1. Parties, roles and scope
The parties are SOFTIUM Sàrl (Softium LLC), UID CHE-303.047.962 ("Polymorfa"), and the customer that accepted the Terms ("Customer").
- For Customer Data, Customer is the controller (under the DPDP Act, the data fiduciary) and Polymorfa is the processor (the data processor). If Customer is itself a processor for someone else, Polymorfa is its subprocessor and Customer passes on the relevant terms.
- This Addendum covers personal data in Customer Data, as defined in the Terms. Annex 1 describes that processing.
- It applies under the Swiss Federal Act on Data Protection (nFADP), the EU General Data Protection Regulation (GDPR), the UK GDPR, Brazil's Lei Geral de Proteção de Dados (LGPD), India's Digital Personal Data Protection Act 2023 and Rules 2025 (DPDP Act), and any other data protection law that applies to the processing ("Data Protection Law").
- Account data of Customer's users, billing data and our own logs are handled by Polymorfa as controller under the Privacy Policy, not under this Addendum.
2. Instructions
Polymorfa processes Customer Data only on Customer's documented instructions. Those instructions are the Terms, this Addendum, Customer's settings in the console, and Customer's API calls. Further instructions must be in writing and consistent with the Service. Polymorfa tells Customer if it believes an instruction breaks Data Protection Law, and may then decline to follow it.
If a law requires Polymorfa to process Customer Data otherwise, Polymorfa tells Customer first, unless that law forbids it.
3. Customer's responsibilities
Customer is responsible for having a lawful basis for the processing, including the consent of message recipients where required, for the accuracy of the data it sends, for notices to the people concerned, and for agreeing a storage region under section 7 if its obligations require one. Customer should not send special categories of personal data or data about children unless it has a lawful basis and has assessed the risk.
4. Personnel
Only staff who need access to run, secure or support the Service can access Customer Data. They are bound by confidentiality duties, and staff actions in the admin tools are reviewed and logged.
5. Security
Polymorfa keeps the technical and organizational measures in Annex 2. It may change them as long as the overall level of protection does not go down.
6. Subprocessors
- Customer gives general authorization for Polymorfa to use the subprocessors on the subprocessor list.
- Polymorfa emails the owners of Customer's team at least 30 days before a new subprocessor starts processing Customer Data.
- Customer can object in writing within those 30 days on reasonable data protection grounds. The parties then try in good faith to find a solution. If they cannot, Customer may end the affected part of the Service, and Polymorfa refunds the purchase price of remaining paid credits.
- Polymorfa remains responsible to Customer for the processing of Customer Data by its subprocessors as if it were its own.
7. Data residency
- Polymorfa stores Customer Data in Switzerland unless the parties agree otherwise under the next point.
- The parties may agree in a signed order form that Polymorfa stores specified Customer Data, such as WhatsApp session data, in Brazil or India. That order form names the region and the data covered. Polymorfa then keeps that data stored in that region and notifies any new regional subprocessor under section 6.
- Polymorfa does not move stored Customer Data out of the agreed country without Customer's instruction. The only exception is a legal requirement, and Polymorfa tells Customer first where it is allowed to.
- Transit through the network edge, remote access by authorized staff, and the subprocessors listed for email, support and analytics are not storage outside the agreed country. Section 8 covers them.
8. International transfers
When Customer Data leaves the country where Data Protection Law requires a safeguard, the following apply and are incorporated into this Addendum by reference:
EU standard contractual clauses
The standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module 2 (controller to processor) or Module 3 (processor to processor) as the case may be. Clause 7 (docking) applies. Clause 9 option 2 (general authorization) applies with the notice period in section 6. In clause 11 the optional language does not apply. Clauses 17 and 18 choose Irish law and Irish courts. Annexes 1 and 2 of this Addendum complete the SCC annexes, and the subprocessor list completes Annex III.
Switzerland
For transfers subject to the nFADP, the SCCs apply with these changes: the FDPIC is the competent supervisory authority; the law of Switzerland governs where the transfer is subject only to the nFADP; references to the GDPR include the nFADP; and "member state" includes Switzerland, so that data subjects in Switzerland can enforce their rights there.
United Kingdom
For transfers subject to the UK GDPR, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies. Table 1 uses the parties in section 1, Table 2 the modules above, Table 3 the Annexes of this Addendum, and in Table 4 either party may end it.
Brazil
For international transfers of personal data subject to the LGPD, the standard contractual clauses in Annex II of ANPD Resolution CD/ANPD No. 19/2024 apply, with Customer as exporter and Polymorfa as importer. They prevail over this Addendum for those transfers.
India
Polymorfa does not transfer personal data subject to the DPDP Act to a country or territory that the Central Government has restricted under section 16 of the Act, and follows any conditions set for transfers.
If a transfer mechanism is invalidated or replaced, the parties switch to its lawful successor.
9. Requests from authorities
If an authority asks Polymorfa for Customer Data, Polymorfa directs it to Customer where it can. Otherwise Polymorfa checks that the request is lawful, challenges it if it is not, discloses the minimum necessary, and tells Customer unless the law forbids it.
10. Help with data subject requests
Customer can read, export and delete Customer Data through the API and the console. If that is not enough, Polymorfa helps Customer answer requests from data subjects and data principals, at no charge unless the effort is excessive. Polymorfa forwards any request it receives directly and does not answer it except on Customer's instruction.
