Data processing
Data Processing Agreement
Last updated: 26 September 2026
This agreement governs the processing that Vecinos Vendemas Publicidad carries out on behalf of the business on the personal data of that business's contacts. It supplements the terms of service and the privacy policy, and forms part of them.
It is mandatory for businesses that process health data — dental clinics, aesthetics, physiotherapy, veterinary practices and similar — and available to any other business that requests it.
1. Parties and purpose
- The Controller: the business that subscribes to Vexiia and connects its WhatsApp Business number. It decides why and how its patients' or customers' data is processed.
- The Processor: Vecinos Vendemas Publicidad, whose registered office is at Vista de Momotombo B-25 L-8, Managua, Nicaragua, which processes that data solely on the Controller's instructions.
2. Definitions
- Personal data: any information about an identified or identifiable natural person.
- Data subject: the person the data relates to; here, the business's patient or customer.
- Processing: any operation on personal data: collecting, storing, consulting, using, disclosing or deleting.
- Sub-processor: a third party the Processor engages to process data on the Controller's behalf.
- Security breach: an incident leading to destruction, loss, alteration or unauthorised access to personal data.
3. Subject matter, duration and nature of the processing
Subject matter. Providing the Vexiia service: attending to the Controller's contacts over WhatsApp, booking, rescheduling and cancelling appointments, sending reminders, and making conversations available to the Controller's staff.
Duration. For as long as the contractual relationship is in force, plus the deletion period set out in clause 13.
Nature. Automated processing supported by an artificial intelligence agent, with human intervention by the Controller's staff whenever they choose to take over a conversation.
Purpose. Solely the administrative management of appointments and communication with the Controller's contacts. The agent does not make diagnoses or give medical advice.
4. Data and data subjects concerned
Categories of data subjects: patients or customers of the Controller who message its WhatsApp number.
Categories of data:
- WhatsApp number and profile name.
- Message content, including attachments.
- Appointment details: date, time, service and assigned practitioner.
- Message delivery status.
- Contacts and chat history for up to the last 6 months, only if the Controller authorises it at connection time. Groups are excluded.
Health data. In the course of conversations, the Controller may receive or generate information relating to its patients' health. Both parties acknowledge this is sensitive data and apply the measures in clause 8 to it. The Processor does not use that data for any purpose of its own.
5. Vexiia's obligations as processor
- Process the data solely on the Controller's documented instructions, which are this agreement, the terms of service and the configuration the Controller chooses in the dashboard.
- Not use the data for its own purposes, not disclose it to third parties and not sell it.
- Not use the data to train artificial intelligence models, its own or anyone else's.
- Not use contacts' messages for advertising.
- Ensure that anyone with access to the data is bound by a duty of confidentiality that survives the end of the relationship.
- Apply and maintain the security measures in clause 8.
- Assist the Controller as set out in clauses 9 and 10.
- Make available to the Controller the information needed to demonstrate compliance with these obligations.
- Warn the Controller if, in the Processor's view, an instruction received infringes data protection law.
6. The business's obligations as controller
- Have a lawful basis for processing its contacts' data and, where applicable, their consent.
- Message only contacts who have given consent or who started the conversation, in line with WhatsApp and Meta policies.
- Inform its patients or customers that WhatsApp support is backed by an automated agent, and who processes their data.
- Supervise conversations and take responsibility for the information given to its contacts.
- Keep the list of people authorised to access the dashboard up to date.
- Communicate any relevant instruction to the Processor in writing.
7. Sub-processors
The Controller gives general authorisation for the Processor to engage the following sub-processors:
- Meta Platforms, Inc. — operator of the WhatsApp Business Platform.
- Hostinger International Ltd., a Lithuanian company — server hosting and email. The Vexiia server is located in the United States; Hostinger may also keep, process or store data in Lithuania, the Netherlands, the United Kingdom and Cyprus.
- Groq, Inc. (United States) — provider of the artificial intelligence models that generate replies.
The Processor imposes on each sub-processor protection obligations equivalent to those in this agreement and remains liable for their acts as for its own.
If the Processor wishes to add or replace a sub-processor, it will notify the Controller at least 30 days in advance. If the Controller objects on reasonable data protection grounds, it may terminate the contract without penalty before the change takes effect.
8. Security measures
- Encryption of communications in transit via HTTPS and TLS.
- Encryption at rest of access tokens and sensitive data.
- Role-based access control, on a least-privilege basis.
- System access logs.
- Regular backups, overwritten on a cycle of at most 30 days.
- Logical separation of each Controller's data.
- Periodic review and updating of these measures.
Measures may be updated to maintain or improve the level of security, never to reduce it.
9. Handling data subject rights
Data subjects exercise their rights of access, rectification, cancellation and objection with the Controller, under Law No. 787 of Nicaragua.
If a data subject contacts the Processor directly, the Processor will not handle the request on its own: it will pass it to the Controller without undue delay and assist with the technical means needed to resolve it, including locating and deleting the data.
The procedure and timings are described on the data deletion page.
10. Security breaches
If the Processor detects a security breach affecting data processed on the Controller's behalf, it will notify the Controller without undue delay and, at the latest, within 72 hours of becoming aware of it.
The notification will include, with the information available at the time:
- The nature of the breach and when it occurred.
- The categories and approximate number of data subjects and records affected.
- The likely consequences.
- Measures taken or proposed to address it and mitigate its effects.
- A contact point for further information.
It is for the Controller to decide whether to notify the competent authority or the data subjects. The Processor will give whatever reasonable assistance is needed.
11. International transfers
The sub-processors in clause 7 are established outside Nicaragua, so data is processed in other countries. The server Vexiia runs on is in the United States, and the artificial intelligence models also run in the United States. In addition, Hostinger may keep, process or store data in Lithuania, the Netherlands, the United Kingdom and Cyprus. The Processor selects providers that apply appropriate security measures and puts in place the contractual safeguards required of them.
12. Audit
The Controller may request, once a year and with reasonable notice of at least 30 days, documented information evidencing compliance with this agreement. If that information is not sufficient, the parties will agree on an audit, whose scope and cost will be agreed beforehand and which may not compromise the confidentiality of other clients' data.
13. Return and deletion on termination
On termination of the contractual relationship, and at the Controller's choice, the Processor will return or delete the data processed on its behalf.
- Deletion completes within 30 days at most of termination or of the request, backups included.
- If the Controller expresses no preference within 30 days of termination, the Processor will proceed with deletion.
- Data that must be kept by law is excepted, in particular billing data, for four (4) years under Nicaraguan tax law. That data is blocked: kept, but not processed for any other purpose.
14. Liability
Each party is liable for damage it causes by breaching the obligations this agreement places on it. The Processor is liable for the acts of its sub-processors.
The Controller is responsible for the lawfulness of the data it provides and the instructions it gives, and for having properly informed its data subjects.
15. Governing law and jurisdiction
This agreement is governed by Law No. 787, the Personal Data Protection Law, and other applicable legislation of the Republic of Nicaragua. The parties submit to the competent courts of the city of Managua.
16. Acceptance
This agreement is deemed accepted by the Controller on subscribing to the service and connecting its number, together with the terms of service.
If your business needs a signed copy of this agreement, or a version adapted to its requirements, write to privacidad@vexiia.com and we will prepare one.