Data Processing Agreement
Version 1.2.0 · Effective 29 August 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between AnnFar Global (Pvt) Ltd, a company incorporated in Sri Lanka and trading as “Unisay” (“Processor”, “Unisay”), and the Vendor (“Controller”) and governs the processing of personal data by Unisay on the Controller’s behalf in the operation of the Service. Capitalised terms not defined here have the meanings given in the Terms of Service or the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as modified by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (the “PDPA”). The substantive controller and processor obligations and the Authority’s penalty powers are not yet operative as of the effective date of this version; this DPA is written to be compliance-ready for those provisions when they commence.
1. Roles of the parties
With respect to personal data of the Controller’s end-customers (“Customers”) processed through the Service, the Controller is the Controller and Unisay is the Processor. The Controller represents and warrants that it has obtained a lawful basis under the PDPA to collect, use, and disclose Customer personal data, and that its instructions to Unisay regarding such data are lawful.
For data Unisay processes for its own purposes (Vendor account management, billing, product analytics aggregated across the platform, fraud prevention, security monitoring, and Service operation including automatic refresh of the Controller’s Meta access tokens), Unisay is the Controller; that processing is described in our Privacy Policy. Unisay does not use Customer message content, Customer Channel-Scoped Identifiers, or any other Customer personal data for its own AI-model training, its own marketing, or any other secondary use that is not strictly instructed by the Controller for the Controller’s benefit. Where any cross-purpose processing arises in future, Unisay shall first secure a separate lawful basis (Controller’s further instruction, Customer’s explicit consent, or another PDPA-permitted ground) and shall surface the new processing in this DPA before commencing it.
2. Subject matter, duration, nature, and purpose
- Subject matter: the provision of the Unisay Service to the Controller, across all Meta Channels (WhatsApp Business, Instagram Direct, Facebook Messenger) and asset surfaces (Catalog, Page, WhatsApp Business Account, Instagram Business account) the Controller has linked.
- Duration: for as long as the Controller maintains an account with Unisay, plus any post-termination period required by §11.
- Nature of processing: storage, retrieval, transmission, search (including AI-assisted), aggregation, deletion, and inter-channel routing of personal data as necessary to operate the Service.
- Purpose: to enable the Controller to communicate with their Customers across the WhatsApp, Instagram Direct, and Messenger surfaces; to manage orders, generate invoices, coordinate deliveries, and analyse their business via the Service; and to call Meta’s Graph, Send, and Subscribed-Apps APIs on the Controller’s behalf using the access tokens the Controller has authorised Unisay to hold.
3. Categories of personal data and data subjects
Categories of data subjects: the Controller’s Customers (the end-customers of the Controller’s business) and the Controller’s authorised staff users.
Categories of personal data processed on the Controller’s behalf:
- Contact data: Customer names (where shared), phone numbers in E.164 format (for WhatsApp Customers), Customer-supplied emails.
- Channel-Scoped Identifiers: WhatsApp profile id (
wa_id), Instagram-Scoped User ID (igsid) for Instagram Direct Customers, Page-Scoped User ID (fbPsid) for Facebook Messenger Customers, the channel-identity row linking each identifier to the Customer record and to the Controller’s asset (Page, Instagram Business account, WhatsApp Business Account) that received the conversation. - Address data: delivery and billing addresses, district, postal code.
- Commercial data: orders, invoices, payments, credit account state, customer segmentation tags assigned by the Controller, source channel, preferred language.
- Conversation content: WhatsApp Business, Instagram Direct, and Facebook Messenger messages (including media attachments — images, audio, video, documents, stickers — and location coordinates when shared); reactions and quoted-reply context.
- Attribution data: the full
referralobject Meta delivers on the first inbound of an ad-driven conversation, with channel-specific identifiers —ctwa_clidfor Click-to-WhatsApp,referral.source: 'ig.me'+reffor Instagram-ad-to-DM, andreferral.source: 'm.me'+reffor Messenger-ad-to-DM. - Vendor Meta access tokens: the long-lived user access token, per-Page access tokens issued via
/me/accounts, the WhatsApp Business Account access token, and the WhatsApp webhook verify token. All stored encrypted at rest under AES-256-GCM with the version prefixv1:. - Technical data: IP address, User-Agent, session metadata, JWT identifiers, message platform IDs, timestamps.
