Data Processing Addendum

How Morasel processes personal data on your behalf when you use the platform.

Last updated: July 28, 2026

This Data Processing Addendum (the “DPA”) forms part of the agreement between Morasel L.L.C. (“Morasel”, “we”, “us”) and the business customer (“you”, “Customer”) that uses our services. It applies where Morasel processes personal data on your behalf in providing the service.

If there is a conflict between this DPA and the Terms of Service on the subject of data processing, this DPA prevails to the extent of that conflict. Capitalised terms not defined here have the meaning given in the Terms of Service.

1. Roles: controller and processor

For personal data you upload or generate through the service about your own contacts and customers (“Customer Personal Data”), you act as the controller and Morasel acts as your processor, processing that data only on your documented instructions.

For limited data we process to run our business — such as your account and billing details, and security and operational logs — Morasel acts as a controller, as described in our Privacy Policy.

2. Scope, nature, and purpose of processing

Morasel processes Customer Personal Data only to provide, secure, and support the service in accordance with your instructions and this DPA. The subject matter is the operation of the platform; the duration is the term of your agreement plus any wind-down period described below.

The types of data typically include contact identifiers (such as names and phone numbers), message content and metadata, appointment and scheduling details, and consent and opt-out records. Data subjects typically include your customers, contacts, and prospects.

3. Your instructions and responsibilities

Your use of the service, together with this DPA and the Terms, constitutes your instructions for processing. You are responsible for the lawfulness of the data you provide and for obtaining any consents required to message your contacts, including consent required under the WhatsApp Business Platform and applicable law.

4. Confidentiality

Morasel ensures that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and access the data only as needed to provide the service.

5. Subprocessors

You authorise Morasel to engage subprocessors to help provide the service. We impose data-protection obligations on subprocessors that are consistent with this DPA, and we remain responsible for their performance. The categories of subprocessors we use, and how we notify you of changes, are described on our Subprocessors page (/subprocessors).

See /subprocessors for the current categories of subprocessors and the change-notification process.

6. Security

Morasel maintains technical and organisational measures designed to protect Customer Personal Data against unauthorised access, disclosure, alteration, and loss, appropriate to the risk. An overview of our security practices is available on our Security page (/security). These measures may evolve, but we will not materially reduce the overall level of protection during your agreement.

See /security for an overview of our security practices.

7. Data-subject requests

The service provides features that let you access, correct, export, and delete Customer Personal Data. Taking into account the nature of the processing, Morasel will reasonably assist you in responding to requests from data subjects to exercise their rights. If a data subject contacts Morasel directly about Customer Personal Data, we will refer them to you unless legally required to respond.

8. Personal data breach notification

Morasel will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your own notification obligations. We will take reasonable steps to contain and remediate the breach.

9. Deletion or return on termination

On termination or expiry of your agreement, Morasel will, at your choice, delete or return Customer Personal Data, and delete existing copies within a reasonable period, except where retention is required by law or for a limited period as part of routine backups that are then overwritten on a rolling basis.

10. International transfers

Providing a global, multilingual service may involve processing and storing Customer Personal Data in more than one country, including via our subprocessors. Where personal data is transferred across borders, Morasel will put in place a lawful transfer mechanism appropriate to the transfer and applicable law.

Morasel is currently finalizing its primary hosting region(s) and the specific international-transfer mechanisms it relies on. This addendum and the Subprocessors page (/subprocessors) will be updated with these details before the relevant services process production customer data.

11. Audits

On reasonable written request, and subject to confidentiality, Morasel will make available information necessary to demonstrate compliance with this DPA. Where more is reasonably required, the parties will agree on the scope, timing, and cost of any further review, conducted in a way that does not compromise the security or privacy of other customers.

12. Changes to this DPA

We may update this DPA to reflect changes in law, our processing, or our subprocessors. Where changes are material, we will provide reasonable notice, and the “Last updated” date above will reflect the current version.

Contact

Questions about this DPA or a data-processing matter? Contact our privacy team.

privacy@morasel.ai