Legal

GDPR Compliance

Last updated: July 1, 2026

Our role

When you use Waboxa to message customers in the EU or EEA, you act as the data controller for that message content and your customers' contact details, while Waboxa acts as a data processor on your behalf — in the same way we rely on Meta as a sub-processor for message delivery.

Data Processing Agreement

Business customers can request a signed Data Processing Agreement (DPA) covering the terms of Article 28 GDPR, including sub-processor lists and audit rights. Contact support@waboxa.com to request one.

International transfers

Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) with our infrastructure and sub-processors to maintain an adequate level of protection.

Data subject rights

We help account holders respond to data subject requests (access, rectification, erasure, portability) from their own customers. Tools for exporting or deleting a contact's conversation history are available directly in the Waboxa dashboard.

Lawful basis for messaging

You remain responsible for establishing a valid lawful basis — typically consent or legitimate interest — before messaging any EU/EEA contact, in line with both GDPR and Meta's opt-in requirements for the WhatsApp Business Platform.