Skip to content
HeloFlow
Legal

Data Processing Agreement

How PureFlow Studios processes your customers' personal data on your behalf when you use HeloFlow.

Last updated 24 September 2026 · In effect from 24 September 2026

HeloFlow is a product of PureFlow Studios, E-4/77, Hardoi Road, Lucknow 226003, Uttar Pradesh, India · GSTIN 09RFSPS2815K1ZA

The short version

  • Your business is the Data Fiduciary for your contacts and conversations; PureFlow Studios is your Data Processor.
  • We process that data only to run HeloFlow for you, keep it confidential and secure, and help you meet your obligations.
  • Our current service providers are listed on the Sub-processors page, and we give 15 days' notice before adding one.
  • We tell you about a personal data breach affecting your data within 48 hours of becoming aware of it.
  • When you delete your workspace, we delete your data after a 7-day grace period.

This summary is here to help. The full text below is what applies.

About this agreement

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between you (the "Customer") and PureFlow Studios ("PureFlow Studios", "we"). It applies whenever we process personal data on your behalf while providing HeloFlow. It is designed to meet India's Digital Personal Data Protection Act, 2023 and the rules under it (the "DPDP Act"). Where the EU or UK GDPR applies to you, the same commitments apply to that data, with "Data Fiduciary" read as "controller" and "Data Processor" as "processor". Terms not defined here have the meaning given in the Terms of Service.

Roles

  • You are the Data Fiduciary for Customer Personal Data, meaning the personal data of your End Customers, prospects and other people whose data you add to or receive through HeloFlow. You decide why and how it is processed.
  • We are your Data Processor. We process Customer Personal Data only on your behalf and only as set out in this DPA.
  • For your Users' account data and our own billing records, we act as a Data Fiduciary under our Privacy Policy.

Details of the processing

Subject matterProviding HeloFlow: a WhatsApp inbox, contacts and leads, broadcasts, automations, AI-assisted replies, forms and integrations
DurationFor as long as we provide HeloFlow to you, and afterwards until the data is deleted under this DPA
Nature and purposeStoring, organising, displaying, transmitting (including through Meta's WhatsApp Business Platform), analysing and deleting data, as your use of HeloFlow requires
Types of personal dataNames, WhatsApp numbers, WhatsApp profile names, message content and media, tags, notes, lead and deal details, custom fields, form responses, payment-link status, and any other data you choose to add
Data principalsYour End Customers and prospects, and your staff who use HeloFlow
Sensitive dataNot required by the service. If you choose to process it, you are responsible for having a lawful basis and appropriate safeguards

Your instructions

We process Customer Personal Data only on your documented instructions. Those instructions are: these Terms and this DPA; the settings and actions you and your Users take in HeloFlow; and any reasonable instructions you send us in writing that are consistent with them. If we believe an instruction breaks the law, we will tell you and may decline to follow it. We may also process data where the law requires it; if so, we will tell you first unless the law forbids us to.

Your responsibilities

  • Give End Customers any notice the DPDP Act requires, and have a lawful basis, usually their consent, for each purpose you use their data for, including WhatsApp opt-in.
  • Make sure the data you give us is accurate and that you are allowed to share it with us.
  • Don't use HeloFlow to process children's data without verifiable parental consent.
  • Set retention periods that fit your obligations, for example the media retention setting in Settings → Data & privacy.
  • Respond to your End Customers' requests to exercise their rights. We will help, as described below.

Our commitments

  • Confidentiality. Everyone we authorise to process Customer Personal Data is bound by confidentiality.
  • Security. We maintain the technical and organisational measures described in Security measures.
  • Assistance with requests. HeloFlow lets you find, export, correct and erase a person's data yourself. If you need more help to respond to a data principal's request, we provide reasonable assistance. If a request reaches us directly, we pass it to you and don't respond ourselves unless you ask us to.
  • Assistance with compliance. We provide reasonable help, with information about our processing, for your breach notifications, data protection assessments and consultations with authorities.
  • Accountability. We keep records of our processing and make the information needed to show compliance with this DPA available to you on request.

Sub-processors

You authorise us to use sub-processors to provide HeloFlow. The current list is on our Sub-processors page. We:

  • impose data protection obligations on each sub-processor that are at least as protective as this DPA;
  • remain responsible for their performance of those obligations;
  • tell Workspace owners by email at least 15 days before adding or replacing a sub-processor.

If you have a reasonable data protection objection to a new sub-processor, tell us within those 15 days. We will try to find a solution. If we can't, you may cancel the affected service and we will refund any prepaid fees for the unused period.

Security measures

  • Encryption of all data in transit (TLS) and at rest.
  • WhatsApp access tokens, AI provider keys and payment keys kept in an encrypted secrets vault.
  • Isolation of every Workspace at the database level, using row-level security policies.
  • Role-based access for Users (owner, admin, agent), with an audit log of important actions.
  • Restricted access for our personnel, on a need-to-know basis, with multi-factor authentication for administrative access.
  • Primary data hosting in India (AWS Mumbai region), with regular backups.
  • Rate limiting and abuse controls on sending and sign-up.
  • Monitoring of errors and security events, and prompt patching of our software and dependencies.

Personal data breaches

If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, disclosure of, or access to Customer Personal Data, we will:

  • notify you without undue delay, and in any case within 48 hours of becoming aware of it;
  • tell you what we know: what happened, the data and data principals affected, the likely consequences, and what we have done and will do;
  • take reasonable steps to contain it and reduce its harm;
  • help you meet your obligations to inform the Data Protection Board of India and affected data principals.

Notifying you is not an admission of fault.

International transfers

Customer Personal Data is primarily stored in India. Some sub-processors process data outside India, as shown on the Sub-processors page. We only transfer data to countries that the Government of India has not restricted under the DPDP Act, and under contracts that protect it.

Deletion and return

  • You can export Workspace data at any time from Settings → Data & privacy.
  • When an owner deletes the Workspace, there is a 7-day grace period. After that, all Customer Personal Data, including files, is permanently deleted, usually within 24 hours.
  • If our agreement ends without the Workspace being deleted, we keep the data for 30 days so you can ask for an export, and then delete it.
  • Deleted data can stay in encrypted backups for up to 30 days, until they are overwritten.
  • We keep data longer only where the law requires it, and only for as long as it does.

Audits

Once a year, or after a breach, you may ask us to answer a reasonable security questionnaire and provide supporting information about our processing. Any other audit must be agreed in advance: reasonable in scope, at your cost, with reasonable notice, and subject to confidentiality.

Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on a data protection matter, this DPA prevails.

Contact

Write to privacy@heloflow.com about this DPA or to request a signed copy.

Operated by
PureFlow Studios, a sole proprietorship registered in India
Registered address
E-4/77, Hardoi Road, Lucknow 226003, Uttar Pradesh, India
GSTIN
09RFSPS2815K1ZA
Privacy and data requests
privacy@heloflow.com
Legal notices
legal@heloflow.com

Questions about this document?

Write to legal@heloflow.com or see all the ways to reach us.