Data Processing Agreement
Effective from 26 August, 2026
Last updated 26 August, 2026
Parties
(1) Legal entity/solo entrepreneur/solo trader, who has signed up to and accepted the edna Terms (the “Customer”)
(2) MF Management Ltd, a limited liability company incorporated under the laws of the Republic of Cyprus, with company registration number ΗΕ 325492 and having its registered office at 10 Parni, 3117, Limassol, Cyprus (the “Supplier”)
(each a party and together the parties)
Background
(A) The Supplier sublicenses a software to the Customer on the basis of a SaaS sublicense model or traditional software sublicense model, the Customer uses the software, inter alia, to aggregate their messaging activity from different channels on one platform, or the Supplier provides messaging services to the Customer with the use of certain messengers and Supplier’s software (Services).
(B) The Services are offered to the Customer on the basis of the Supplier’s edna Terms signed up to and accepted by the Customer on or about the date according to the conditions of the edna Terms (Terms).
(C) The parties have agreed to enter into this Agreement in relation to the processing of personal data by the Supplier in the course of providing the Services and, subject to clause 1.10, the terms of this Agreement are intended to apply in addition to and not in substitution of the conditions of the Terms.
(D) This Agreement is subject to the conditions of the Terms and is incorporated into the Terms. The terms used in this Agreement shall have the meanings set out in this Agreement. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Terms.
Agreed terms
1. Definitions and interpretation
1.1 In this Agreement the terms controller, processor, personal data, special categories of personal data, processing, pseudonymisation, personal data breach and supervisory authority shall have the meanings given to them in the Data Protection Legislation (as defined in clause 1.2 below).
1.2 In addition to those terms referred to in clause 1.1, the following definitions shall apply in this Agreement:
| Affiliates | in relation to a Customer which is a company, each and any business entity or undertaking under the Customer’s direction and in relation to either party, any entity that directly or indirectly controls, is controlled by or is under common control with that party (where control is defined as the direct or indirect ownership or control of more than 50% of the shares, of an entity or of the power to direct or significantly influence the direction of the management, policies and voting interests of an entity whether by contract or otherwise). |
| Authorised Person | a person authorised by the Customer, from time to time, to represent the Customer under Terms. Where the Customer is a sole trader or individual entrepreneur, the Customer shall be deemed to representing himself, without prejudice to its right to notify the Supplier in writing of any other Authorised Person. |
| Business Day | a day other than a Saturday, Sunday or public holiday in the Republic of Cyprus. |
| Data Protection Legislation | the GDPR as transposed into Cyprus law through the enactment of the Law Providing for the Protection of Natural Persons with Regard to the Processing of Personal Data and for the Free Movement of Such Data (Law 125(I)/2018), as amended and/or supplemented and/or replaced from time to time. |
| EEA | the European Economic Area. |
| GDPR | Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) as amended and/or supplemented and/or replaced from time to time. |
| Personnel | in relation to party, those of its employees, workers, agents, consultants, contractors, sub-contractors, representatives or other persons employed or engaged by that party on whatever terms. |
| Sub-processor | any entity (whether or not an Affiliate of the Supplier, but excluding the Supplier’s Personnel) appointed by or on behalf of the Supplier to process personal data on behalf of the Customer under this Agreement. Such entity may be located outside of the European Union or European Economic Area |
1.3 Clause, schedule and paragraph headings shall not affect the interpretation of this Agreement.
1.4 A person includes a natural person, corporate or unincorporated body (whether or not having separate legal personality). A reference to a company shall include any company, corporation or other body corporate, wherever and however incorporated or established.
1.5 Unless the context otherwise requires, any reference to a party shall be deemed to include that party’s Affiliates and where an obligation is imposed on a party under this Agreement, it will be required to procure compliance with such obligation by that party’s Affiliates where appropriate.
1.6 Unless the context otherwise requires, words in the singular shall include the plural and in the plural shall include the singular and a reference to one gender shall include a reference to the other genders.