11. Personal data breaches
Polymorfa notifies Customer without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notice gives what is known at the time, and Polymorfa adds details as it learns them:
- what happened, and when;
- the categories and approximate number of people and records affected;
- the likely consequences;
- what Polymorfa has done and will do, and what Customer can do;
- a contact for more information.
This timing lets Customer meet its own deadlines, including 72 hours under the GDPR and the DPDP Rules, three working days under the ANPD incident regulation, and six hours for reports to CERT-In where those apply. Notifying Customer is not an admission of fault.
12. Assessments and consultations
Polymorfa gives Customer the information it reasonably needs for data protection impact assessments and prior consultations with authorities about the Service.
13. Deletion and return
During the contract, Customer can read Customer Data through the API and delete sessions and its team. Deleting a team deletes the team's records from Polymorfa's account database. If the console cannot delete a team, for example because it has billing or support history, Polymorfa deletes its records on Customer's written request and keeps the billing records the law requires. Customer deletes uploaded media through the API. Logging out a number or deleting its session deletes its WhatsApp session keys; deleting a team does not, so Customer logs out its numbers first. After the contract ends, Polymorfa deletes remaining Customer Data within 90 days of Customer's written request. Polymorfa keeps Customer Data longer only where a law requires it, and then keeps it protected and uses it for nothing else.
14. Information and audits
Polymorfa answers reasonable written questions about its compliance with this Addendum. Customer may audit Polymorfa's compliance once a year, or more often after a breach or when an authority requires it. Customer gives 30 days' notice, and an independent auditor bound by confidentiality carries out the audit during business hours without access to other customers' data. Customer bears its own costs. Polymorfa may offer a current third-party audit report instead where it covers the questions.
15. Rules for specific laws
Brazil (LGPD)
Polymorfa processes Customer Data according to Customer's instructions and the LGPD (art. 39), and helps Customer report incidents to the ANPD and data subjects.
India (DPDP Act)
Polymorfa processes personal data only under this valid contract, as section 8(2) of the Act requires. It keeps reasonable security safeguards and erases personal data when Customer tells it that consent has been withdrawn or that the purpose is no longer served.
Switzerland (nFADP)
Polymorfa protects Customer Data with the measures in Annex 2, as article 8 of the nFADP and the Data Protection Ordinance require.
16. Liability and precedence
The liability terms of the Terms apply to this Addendum, except where the SCCs or Data Protection Law do not allow a limit. For personal data, this Addendum prevails over the Terms, and the SCCs and the ANPD clauses prevail over this Addendum.
Annex 1: Description of the processing
| Item | Description |
|---|---|
| Data exporter | Customer, as identified by its team in the console. Contact: the team owners. |
| Data importer | SOFTIUM Sàrl, Rue des Musées 58, 2300 La Chaux-de-Fonds, Switzerland. Contact: privacy@polymorfa.com. |
| Data subjects | People Customer messages or calls on WhatsApp, or who message or call Customer; Customer's contacts and campaign recipients; Customer's own staff and end users whose data Customer sends through the Service. |
| Categories of data | Phone numbers and WhatsApp identifiers; names and profile details visible on WhatsApp; message content and media; call metadata; opt-in and opt-out records; any other data Customer includes in messages, contacts or API calls. |
| Special categories | None intended. Message content may contain them if Customer or recipients send them. Annex 2 applies to all content. |
| Frequency | Continuous, for as long as Customer uses the Service. |
| Nature and purpose | Connecting Customer's WhatsApp numbers; sending, receiving and relaying messages, media and calls; delivering webhooks and events; supporting Customer and securing the Service. |
| Duration and retention | The term of the contract, then deletion under section 13. |
| Location | Switzerland, or Brazil or India where agreed under section 7. Subprocessors as listed on the subprocessor list. |
| Competent supervisory authority | The FDPIC for processing subject to the nFADP; for the GDPR, the authority determined under clause 13 of the SCCs; the ANPD for the LGPD; the Data Protection Board of India for the DPDP Act. |
Annex 2: Technical and organizational measures
- Encryption. TLS for traffic to and from the Service. Meta credentials that Customer provides are encrypted at rest with AES. API keys are stored only as hashes.
- Tenant isolation. Database row-level security scopes every customer query to its team and fails closed. Account data and WhatsApp session data live in separate databases.
- Access control. Least privilege. Staff tools sit behind single sign-on restricted to a staff group, and every staff write is a named, reviewed and audited action.
- Customer controls. API keys with scopes, revocable project and client credentials, passkeys and two-factor authentication, signed webhooks, and an audit log of sensitive actions.
- Data minimization. No history of sent and received messages is kept. Message events, including their content, stay in the delivery queue for at most 24 hours. Media Customer uploads for sending is kept until Customer deletes it. Call audio and video are not recorded.
- Availability. Uptime monitoring and alerting.
- Development. Code review, automated tests for tenant isolation and secret scanning, and separate development and staging environments.
- Vendors. Subprocessors process data under the data processing terms that apply to Polymorfa's account with them.
Contact
Rue des Musées 58
2300 La Chaux-de-Fonds
Switzerland
UID CHE-303.047.962
Email: privacy@polymorfa.com
Web form: polymorfa.com/contact