Legal

Data Processing Addendum

Version 2026-10-10 · Last updated 10 October 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between ZaLink LLC ("ZaLink") and the business using ZaLink AI ("the Customer"). It applies when ZaLink processes personal data on the Customer's behalf, and it is written to meet the requirements of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) for agreements between a controller and a processor.

1. Roles

For the personal data of the Customer's own customers and contacts (the "Customer Data"), the Customer is the controller and ZaLink is the processor. ZaLink is a controller only for its own account, billing and website data, which is covered by its Privacy Policy. Annex 1 describes the processing.

2. Processing only on the Customer's instructions

ZaLink processes Customer Data only to provide ZaLink AI as described in the Terms, as configured by the Customer in the app (for example its AI settings, reply mode, campaigns and connected systems), and as the Customer otherwise instructs in writing. ZaLink does not use Customer Data for its own purposes, does not sell it, and does not use it to train AI models. If ZaLink believes an instruction breaks the law, it will tell the Customer.

ZaLink may process Customer Data where the law requires it; if so, it will tell the Customer first unless the law forbids that.

3. The Customer's responsibilities

  • having a lawful basis for the processing, and giving its customers a privacy notice that covers the use of ZaLink and its service providers (including WhatsApp messaging and AI processing) and processing outside the UAE;
  • obtaining and recording opt-in consent for marketing campaigns, and acting on opt-outs;
  • deciding whether ZaLink is suitable for any special-category data, such as health data, and obtaining any regulatory approval this requires (see the healthcare section of the Terms);
  • configuring ZaLink so that people can reach a member of staff and are not subject to significant automated decisions without human involvement.

4. Confidentiality and personnel access

Only authorised ZaLink personnel who need it can access Customer Data, and only to provide support, keep the service secure, investigate problems, or comply with the law. They are bound by confidentiality obligations.

5. Security

ZaLink applies the technical and organisational measures in Annex 2 and keeps them under review. ZaLink may improve them over time but will not reduce the overall level of protection.

6. Subprocessors

The Customer authorises ZaLink to engage subprocessors in the categories described in Annex 3 and on the Service Providers & Subprocessors page. ZaLink keeps a current Subprocessor Schedule that names each subprocessor, what it does and where it processes data, and provides it to the Customer on request. ZaLink remains responsible for its subprocessors' processing of Customer Data and is putting in place, with each of them, written data-protection terms that protect the data at least as well as this DPA requires. ZaLink will update the Schedule, and tell Customers who have asked to be notified, at least [number of days — to be confirmed] days before a new subprocessor starts processing Customer Data. If the Customer reasonably objects on data-protection grounds, the parties will discuss it in good faith; if they cannot resolve it, the Customer may cancel the affected service and receive a refund of fees paid in advance for the period after cancellation.

The WhatsApp platform processes WhatsApp messages under the business terms the Customer accepts directly with the platform. Systems the Customer chooses to connect (such as a point-of-sale system) act under the Customer's own agreement with them and are not ZaLink's subprocessors.

7. Transfers outside the UAE

Customer Data is stored in Singapore and processed by subprocessors on their global infrastructure, as shown on the Subprocessors page. For these transfers ZaLink relies on contractual data-protection terms with its subprocessors, which it is putting in place with each of them. The Customer acknowledges these locations and is responsible for informing its customers of them.

8. Help with requests from individuals

ZaLink provides in-app tools for the Customer to find, export, correct and delete data (described on the Data Requests & Deletion page) and will help with anything those tools do not cover. If ZaLink receives a request directly from one of the Customer's customers, it will pass it on to the Customer without undue delay and will not answer it itself unless the Customer asks.

9. Security incidents

ZaLink will notify the Customer without undue delay, and in any case within [number of hours — to be confirmed] hours, after becoming aware of a security incident affecting Customer Data. The notice will describe what happened, the data and people likely affected, the likely consequences, and the measures taken or proposed, with further details as they become available. ZaLink will help the Customer meet any obligation it has to notify the authorities or affected people.