1.7 A reference to a statute or statutory provision is a reference to it as amended, extended or re-enacted from time to time and shall include all subordinate legislation made from time to time under that statute or statutory provision.
1.8 Unless the context otherwise requires, a reference to writing or written includes email but not fax.
1.9 Any words following the terms including, include, in particular or for example or any similar phrase shall be construed as illustrative and shall not limit the generality of the related general words.
1.10 In the event of any ambiguity or inconsistency between the terms of this Agreement (including its Schedules) and the conditions of the Terms, the terms of this Agreement shall take precedence.
1.11 The Schedules form part of this Agreement and will have effect as if set out in full in this Agreement. Any reference to this Agreement includes Schedules.
1.12 This Agreement is subject to the terms of the Terms and is incorporated into the Terms. The terms used in this Agreement shall have the meanings set out in this Agreement. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Terms.
2. Roles and responsibilities
2.1 The parties hereby record their intention that, for the purposes of the Data Protection Legislation, the Customer shall be the controller and the Supplier shall be the processor.
2.2 Schedule 1 sets out the scope and purpose of the processing of personal data by the Supplier, the duration of the processing and the types of personal data and categories of data subject concerned.
3. Compliance with Data Protection Legislation
3.1 Each party shall comply with all applicable requirements of the Data Protection Legislation. This clause 3.1 is in addition to, and does not relieve any party from complying with, a party’s obligations under the Data Protection Legislation.
3.2 Without prejudice to the generality of clause 3.1, the Customer will ensure that it has all necessary appropriate consents and notices in place to enable the lawful transfer to and processing of the personal data by the Supplier in connection with the performance by the Supplier of its obligations under the Terms and this Agreement.
3.3 To the extent within the Customer’s control having regard to the Supplier’s obligations under the Terms and this Agreement, the Customer shall be responsible for the accuracy and quality of the personal data processed by the Supplier under this Agreement.
4. Processing of personal data by the Supplier
4.1 The Supplier shall only process personal data:
4.1.1 for the purposes expressly specified in the Terms;
4.1.2 for any purposes specified in Schedule 1; and
4.1.3 otherwise in accordance with the Customer’s documented instructions [as given by an Authorised Person and they can be provided electronically by working in the Software (and its configuration), access to which is provided under the Terms.],
unless the Supplier is required by any applicable law to which the Supplier is subject, to process personal data for any other purposes (in which case the Supplier shall, to the extent permitted by such applicable law, inform the Customer of such legal requirement before undertaking such processing).
4.2 The Customer shall ensure that any Authorised Person is fully aware of the conditions of the Terms and this Agreement such that the Supplier shall be entitled to assume that any instruction given by any Authorised Person to the Supplier under clause 4.1 shall be given with the Customer’s full authority. The Customer further acknowledges and agrees that the Supplier shall not be under any duty to investigate the completeness, accuracy or sufficiency of any instructions given to it by any Authorised Person.
5. Supplier’s Personnel
5.1 The Supplier shall take reasonable steps to ensure the reliability of those of its Personnel who may have access to any personal data.
5.2 The Supplier shall ensure that those of its Personnel authorised to process personal data under this Agreement:
5.2.1 are aware of the confidential nature of the personal data;
5.2.2 are bound by obligations of confidentiality by virtue of a written agreement between the Supplier and such persons; and
5.2.3 have received appropriate training on the handling of personal data and on their responsibilities in relation to the processing of personal data.
5.3 The Supplier shall implement appropriate technical and organisational measures to ensure that those of its Personnel only have access to such part or parts of the personal data as is strictly necessary for the performance of their duties and obligations.
6. Security of the processing
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of the data subjects the Supplier shall, in relation to the processing of personal data under this Agreement, implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including, as appropriate:
6.1.1 the pseudonymisation and encryption of personal data;
6.1.2 the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services in accordance with SLA (the Service Level Agreement);
6.1.3 the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
6.1.4 a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
6.2 In assessing the appropriate level of security, the Supplier shall take into account any risks that are presented by the processing, in particular, from a personal data breach.
