Data Processing Addendum
How OctaPages processes the personal data a business keeps in its workspace, on the business's behalf. It forms part of the Terms of Service for every business that uses a plugin.
Last updated: 30 September 2026
1. Roles
For personal data a business stores in its workspace (for example its customers' names, phone numbers, conversations and notes), the business is the Data Fiduciary (the "controller" under the GDPR) and Minivet System LLP is its Data Processor. The business decides why that data is processed; we process it only to provide the service.
2. Processing on instructions
We process workspace data only to run the plugins the business uses, to support it when it asks, to keep the service secure, and where the law requires. We never sell it, never use it for advertising, and never use it to train AI models for anyone else.
3. The business's responsibilities
The business must have a lawful basis (usually consent) for the data it collects and the messages it sends, must give its customers the notice the DPDP Act requires, and must answer their requests to access, correct or erase their data. We provide the tools to do so and help when asked.
4. Security measures
- A separate database for every business; no other business's request can reach it, and our automated tests check that on every change.
- Encryption in transit (HTTPS) and encrypted backups, each with its own key.
- Access by our staff only for support or security, recorded in an audit log.
- Rate limits, bot checks and monitoring against abuse.
5. Sub-processors
We use these sub-processors, each under a contract that protects the data:
- Hetzner Online GmbH (Germany) — servers and databases.
- Cloudflare, Inc. — file storage, backups, content delivery and custom domains.
- Resend — email delivery.
- Razorpay Software Pvt. Ltd. (India) — payments.
- Meta Platforms — WhatsApp messaging, when the business connects its WhatsApp number.
6. Personal data breaches
If a breach affects a business's workspace data, we tell the business without undue delay, and in any case within 72 hours of becoming aware of it, with what we know and what we are doing, so it can meet its own duties to its customers and the Data Protection Board.
7. When the service ends
When a workspace is deleted, we first take a verified, encrypted backup and keep it for 30 days (1 month) so the business can ask us to restore it. After that the backup and the workspace's files are deleted permanently. A business that wants a copy of its data should ask before deletion.
8. Transfers and audits
Workspace data is hosted in the European Union (Germany); transfers are made only as the DPDP Act and, where it applies, the GDPR allow. On reasonable written request we will answer a business's questions about how its data is protected.