1. How this DPA works
This page is the Cover Page for a Data Processing Agreement between you (the merchant / Customer) and Toward Technology Private Limited (Provider) for Waktaa. It incorporates by reference the Common Paper DPA Standard Terms Version 1.1. If anything on this Cover Page conflicts with those Standard Terms, this Cover Page controls.
Common Paper agreements are available under CC BY 4.0. We adapted the Cover Page for Waktaa; we did not rewrite the hosted Standard Terms.
This DPA supplements our Terms of Use and Privacy Policy for Customer Personal Data you instruct us to process in the Waktaa service (inbox, catalog, orders, optional AI Assist, and related features). It does not replace those documents for the marketing website or for data we process as an independent controller (for example account billing contacts).
2. Key terms (Cover Page)
2.1 Agreement
This DPA supplements the Waktaa Terms of Use (as updated, last posted September 29, 2026) and the Privacy Policy.
2.2 Parties
- Provider: Toward Technology Private Limited, Biratnagar, Koshi, Nepal (operating Waktaa).
- Customer: the organisation that creates a Waktaa account and connects channels (controller of shopper / buyer data, or processor when acting for its own controller).
2.3 Roles
Where Customer is a Controller of Customer Personal Data, Provider is a Processor. Where Customer is a Processor, Provider is a Subprocessor. See Privacy Policy Section 2.
2.4 Provider security contact
privacy@waktaa.com · Biratnagar, Koshi, Nepal
2.5 Security policy
As described in the Privacy Policy (Security) and Privacy Policy Section 8 (Hosting): TLS in transit, authentication, tenant isolation, and role-based access. We do not claim SOC 2, ISO 27001, or similar certifications on this Cover Page.
2.6 DPA Covered Claim / extra liability
None / not applicable. Liability for the service remains as stated in the Terms of Use. We have not added a separate DPA indemnity or increased DPA liability cap on this Cover Page.
2.7 Governing law
Same as the Terms of Use: laws of Nepal; exclusive jurisdiction of the competent courts in Kathmandu, Nepal, unless Applicable Data Protection Laws require otherwise for a specific transfer mechanism (for example EEA SCCs incorporated by the Standard Terms when GDPR applies).
2.8 CCPA service-provider language (when CCPA applies)
To the extent the California Consumer Privacy Act (as amended, including CPRA) applies to Customer Personal Data provided under the Agreement, the parties acknowledge that Provider is a service provider (and/or processor) receiving that Personal Data to provide the Service for a limited and specified business purpose. Provider will not sell or share that Personal Data, and will not retain, use, or disclose it except as necessary to provide the Service, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands these restrictions. Provider will notify Customer if it can no longer meet its CCPA obligations.
This paragraph does not replace a full US privacy addendum (categories, sale/share opt-out UI, verified request process). See Limits below.
3. Approved Subprocessors
Customer approves the Subprocessors listed below. Provider will give written notice of intended additions or replacements (email to the Customer admin address on file, or an in-product notice when available) before putting a new Subprocessor into production use for Customer Personal Data, consistent with the Common Paper DPA Standard Terms (advance notice and objection window).
- Meta (WhatsApp Cloud, Instagram, Messenger)
- Shopify (store connection, product catalog, and the theme embed that loads store chat)
- Google (OAuth sign-in, Gemini/Vertex AI inference, Firebase Cloud Messaging for the Android/iOS apps, Google Analytics on marketing site)
- Paddle (USD card checkout on the website)
- Cloudflare (marketing CDN and edge)
- Cloud infrastructure providers (product data storage)
Primary product data location (Provider-controlled systems): Virginia, United States. Marketing site edge: Cloudflare (global edge network; may process outside Nepal). Channel platforms (Meta, Shopify) and payment partners also process data in their own regions under their terms.
Same list appears in the Privacy Policy (sub-processors / hosting).
4. Annex — description of processing
4.1 Service
Waktaa — multi-channel inbox, catalog, order updates, optional AI Assist, billing, and related features configured by Customer.
4.2 Categories of data subjects
- Customer's end users / buyers / shoppers (channel contacts)
- Customer's staff users (seats who sign in to Waktaa) — to the extent their account data is needed to provide the Service
4.3 Categories of personal data
- Contact information (for example name, phone, email, channel IDs)
- Transactional / order information Customer stores or sends through Waktaa
- Message content and media Customer or buyers send in connected channels
- User activity / technical data (for example device or IP in logs, push tokens when enabled)
- Catalog and knowledge files Customer uploads (may include personal data if Customer includes it)
Special category data: Not intentionally collected. Customer must not instruct Provider to process special category data unless separately agreed in writing. If such data appears in message content, Customer is responsible for lawful basis; Provider processes only as instructed to provide the Service, with Privacy Policy security measures.
4.4 Frequency
Continuous while Customer uses the Service.
4.5 Nature and purpose
Receiving, holding, using (including optional AI inference Customer enables), updating, protecting, sharing with Approved Subprocessors and connected platforms as instructed, returning or exporting on request, and erasing per retention and deletion rules — in each case to provide and maintain the Service under Customer's instructions.
4.6 Duration
For as long as required to provide the Service under the Terms and Privacy Policy retention rules, or as required by Applicable Laws.
4.7 Restricted transfers
Customer authorizes transfers needed to provide the Service, including to Virginia, United States and to Approved Subprocessors. Where GDPR (or UK GDPR) protects the transfer and no adequacy decision applies, the Common Paper DPA Standard Terms deem the parties to have entered into the applicable EEA SCCs / UK addendum modules as set out in those Standard Terms.
- Data exporter: Customer (controller or processor as applicable).
- Data importer: Toward Technology Private Limited as Processor / Subprocessor, Biratnagar, Koshi, Nepal.
5. How to accept
Self-serve: By creating or continuing a Waktaa organisation and agreeing to the Terms of Use, Customer agrees to this DPA Cover Page (as of the "Updated" date above) for Customer Personal Data processed in the Service.
Signed copy: If you need a countersigned PDF Cover Page, email privacy@waktaa.com with subject DPA countersign, your legal entity name, and the admin email on the Waktaa account.
6. Limits (read this)
Common Paper designed this DPA mainly for GDPR controller→processor (and processor→subprocessor) relationships, including cross-border transfer tools. Optional CCPA service-provider language is included above when CCPA applies.
- This page is not a substitute for a counsel-reviewed US state privacy addendum (full categories, sale/share opt-out, verified consumer request workflow).
- Nepal governing law in the Terms still applies to the commercial relationship unless a specific transfer mechanism requires otherwise.
- Provider does not run Customer marketing lists; Customer remains responsible for messaging lawfulness (see Terms merchant duties and Privacy Section 2).
- Subprocessor change notices depend on us emailing admins (or shipping in-product notice). Keep your org admin email current.
Not legal advice. If your buyer base is primarily EEA/UK, ask counsel whether this Cover Page + Standard Terms 1.1 is enough for your compliance program.