6.3 Without prejudice to the generality of clauses 6.2 and 6.3, the Supplier shall implement the specific security measures implemented pursuant to any applicable privacy policies for the purpose of processing personal data pursuant to this Agreement.
7. Sub-processors
7.1 The Customer hereby authorises the Supplier to appoint Sub-processors as this may be required, subject to the provisions of this clause 7 (Approved Sub-processors).
7.2 With respect to each Sub-processor appointed by the Supplier, the Supplier shall:
7.2.1 undertake appropriate due diligence prior to the processing of personal data by such Sub-processor to ensure that it is capable of providing the level of protection for personal data required by the conditions of the Terms and this Agreement;
7.2.2 enter into a written agreement with the Sub-processor incorporating terms which are substantially similar (and no less onerous) than those set out in this Agreement and which meets the requirements stipulated in article 28(3) of the GDPR; and
7.2.3 as between the Customer and the Suppler, remain fully liable to the Customer for all acts or omissions of such Sub-processor as though they were its own.
7.3 To the extent that the Supplier has already appointed any Sub-processors prior to the processing of any personal data under this Agreement, the Supplier shall ensure that its obligations under clause 7.2 are met as soon as practicable.
7.4 Where the Supplier proposes any changes concerning the addition or replacement of any Approved Sub-processor, it shall notify the Customer in writing as soon as reasonably practicable prior to implementing such change specifying:
7.4.1 the name of any Sub-processor which it proposes to add or replace;
7.4.2 the processing activity or activities affected by the proposed change;
7.4.3 the reasons for the proposed change; and
7.4.4 the proposed date for implementation of the change.
7.5 If within thirty (30) days of receipt of a notice under clause 7.4 the Customer [(acting reasonably and in good faith)] notifies the Supplier in writing of any objections to the proposed change, the parties shall use their respective reasonable endeavours to resolve the Customer ’s objections. Where such resolution cannot be agreed within thirty (30) days of the Supplier’s receipt of the Customer’s objections (or such longer period as the parties may agree in writing) the Customer may, notwithstanding the conditions of the Terms, serve written notice on the Supplier to terminate the Terms (to the extent that the provision of the Services is or would be affected by the proposed change).
7.6 The Supplier shall, upon the Customer’s request, provide the Customer with copies of any agreements between the Supplier and its Sub-processors (which may be redacted to remove information which is confidential to the Supplier and/or its Sub-processors and which is not relevant to the terms of this Agreement).
8. Rights of data subjects
8.1 Taking into account the nature of the processing, the Supplier shall assist the Customer by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the data subject’s rights under the Data Protection Legislation.
8.2 Without prejudice to the generality of clause 8.1, the Supplier shall implement measures intended to uphold the rights of data subjects.
8.3 The Supplier shall:
8.3.1 promptly and in any case within twenty-four (24) hours/one (1) Business Day notify the Customer if it (or any of its Sub-processors) receives a request from a data subject under the Data Protection Legislation in respect of any personal data processed by the Supplier under the conditions of the Terms or this Agreement; and
8.3.2 give to the Customer its full co-operation and assistance in relation to any request made by a data subject to have access to their personal data.
8.4 The Customer shall:
8.4.1 promptly and in any case within twenty-four (24) hours/one (1) Business Day notify the Supplier (or any of its Sub-processors) with request from a data subject under the Data Protection Legislation in respect of any personal data processed by the Supplier (or any of its Sub-processors) under the conditions of the Terms or this Agreement.
9. Notification of personal data breaches
9.1 The Supplier shall notify the Customer without undue delay after becoming aware of any personal data breach affecting the personal data processed by the Supplier under this Agreement, providing sufficient information to enable the Customer to evaluate the impact of such personal data breach and to meet any obligations on the Customer to report the personal data breach to a supervisory authority and/or notify the affected data subjects in accordance with the Data Protection Legislation.
