SabNode
    How it worksPricingCustomers
    Log inStart free
    ProductsHow it worksPricingCustomersStart free
    Legal

    Data Processing Agreement

    Last updated: 2 August 2026

    This DPA describes how SabNode processes personal data on your behalf as your processor, and the safeguards we apply — for compliance with the DPDP Act, the GDPR and similar laws.

    On this page
    • Scope & roles
    • Nature & purpose of processing
    • SabNode obligations
    • Security measures
    • Sub-processors
    • Data-subject rights
    • Personal-data breach notification
    • Audits
    • International transfers
    • Return & deletion of data
    • Liability
    • How to sign & contact

    1. Scope & roles

    This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer”, the controller) and SabNode (the processor) for your use of the Service. It governs SabNode’s processing of personal data that Customer submits to the Service (“Customer Data”), and applies to the extent required by the DPDP Act, the GDPR and other applicable data-protection laws.

    2. Nature & purpose of processing

    SabNode processes Customer Data only to provide, secure and support the Service, and only on Customer’s documented instructions (including through use of the product).

    • Subject matter — provision of SabNode’s messaging, CRM, email, automation and related products.
    • Duration — for the term of the agreement and until deletion/return of Customer Data.
    • Data subjects — Customer’s contacts, leads, recipients, employees and end-users.
    • Data types — identifiers, contact details, message and email content, CRM records and metadata that Customer chooses to process.

    3. SabNode obligations

    • Process Customer Data only on Customer’s instructions and for the purposes above;
    • Ensure persons authorised to process Customer Data are bound by confidentiality;
    • Implement appropriate technical and organisational security measures (Section 4);
    • Assist Customer, taking into account the nature of processing, with data-subject requests, security, breach notification and impact assessments; and
    • Make available information necessary to demonstrate compliance.

    4. Security measures

    SabNode maintains measures including:

    • Encryption of Customer Data in transit (TLS) and at rest;
    • Role-based access control, least-privilege and authentication controls;
    • Network isolation, secrets management and encrypted credential storage;
    • Signed, immutable audit logs and monitoring/alerting; and
    • Backup, recovery and secure software-development practices.

    See our security overview for more detail.

    5. Sub-processors

    Customer authorises SabNode to engage sub-processors (for hosting/storage, payment processing, message and email delivery, and analytics) to provide the Service. SabNode imposes data-protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance. A current list is available on request from privacy@sabnode.com, and SabNode will give notice of new sub-processors so Customer may object on reasonable grounds.

    6. Data-subject rights

    Taking into account the nature of the processing, SabNode will provide product features and reasonable assistance to help Customer respond to requests from data subjects to access, correct, delete, restrict, port or object to processing of their personal data.

    7. Personal-data breach notification

    SabNode will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to help Customer meet its notification obligations to authorities and data subjects.

    8. Audits

    SabNode will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor, subject to reasonable notice, confidentiality and frequency limits.

    9. International transfers

    Where SabNode transfers Customer Data across borders, it will do so with appropriate safeguards required by applicable law (such as contractual data-protection clauses), consistent with the DPDP Act and the GDPR.

    10. Return & deletion of data

    On termination of the agreement, and at Customer’s choice, SabNode will delete or return Customer Data and delete existing copies within a reasonable period, unless retention is required by law. Customer can export Customer Data from the product before deletion.

    11. Liability

    Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

    12. How to sign & contact

    To execute a countersigned copy of this DPA, or for questions, email privacy@sabnode.com. This DPA is incorporated into and forms part of your agreement with SabNode.

    Questions about this document? Email privacy@sabnode.com.

    SabNode

    The operating system for your customer-facing business. 19 products, one tenant, one bill.

    Products

    • Wachat
    • SabFlow
    • SabChat
    • CRM

    Resources

    • Pricing
    • Start free
    • All-in-one
    • Customers
    • Features
    • Blog
    • Help center
    • Changelog

    Company

    • About
    • Careers
    • Contact
    • Partners
    • Press

    Legal

    • Terms
    • Privacy
    • DPA
    • Security
    • Status
    © 2026 SabNode. All rights reserved.
    All systems operational