Skip to content

Data Processing Agreement

This DPA explains how sendom processes personal data on your behalf when you use the Atlas Engine WhatsApp agent service. It forms part of the Service Agreement between us and takes effect when you accept that agreement (or, if earlier, when we first process personal data for you).

Version 1.0 · Updated 29-07-2026

Parties

Processor: sendom (Adam Sendrey), an Israeli exempt sole proprietorship ('עוסק פטור') operating as 'Atlas Engine.' Registered details as stated in your Service Agreement. Contact: hello@sendom.net. Controller: your business, as identified in your Service Agreement — you determine why and how your customers' personal data is processed; we process it only to provide the Service.

Definitions

Terms like 'Personal Data', 'Data Subject', 'Processing', 'Controller', 'Processor', 'Sub-processor', and 'Personal Data Breach' have the meanings given to them under the GDPR and the Israeli Protection of Privacy Law as amended by Amendment 13, whichever applies to the processing in question.

What We Process, and Why

We process your end-customers' personal data solely to provide the Service: an AI WhatsApp booking and qualification agent. That means their name, phone/WhatsApp number, message content, booking details and preferences — and, only if a customer volunteers it, health or treatment-related details, which we treat as especially sensitive (see below). Processing lasts for the term of your Service Agreement.

Our Obligations as Processor

We process personal data only on your documented instructions, unless a law requires otherwise (in which case we tell you first, unless the law forbids it). Everyone on our side with access to the data is bound by confidentiality. We apply the technical and organizational security measures described below. We follow the sub-processor rules in the next section. We help you respond to data-subject requests and to security, breach-notification, and impact-assessment obligations, so far as we reasonably can. At your choice, and at the end of the Service Agreement, we delete or return all personal data — except where the law requires us to keep a minimal record. And we make available what you reasonably need to confirm we're complying with this DPA.

Sub-processors

You give us general authorization to use the sub-processors below to deliver the Service. We impose data-protection terms on each of them that are no less protective than this DPA, we stay responsible for their performance, and we'll notify you before adding or changing one so you have a reasonable chance to object.

Anthropic (Claude API)

Powers the agent's conversation and decisions. Processes message content and booking context. Prompts and outputs are not retained by Anthropic by default and are not used to train their models.

Google Cloud / Vertex AI

Powers message-retrieval embeddings and Google Calendar booking. Processes message snippets and booking event data. Configured for an EU region where possible; not used to train Google's models.

Twilio

Transports WhatsApp messages in and out. Processes phone numbers and message content.

Railway

Hosts our application and primary database — where all stored personal data actually lives. EU-region hosting, encrypted at rest.

Langfuse

Observability and tracing for the agent. Processes hashed phone numbers and turn metadata only — no raw personal data.

International Transfers

Transfers between Israel and the EU rely on mutual adequacy (the EU has recognized Israel as adequate since January 2024). Where a sub-processor processes data outside Israel or the EEA (for example, in the US), that transfer is covered by appropriate safeguards — such as standard contractual clauses or the sub-processor's own DPA — and, where Israeli law requires it, a binding agreement against unauthorized onward transfer. We pin data residency to the EU wherever a sub-processor lets us configure it.

Data-Subject Requests

Your customers' access, correction, deletion, and portability requests are yours to decide on — you're the Controller of that relationship. We carry out the technical action on your instruction: producing a copy of everything held about a customer, or erasing it (PII scrubbed everywhere except a minimal record we're legally required to keep, for example for tax purposes). If one of your customers contacts us directly, we forward the request to you and act on your instructions. Every request we act on is logged. Our own privacy policy describes how we handle requests about people who interact directly with sendom (for example, through our demo chat or lead form) — this DPA covers requests about your customers.

Security Measures

Encryption in transit (TLS) and at rest; access to systems and secrets restricted on a least-privilege basis and pulled from environment configuration, never hardcoded; each client's data logically isolated from every other client's; an append-only audit log of data actions; data minimization, including hashed phone numbers in logs and traces; configurable retention with automatic purge; the export and erasure capabilities described above; and guardrails against prompt injection and unintended PII exposure. No sub-processor is permitted to train AI models on your data.

Especially Sensitive Data

If your customers volunteer health, medical-aesthetic, or other especially sensitive information during a conversation, we apply heightened safeguards to it. You're responsible for having a valid legal basis to collect it (including explicit consent where GDPR applies) and for giving your customers the notice the law requires.

Personal Data Breach

If a personal data breach occurs, we notify you without undue delay, with what you need to meet your own notification duties. Under Israeli law, a serious information-security incident may require immediate notice to the Privacy Protection Authority; under GDPR, you (as Controller) generally have 72 hours to notify your supervisory authority once you're aware. We follow a documented internal breach-response procedure covering containment, notification, and post-incident review.

Retention & Deletion

We retain personal data only for as long as needed to provide the Service, per retention periods configured for your account and enforced by automatic and manual purge processes. At your choice, and at the end of the Service Agreement, we delete or return your data and delete existing copies — except where we're legally required to keep a minimal record (for example, statutory business or tax record-keeping), in which case identifying details are removed and only the minimum legally required record remains.

Liability, Term & Governing Law

Liability is governed by the Service Agreement. This DPA lasts as long as we process personal data on your behalf. It's governed by Israeli law, and by the GDPR where the GDPR applies. Disputes go to the competent courts of Tel Aviv-Yafo.

Amendments

We may update this DPA — the version and date at the top of this page reflect the most recent revision. Changes to our sub-processor list are notified to you in advance, as described above.