regulations applicable to the Processing of Personal Data under the Agreement, including the European Union General Data Protection Regulation 2016/679 ("GDPR"), the UK Data Protection Act 2018 / UK GDPR, and the Swiss Federal Act on Data Protection.
1.2. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", and "Special Categories of Data" shall have the meanings given to them in the GDPR.
1.3. "Customer Personal Data" means any Personal Data Processed by Peach on behalf of Customer in the course of providing the Services.
1.4. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries (Module 2: Controller-to-Processor), incorporated herein by reference.
1.5. "Subprocessor" means any third party engaged by Peach to Process Customer Personal Data in connection with the Services.
2. Scope and Roles of the Parties
2.1. Roles: The parties acknowledge and agree that with respect to the Processing of Customer Personal Data, Customer is the Controller and Peach is the Processor.
2.2. Customer Responsibilities: Customer warrants that it has provided all necessary notices and obtained all necessary consents, legal bases, and authorizations required under Applicable Data Protection Law to transfer Customer Personal Data to Peach for Processing.
2.3. Peach Responsibilities: Peach shall Process Customer Personal Data solely on behalf of Customer and in accordance with Customer's documented instructions, including as specified in the Agreement, this DPA, and through Customer's configuration and use of the Services, unless required to do so by applicable law.
3. Details of Data Processing (Annex I.B)
- Subject Matter & Nature of Processing: Provision of messaging indexing, synchronization, search, draft generation, and workflow automation services via official WhatsApp Business APIs and customer-enabled connectors.
- Duration: The term of Customer’s active subscription or workspace under the Agreement, plus retention periods until data deletion is requested or completed.
- Categories of Data Subjects: Individuals who communicate with Customer via WhatsApp, including Customer’s customers, prospective clients, donors, volunteers, employees, contractors, and partners.
- Categories of Personal Data: Contact information (names, phone numbers, WhatsApp IDs, profile avatars), message content (text, timestamps, direction, metadata, audio/document/image attachment URLs), and interaction logs.
- Special Categories of Data (Article 9 GDPR): Peach does not intentionally solicit or require Special Categories of Data. To the extent Customer or end-users incidentally transmit Special Categories of Data in communications, Peach Processes such data solely as an encrypted conduit under Customer’s instructions, with zero profiling or proprietary model training.
4. Subprocessors
4.1. Authorized Subprocessors: Customer provides general written authorization for Peach to engage the Subprocessors listed in the Peach Subprocessor Directory (/legal/subprocessors).
4.2. Obligations on Subprocessors: Peach imposes data protection terms on each Subprocessor that provide at least the same level of protection as those contained in this DPA. Peach remains responsible for the acts and omissions of its Subprocessors.
4.3. Customer-Configured Direct Integrations: For clarity, third-party AI platforms (e.g., OpenAI/ChatGPT or Anthropic/Claude) or webhook endpoints configured directly by the Customer via Model Context Protocol (MCP), OAuth, or custom API endpoints are independent tools selected and operated under Customer’s direct instructions and accounts, and do not constitute Peach Subprocessors.
5. Security Measures (Article 32 GDPR / Annex II)
Peach implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:
- Encryption: Encryption of all data in transit using TLS 1.3 and at rest using industry-standard AES-256 encryption.
- Tenant Isolation: Logical separation of customer data within databases ensuring strict tenant boundaries.
- Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA) for administrative access, and strict least-privilege policies.
- Resilience & Backups: Automated backups, redundancy across secure cloud data centers, and continuous system monitoring.
6. Personal Data Breaches
6.1. Peach shall notify Customer without undue delay (and in any event within 48 hours) upon becoming aware of a confirmed Personal Data Breach impacting Customer Personal Data.
6.2. Peach shall take prompt remedial action to mitigate the effects and provide reasonable assistance to Customer in meeting its breach notification obligations under Applicable Data Protection Law.
7. International Data Transfers & Standard Contractual Clauses
7.1. Transfer Mechanism: Where the Processing of Customer Personal Data involves a transfer from the EEA, Switzerland, or the UK to a third country not recognized as providing an adequate level of data protection, the parties agree to be bound by the EU Standard Contractual Clauses (Module 2: Controller to Processor).
7.2. SCC Specifications:
- Clause 7 (Docking Clause): Optional docking clause applies.
- Clause 9 (Use of Subprocessors): Option 2 (General written authorization) applies with a 14-day notice period.
- Clause 11 (Redress): Optional redress mechanism is not selected.
- Clause 17 & 18 (Governing Law & Jurisdiction): The laws and courts of the Republic of Ireland shall govern.
8. Data Subject Rights & Assistance
8.1. Peach shall, taking into account the nature of the Processing, provide reasonable assistance to Customer to enable Customer to respond to requests from Data Subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, and objection).
8.2. If Peach receives a request directly from a Data Subject, Peach shall advise the Data Subject to submit their request directly to Customer.
9. Deletion and Return of Personal Data
9.1. Upon termination of the Agreement or upon Customer’s request via the Peach Dashboard, Peach shall delete or return all Customer Personal Data within 30 days, unless applicable law requires retention.
9.2. Customer may also utilize granular deletion controls within the Services (or configure Sync Exclusions) to permanently remove specific contacts or conversation histories.
10. Contact Information
For inquiries regarding this DPA, data protection, or compliance, please contact:
Peach AI Legal & Privacy Team
Email: legal@trypeach.ai / privacy@trypeach.ai
Address: Plot no 77, Sy No 150, EPIP Layout, Whitefield, Bangalore, Karnataka, India 560066