Last updated: August 26, 2026 · Webeeyo Softwers Pvt. Ltd.
This Data Processing Agreement ("DPA") supplements the Stynar Terms of Use (or, where applicable, a Master Services Agreement and Order Form) (together, the "Agreement") between Webeeyo Softwers Pvt. Ltd. ("Webeeyo", "Processor", "we", "us", or "our") and the customer entity that has agreed to the Agreement ("Customer", "Controller", "you"). This DPA is automatically incorporated into and forms part of the Agreement for any Customer whose use of the Stynar platform (the "Services") involves the Processing of Personal Data subject to Data Protection Law.
This DPA applies to the Processing of Personal Data by Webeeyo on behalf of Customer in the course of providing the Services — principally, lead and prospect records, campaign recipients, and reply/inbox content that Customer uploads to or generates within Stynar. It does not apply to Webeeyo's Processing of Customer's own account, billing, and authorized-user data, which Webeeyo Processes as an independent controller under the Privacy Policy.
"Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Data Fiduciary", and "Data Principal" have the meanings given in the applicable Data Protection Law.
If you require a version of this DPA countersigned by both parties (for example, to satisfy a vendor security review), email legal@stynar.email — the terms will be the same as published here unless the parties expressly agree otherwise in writing.
As between Customer and Webeeyo, Customer is the Controller (Data Fiduciary) and Webeeyo is the Processor (Data Processor) with respect to Personal Data contained in Customer's leads, campaign recipients, and reply content Processed through the Services. Customer is solely responsible for the accuracy, quality, and legality of the Personal Data it provides to Webeeyo and for the means by which it acquired that Personal Data, including having a valid legal basis to collect and Process it and to instruct Webeeyo to Process it as described in this DPA.
Where Customer itself acts as a processor on behalf of its own customer (a sub-controller arrangement), Customer warrants that its instructions to Webeeyo, and its use of the Services generally, are authorized by the relevant controller.
Subject matter: Webeeyo's provision of the Services, which involves Processing Personal Data that Customer uploads, imports, or receives in reply through the Services.
Duration: for the term of the Agreement, and thereafter for the period Webeeyo retains Customer data under Section 11 of the Privacy Policy (generally up to 30 days post-termination, subject to legally required retention).
Nature and purpose of Processing: storage, organization, transmission, analysis, and deletion of Personal Data as necessary to operate the Services — specifically, sending AI-personalized email sequences, syncing and classifying inbox replies, detecting meeting intent, generating deliverability and campaign analytics, and providing customer support.
Categories of Data Subjects: Customer's leads and prospects, and individuals who reply to Customer's campaigns.
Categories of Personal Data: contact details (name, email address, job title, company, phone number where provided), engagement data (opens, clicks, replies, meeting-booking status), and any custom fields or free-text content Customer chooses to upload or that a Data Subject includes in a reply. Customer should not upload special categories of Personal Data (health, biometric, religious, or similar sensitive data) unless it has independently assessed this is lawful and has informed Webeeyo in advance.
Webeeyo will Process Personal Data only on documented instructions from Customer, including as necessary to provide the Services under the Agreement, unless required to do otherwise by law applicable to Webeeyo — in which case Webeeyo will, where legally permitted, inform Customer of that legal requirement before Processing.
Customer's use of Stynar's product features (for example, configuring a sequence, enabling reply sync, or importing a CSV of leads) constitutes a documented instruction to Process the corresponding Personal Data for that purpose. If Customer requires Webeeyo to carry out Processing outside the ordinary functionality of the Services, the parties will agree the scope, and any additional fees, in writing.
Webeeyo ensures that personnel authorized to Process Personal Data have committed themselves to confidentiality (whether by contract or statutory duty) and Processes Personal Data on a least-privilege, need-to-know basis, consistent with Section 5 (Your account & mailboxes) and Section 8 (Data security) of the Privacy Policy.
Webeeyo implements the technical and organisational measures described in Section 8 (Data security) of the Privacy Policy, including encryption of connected-mailbox credentials and OAuth tokens at rest, TLS for data in transit, secrets managed outside source code, and least-privilege access controls, taking into account the state of the art, the costs of implementation, and the risk to Data Subjects presented by the Processing.
Webeeyo does not currently hold a formal third-party security certification (such as ISO 27001 or SOC 2); Customer should factor this into its own risk assessment when deciding whether to use the Services for a particular category of Personal Data.
Customer provides Webeeyo general written authorization to engage the Sub-processors listed in Section 7 (We never sell your data — sub-processors) of the Privacy Policy — currently Amazon Web Services, Paddle, OpenAI, Anthropic, Google, and Microsoft — for the purposes described there.
