GDPR Compliance
1. Controller vs. Processor Roles
Under GDPR, roles are divided based on who controls the handling guidelines of personal data:
- Data Controller: Our customers (businesses utilizing MSGTODAY to message their clients) act as the Data Controllers. You control the recipient list, the variables populated inside templates, and the scheduling of campaigns.
- Data Processor: MSGTODAY acts as the Data Processor. We process customer metadata and route message payloads to Meta's WhatsApp network solely on the instructions of our customers.
2. Data Subject Rights
GDPR grants European Union residents specific rights regarding their personal data. MSGTODAY provides tools within our dashboard to help Controllers comply with these rights:
| Right | Description | Implementation in MSGTODAY |
|---|---|---|
| Access & Portability | Request details on stored data and export in structured format. | Download full message delivery logs and contact list exports from console settings. |
| Rectification | Request correction of inaccurate personal data. | Instantly update contact details, team members, or profile fields in settings. |
| Erasure ("Right to be Forgotten") | Request complete deletion of personal data. | Permanently purge contact records, delete templates, or close account to wipe workspace logs. |
| Restriction / Objection | Object to specific automated marketing or data operations. | Configurable webhook triggers and simple customer opt-out keywords (e.g. STOP). |
3. Data Transfer Safeguards
WhatsApp API message processing utilizes cloud hosting regions in Europe and India. To ensure safety during cross-border operations, MSGTODAY implements:
- Standard Contractual Clauses (SCCs) in our agreements with sub-processors (including Meta Platforms Ireland Ltd.).
- AES-256 grade storage encryption at rest and secure TLS 1.3 encryption channels in transit.
- Access controls restricted by Multi-Factor Authentication (MFA) and granular IAM developer permissions.
4. Data Processing Addendum (DPA)
We offer a pre-signed Data Processing Addendum (DPA) which governs the terms of data processing, compliance obligations, and transfer protocols under GDPR. You can download and request execution of our DPA inside the workspace compliance console.
5. Breach Notification Protocol
In the highly unlikely event of a security incident resulting in a breach of personal data, MSGTODAY will notify the relevant supervisory authorities and affected Data Controllers within 72 hours of verification, as mandated by Articles 33 and 34 of the GDPR.
6. Contact DPO
For questions regarding our privacy practices, GDPR compliance audit logs, or to execute a custom DPA, please contact our Data Protection Officer:
Email: dpo@msgtoday.com | Address: Msgtoday Technologies, Floor 1, Flat 905, Anandam Apartment, Hossainpur Main Road, Madurdaha, Kolkata, West Bengal 700107.