- Inferred data: segmentation tags, AI-classified intents, embedding vectors derived from product names and descriptions.
3A. Cross-channel identity merge
Under PDPA principles of data minimisation and purpose limitation, Unisay doesnot automatically infer that two channel-scoped identifiers (e.g. a Customer’s WhatsApp number and their Instagram-Scoped ID) belong to the same natural person. Cross-channel identity merge — recognising the same Customer across two different channels — is performed only by explicit Vendor staff action in the Unisay dashboard (an operator clicks “merge into existing customer” with full visibility of what they are merging). The Controller is responsible for ensuring such a merge is justified by their lawful basis with the Customer (typically the Customer’s self-identification across channels). Merges are recorded in the audit log and may be reversed by the Controller within the audit-log retention window.
4. Controller instructions
Unisay processes personal data only on the documented instructions of the Controller, unless required to do otherwise by Sri Lankan law. The Terms of Service, this DPA, the Privacy Policy, and the configuration choices the Controller makes in the Unisay dashboard together constitute the Controller’s documented instructions, including:
- The OAuth Login Configuration flow(s) the Controller has completed (Commerce flow, Messaging flow, WhatsApp Embedded Signup) — each grants Unisay a discrete scope bundle.
- The Vendor Meta Assets the Controller has selected in the asset-picker (specific Pages, Catalogs, Instagram Business accounts) — Unisay will not act on assets not selected.
- AI Agent enablement, provider selection, response-mode (OFF / SUGGEST / AUTO), AUTO threshold, guarded-topic regex list, and per-Customer
forceSuggestoverrides. - Retention settings, opt-out keyword list, and consent records.
- The list of cross-channel identity merges performed by the Controller’s staff (per §3A).
Unisay will inform the Controller if, in its opinion, an instruction infringes the PDPA or other applicable data protection law.
5. Confidentiality of personnel
Unisay shall ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations (whether contractual or statutory) and have received appropriate training on data protection.
6. Security measures
Unisay shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including those described in §13 of the Privacy Policy: TLS 1.2+ in transit; application-layer AES-256-GCM at rest for all Meta access tokens, per-Page access tokens, webhook verify tokens, password reset tokens, and Courier API keys; HMAC-SHA256 verification of every inbound Meta webhook (X-Hub-Signature-256); the appsecret_proof parameter on every outbound Graph API call; bcrypt password hashing; multi-tenant isolation enforced at every database query; role-based access control; append-only audit logging; and five offline breach detectors running on a 10-minute cron.
Unisay reviews and updates these measures from time to time. Unisay may make changes to the security measures provided that such changes do not materially decrease the level of protection.
7. Sub-processors
The Controller authorises Unisay to engage the sub-processors listed at /sub-processors as of the effective date of this DPA, and further authorises Unisay to engage additional sub-processors subject to the prior-notice process described in §7.2.
For the avoidance of doubt, Meta Platforms, Inc. operates as a sub-processor across all Meta surfaces the Controller has connected — WhatsApp Business Platform, Instagram Platform (graph.instagram.com), Messenger Platform (graph.facebook.com), Catalog API, and Facebook Login for Business. Each connection is initiated by the Controller’s explicit OAuth consent.
7.1. Unisay shall enter into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this DPA, to the extent applicable to the nature of the sub-processor’s services.
7.2. Unisay shall provide at least 30 days’ advance notice via the Unisay dashboard before adding any new sub-processor that processes personal data. The Controller may object in writing within the notice period. If Unisay cannot accommodate the objection, the Controller’s exclusive remedy is to terminate the affected feature or, where the sub-processor is essential to the Service, to terminate the Service in accordance with Terms §13–14, and to receive a pro-rata refund of pre-paid fees.
7.3. Unisay remains liable for the acts and omissions of its sub-processors with respect to the obligations under this DPA, subject to the limitations in Terms §11.
