Legal

Data Processing Agreement

Last updated: July 30, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer”, acting as data controller) and Swiffer (acting as data processor) and applies whenever Swiffer processes personal data on the Customer’s behalf.

1. Definitions

“Personal data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given in the applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the UK GDPR.

2. Roles and scope

The Customer determines the purposes and means of processing. Swiffer processes personal data only on documented instructions from the Customer, including as set out in this DPA and as required to provide the service.

3. Nature and purpose of processing

Swiffer processes personal data to deliver messaging, CRM, marketing, support, automation, and analytics features requested by the Customer.

Categories of data subjects: the Customer’s end users, contacts, leads, customers, and authorised team members.

Categories of personal data: identifiers (name, phone number, email address), message and conversation content, account and usage metadata, and any other data the Customer chooses to submit.

4. Customer obligations

The Customer warrants that it has a valid legal basis for the processing, has provided all required notices, and has obtained any consents needed for the data it submits to Swiffer, including consents required for messaging channels such as WhatsApp.

5. Confidentiality

Swiffer ensures that personnel authorised to process personal data are bound by confidentiality obligations and receive appropriate data protection training.

6. Security measures

Swiffer implements appropriate technical and organisational measures, including encryption in transit and at rest, tenant isolation enforced at the database layer, role-based access control, least-privilege access to production systems, audit logging, and regular backups.

7. Sub-processors

The Customer grants general authorisation for Swiffer to engage sub-processors for hosting, infrastructure, messaging delivery, payments, and analytics. Swiffer imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains liable for their performance. Swiffer will give reasonable notice of new sub-processors so the Customer may object on legitimate grounds.

8. International transfers

Where personal data is transferred outside the EEA or the UK, Swiffer relies on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses together with any supplementary measures required.

9. Data subject rights

Taking into account the nature of the processing, Swiffer assists the Customer with responding to data subject requests for access, rectification, erasure, restriction, portability, and objection, using the tools available in the product and reasonable support where those tools are insufficient.

10. Personal data breaches

Swiffer notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and provides information reasonably available to support the Customer’s own notification obligations.

11. Audits

Swiffer makes available information reasonably necessary to demonstrate compliance with this DPA and allows for audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, on reasonable notice and subject to confidentiality.

12. Deletion and return of data

On termination of the service, Swiffer deletes or returns the Customer’s personal data in accordance with the retention periods described in the Privacy Policy, unless applicable law requires further storage.

13. Contact

For questions about this DPA or to request a signed copy, contact our privacy team through the contact page.