Version 2.0 — July 1, 2026
1. Definitions
Capitalized terms used in this DPA have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679) where applicable.
- Controller: The entity that determines the purposes and means of processing personal data.
- Processor: The entity that processes personal data on behalf of the Controller.
- Personal Data: Any information relating to an identified or identifiable natural person.
- Subprocessor: A third-party processor engaged by the Processor.
2. Scope and Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service between White Dot ("Processor") and the Customer ("Controller") when the Customer uses White Dot's services in a business or enterprise capacity. It sets out the terms governing the Processing of Personal Data by the Processor on behalf of the Controller.
3. Roles of the Parties
The Customer is the Controller of Personal Data processed under this DPA. White Dot is the Processor. White Dot processes Personal Data only on documented instructions from the Controller, unless required to do otherwise by applicable law.
4. Description of Processing
Categories of data subjects: End users of the Customer who use White Dot messaging services.
Categories of personal data: Phone numbers, display names, profile pictures, device identifiers, and encrypted message metadata.
Special categories of data: None. White Dot's architecture prevents processing of special category data as all message content is end-to-end encrypted and inaccessible.
Processing operations: Collection, storage, transmission, and deletion of the above data for the purpose of providing messaging services.
5. Processor Obligations
White Dot shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorized to process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational measures as described in Section 8
- Not engage Subprocessors without prior notice and the Controller's consent
- Assist the Controller in responding to data subject requests
- Notify the Controller of any Personal Data breach without undue delay
- Delete or return all Personal Data at the end of the Service
6. Data Subject Rights
White Dot shall assist the Controller in fulfilling its obligations to respond to data subject requests under Chapter III of the GDPR. Because of White Dot's zero-knowledge architecture:
- Access requests: White Dot can provide account metadata and encrypted message blobs.
- Rectification requests: Controllers can modify display names and profile information directly.
- Erasure requests: White Dot will delete all associated Personal Data within 30 days of account deletion.
- Portability requests: White Dot can export account metadata in a structured format.
7. Subprocessing
The Controller provides general authorization for White Dot to engage Subprocessors. A current list of Subprocessors is maintained at whitedot.chat/subprocessors. White Dot shall notify the Controller at least 30 days before adding or replacing any Subprocessor.
8. Technical and Organizational Measures
White Dot maintains the following security measures:
- End-to-end encryption for all messages, media, and calls
- Encryption at rest for all stored data (AES-256)
- TLS 1.3 with certificate pinning for all data in transit
- Hardware-backed key storage in device secure enclaves
- Access controls with role-based permissions and audit logging
- Regular security training for all employees
- Annual third-party security audits and penetration testing
- 24/7 intrusion detection and security monitoring
- Incident response plan with defined SLAs
9. Security Breach Notification
White Dot shall notify the Controller within 48 hours of becoming aware of a Personal Data breach. The notification shall include:
- The nature of the breach, including categories and approximate number of data subjects affected
- Contact information for further information
- Likely consequences and measures taken or proposed
10. Data Retention and Deletion
Upon termination of the Service, White Dot shall delete all Personal Data within 30 days, unless retention is required by applicable law. Encrypted messages that have been delivered may be deleted from servers within 7 days of delivery.
11. Governing Law
This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising under this DPA shall be resolved in the courts of Kota, Rajasthan.
12. Contact
For DPA requests or questions:
Email: dpo@whitedot.chat