Data Processing Addendum
The terms on which we process personal data on your behalf. This addendum is incorporated into the Terms of Service and applies automatically when you use the service.
OmniMessage is a GridStudio product.
Last updated: 5 October 2026
1.Scope and roles
This Data Processing Addendum (the Addendum) forms part of the Terms of Service between you and the GridStudio group company named on your invoice (we, us). It applies whenever we process personal data contained in Customer Data on your behalf. Capitalised terms that are not defined here have the meaning given in the Terms of Service.
For that processing you are the controller, or a processor acting for your own clients, and we are your processor. Each party complies with the data protection laws that apply to it, including, where relevant, the EU and UK General Data Protection Regulation, the Turkish Law on the Protection of Personal Data (KVKK) and the UAE Personal Data Protection Law.
This Addendum does not cover the data we process as a controller for our own purposes, such as account and billing data. The Privacy Policy describes that processing.
If this Addendum and the rest of the Terms of Service conflict about the processing of personal data, this Addendum prevails.
2.Details of the processing
- Subject matter and purpose: sending and receiving messages on the Channels you connect, reporting their status, delivering webhook events to you, billing, and keeping the Service secure.
- Duration: for as long as you have an Account, and afterwards until the data is deleted as described in section 10.
- Nature of the processing: receiving, storing, transmitting to Channel Providers, logging, displaying to you and deleting.
- Data subjects: the people you send messages to and receive messages from, and anyone else mentioned in the messages.
- Categories of data: identifiers such as phone numbers, chat IDs and platform user IDs; message content and referenced media; delivery and read statuses; and the references and metadata you attach.
- Special categories: the Service is not designed for special categories of personal data. You decide what your messages contain and must not send such data unless you have a lawful basis and the Channel Provider permits it.
3.Your instructions
We process the personal data only on your documented instructions. The Terms of Service, this Addendum and your use of the API and the console are your complete instructions. We tell you if, in our opinion, an instruction infringes data protection law, and we are not required to follow an instruction that does.
We may also process the data where a law that applies to us requires it. In that case we tell you first, unless that law prohibits it.
You are responsible for the lawfulness of the processing: for having a legal basis, for the consents and notices that data subjects are owed, and for the accuracy of the data you submit.
4.Confidentiality
We make sure that the people who are authorised to process the personal data are bound by a duty of confidentiality and access the data only as far as their work requires.
5.Security measures
We apply technical and organisational measures that are appropriate to the risk, and we may update them as long as the level of protection does not decrease. At present they include:
- encryption of data in transit with TLS;
- passwords stored as Argon2id hashes, and session tokens and API keys stored only as hashes;
- encryption at rest, with AES-256-GCM, of webhook signing secrets and of the keys that link an Account to the delivery platform;
- Channel credentials, tokens and authorisation codes passed through to the delivery platform without being stored or logged by the gateway;
- role-based access for the members of an Account, API keys limited by scope and by IP address, rate limiting and lockout after repeated failed sign-ins;
- logical separation of the data of each Account;
- an audit log of administrative actions, including every time our staff access an Account to give support;
- signed webhook deliveries, and validation of webhook addresses against private network ranges.
6.Sub-processors
You give us a general authorisation to engage sub-processors. We engage them under a written contract that imposes data protection obligations equivalent to those in this Addendum, and we remain responsible to you for their work.
The categories of sub-processors we use for Customer Data are:
- Hosting and infrastructure: the providers that host our servers, databases and backups;
- GridStudio group companies: which operate the delivery platform that connects to the Channel Providers and which support the Service.
We tell the owners of your Account before we add or replace a sub-processor. You may object on reasonable data protection grounds within fourteen days. If we cannot resolve the objection, you may end the agreement, and we then refund the unused Wallet balance that you paid for and the unused part of unexpired Packages you bought, calculated pro rata.
Channel Providers, such as Meta, Telegram, TikTok, Twilio and other SMS providers and carriers, are not our sub-processors. You choose them, you have your own agreement with each of them, and we transmit data to them on your instructions. Our payment processor and our email delivery provider process account and billing data for us as a controller and do not receive Customer Data.
7.Assistance
Taking into account the nature of the processing, we help you, by appropriate technical and organisational measures, to respond to requests from data subjects who exercise their rights. The console and the API let you search for and retrieve the messages of a recipient. If a data subject contacts us directly, we refer them to you and do not answer the request ourselves unless you ask us to or the law requires it.
We also give you reasonable help with data protection impact assessments, with consultations with supervisory authorities and with the security of the processing, as far as these relate to the Service and you cannot obtain the information yourself.
8.Personal data breaches
We notify the owners of your Account without undue delay after we become aware of a personal data breach that affects Customer Data. The notification describes what we know about the nature of the breach, the data concerned, its likely consequences and the measures taken or proposed, and we add information as it becomes available. A notification is not an admission of fault.
9.International transfers
You instruct us to transmit Customer Data to the Channel Providers and to the recipients you address, wherever they are located. We and our sub-processors may process Customer Data in countries other than the one where you are established.
Where data protection law restricts a transfer, the parties rely on a transfer mechanism it recognises. Where the standard contractual clauses approved by the European Commission, with the UK addendum where relevant, are required for a transfer from you to us, they are incorporated into this Addendum by reference, with you as the data exporter and us as the data importer, and with the details of the processing set out in sections 2 and 5.
10.Deletion and return
While the agreement lasts you can retrieve Customer Data through the console and the API. When the agreement ends, we delete Customer Data within a reasonable period, unless a law that applies to us requires us to keep it; in that case we keep it confidential and use it for no other purpose. On request before the Account is closed, we give you reasonable help with exporting the data.
Backups are overwritten according to our backup cycle. Records that we need as a controller, such as usage totals for billing, are kept under the Privacy Policy.
11.Information and audits
We make available the information that is reasonably necessary to show that we comply with this Addendum, and we answer written questions about our security measures.
Where that information is not enough to meet a legal requirement, you may, at most once in a twelve-month period and on thirty days’ written notice, carry out an audit yourself or through an independent auditor who is bound by confidentiality. The audit takes place during business hours, must not disrupt the Service or expose the data of other customers, and is at your cost. More frequent audits are possible where a supervisory authority requires them or after a personal data breach.
12.Liability and term
The limits and exclusions of liability in the Terms of Service apply to this Addendum, except where data protection law does not allow them to be applied to the rights of data subjects.
This Addendum applies for as long as we process personal data on your behalf. If you need a signed copy, write to support@omnimessage.co.
Questions about this document: support@omnimessage.co