This Data Processing Agreement ("DPA") governs the processing of personal data that Datametrics Technology S.A.C. carries out on behalf of its business clients when providing professional services and operating Datametrics Applications — including Chato (chato.lat). It is incorporated by reference into every proposal, order or services agreement between Datametrics and the Client and forms part of our Terms.
1. Parties and roles
- Client ("Controller"): the business or professional that contracts Datametrics' services or connects its platform accounts to a Datametrics Application. The Client determines the purposes and means of processing the personal data of its end users and staff.
- Datametrics ("Processor"): Datametrics Technology S.A.C., RUC 20611645971, Cal. Enrique Palacios 360, Int. 608, Miraflores, Lima 15074, Peru, which processes personal data only on behalf of and under the documented instructions of the Client.
2. Definitions
"Personal data", "processing", "data subject", "controller", "processor" and "personal data breach" have the meanings given in Peruvian Law No. 29733 and, where applicable, the GDPR, the LGPD or the local data-protection law that governs the Client. "Datametrics Applications" means the software Datametrics connects, with the Client's authorisation, to third-party platforms (Meta, TikTok, Google, LinkedIn, Twilio and similar) through their official APIs. "Subprocessor" means a third party engaged by Datametrics to process Client personal data. "Platform" means the messaging or social-media platform whose API a Datametrics Application uses.
3. Subject matter, duration, nature and purpose
| Item | Description |
|---|---|
| Subject matter | Operation of Datametrics Applications (Chato) and delivery of professional services (Odoo ERP implementation, audit, data engineering, integrations) for the Client. |
| Duration | For as long as the Client uses the services or keeps an application connected, plus the deletion period in section 9. |
| Nature | Receipt, storage, transmission, automated analysis (including AI-generated replies and summaries), human review by authorised staff, and synchronisation of end-user messages received on the Client's business accounts on messaging Platforms; synchronisation of contacts into the Client's CRM; access to the Client's business systems for contracted professional services. |
| Purpose | Enabling the Client to reply to, route and record conversations with its end users, and to obtain the contracted professional services. No other purpose. |
4. Categories of data subjects and data
Data subjects: (a) the Client's end users and customers who write to the Client's business accounts on WhatsApp, Instagram, Facebook Messenger, TikTok or other channels; (b) the Client's staff and collaborators who use the applications or interact with Datametrics; (c) where professional services are contracted, the contacts, customers, suppliers and employees recorded in the Client's business systems.
Categories of data: identifiers (name, profile name, phone number, platform user and conversation IDs, email); message content (text, comments); message metadata (timestamps, delivery and read status, channel); attachments (images, audio, documents) and their transcriptions; CRM records created from conversations; business data held in the Client's systems for professional services. Datametrics does not intentionally process special categories of data; if end users include such data in messages, it is processed only as part of the message content and under the same safeguards.
5. Processor obligations
Datametrics shall:
- Instructions only. Process personal data solely on the Client's documented instructions — this DPA, the proposal or services agreement, the configuration the Client sets in the application and the authorisations granted through the Platforms — unless required by law, in which case Datametrics informs the Client beforehand where legally permitted. Datametrics will inform the Client if an instruction, in its opinion, infringes applicable data-protection law.
- Confidentiality. Ensure that every person authorised to process the data is bound by a confidentiality agreement and has received appropriate training.
- Security. Implement and maintain the technical and organisational measures described on our Security page — encryption in transit and at rest, encrypted token storage, role-based access with MFA, per-client isolation, access logging, daily encrypted backups, vulnerability management and incident response — and not reduce their overall level during the term.
- Data subject requests. Assist the Client, taking into account the nature of the processing, in responding to requests to exercise data-subject rights (access, rectification, deletion, objection, portability). Datametrics will forward any request it receives directly to the Client and will act on the Client's instructions within 10 business days.
- Breach notification. Notify the Client without undue delay and in any case within 72 hours of confirming a personal data breach affecting Client data, providing the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Datametrics will cooperate with the Client in notifying authorities, data subjects and Platforms where required.
- Assistance. Assist the Client with data-protection impact assessments and prior consultations with supervisory authorities, where required, in relation to the processing performed by Datametrics.
- Records. Maintain a record of the processing activities carried out on behalf of the Client, including the subprocessors involved, and make it available on request.