8. International transfers
Where Unisay or its sub-processors transfer personal data outside Sri Lanka, Unisay shall ensure that one or more of the instruments contemplated by the Sri Lanka Data Protection Authority’s draft Directive on Cross-Border Transfers (issued for public consultation 2 October 2024) is in place, namely: (a) binding corporate rules within the recipient’s corporate group; (b) contractual agreements imposing binding and enforceable data-protection commitments; (c) industry codes of conduct subscribed to by the recipient; (d) binding certification schemes; or (e) cross-border processing impact assessments where required. The Sri Lanka Data Protection Authority has not yet designated any third country as having an adequate level of protection under PDPA s.26(2).
9. Assistance with data subject requests
Unisay shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests from data subjects exercising their rights under the PDPA. Unisay provides:
- A self-service data export endpoint accessible to the Controller via the Unisay dashboard, fulfilling the right of access and right to data portability. The export includes data across all connected Meta Channels for the requested Customer.
- A self-service deletion endpoint for the right to erasure, subject to legal retention obligations (including the 5-year tax-record retention under Inland Revenue Act §123). Erasure is performed as PDPA-compliant anonymisation rather than hard deletion where the Controller has a competing tax-record obligation.
- A Meta Data Deletion Callback at
/api/legal/data-deletion-callbackthat accepts Meta-initiated deletion requests for Customers who have revoked the Controller’s app on their Meta side. The callback returns the JSON shape required by Meta —{ url, confirmation_code }— and triggers the erasure flow asynchronously. - Reasonable assistance via support channels for other rights requests.
Response timeline. Unisay supports the Controller in responding to data subject requests within one (1) month of receipt by the Controller, extendable by a further two (2) months for complex requests (totalling no more than three months), in line with the PDPA. Where a Customer contacts Unisay directly because the Controller has not responded, Unisay will assist within the same statutory timeframe and notify the Controller.
10. Personal data breach assistance
Unisay shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and in any event within 24 hours of confirmed identification, providing the information necessary for the Controller to meet its own notification obligations under the PDPA (target: 72 hours from awareness). The notification will include, to the extent known: the nature of the breach, the Meta Channels affected, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
11. Deletion or return on termination
On termination of the Service contract, the Controller may export their data via the Service for 30 calendar days. Thereafter, Unisay shall delete all personal data processed on the Controller’s behalf within 60 calendar days, except: (a) backups subject to standard rotation (expired within 30 further days); (b) data Unisay or the Controller is legally required to retain (including the 5-year tax-record period under Inland Revenue Act §123 — retained in a purpose-locked store, not available for any non-statutory processing); and (c) anonymised analytics that do not identify any data subject. The Controller’s Meta access tokens (long-lived user token; per-Page access tokens for Messenger Send; IG-side access tokens; the WhatsApp Business Account access token) and webhook verification secrets are cleared on termination across all connected channels; encrypted-at-rest backup snapshots containing them expire on the standard 30-day rotation. Unisay shall confirm deletion in writing on Controller’s reasonable request.
12. Audit rights
Unisay shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. The Controller’s audit right is satisfied by:
- Unisay’s response to a reasonable security questionnaire.
- Provision of any third-party audit reports Unisay obtains (for example, SOC 2 reports when available).
- On-site or remote audits at the Controller’s expense, conducted no more than once per year (except in the event of a confirmed material breach), on at least 30 days’ prior written notice, during business hours, and subject to mutually agreed scope and confidentiality terms.
13. Liability
Liability under this DPA is subject to the limitation of liability set out in §11 of the Terms of Service (12-month fees cap, with carve-outs for gross negligence, willful misconduct, fraud, intentional confidentiality breach of personal data, and mandatory non-waivable rights). For the avoidance of doubt, this DPA does not increase or decrease the aggregate liability cap.
14. Order of precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to processing of personal data on the Controller’s behalf. The Terms of Service prevail on all other matters.
15. Updates to this DPA
Unisay may update this DPA from time to time. Material changes will require the Controller’s re-acceptance via click-through; non-material changes take effect on posting at /dpa. Past versions are at /legal/history/dpa.