Data processing & sub-processors
Last updated: 23 August 2026. This page is for the person at your company who has to sign off on a vendor: what we do with your customers’ data, who else touches it, where it sits, and what we commit to in writing. The plain-language overview is on our privacy page.
Roles
When you run WhatsApp support through CustomerX, you are the controller of your customers’ personal data and CustomerX (RidexGo MMC) is your processor. We process that data only to deliver the service and only on your documented instructions — the instructions being your use of the product and the settings you choose in it.
The data-processing agreement
A data-processing agreement under Article 28 GDPR is part of every CustomerX contract and is available on request — email hello@customerx.dev to receive it, or to put one in place for an existing workspace. It covers the things Article 28(3) requires, in plain words:
- We process personal data only on your instructions and only for providing the service.
- Everyone at CustomerX with access is bound by confidentiality.
- We maintain the technical and organisational security measures listed below and on the privacy page.
- We engage sub-processors only under written terms at least as protective as ours, we publish the list on this page, and we give you 30 days’ notice by email before adding or replacing one. If you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected part of the service.
- We help you respond to your customers’ requests — access, correction, deletion, export — including deleting message history and voice transcripts properly.
- We help you meet your security, breach-notification and impact-assessment duties, with the information we hold.
- At the end of the contract we delete your workspace and its data within 30 days, or return it first if you ask.
- We make available the information needed to demonstrate compliance and allow audits by arrangement.
- Transfers outside the EEA/UK — including our own team’s access from Azerbaijan — are covered by the EU Standard Contractual Clauses incorporated in the agreement.
Where your workspace is hosted
Each workspace has its own PostgreSQL database on Railway, in either EU — Amsterdam (europe-west4) or US — California (us-west2). You choose at onboarding; we confirm the region in writing and it does not change without your agreement. EU hosting is available to every customer.
Sub-processors
These providers process your customers’ data (or, for Vercel, this website’s traffic) in order to run CustomerX. We sell or share nothing with anyone else.
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Meta Platforms WhatsApp Ireland Limited (EEA customers); WhatsApp LLC / Meta Platforms, Inc. | WhatsApp Business Platform — message and call delivery | Message content, media, phone numbers, delivery status | Ireland · United States | WhatsApp Business Data Processing Terms + Data Transfer Addendum (EU SCCs; EU–US DPF where applicable) terms ↗ |
| Google Cloud Google LLC and affiliates | Gemini API (AI drafts, summaries, knowledge-base answers), Cloud Translation, Speech-to-Text | Message text and voice audio, per request. Paid tier: not used to train models; abuse-monitoring logs kept up to 55 days | United States / global | Google Cloud Data Processing Addendum (EU SCCs); Google LLC is EU–US DPF-certified terms ↗ |
| OpenAI OpenAI, L.L.C. | Whisper speech-to-text — voice-note transcription, on workspaces configured to use it instead of Google Speech-to-Text | Voice-note audio and the resulting transcript, per request. Not used to train models; API data may be kept up to 30 days for abuse monitoring | United States | OpenAI Data Processing Addendum (EU SCCs); OpenAI, L.L.C. is EU–US DPF-certified terms ↗ |
| Railway Railway Corporation | Application and PostgreSQL database hosting — one database per workspace | All workspace data at rest | EU — Amsterdam (europe-west4) or US — California (us-west2), per workspace | Data Processing Addendum incorporating the EU SCCs and UK Addendum; EU–US DPF where certified terms ↗ |
| Vercel Vercel Inc. | Hosting of customerx.dev (this website only) | Website request logs — no workspace data | United States / global edge | Data Processing Addendum incorporating the 2021 EU SCCs and the UK IDTA terms ↗ |
Optional — only if you enable them
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Customer.io Peaberry Software, Inc. | CRM / marketing-automation sync — only if you enable the integration in Settings | Customer identifier, tags and tag-change events, last-contact timestamp, rating. No message content, no phone numbers | EU data centre (cdp-eu.customer.io) | Customer.io Data Processing Agreement (EU SCCs) terms ↗ |
| Calendly Calendly LLC | Demo booking calendar embedded on this website — only if you book | Name, email and booking details you enter | United States | Calendly privacy notice and DPA terms ↗ |
Changes to this list: 30 days’ notice by email to the workspace owner before a provider is added or replaced. Removals are reflected here without notice.
Security measures
- TLS for all traffic in transit; databases encrypted at rest.
- One database per workspace — no shared tables between customers.
- Individual agent logins, role-based access, bcrypt-hashed passwords, rate-limited sign-in, idle-session expiry, and immediate sign-out when an account is disabled.
- Signature-verified inbound webhooks; per-key API secrets that you rotate or revoke yourself; audit log of administrative actions.
- Media is never stored by us — it is fetched from Meta by reference when an agent opens it.
- Operational logs are kept 30 days; per-recipient broadcast reports 90 days; an optional rolling purge permanently erases deleted customer records after a retention period you set.
If there is a breach
We notify you without undue delay and in any case within 72 hours of becoming aware of a personal-data breach affecting your workspace, with the nature of the breach, the data and people affected, the likely consequences, and the measures taken — and we keep you updated as we learn more.
Contact
Questions, the agreement itself, or a security questionnaire: hello@customerx.dev.