Trusted AI·Local languages
Docs↗︎Trust Centre↗︎About ProtoSign in↗︎
Pricing
Book a demo
Book a demo
Proto V3.0
AI AgentsAutonomous resolutionInboxAll channels, one queueLivechatLive web and app messagingTicketsStructured case trackingPeopleEnduser profile trackingAnalyticsGranular AI performancePerceptionDetect trends before crisesChannelsWhatsApp, LINE, voice, web
Trust layer
RedressConsumer grievance managementMediationDispute resolution AI for mediatorsRecoveryTrace and freeze fraudulent fundsOpen LicenseFor inclusive instant payment systemsIPS Integration ↗︎Connect directly to instant payment rails
Workflow index
Complaints intake
Health plan eligibility
Auto-populate fields with OCR
Request loans through AI chat
Explore workflows →︎
Local languages
Kinyarwanda15M speakers · AfricaOshiwambo1M speakers · AfricaTagalog45M speakers · AsiaPunjabi100M speakers · AsiaCebuano22M speakers · AsiaUrdu100M speakers · AsiaIlocano9M speakers · AsiaPashto35M speakers · Asia
The stack
On-Premise HostingDeploy inside your own infrastructureSecurityHow Proto protects every deploymentVoice API50 credits freeTwo endpoints, prepaid creditsDocs & APIs ↗︎API and integration referenceTrust Centre ↗︎Security posture and compliance
Partner ecosystem
Gates FoundationDEV
Financial Network AnalyticsTECH
Eclectics InternationalRSLR
Mojaloop FoundationTECH
See the ecosystem →︎
Usecases
Grievance RedressComplaints resolved and auditableInsight AdvisorDecisions from institutional dataAnti-Scam UtilitiesReport, trace, recover fundsContact CentresDeflect routine volume at scalePatient ExperienceTriage, booking and follow-upDispute MediationAI-proposed, officer-approved
Industry
GovernmentMinistries, agencies, regulatorsPaymentsRemittance & instant payment systemsHealthcareHospital and clinic networksTelecomMobile, broadband, ISPs

550K

monthly interactions

The National Bank of Rwanda is responsible for protecting financial consumers and maintaining trust across Rwanda’s financial system.

Read the story →︎
Resources
BlogNews, updates and deep divesVideosProduct features and client winsRelease NotesWhat shipped, and whenClient StoriesDeployments across 10+ marketsWorkflow IndexPrebuilt journeys you can shipDocs & APIs ↗︎API and integration reference
Company
CareersOpen roles across the teamPress KitLogos, brand assets and mediaService CommitmentUptime SLA and service credits
About Proto
Steering local AI

We're in this to protect our fellow citizens.

Meet the team →︎

Data processing addendum

Last Updated: September 17, 2026

‍

1. Definitions

Applicable Laws: the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and, where applicable, Ontario’s Personal Health Information Protection Act (“PHIPA”), the General Data Protection Regulation (“GDPR”) where Proto processes personal data of individuals in the European Union, and any other data protection legislation that applies directly to Proto as a matter of Canadian or EU law. Where the Services are deployed by a Reseller or Client in another jurisdiction, that Reseller or Client is responsible for compliance with the law of its own jurisdiction, as set out in Proto’s Privacy Policy and in section 8 below.

Client: as defined in Proto’s Terms of Use — an organisation using the Services, whether contracting with Proto directly or as a customer of a Reseller.

Reseller: a partner authorised under a Reseller Agreement to sublicense, implement, or deploy the Services for its own Clients, designated as either a Standard or White-Label Reseller as defined in that agreement.

Customer: an end-user of a Client’s or Reseller’s own product or service who interacts with the Services.

Controller, Processor, Sub-Processor, Data Subject, Personal Data, Personal Data Breach, and processing: for the purposes of this Addendum, these terms carry their commonly understood meaning as reflected in the GDPR, regardless of whether Applicable Law formally uses this terminology, so that the parties’ respective roles are clear even where Canadian law does not itself define these terms.

2. General

Proto and Client will comply with their respective obligations under Applicable Law. This Addendum supplements, and does not replace, either party’s statutory obligations.

3. Roles

Subject to section 8 (Reseller engagement structure), the parties acknowledge that Client is the Controller and Proto is the Processor of Personal Data processed in connection with the Services.

Client warrants that it has all necessary consents and legal basis to lawfully provide Personal Data to Proto for the purposes of this Addendum.

