- You are the controller of the data you put into startbuddi. We are your processor.
- We only process it on your instructions, never sell it and never use it to train AI.
- We tell you about a breach affecting your data within 48 hours.
- Our main database is in the EU (Ireland); transfers use Standard Contractual Clauses.
- Deleted workspaces are removed from live systems within 30 days and from backups within 90 days.
- We give 14 days' notice before adding a subprocessor, and you can object.
This data processing agreement (DPA) explains how startbuddi handles the personal data your workspace puts into it: your contacts, subscribers, customers, booking guests, form respondents and team. It forms part of our Terms of service and applies automatically to every workspace, so you do not need to sign anything separately. It is written to meet Article 28 of the EU and UK GDPR and sections 29 and 30 of Nigeria’s Data Protection Act 2023 (NDPA), so one agreement works for a business in Lagos, London or Berlin.
The same agreement is published inside the app at app.startbuddi.com/legal/dpa. If you need a signed copy for your records or your regulator, email privacy@startbuddi.com.
Who is who
- You are the controller. You, the business that owns the workspace, decide why personal data is collected and what happens to it.
- We are the processor. startbuddi is run by Tech Della Solutions Ltd, a private company limited by shares registered in Nigeria with the Corporate Affairs Commission (RC 7038770), based in Ibadan (“we”, “us”). We store, send, sync and analyse that data only to provide startbuddi to you, on your instructions.
- For your own account details (your name, email, sign-in and billing), we are the controller, and our Privacy policy applies instead.
What we process and why
- Contact details (names, email addresses, phone numbers, company, notes, tags, custom fields) about your contacts, leads and customers: we store and show them in your CRM, send the email, SMS and WhatsApp messages you compose, and run the automations you set up.
- Messages and conversation history from anyone who writes to you through a connected channel (email, WhatsApp, SMS, Messenger, Instagram, Telegram or website live chat): we show them in your inbox, let Chip draft replies you approve or, where you switch it on, answer for you, and keep them for as long as you keep the conversation.
- Form answers and booking details from people who fill in your forms or book with you: we store them, create contacts and trigger the automations you chose.
- Calls handled by the AI voice agent or through a connected phone provider: where recording or transcription is switched on, we keep the recording or transcript in your workspace so you can review it.
- Invoices, payment references and amounts for your customers: we issue and track bills and pass payment details to the payment provider you connected. Card numbers go straight to that provider; we never see or store them.
- Team members’ names, emails, roles and activity: we sign them in, apply the permissions you set and keep the audit log.
- Delivery, open and click events for your email recipients: we show you campaign results and honour unsubscribes and complaints automatically.
We do not ask for special category data (such as health, biometric data, religious beliefs or sexuality). If you choose to store it in a free-text field or custom field, you are responsible for having a lawful basis for it.
Our commitments
- Only on your instructions. Your use of the product is your instruction. We never use your contacts’ data for our own marketing, never sell it, and never use it to train AI models.
- Confidentiality. Everyone at startbuddi who can reach customer data is bound by confidentiality and can reach only what their job needs.
- Security. We protect the data with the measures summarised below and described on our Security page.
- Helping with people’s rights. Tools to export, correct and delete a person’s data, and to handle objections, are built into the product (Settings, then Privacy and data, plus the unsubscribe and preference links in every email). If a request reaches us directly, we pass it to you within 3 business days and help you answer it.
- Breach notification. If we become aware of a personal data breach affecting your data, we tell you without undue delay and within 48 hours, with what we know, what it affects and what we are doing, so you can meet your own deadlines (72 hours under the GDPR and the NDPA).
- Deletion. When you delete a workspace, its data is removed from live systems within 30 days (in practice straight away) and from backups within 90 days, unless the law requires us to keep part of it (invoice records, for example). You can export everything first from Settings, then Danger zone.
- Audits. Once a year, with 30 days’ notice, you can ask us for the information you need to show we meet this agreement: our current security summary, our subprocessors’ terms and, where available, third-party assessment reports. If that is not enough for your regulator, we will cooperate with an audit at your cost, scoped so it does not expose other customers’ data.
Your commitments
- Have a lawful basis for every contact you add and every message you send: consent where the law requires it (for example marketing email in the EU and UK, and under the NDPA where the processing is not needed for a contract or your legitimate interests), and a working opt-out everywhere.
- Follow our Acceptable use policy and the Sending policy: no bought or scraped lists, no misleading subject lines, a real business mailing address in your workspace profile, and honour unsubscribes.
- Tell the people whose data you hold that you use startbuddi as a provider, in your own privacy notice.
- Keep your team’s access appropriate, and remove people who leave.
Subprocessors
We use other companies to run parts of startbuddi, such as hosting, the database, email sending, payments, AI and the messaging channels you connect. Each one works under written terms at least as protective as this agreement, and we stay responsible for them. The current list, with what each provider sees and where it runs, is on our Security page and in the app at app.startbuddi.com/legal/subprocessors.
Providers of channels you connect yourself (for example Meta for WhatsApp, Messenger and Instagram, or Google for Calendar and Gmail) only receive data after your workspace links that service.
We email workspace owners at least 14 days before we add a new subprocessor. To object, email privacy@startbuddi.com within those 14 days, saying which provider and why. We will offer an alternative where one exists. If none does and the provider is essential, you may end the affected feature or your subscription without penalty and receive a pro-rata refund for the rest of the term.
Where data is kept and international transfers
Our main database is hosted in the European Union (Ireland), our app servers run in the EU (Frankfurt) and email is sent from the EU. Uploaded files are stored with Cloudflare. Some subprocessors operate in the United States or globally, including our AI, analytics, SMS and payment providers and the channels you connect.
- Transfers out of the EU and UK rely on the European Commission’s Standard Contractual Clauses (2021) and the UK Addendum to them.
- Transfers out of Nigeria rely on the safeguards allowed by Part VIII of the NDPA, including the recipient’s adequate protection and the same contractual clauses.
The workspace setting “Where your data is kept” records your requirement. It does not move data to a different region today.
Security measures (summary)
- Encryption in transit (TLS) for every connection, and encryption at rest for the database and file storage.
- A second layer of encryption for connected-account tokens and API secrets, with keys kept outside the database.
- Role-based access inside each workspace, workspace isolation on every query, and an audit log of who changed what.
- Sign-in protection: rate limits and account lockout after repeated failed attempts, and Google sign-in that asks only for your identity.
- Email authentication for mail we send, one-click unsubscribe, and automatic suppression of bounces and complaints.
- Daily database backups, error monitoring, and secrets kept out of code.
- AI providers are called under business API terms that do not allow them to train their models on your data, and Chip only sees what the person asking is allowed to see.
How long this agreement lasts
This agreement applies for as long as we process personal data for you, including the deletion periods above. Liability is as set out in the Terms of service, and the agreement is governed by the same law. Where the GDPR or UK GDPR applies to your data and this agreement conflicts with it, the GDPR wins.
Contact
For questions, requests, a signed copy, or to reach the person responsible for data protection at startbuddi, email privacy@startbuddi.com.
Version history
Earlier versions
- Current version1 October 2026
- Earlier version (replaced in full by this version)
Questions about this document? Email privacy@startbuddi.com.