Data Processing Agreement
Last updated: 19 July 2026
This Data Processing Agreement ("DPA") forms part of the WhiteBoar Terms & Conditions (the "Terms") between Conscious Digital MTÜ, a registered Estonian non-profit organization (registration number 80600079, registered address: Sakala tn 7-2, 10141 Tallinn, Estonia) ("WhiteBoar", the "processor") and the customer organization that accepts the Terms (the "Customer", the "controller"). The DPA is accepted together with the Terms; no separate signature is required.
This DPA sets out the parties’ agreement on the processing of personal data that WhiteBoar carries out on the Customer’s behalf in providing the Service, as required by Article 28(3) of the EU General Data Protection Regulation ("GDPR"). Capitalized terms not defined here have the meaning given in the Terms; "personal data", "processing", "data subject", "controller", "processor", "sub-processor", and "personal data breach" have the meanings given in the GDPR.
1. Scope and roles
This DPA applies to the personal data described in Section 2 that WhiteBoar processes on the Customer’s behalf. For that data, the Customer is the controller and WhiteBoar is its processor. For personal data WhiteBoar processes for its own purposes — such as managing accounts, billing, security, and improving the Service — WhiteBoar is an independent controller and the Privacy Policy applies instead of this DPA.
2. Details of processing
- Subject matter and purpose: operating the Service — inviting the Customer’s experts, collecting their contributions over WhatsApp, transcribing and enriching them, and drafting, managing, and publishing the content the Customer approves.
- Nature of processing: collection, recording, storage, transcription, translation, structuring, adaptation, retrieval, disclosure to the publishing destinations the Customer connects, and deletion.
- Duration: the term of the Customer’s use of the Service, until the personal data is deleted or returned under Section 11.
- Categories of data subjects: the Customer’s managers and staff who use the Service, and the experts and contributors the Customer invites.
- Categories of personal data: identification and contact details (name, email address, WhatsApp phone number), language and role, consent records, messages, voice notes, transcripts, and the content and metadata created from them.
The Service is not intended for special categories of personal data (Article 9 GDPR), and the Customer agrees not to submit or direct such data to it.
3. Instructions
WhiteBoar processes the personal data only on the Customer’s documented instructions — which consist of the Terms, this DPA, and the Customer’s configuration and use of the Service — unless processing is required by EU or member-state law to which WhiteBoar is subject; in that case WhiteBoar informs the Customer of the legal requirement before processing, unless the law prohibits it on important grounds of public interest.
WhiteBoar will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.
4. Confidentiality
WhiteBoar ensures that the persons it authorizes to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what each person needs to provide the Service.
5. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, WhiteBoar implements appropriate technical and organizational measures as required by Article 32 GDPR. These include encryption of data in transit, encryption of stored credentials, per-tenant isolation of Customer data enforced at the database layer, access controls with least-privilege scopes, and safeguards against server-side request forgery on URL ingestion and in-generation fetches.
6. Sub-processors
The Customer grants WhiteBoar general authorization to engage sub-processors for the processing described in this DPA. The sub-processors engaged at the date of this DPA are listed in Section 13.
WhiteBoar will give the Customer prior notice of any intended addition or replacement of a sub-processor — by updating the list on this page and notifying the Customer by email or in the Service — and a reasonable opportunity to object on justified data-protection grounds. If the parties cannot resolve a justified objection, the Customer may terminate its use of the affected part of the Service.
WhiteBoar imposes on each sub-processor, by contract, data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the sub-processor’s performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, WhiteBoar assists the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to data subjects’ requests to exercise their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection). If a data subject contacts WhiteBoar directly about data controlled by the Customer, WhiteBoar will refer the request to the Customer without undue delay.
8. Personal data breach
WhiteBoar notifies the Customer without undue delay after becoming aware of a personal data breach affecting the personal data processed under this DPA, and provides the information reasonably available to it under Article 33(3) GDPR — the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed — supplementing the notice as further information becomes available.
9. Impact assessments and consultation
Taking into account the nature of the processing and the information available to it, WhiteBoar provides reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, insofar as they relate to the processing under this DPA.
10. Audits and information
WhiteBoar makes available to the Customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits require reasonable prior notice, take place during business hours no more than once in any twelve-month period (except after a personal data breach or where required by a supervisory authority), are subject to confidentiality, and are at the Customer’s cost.
11. Deletion and return
Upon termination of the Customer’s use of the Service, WhiteBoar deletes or returns, at the Customer’s choice, the personal data processed under this DPA, and deletes existing copies within a reasonable period, unless EU or member-state law requires further storage. Limited records retained under a legal obligation (for example consent logs and billing records) remain protected under this DPA for as long as they are kept.
12. International transfers
WhiteBoar hosts personal data in the EU. Where a sub-processor processes personal data outside the EU/EEA, WhiteBoar ensures the transfer is covered by an adequacy decision of the European Commission or by appropriate safeguards under Article 46 GDPR — such as the European Commission’s Standard Contractual Clauses — together with supplementary measures where needed.
13. Current sub-processors
WhiteBoar currently engages the following sub-processors:
- Vercel Inc. (USA) — application hosting, serverless infrastructure, and the AI model gateway;
- Supabase, Inc. (USA) — database, file storage, and authentication;
- OpenAI, L.L.C. (USA) — transcription of voice notes;
- AI model providers routed through the model gateway, including Anthropic, PBC (USA) and OpenAI, L.L.C. (USA) — generation of drafts, translations, and images;
- Meta Platforms Ireland Limited (Ireland) — WhatsApp Business Platform messaging;
- Resend, Inc. (USA) — transactional email delivery.
Personal data at rest is hosted in the EU. Where a provider processes personal data outside the EU/EEA, the safeguards in Section 12 apply.
WhiteBoar keeps this list current on this page; additions and replacements are notified as described in Section 6.
14. Liability and precedence
The liability provisions of the Terms apply to this DPA. In case of conflict between this DPA and the Terms or the Privacy Policy with respect to the processing of personal data on the Customer’s behalf, this DPA prevails.
15. Governing law, language, and contact
This DPA is governed by the same law and jurisdiction as the Terms. It is published in English, Italian, and Polish; the English version is the authoritative legal text and prevails in case of any discrepancy.
Questions about this DPA can be sent to Conscious Digital MTÜ (WhiteBoar), Sakala tn 7-2, 10141 Tallinn, Estonia, or by email at privacy@whiteboar.it.