4. Proto’s obligations as Processor

Proto shall, in relation to Personal Data processed in connection with the Services:

(a) process Personal Data only on Client’s documented instructions, unless required to do otherwise by Applicable Law, in which case Proto will notify Client before processing (unless prohibited from doing so by law);

(b) maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage;

(c) ensure that personnel authorised to process Personal Data are subject to confidentiality obligations;

(d) apply appropriate safeguards to any transfer of Personal Data across a national border, proportionate to the sensitivity of the data and the risk involved. Proto’s default cloud hosting is provided by reputable third-party cloud providers, which may host Personal Data in more than one country; the current providers and their hosting regions are identified in the sub-processor list in the Appendix. Where Personal Data originating in the European Economic Area is transferred outside the EEA, Proto will rely on the European Commission’s Standard Contractual Clauses or another valid GDPR Chapter V transfer mechanism, in addition to the general safeguards described in this clause;

(e) not share Personal Data with, or permit any sub-processor to use Personal Data to train, fine-tune, or otherwise improve, any artificial intelligence or machine learning model, for that sub-processor’s own purposes or for any third party. Proto does not use any Client’s Personal Data to train third-party AI models; Proto’s AI providers are limited to Microsoft’s Azure OpenAI Service (which does not train on customer data submitted through that service) and open-weight models (currently including Llama, DeepSeek, and Qwen) that Proto hosts locally, rather than through any third-party provider;

(f) assist Client, at Client’s reasonable cost, in responding to requests from Data Subjects (including access, correction, deletion, and data mobility requests recognised under Applicable Law) and in meeting Client’s obligations relating to security, breach notification, impact assessments, and regulator consultations;

(g) where Proto processes personal health information on behalf of an Ontario health information custodian as its “agent” under PHIPA, apply safeguards appropriate to that information and notify Client promptly of any breach so Client can meet its own notification obligations to the Information and Privacy Commissioner of Ontario;

(h) notify Client within 24 hours of becoming aware of a Personal Data Breach. For clarity, this is a formal breach-notification commitment, separate from the one-hour initial-response target for a P1 incident under the Service Level Agreement in Proto’s Terms of Use: the two describe different stages of the same event — an initial operational response, and formal notification once a Personal Data Breach is confirmed;

(i) retain Personal Data for the duration of the Services and, following termination or expiry, during the offboarding period and for up to twelve (12) months thereafter, unless a different period is agreed with Client or required by Applicable Law, after which Proto shall delete or return Personal Data at Client’s written direction and in accordance with the agreed retention and deletion policy; and

(j) maintain records sufficient to demonstrate compliance with this Addendum and, at Client’s request, make them available for audit, subject to:

  • at Client’s cost, except where the audit reveals a material non-compliance by Proto, in which case Proto bears the reasonable cost of that audit;
  • 30 days’ prior notice, no more than once per year absent a Personal Data Breach, and a scope agreed in advance; and
  • Proto may satisfy a routine audit request by providing Client with its current SOC 2 Type II report, where that report reasonably addresses the scope of Client’s request, rather than requiring an on-site audit.

5. Sub-processors

Client provides general authorisation for Proto to engage sub-processors, provided Proto:

(a) imposes data protection obligations on sub-processors consistent with this Addendum;

(b) remains responsible for sub-processors’ acts and omissions as if they were Proto’s own; and

(c) notifies Client of any intended change to its sub-processor list, giving Client an opportunity to object; where Client objects without being able to show the objection relates to an actual or likely breach of Applicable Law, Client agrees to indemnify Proto for costs reasonably incurred in accommodating the objection.

Proto’s current sub-processors are listed in the Appendix below.

6. Term

This Addendum remains in effect for as long as Proto holds Personal Data provided by Client.

7. Categories of data and data subjects

See the Appendix below.

8. Reseller engagement structure

Where the Services are provided to a Client through a Reseller, the Reseller Agreement between Proto and the Reseller determines two independent things that affect the parties’ data protection roles: the Reseller’s designated Reseller Type (Standard or White-Label, selected once and fixed for that Reseller, save that a Reseller may move from Standard to White-Label but not the reverse), and the Revenue Share Category assigned to a particular sale (Handover, Referral, Collaborative, or Autonomous, determined by Proto in its sole discretion under the Reseller Agreement).

8.1 Reseller Type — determines Controller/Processor structure

Standard. Each Client is onboarded into its own separate workspace within the Services, contracts and is billed individually, and interacts with the Services under Proto’s own branding. In this case, the Client is the Controller and Proto is the Processor under sections 1 to 7 of this Addendum, regardless of Revenue Share Category, and the Reseller is not itself a Controller or Processor of that Client’s Personal Data by virtue of its Reseller Type alone. Any Personal Data the Reseller accesses in providing support is addressed separately under section 8.2.

White-Label. The Reseller’s Clients are onboarded into the Reseller’s own workspace, under the Reseller’s own branding, under a licence held by the Reseller. In this case:

(a) the Reseller determines the purposes and means of processing its own Clients’ Personal Data and is treated as the Controller of that data (or, where the Reseller’s own arrangements designate its Client as Controller, the Reseller is a Processor to that Client);

(b) Proto acts as a Sub-Processor to the Reseller, and Proto’s obligations under sections 1 to 7 of this Addendum run to the Reseller in that capacity;

(c) the Reseller is responsible for its own data processing agreement with its Clients, imposing obligations at least equivalent to this Addendum, and for compliance with the law applicable to those Clients, consistent with the allocation of responsibility described in Proto’s Privacy Policy; and

(d) Proto has no direct contractual relationship with the Reseller’s Clients under this Addendum unless separately agreed in writing.