Webeeyo will impose data-protection terms on each Sub-processor that are no less protective than this DPA with respect to the Personal Data it Processes, and remains liable to Customer for a Sub-processor's performance of its data-protection obligations.
Where Webeeyo intends to engage a new Sub-processor, it will provide notice by updating the Privacy Policy and, where Customer has provided a contact email for this purpose, by emailing that address at least 14 days before the new Sub-processor begins Processing Personal Data. Customer may object on reasonable data-protection grounds by emailing legal@stynar.email within that period; if the parties cannot resolve the objection, Customer's remedy is to terminate the affected Service in accordance with the Agreement.
Taking into account the nature of the Processing, Webeeyo will provide reasonable assistance to Customer, by appropriate technical and organisational measures, to help Customer respond to requests from Data Subjects seeking to exercise their rights under Data Protection Law (such as access, correction, erasure, or restriction). Many such requests can be fulfilled directly by Customer using in-product tools (for example, editing or deleting a lead record).
If Webeeyo receives a request directly from a Data Subject that relates to Personal Data Webeeyo Processes on Customer's behalf, Webeeyo will, where legally permitted, promptly forward it to Customer without responding to it substantively, since Customer is best placed to verify identity and validity.
Webeeyo will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data Processed on Customer's behalf, consistent with Section 9 (Data breach notification) of the Privacy Policy, and will provide the information reasonably available to it to help Customer meet its own notification obligations to regulators and affected Data Subjects, including under applicable timelines (for example, 72 hours under the GDPR, or as required under the DPDP Act and CERT-In directions in India).
Webeeyo will provide reasonably requested information about the Services to assist Customer in carrying out a data protection impact assessment or prior consultation with a supervisory authority, to the extent Customer does not otherwise have access to the relevant information and such an assessment is required under Data Protection Law.
Webeeyo Processes Personal Data on infrastructure hosted with AWS and may transfer Personal Data to Sub-processors located outside the country in which it was collected, including the United States. Where such a transfer involves Personal Data of individuals in the EEA, UK, or Switzerland, Webeeyo relies on the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable), incorporated into this DPA by reference, and, for UK transfers, the UK International Data Transfer Addendum to those Clauses.
Customer, as data exporter, and Webeeyo, as data importer, are deemed to have executed the applicable Clauses effective as of the date Customer's Personal Data is first transferred under the Agreement. Where required by Data Protection Law, the parties will complete the annexes to the Clauses with the details set out in Section 3 of this DPA and the Sub-processor list referenced in Section 7.
On reasonable prior written notice (at least 30 days), and no more than once per 12-month period unless required by a supervisory authority or following a Personal Data breach, Webeeyo will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.
In the first instance, Webeeyo may satisfy an audit request by providing a written response to a reasonable security questionnaire and relevant policy documentation. Any on-site or system-level audit will be conducted during business hours, subject to reasonable confidentiality safeguards, will not unreasonably interfere with Webeeyo's operations or other customers' data, and Customer will bear its own costs and Webeeyo's reasonable costs of facilitating the audit unless the audit reveals a material breach of this DPA.
On termination of the Agreement, Webeeyo will delete or anonymize Personal Data Processed on Customer's behalf in accordance with Section 11 (Data retention) of the Privacy Policy — generally within 30 days of termination — except to the extent Webeeyo is required by applicable law to retain some or all of the Personal Data, in which case Webeeyo will isolate and protect that data from further Processing except as required by that law.
Customer is responsible for exporting any Personal Data it wishes to retain before termination, using the export tools available in the Services or by requesting an export from support@stynar.email before the account is closed.
Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement (including the Terms of Use), which are incorporated into this DPA by reference and apply in aggregate across the Agreement and this DPA and not separately for each.
This DPA applies for as long as Webeeyo Processes Personal Data on Customer's behalf under the Agreement. In the event of a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA prevails; in all other respects, the order of precedence set out in Section 30 (Entire agreement & order of precedence) of the Terms of Use applies.
This DPA is governed by the laws of India and is subject to the dispute-resolution process set out in the Terms of Use, without prejudice to any mandatory rights a Data Subject or supervisory authority may have under Data Protection Law to bring a claim in their own jurisdiction.
For questions about this DPA, a countersigned copy, or your Standard Contractual Clauses annexes, contact us:
• Company: Webeeyo Softwers Pvt. Ltd. (operating Stynar)
• Location: Pune, Maharashtra, India
• Legal: legal@stynar.email
• Privacy: privacy@stynar.email
Need a countersigned copy? Contact us →