GDPR Compliance
Tenashi (“Tenashi”, “we”, “us”) provides a shared WhatsApp workspace — inbox, CRM, and support desk — that lets teams manage the messages and contacts flowing through their WhatsApp accounts. Because that work involves personal data of people in the European Economic Area (EEA), the United Kingdom, and beyond, we take the EU General Data Protection Regulation (GDPR) seriously and have built our product and processes to support it.
This page summarises how we approach GDPR: the roles we play, the agreements we offer, the sub-processors we rely on, the rights available to individuals, and the safeguards we keep around personal data. It is provided for transparency and does not replace our Privacy Policy or any contract you have with us.
Controller and processor roles
GDPR draws a line between the party that decides why and how personal data is processed (the controller) and the party that processes it on someone else’s behalf (the processor). Tenashi sits on both sides of that line depending on the data:
- We are the controller for the account and billing data you give us directly — the names, email addresses, workspace details, and payment records we need to create your account, operate the service, invoice you, and provide support.
- We are a processor for the WhatsApp conversation data inside your workspace — the messages, contacts, group metadata, and media we handle so your team can run its inbox, CRM, and support desk. For that data you are the controller, and we process it only on your documented instructions.
Data Processing Agreement (DPA)
Where Tenashi acts as your processor, GDPR requires a Data Processing Agreement between us. We make a DPA available to any customer who needs one. It sets out the scope and purpose of our processing, our confidentiality and security obligations, our use of sub-processors, and how we assist you with data subject requests and breach notifications.
To request a copy — or to have our DPA countersigned — email hello@usetenashi.com and we will send you the current version.
Sub-processors
To deliver the service we rely on a small, carefully chosen set of sub-processors. Each is bound by a data processing agreement and is engaged only to the extent needed to run Tenashi:
- Amazon Web Services (AWS) — cloud hosting and infrastructure. The AWS infrastructure we build on holds SOC 2 and ISO 27001 certifications.
- Payment processor — securely handles billing and subscription payments so that we do not store full card details ourselves.
- Email provider — delivers transactional email such as sign-in links, notifications, and account notices.
We keep this list current and will give customers advance notice of material changes to our sub-processors so you have an opportunity to object where our DPA provides for it.
Data subject rights
GDPR gives individuals a set of rights over their personal data. Subject to the conditions in the regulation, these include the right to:
- Access — obtain confirmation of, and a copy of, the personal data we hold.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have personal data deleted (the “right to be forgotten”).
- Portability — receive your data in a structured, commonly used format.
- Restriction — limit how we process your data in certain circumstances.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing relies on consent, withdraw it at any time.
For the account data where we are the controller, we handle these requests directly — reach us at hello@usetenashi.com. For the WhatsApp conversation data where we act as a processor, requests should be directed to the customer whose workspace holds the data; we will assist that customer in responding as required by our DPA.
International data transfers
Tenashi is hosted on AWS. Where personal data is transferred outside the EEA or the United Kingdom, we rely on appropriate safeguards recognised under GDPR — including the European Commission’s Standard Contractual Clauses (SCCs) and equivalent mechanisms — so that your data continues to receive an essentially equivalent level of protection.
Security
We protect personal data with encryption in transit, strict access controls, and a least-privilege model that limits who and what can reach production data. Access is granted only where it is needed to operate or support the service, and is logged and reviewed. You can read more about our safeguards on our Security page.
Data retention and deletion
We retain personal data for as long as your workspace is active and we need it to provide the service. When a workspace is closed, we delete or anonymise the associated personal data within a reasonable period, except where we are required to keep certain records to meet legal, tax, or accounting obligations, or to resolve disputes and enforce our agreements.
Breach notification
If a personal data breach affecting your data occurs, we will notify affected customers without undue delay, consistent with our obligations under GDPR, and provide the information you need to meet your own notification duties to supervisory authorities and data subjects.
Contact and Data Protection queries
For any GDPR request or question — including exercising your rights, requesting our DPA, or asking about our processing — contact us at hello@usetenashi.com and we will respond promptly.