Legal
Data Processing Addendum
How startbuddi handles the personal data your workspace puts in it — your contacts, subscribers, customers, bookings and team. Part of the Terms of Service. Last updated 16 September 2026.
1. Who is who
You (the workspace owner and the business it belongs to) are the controller of the personal data you add to startbuddi: your contacts, email subscribers, customers, booking guests, form respondents, and the people you invite to your team. You decide why that data is collected and what happens to it.
startbuddi (Tech Della Solutions Ltd, Lagos, Nigeria — “we”) is the processor. We store, send, sync and analyse that data only to provide the service to you, on your instructions.
For your own account details (your name, email, billing), startbuddi is the controller and our Privacy Policy applies instead.
2. What we process, and why
| Data | People it is about | What we do with it |
|---|---|---|
| Names, email addresses, phone numbers, company, notes, tags, custom fields | Your contacts, leads and customers | Store and display in your CRM; send the email, SMS and WhatsApp you compose; run the automations you set up |
| Messages and conversation history | Anyone who writes to you through a connected channel | Show in your inbox; let Chip draft replies you approve; keep as long as you keep the conversation |
| Form and survey answers, booking details | People who fill in your forms or book with you | Store; create contacts; trigger the automations you chose |
| Invoices, payment references, amounts | Your customers | Issue and track bills; pass payment details to the payment provider you chose |
| Names, emails, roles, activity | Your team members | Sign them in, apply the permissions you set, keep the audit log |
| Delivery, open and click events | Recipients of your email | Show you campaign results; honour unsubscribes and complaints automatically |
We do not process special-category data (health, biometrics, beliefs, sexuality) unless you choose to put it in a free-text field; if you do, you are responsible for the lawful basis.
3. Our obligations
- Only on your instructions. Your use of the product is the instruction. We never use your contacts’ data for our own marketing, never sell it, and never train AI models on it.
- Confidentiality. Everyone at startbuddi with access to customer data is bound by confidentiality and has access only to what their job needs.
- Security. Data is encrypted in transit (TLS) and at rest; connected-account tokens are additionally encrypted with keys held outside the database; access is logged. Details in section 7.
- Subprocessors. We use the providers listed at /legal/subprocessors under written terms at least as protective as this addendum, and we remain responsible for them. We give 14 days’ notice by email before adding one; if you object on reasonable grounds and we cannot resolve it, you may end the affected part of the service and receive a pro-rata refund.
- Helping you with people’s rights. Export, correction, deletion and objection tools are built into the product (Settings → Privacy, and the unsubscribe and preference links on every email). Where a request reaches us directly, we forward it to you within 3 business days and help you answer it.
- Breach notification. If we become aware of a personal data breach affecting your data, we tell you without undue delay and within 48 hours, with what we know, what it affects, and what we are doing — early enough for you to meet your own 72-hour deadline.
- Deletion. When you delete a workspace, its data is deleted from live systems within 30 days and from backups within 90 days, unless the law requires us to keep it (invoice records, for example). You can export everything first from Settings → Danger zone.
- Audits. Once a year, on 30 days’ notice, you may ask us for the information needed to show we meet this addendum — our current security summary, subprocessor terms and, where available, third-party assessment reports. Where that is not enough for your regulator, we will cooperate with an audit at your cost, scoped to avoid exposing other customers’ data.
4. Your obligations
- Have a lawful basis for every contact you add and every message you send — consent where the law requires it (marketing email in the EU and UK; anything under Nigeria’s NDPA that is not a contract or legitimate interest), and a working opt-out everywhere.
- Keep the Sending Policy: no bought or scraped lists, no misleading subject lines, a real business mailing address in your workspace profile, and honour unsubscribes. Spam complaints above 0.5% pause sending for your workspace.
- Tell the people whose data you hold that you use startbuddi as a provider, in your own privacy notice.
- Keep your team’s access appropriate and remove people who leave.
5. Where data lives, and transfers
Your workspace data is stored in the European Union (Ireland). Email is sent from the EU. Some subprocessors operate in the United States or globally — AI providers, payment providers, and the channels you connect (Meta, Google). Transfers out of the EU/UK rely on the EU Standard Contractual Clauses (2021) and the UK Addendum; transfers out of Nigeria rely on the recipient’s adequate protection under NDPA section 43 and the same contractual clauses. The subprocessor list shows the region for each provider.
6. Objecting to a subprocessor
Email privacy@startbuddi.com within 14 days of our notice, saying which provider and why. We will offer an alternative where one exists; if none does and the provider is essential, you may terminate the affected feature or your subscription without penalty for the remaining term.
7. Security measures (summary)
- TLS for every connection; HSTS; a content security policy on every page.
- Encryption at rest for the database and file storage; a second layer of AES-256-GCM encryption for connected-account tokens and API secrets, with keys kept outside the database.
- Role-based access inside a workspace; workspace isolation enforced on every query; audit log of who did what.
- Sign-in protection: rate limits, account lockout after repeated failures, session timeouts, optional Google sign-in with identity-only scope.
- Email authentication for everything we send (SPF, DKIM, DMARC); one-click unsubscribe; automatic suppression of bounces and complaints.
- Daily backups; monitored error reporting; least-privilege access for staff; secrets in a managed vault, never in code.
- AI providers are called under zero-retention API terms; Chip only ever sees the data the requesting user is allowed to see.
8. Term, liability, law
This addendum lasts as long as we process personal data for you. Liability is as set in the Terms of Service. It is governed by the same law as the Terms; where the GDPR or UK GDPR applies to your data, this addendum is intended to meet Article 28(3) and, in the event of a conflict, the GDPR prevails.
Questions, requests and the contact for our Data Protection Officer: privacy@startbuddi.com.