9.2 The Supplier shall provide the Customer with such assistance as the Customer may reasonably request and take such reasonable commercial steps as the Customer may request in order to evaluate, investigate, mitigate and remediate any personal data breach (including, where applicable, communicating any personal data breach to affected data subjects).
10. Data Protection Impact Assessments and Prior Consultation
The Supplier shall provide the Customer with such assistance as the Customer may reasonably request with any data protection (or privacy) impact assessments and prior consultation with any supervisory authority or other competent authorities which the Customer considers necessary pursuant to Articles 35 and 36 of the GDPR respectively. The Supplier’s assistance shall, in each case, be limited to the processing of personal data under this Agreement.
11. Obligations upon expiry or termination of the Terms
11.1 Notwithstanding the Supplier’s obligations under the Terms following its expiry or termination, the Supplier shall promptly and in any event within thirty (30) days of the expiry or termination of the Terms, at the Customer’s option (given by any Authorised Person) delete all personal data processed by the Supplier and/or its Sub-processors on behalf of the Customer under this Agreement.
11.2 Where the Customer has instructed the Supplier to delete the personal data under clause 11.1, the Supplier shall do so in accordance with best industry practice for the reliable and secure deletion of data for the secure destruction of confidential material.
11.3 The Supplier (and those of its Sub-processors, as appropriate) may retain a copy of the personal data processed by it under this Agreement to the extent required by any applicable law to which the Supplier (or any Sub-processor) is subject and only for such period as shall be required by such applicable law. Where applicable, the Supplier shall notify the Customer of such requirement and shall ensure that such personal data are kept confidential and not processed for any other purpose.
12. Record-keeping requirements and audit rights
12.1 The Supplier shall maintain a record of all categories of processing activities carried out by it on behalf of the Customer under this Agreement in accordance with Data Protection Legislation (Processing Records).
12.2 The Supplier shall permit the Customer, any Authorised Person or any other auditor mandated by the Customer, on reasonable notice and during the Supplier’s normal business hours (but without notice, in the case of any reasonably suspected breach of this clause 12) to:
12.2.1 gain access to, and take copies of, the Processing Records and any other information held at the Supplier’s premises; and
12.2.2 inspect all Processing Records, documents and electronic data and the Supplier’s systems, facilities and equipment,
for the purpose of auditing and certifying the Supplier’s compliance with its obligations under this Agreement. Such audit rights may be exercised only once in any calendar year during the duration of the Terms and for a period of three (3) years following the expiry or termination of the Terms.
12.3 The Supplier shall give all necessary assistance to the conduct of any audits under clause 12.2.
12.4 The Supplier further agrees that it shall provide the Customer with such assistance as it may reasonably request in connection with any compulsory or voluntary audit or inspection by a supervisory authority or other competent authority.
12.5 The Supplier shall immediately inform the Customer if, in its opinion, any instruction infringes the Data Protection Legislation.
13. Transfers of personal data outside of the EEA
13.1 For the purposes of this clause 13, the transfer of any personal data shall include:
13.1.1 storing personal data on servers located or co-located outside the EEA;
13.1.2 appointing any Sub-processor which is located outside the EEA (in accordance with clause 7; or
13.1.3 granting access rights to any of the Supplier’s Personnel who are located outside the EEA.
13.2 The Supplier shall not transfer any personal data processed under this Agreement outside of the EEA except with the Customer y’s prior written consent and provided that the Customer is satisfied that the following conditions have been met:
13.2.1 the Customer, the Supplier and/or any Sub-processor (as appropriate) has provided appropriate safeguards in relation to the transfer;
13.2.2 the data subject has enforceable rights and effective legal remedies in relation to the processing of personal data relating to them; and
13.2.3 the Supplier and/or Sub-processor (as appropriate) complies with its obligations under the Data Protection Legislation by providing an adequate level of protection for any personal data that are transferred.