10. Impact assessments and information

ZaLink will provide the information reasonably needed for the Customer to carry out a data-protection impact assessment, to show compliance with this DPA, and to answer a competent authority. ZaLink keeps a record of the processing it carries out for customers. Any audit beyond written information will be agreed in advance, on reasonable notice and at the Customer's cost, and must not compromise other customers' data.

11. When the service ends

After the subscription ends, the Customer may ask for a copy of its Customer Data in a common machine-readable format and for it to be deleted. On a confirmed deletion request, ZaLink deletes the Customer's workspace data as described on the Data Requests & Deletion page, except where the law requires it to be kept. Copies in backups and system logs are removed as these expire. [period after which data of ended workspaces is deleted without a request, if any — to be confirmed].

12. Liability and order of precedence

The limitation of liability in the Terms applies to this DPA. If this DPA conflicts with the Terms on data protection, this DPA wins.

13. Annex 1: Description of the processing

Subject matter and durationProviding ZaLink AI to the Customer, for as long as the Customer's workspace exists.
Nature and purposeReceiving, storing and sending WhatsApp messages; generating AI replies; understanding voice notes and images; managing contacts, escalations, campaigns, appointments, orders and the knowledge base; producing alerts to the Customer's staff; support and security.
People concernedThe Customer's customers and prospective customers who message it or are contacted by it; people named in the Customer's knowledge base; the Customer's staff.
Types of personal dataWhatsApp numbers and profile names; contact details and notes added by the Customer; message content, voice notes and transcripts, images, documents and other media; advertisement information that started a conversation; appointments, orders and sales opportunities; marketing opt-in and opt-out status; AI results.
Sensitive dataNot requested by ZaLink, but customers may include it in messages (for example health information in messages to a clinic). The Customer controls whether it collects such data.
RetentionAs set out in the Privacy Policy: workspace data is kept until the Customer deletes it or the workspace is deleted; the full technical AI output for each message is cleared after 14 days.

14. Annex 2: Security measures

  • Every workspace's records carry a workspace identifier, and database access rules (row-level security) are enabled on every application table so that users can only reach their own workspace's data. Server functions also filter by workspace.
  • Role-based access within each workspace (administrators, including the owner, and support staff).
  • A new workspace owner must confirm their email address with a one-time code before the workspace is created. Passwords are stored only in hashed form by the sign-in service.
  • Stored files are kept in private storage. Customer media is served only through links that expire after one hour, and knowledge-base files are available only to signed-in members of the workspace.
  • Encrypted connections (HTTPS/TLS) to the app and APIs. The cloud infrastructure provider encrypts stored data.
  • Incoming WhatsApp webhooks are accepted only with a valid signature from the WhatsApp platform.
  • Credentials for connected point-of-sale systems are stored in a dedicated secrets vault.
  • Retrieved knowledge-base content is checked for known AI-manipulation phrases; a match sends the reply to staff review instead of sending it automatically.
  • A log of high-risk actions (such as changes to subscriptions, WhatsApp connections, AI reply mode, knowledge and team membership) is kept for 90 days.
  • The full technical AI output for each message is cleared after 14 days.
  • Access to all workspaces is limited to a small number of authorised ZaLink administrators.
  • Database and file storage are hosted by our cloud infrastructure provider in Singapore.

15. Annex 3: Subprocessors

ZaLink uses subprocessors in these categories: cloud infrastructure and hosting service providers (the infrastructure the ZaLink platform runs on: database, file storage, sign-in and server functions, hosted in Singapore); AI processing service providers (the AI processing used by ZaLink AI); communications and messaging service providers (WhatsApp messaging); payment processing service providers (once online payment is active); and security, email and operational service providers.

The Subprocessor Schedule (each subprocessor's name, function and processing location) is provided to the Customer on justified request, or as required by applicable law or contract, at support@zalink.ai.

16. Contact

Questions about this DPA: support@zalink.ai.