8.2 Revenue Share Category — determines the Reseller’s access to Personal Data for support purposes

Independently of Reseller Type:

  • Handover. The Reseller’s role is limited to invoicing and billing administration for existing Clients; Proto continues to provide support directly. The Reseller’s access to Personal Data is limited to billing-related information reasonably necessary for that purpose, handled under confidentiality obligations at least equivalent to section 4(c).
  • Referral. The Reseller has no ongoing access to Personal Data; Proto provides support directly.
  • Collaborative and Autonomous. The Reseller provides first-tier support to Clients and will, in doing so, have access to Personal Data (for example, in reviewing support tickets or chat history). The Reseller must be bound by confidentiality and data-protection obligations at least equivalent to section 4(c) of this Addendum in respect of that access.

8.3 Hosting model — effect on Proto’s role

Independently of Reseller Type and Revenue Share Category, the Client’s chosen hosting model affects what Proto actually processes:

  • Default cloud hosting. Sections 1 to 7 apply in full; Proto hosts and processes Personal Data on its own infrastructure (see section 4(d) for hosting providers and regions).
  • Hybrid Hosting (available under the Enterprise Max Add-On). Proto continues to host and maintain the application layer, and remains Processor under sections 1 to 7 in respect of any Personal Data that passes through it. Personal Data held in the Client’s own database and file storage remains under the Client’s own control and is outside the scope of Proto’s processing.
  • On-Premise (available under the Enterprise Max Add-On). The Client hosts the application, database, and file storage independently of Proto. Proto does not process Personal Data as a host or Processor in this model; its role is limited to providing the Software and applicable Maintenance Releases. Where Proto personnel are given access to the Client’s environment for support purposes, Proto is a Processor solely in respect of that limited access, and sections 1 to 7 apply only to that extent.

Appendix

Description of processing activities:

Subject matter and nature of Processing:
Processing of Personal Data to the extent necessary for the provision of Services to Client by Proto.
Duration of Processing:
For the duration of the Subscription Term.
Purpose of Processing:
To provide the Services to Client in accordance with the Terms of Use and Proto’s Privacy Policy, available at proto.cx/legal/privacy-policy
Categories of Personal Data Processed:
Name, age, sex, and contact details including but not limited to email, phone number, and support case numbers; financial information including bank account details where the Services are used for financial workflows; health information where the Services are used in a patient-facing context; voice and biometric information where voice-enabled channels are used; and chat, voice, and other interaction content submitted through the Services.
Categories of data subject:
Customers and Authorised Users.
List of Known Sub-Processors:
Google Cloud Platform, Amazon Web Services, Microsoft (Azure OpenAI Service), Sendgrid, Africa’s Talking, Meta (Facebook Messenger, WhatsApp), LINE, Telegram, Bitrix24, Retool. Open-weight models that Proto hosts locally (currently including Llama, DeepSeek, and Qwen) are not separate sub-processors, since no data is sent to a third party that operates them — see clause 4(e).

Proto is on a mission to deploy AI that includes everyone.

Canada

14 Erb St. W., Waterloo, ON N2L 1S7

Philippines

One Park Drive, 707, 11th cor 9th Ave, BGC, Taguig 1635

Rwanda

Norrsken House, 1 KN 78 St., Kigali

Proto is an official WhatsApp Business Tech Provider and Meta Business Partner.

WhatsAppMeta
+1 226 244 9970team@proto.cx
LinkedInYoutube
Proto Global Ltd. © 2026Cookie Preferences
Platform
AI AgentsInboxLivechatTicketsPeopleAnalyticsPerceptionChannelsVoice API50 credits free
Languages
CebuanoIlocanoKinyarwandaOshiwamboPashtoPunjabiTagalogUrduLanguages115
Resources
Client StoriesWorkflowsBlogVideosRelease NotesRoadmap ↗︎System Status ↗︎Docs & APIs ↗︎
Inclusion & Trust
Terms of UsePrivacy PolicyData ProcessingService CommitmentCode of EthicsSecurityTrust Centre ↗︎
Usecases
Grievance RedressAnti-Scam UtilitiesPatient ExperienceInsight AdvisorContact CentresDispute Mediation
Industries
PaymentsGovernmentHealthcareTelecom
Company
About UsCareersWe're hiringPress KitPricingROI CalculatorEnterprise CalculatorPartner Ecosystem
Comparisons
Proto vs FreshdeskProto vs ExotelProto vs WizAIProto vs Oracle AssistantComparisons6
Status
ISO 27001SOC 2 Type IIHIPAAGDPR