Last updated: July 1, 2026
When you use Waboxa to message customers in the EU or EEA, you act as the data controller for that message content and your customers' contact details, while Waboxa acts as a data processor on your behalf — in the same way we rely on Meta as a sub-processor for message delivery.
Business customers can request a signed Data Processing Agreement (DPA) covering the terms of Article 28 GDPR, including sub-processor lists and audit rights. Contact support@waboxa.com to request one.
Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) with our infrastructure and sub-processors to maintain an adequate level of protection.
We help account holders respond to data subject requests (access, rectification, erasure, portability) from their own customers. Tools for exporting or deleting a contact's conversation history are available directly in the Waboxa dashboard.
You remain responsible for establishing a valid lawful basis — typically consent or legitimate interest — before messaging any EU/EEA contact, in line with both GDPR and Meta's opt-in requirements for the WhatsApp Business Platform.