14. Standard clauses and certification schemes
If at any time the European Commission or any supervisory authority shall adopt any controller-to-processor standard clauses or similar terms forming part of an applicable certification scheme (whether or not relating to the transfer of personal data outside the EEA), either party may request that this Agreement shall be reviewed with a view to adopting the same (in whole or in part).
15. General provisions
15.1 Term and termination: Except in respect of any provision of this Agreement that expressly or by implication is intended come into or continue in force on or after the expiry or termination of the Terms, this Agreement shall be coterminous with the Terms.
15.2 Severance:
15.2.1 If any provision or part-provision of this agreement is or becomes invalid, illegal or unenforceable, it shall be deemed modified to the minimum extent necessary to make it valid, legal and enforceable. If such modification is not possible, the relevant provision or part-provision shall be deemed deleted. Any modification to or deletion of a provision or part-provision under this clause shall not affect the validity and enforceability of the rest of this Agreement.
15.2.2 If any provision or part-provision of this Agreement is invalid, illegal or unenforceable, the parties shall negotiate in good faith to amend such provision so that, as amended, it is legal, valid and enforceable, and, to the greatest extent possible, achieves the intended commercial result of the original provision.
15.3 Variation: This Agreement could be amended, updated or changed from time to time. The Supplier reserves the right to unilaterally change the terms hereof. In case of any amends, updates or changes the Supplier shall notify the Customer of any changes to the Agreement in electronic form in any way, including but not limited to through the Dashboard per the Terms and / or e-mail specified in the Dashboard per the Terms (“Change notification”). The Agreement can be amended in whole or in part. The Customer undertakes to independently monitor any amendments in the Agreement.
Any amends, changes or updates hereto shall come into force as follows: when the text of the Agreement is amended, gets updated – from the date of amended, updated Agreement is uploaded, unless another date of entry into force of such changes, updates not defined additionally in the Agreement or the Change notification.
In the event of a conflict between the terms of Change notification and the terms of the new version of the Agreement or part thereof, the corresponding terms of the published new version of the Agreement or part thereof shall prevail.
15.4 Notices:
All notices, demands and other communications required to be given pursuant to the present Agreement shall be in writing and shall be deemed to have been received if given or made by email and transmitted by email. Notices to the Supplier under this Agreement will be provided via email to [email protected]. Notices to the Customer under this Agreement will be provided via email to the email address specified in the Customer’s Dashboard per the Terms.
Except as otherwise provided in this Agreement, all such communications shall be deemed to have been duly given and shall be effective when transmitted by email.
15.5 Governing law: This Agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of the Republic of Cyprus.
15.6 Jurisdiction: Each party irrevocably agrees that the courts of the Republic of Cyprus shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Agreement or its subject matter or formation (including non-contractual disputes or claims).
Schedule 1 – Summary of the processing activities
1. Processing by the Supplier
a. Scope of the processing
Storage, transfer, recording, use, systematisation, erasure and destruction of personal data in the Supplier’s software/platform for the purpose of a Supplier’s client/partner sending electronic messages to other addresses indicated by him; and for the purposes of a Supplier’s client/partner using a personal account in the Supplier’s software/platform (when applicable).
b. Purpose of the processing
For the purposes set out under the Terms, more specifically in order for the Customer to use the Supplier’s software, ensure its use by the Customer, fulfil the Customer’s requests (for checking the quality of the provided services or as responses to requests from authorized bodies) for the purpose of aggregating their messaging activity of the Customer or the Customer’s end users/users from different channels on the Supplier’s platforms.
c. Duration of the processing
For the duration of the Terms.
2. Types of personal data
The types of personal data to be processed by the Supplier in the course of providing the Services are as follows:
(a) Name, Middle Name and Surname of data subject.
(b) Phone number of data subject.
(c) Other data contained in the messages sent through the services.
(d) Account Username
(e) Registration information (such as ID from messenger, device information, etc.)
(f) Other data which may be technically provided (via account or API) to the Supplier’s software/platform by the Customer (e.g. date of birth, gender, tags for groping of data subject).