- Audits. Make available all information necessary to demonstrate compliance with this DPA and allow audits by the Client or an independent auditor bound by confidentiality, once per calendar year on at least 30 days' written notice, during business hours and without disrupting operations — or more frequently where required by a Platform, a supervisory authority or following a personal data breach. Datametrics may first satisfy the request with its most recent independent vulnerability assessment report, made available under NDA.
- Platform terms. Comply with the Meta Platform Terms, TikTok Developer Terms and Business Messaging policies, and the Google API Services User Data Policy in relation to Platform data, and not use Platform data or Client data for advertising, profiling, resale or training artificial-intelligence models.
6. Subprocessors
The Client grants Datametrics a general authorisation to engage subprocessors for the processing described in this DPA. The current list, with purpose, data and location of each, is published on our Subprocessors page. Datametrics will:
- impose on each subprocessor, by written contract, data-protection obligations at least equivalent to those in this DPA;
- remain fully liable to the Client for the performance of each subprocessor;
- notify the Client by email at least 15 days before adding or replacing a subprocessor. The Client may object within that period on reasonable, documented data-protection grounds; if the parties cannot resolve the objection in good faith, the Client may terminate the affected service without penalty and Datametrics will return or delete the data under section 9.
7. International transfers
Client data is stored on servers in London, United Kingdom, and processed by subprocessors located in the United States, the European Union and Singapore, as indicated on the Subprocessors page. Datametrics ensures that every transfer outside the Client's country is covered by adequate safeguards: data-processing agreements with each provider containing contractual data-protection clauses and, for Clients subject to the GDPR or UK GDPR, the Standard Contractual Clauses adopted by the European Commission (or the UK International Data Transfer Addendum), which are deemed incorporated into this DPA with the Client as data exporter and Datametrics as data importer. For Clients in Peru, transfers are notified and performed in accordance with Law No. 29733 and its Regulations; for Brazil, in accordance with the LGPD.
8. Client obligations
The Client warrants that it has a lawful basis for the processing, that it has provided its end users with the required information (including that conversations may be handled by automated systems and by Datametrics as processor), that it has obtained any necessary consents or opt-ins required by the Platforms' messaging policies, and that its instructions comply with applicable law. The Client is responsible for the accuracy of the data and for the configuration it sets in the applications.
9. Return and deletion at end of service
- On request, and before deletion, Datametrics will provide the Client with an export of its conversation and contact data in a common machine-readable format (JSON or CSV).
- Platform access and refresh tokens are deleted immediately when the Client disconnects an application or revokes authorisation.
- All other Client personal data is deleted within 30 days of termination or disconnection, including from backups within the backup rotation period (30 days), unless the law requires longer retention of specific records (for example invoices).
- Datametrics provides a written certification of deletion on request.
End users and Clients may also request deletion at any time as described on the Data Deletion page.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms or the services agreement between the parties, except where such limitation is not permitted by applicable data-protection law. Nothing in this DPA limits a party's liability towards data subjects or supervisory authorities where the law establishes it.
11. Governing law and compatibility
This DPA is governed by the laws of the Republic of Peru, in particular Personal Data Protection Law No. 29733 and its Regulations, and any dispute is subject to the courts of Lima, Peru, unless the services agreement provides otherwise. Where the Client is subject to the GDPR (EU/EEA), the UK GDPR, the Brazilian LGPD or another local data-protection law, this DPA is intended to satisfy the processor-contract requirements of that law (including Article 28 GDPR), and its provisions shall be interpreted so as to comply with it; in the event of conflict, the stricter requirement applies.
12. Term and changes
This DPA takes effect when the Client accepts a proposal, order or Terms that reference it, or connects a Datametrics Application, and remains in force until all Client personal data has been returned or deleted. Datametrics may update this DPA to reflect changes in the law, the Platforms' requirements or its services; material changes are notified to Clients by email at least 15 days before they take effect, and the current version is always published on this page with its effective date.
13. How to execute this DPA
This DPA is incorporated by reference into every proposal, order and services agreement and applies automatically. Clients who require a signed copy — for their own compliance records, a Platform review or a supervisory authority — should email privacy@data-metrics.pro with the company name, tax ID and signatory; Datametrics will return a countersigned PDF within 5 business days. Clients subject to the GDPR may request the Standard Contractual Clauses to be executed together with this DPA.
14. Contact
Datametrics Technology S.A.C. · RUC 20611645971 · Cal. Enrique Palacios 360, Int. 608, Miraflores, Lima 15074, Peru · Privacy: privacy@data-metrics.pro · Security: security@data-metrics.pro · General: sergio@data-metrics.pro · +51 933 363 169