1. Overview
You, the Customer, are the data fiduciary (or data controller where applicable). SMSLocal is the data processor — we process personal data only on your instructions.
This DPA covers all personal data SMSLocal handles on your behalf across our messaging products: SMS, WhatsApp Business API, OTP, and AI agents.
Executing a signed DPA is optional for most customers. It becomes necessary when your processing volume, industry, or enterprise procurement process requires one. To request an executable copy, email dpo@smslocal.in.
2. Roles
- Customer (Data Fiduciary): decides the purposes and means of processing the personal data you upload to, or generate within, SMSLocal.
- SMSLocal (Data Processor): processes personal data only on your documented instructions — as set out in the Services, this DPA, the Terms of Service, and the Privacy Policy.
- Data Principal: the individual (typically your end customer or user) to whom the personal data relates.
3. Scope of processing
Nature and purpose. SMSLocal processes personal data to deliver the messaging services you request. This includes:
- Sending SMS, WhatsApp, and OTP messages on your behalf.
- Routing messages through telecom operators and logging delivery status.
- Providing campaign analytics and reporting.
- Honouring DND and opt-out requests.
- Providing customer support for your account.
Duration. For the term of your subscription, plus any additional retention required by law — for example, records mandated by the Telecom Commercial Communications Customer Preference Regulations, 2018 — or by operational necessity, such as delivery reports needed for billing disputes.
Categories of data principals. Your customers, leads, employees, or users to whom you send messages.
Categories of personal data. Mobile numbers, names included in message templates, message content, delivery metadata, opt-out flags, and any other fields you upload as part of a campaign or API call.
4. Security measures
SMSLocal applies appropriate technical and organisational safeguards to protect personal data. These include:
- TLS 1.2+ encryption in transit and AES-256 encryption at rest.
- Role-based access control with least-privilege defaults.
- Audit logs for sensitive operations and API access.
- Annual third-party penetration testing.
- Employee background checks, confidentiality agreements, and mandatory security training.
- Formal incident response runbooks and an on-call rotation.
5. Sub-processors
We use sub-processors to deliver the Services. Current categories include:
- Cloud infrastructure hosted in India.
- Telecom aggregators and operators.
- The WhatsApp Business Platform (Meta).
- Payment processors.
- Customer support tooling.
A current list of sub-processors and their purposes is available in the Privacy Policy and on request.
We will notify you before adding any new sub-processor that accesses personal data. If you object on reasonable grounds, we will work in good faith to resolve the concern. If we cannot resolve it, you may terminate the affected Services.
6. Cross-border transfers
SMSLocal processes personal data primarily in India. Some sub-processors — such as the WhatsApp Business Platform — may process data outside India.
Where we transfer data internationally, we rely on the mechanisms permitted under the DPDPA and require our sub-processors to apply equivalent safeguards.
7. Breach notification
If we become aware of a personal data breach affecting your data, we will:
- Notify you without undue delay.
- Share all information reasonably available to us about the breach.
- Co-operate with your own notifications and any Data Protection Board requirements.
8. Data principal rights
SMSLocal will provide reasonable technical and organisational assistance to help you respond to data principal requests. This covers requests to:
- Access, correct, or erase personal data.
- Port personal data to another service.
- Withdraw consent.
Assistance is available through self-service tools in your dashboard and, where necessary, direct engineering support.
9. Audits
You may request an audit of SMSLocal's processing once per year, or additionally following a material security incident.
We will satisfy most audit requests through written responses, independent certifications, or summary reports. On-site audits are subject to:
- At least 30 days' advance written notice.
- A mutually agreed scope and confidentiality protections.
- Scheduling during normal business hours.
10. Return or deletion of data
When your Services end, you may choose to have your personal data returned or deleted. We will carry out your choice unless retention is required by law.
Backups are overwritten in the ordinary course of our operations and are not accessible after disposal.
11. Term and termination
This DPA takes effect on the later of:
- The date both parties sign it, or
- The start date of your Services subscription.
It remains in force for as long as SMSLocal processes personal data on your behalf.
12. How to execute
To request an executable DPA, email dpo@smslocal.in with the following details:
- Your company name and registered address.
- Authorised signatory name and title.
- Your expected message volume.
We return a signed copy within five business days in most cases.