This Addendum forms part of the Navaa Terms of Service and applies where Navaa processes personal data on behalf of a customer subject to the EU GDPR, the UK GDPR or the Swiss FADP. The customer is the controller. Navaa is the processor. Where this Addendum conflicts with the Terms, this Addendum prevails for personal data governed by it.
1. Details of processing
| Subject matter | Provision of the Navaa kanban workspace and WhatsApp task capture service |
|---|---|
| Duration | The term of the customer's subscription, plus the retention periods set out in the Privacy Policy |
| Nature and purpose | Hosting, storage, transmission, display and AI-assisted interpretation of workspace content so the customer's team can manage work |
| Types of personal data | Names, email addresses, job titles, mobile numbers, WhatsApp message content, task content, activity records, IP addresses, and any personal data the customer chooses to put into its workspace |
| Categories of data subjects | The customer's employees, contractors and collaborators, and any individual named in workspace content or messaged through the integration |
| Special category data | Not permitted. The Acceptable Use Policy prohibits it |
2. Navaa's obligations
Navaa will:
- Process personal data only on the customer's documented instructions, including in relation to international transfers, unless required otherwise by law, in which case Navaa will inform the customer before processing unless the law prohibits it. The Terms, this Addendum and the customer's use of the service constitute those instructions.
- Ensure that everyone authorised to process the personal data is bound by an appropriate duty of confidentiality.
- Implement and maintain the technical and organisational measures set out in Annex A.
- Assist the customer, taking into account the nature of the processing and the information available to Navaa, in responding to data subject requests and in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation.
- Notify the customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the customer's personal data, with the information available at that time.
- Make available to the customer the information reasonably necessary to demonstrate compliance with Article 28.
- At the customer's choice, delete or return the personal data at the end of the service, as set out in clause 5.
3. Sub-processors
The customer gives general written authorisation for Navaa to engage the sub-processors listed at navaa.app/subprocessors.
Navaa will give at least 30 days' notice before adding or replacing a sub-processor. The customer may object on reasonable data protection grounds within that period, in which case the parties will discuss the objection in good faith, and if it cannot be resolved the customer may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees for the unused period.
Navaa imposes on each sub-processor data protection obligations no less protective than those in this Addendum, and remains fully liable to the customer for each sub-processor's performance.
4. International transfers
Personal data is stored in Tokyo, Japan, and is processed by sub-processors in the United States, Ireland and India as set out in the sub-processor list.
For transfers of personal data from the EEA, the parties adopt the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated by reference, with:
- Clause 7 (docking clause): not applicable
- Clause 9 (sub-processors): Option 2, general written authorisation, with 30 days' notice
- Clause 11 (redress): the optional independent dispute resolution provision does not apply
- Clause 17 (governing law): the law of Ireland
- Clause 18 (forum): the courts of Ireland
- Annexes I, II and III: populated by clause 1, Annex A and the sub-processor list of this Addendum
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with Tables 1 to 3 populated as above and Table 4 set to “neither party”. For transfers from Switzerland, the Standard Contractual Clauses apply with references to the GDPR read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as competent authority.
5. Deletion and return
On termination or expiry, the customer may export its data through the service for 30 days. After that period Navaa will delete the personal data, and will delete it from backups within 90 days, except where Navaa is required by law to retain it.
6. Audit
Navaa will respond to reasonable written audit enquiries from the customer once in any 12-month period. Where that is insufficient to demonstrate compliance with Article 28, the customer may conduct an audit on 30 days' written notice, at its own cost, during normal business hours, no more than once in any 12-month period, subject to confidentiality obligations and without disrupting Navaa's operations or the data of other customers.
7. Liability
Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the Terms of Service.
Annex A: technical and organisational measures
Authentication. Passwordless sign-in. Six-digit codes expire after 10 minutes and are invalidated after 5 failed attempts. Sign-in links are single use and expire after 24 hours. Rate limiting on code issuance and verification by IP address. OAuth tokens are used only to confirm identity and are not retained.
Session management. Access tokens valid for 15 minutes. Refresh tokens valid for 7 days and rotated on every use. Both held in HTTP-only cookies inaccessible to page scripts. Users can enumerate and revoke all active sessions.
Access control. Workspace scope resolved server-side from the authenticated session, never from client-supplied input. Role and object-level permissions enforced server-side. Logical separation of customer workspaces.
Integrity of third-party callbacks. All WhatsApp webhooks verified against Meta's cryptographic signature before processing. All Razorpay payment notifications verified by signature before any change to subscription state. Phone numbers bound to a single account following code verification.
Data handling. TLS in transit and provider-managed encryption at rest. Input validation on all requests. Uploaded files validated by content type and size, stored privately, and served through links expiring after 1 hour. Output escaped before insertion into email templates. Secrets and database credentials held server-side only. Security headers applied to all responses; cross-origin requests rejected.
Administrative access. The internal admin console has separate authentication, a hashed credential and 8-hour session expiry. Access is restricted to authorised personnel, used only to operate the service and provide support, and logged.
Logging. Access and security logs retained for 12 months.
Backups. [BACKUP FREQUENCY, RETENTION AND RESTORE TESTING. Do not publish this page without it, and do not overstate it.]
Personnel. Confidentiality obligations for all personnel with access to customer data.
Incident response. Documented procedure, with notification to the customer without undue delay and within 48 hours of becoming aware of a breach affecting their data.