Skip to content
WaselChat
  • Product
  • Pricing
  • Docs
  • Security
  • About
العربية Book a demo

The English version is legally governing; Arabic translation coming soon.

Data Processing Addendum (DPA)

Version 1.0 — August 11, 2026 — published for customer review; executed as part of each customer’s signed agreement. This addendum reflects our standard processing terms and is subject to counsel review in the customer’s jurisdiction before signature.

1. Roles and scope

For personal data submitted to a Customer Instance (“Service Data” — including student profiles, enrollment records, activity events, and conversation content), the customer is the controller and Molab LLC is the processor. Much of this data relates to minors; the customer is responsible for the lawful basis, notices, and any parental consents its own service requires, and Molab designs the service so each customer’s data stays architecturally isolated.

2. Instructions

Molab processes Service Data only: (a) to provide, secure, and support the Customer Instance; (b) as documented in the agreement and this DPA; and (c) per the customer’s other documented instructions. Molab does not use Service Data for advertising, profiling for its own purposes, or training models.

3. Confidentiality and personnel

Access to Service Data is limited to personnel who need it to deliver the service and who are bound by confidentiality obligations.

4. Security measures

  • One dedicated, isolated instance per customer: separate application, database, and storage; no shared database and no cross-customer access path.
  • Hosting in EU data centers; TLS encryption in transit on all connections.
  • Server-side HMAC verification of end-user identity.
  • Scheduled database backups, with restore procedures tested before go-live.
  • Secrets management separated from code; least-privilege operational access.

5. Sub-processors

The current list is published at /legal/subprocessors. The customer consents to those sub-processors and will be notified of intended additions or replacements at least 30 days before they take effect, with the right to object on reasonable data-protection grounds.

6. Assistance

Taking into account the nature of the processing, Molab will reasonably assist the customer with data-subject requests (access, correction, deletion, export) and with the customer’s security and impact-assessment obligations.

7. Personal data breach

Molab will notify the customer without undue delay after becoming aware of a personal data breach affecting Service Data, and will provide information reasonably required for the customer’s own notification obligations as it becomes available.

8. International transfers

Service Data is hosted in the EU. Where a transfer of Service Data to a country without an adequacy finding is necessary (including operational access), the parties will rely on appropriate safeguards such as the EU Standard Contractual Clauses, incorporated into the signed agreement as needed.

9. Return and deletion

On termination or expiry, Molab will make Service Data available for export in a commonly used format and, after the customer confirms export (or after 30 days), delete Service Data from the instance and subsequently from backups in the ordinary backup cycle.

10. Audit

Molab will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow audits as agreed in the signed agreement, no more than annually absent a supervisory-authority requirement or a material incident.

WaselChat

WaselChat is a product of Molab LLC.

© 2026 Molab LLC.

  • Product
  • Pricing
  • Docs
  • Security
  • About
  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Sub-processors