GDPR Compliance

Tenashi (“Tenashi”, “we”, “us”) provides a shared WhatsApp workspace — inbox, CRM, and support desk — that lets teams manage the messages and contacts flowing through their WhatsApp accounts. Because that work involves personal data of people in the European Economic Area (EEA), the United Kingdom, and beyond, we take the EU General Data Protection Regulation (GDPR) seriously and have built our product and processes to support it.

This page summarises how we approach GDPR: the roles we play, the agreements we offer, the sub-processors we rely on, the rights available to individuals, and the safeguards we keep around personal data. It is provided for transparency and does not replace our Privacy Policy or any contract you have with us.

Controller and processor roles

GDPR draws a line between the party that decides why and how personal data is processed (the controller) and the party that processes it on someone else’s behalf (the processor). Tenashi sits on both sides of that line depending on the data:

Data Processing Agreement (DPA)

Where Tenashi acts as your processor, GDPR requires a Data Processing Agreement between us. We make a DPA available to any customer who needs one. It sets out the scope and purpose of our processing, our confidentiality and security obligations, our use of sub-processors, and how we assist you with data subject requests and breach notifications.

To request a copy — or to have our DPA countersigned — email hello@usetenashi.com and we will send you the current version.

Sub-processors

To deliver the service we rely on a small, carefully chosen set of sub-processors. Each is bound by a data processing agreement and is engaged only to the extent needed to run Tenashi:

We keep this list current and will give customers advance notice of material changes to our sub-processors so you have an opportunity to object where our DPA provides for it.

Data subject rights

GDPR gives individuals a set of rights over their personal data. Subject to the conditions in the regulation, these include the right to:

For the account data where we are the controller, we handle these requests directly — reach us at hello@usetenashi.com. For the WhatsApp conversation data where we act as a processor, requests should be directed to the customer whose workspace holds the data; we will assist that customer in responding as required by our DPA.

International data transfers

Tenashi is hosted on AWS. Where personal data is transferred outside the EEA or the United Kingdom, we rely on appropriate safeguards recognised under GDPR — including the European Commission’s Standard Contractual Clauses (SCCs) and equivalent mechanisms — so that your data continues to receive an essentially equivalent level of protection.

Security

We protect personal data with encryption in transit, strict access controls, and a least-privilege model that limits who and what can reach production data. Access is granted only where it is needed to operate or support the service, and is logged and reviewed. You can read more about our safeguards on our Security page.

Data retention and deletion

We retain personal data for as long as your workspace is active and we need it to provide the service. When a workspace is closed, we delete or anonymise the associated personal data within a reasonable period, except where we are required to keep certain records to meet legal, tax, or accounting obligations, or to resolve disputes and enforce our agreements.

Breach notification

If a personal data breach affecting your data occurs, we will notify affected customers without undue delay, consistent with our obligations under GDPR, and provide the information you need to meet your own notification duties to supervisory authorities and data subjects.

Contact and Data Protection queries

For any GDPR request or question — including exercising your rights, requesting our DPA, or asking about our processing — contact us at hello@usetenashi.com and we will respond promptly.