Mumble Data Processing Addendum
Last Updated: June 29, 2026
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service (the “Agreement”) between MUMBLE GROUP, INC (“Mumble”, “we”, “us”, or “our”) and the customer identified in the Agreement (“Customer”, “you”, or “your”). It governs the Processing of Personal Data carried out by Mumble on behalf of the Customer in connection with the Service.
If there is any conflict between this DPA and the Agreement on matters relating to data protection, this DPA controls.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement or, where relevant, in the GDPR or Israeli Privacy Protection Law.
• Applicable Data Protection Law means all data protection and privacy laws applicable to the Processing under this DPA, including (a) the EU General Data Protection Regulation 2016/679 (“GDPR”); (b) the UK GDPR and the Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; (d) the Israeli Privacy Protection Law, 5741-1981, and its regulations and amendments (“Israeli PPL”); and (e) the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
• Customer Personal Data means Personal Data Processed by Mumble on behalf of the Customer through the Service.
• Controller, Processor, Sub-processor, Data Subject, Personal Data, Processing, Personal Data Breach have the meanings given in the GDPR.
• Standard Contractual Clauses or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries approved by European Commission Decision 2021/914.
• UK IDTA means the International Data Transfer Addendum issued by the UK Information Commissioner’s Office.
2. Roles and Scope
In respect of Customer Personal Data:
(a) the Customer is the Controller and is responsible for the lawfulness of the Processing, including establishing a valid legal basis, providing required notices to Data Subjects, and obtaining any necessary consents (including under WhatsApp/Meta opt-in requirements);
(b) Mumble is the Processor acting on the Customer’s documented instructions; and
(c) where Mumble engages another party to assist with the Processing, that party acts as a Sub-processor.
For Personal Data that Mumble collects directly through the Mumble website or as part of operating the Service for its own business purposes (e.g., account administration, billing, security, analytics about how the Service is used), Mumble acts as a Controller, and that Processing is governed by the Mumble Privacy Policy rather than by this DPA.
3. Subject Matter and Description of Processing
Subject matter: Processing of Customer Personal Data necessary for Mumble to provide the Service under the Agreement.
Duration: For the duration of the Agreement, plus any period required for return or deletion of data under Section 11.
Nature and purpose: Sending, receiving, storing, routing and analyzing WhatsApp messages and related conversational data; operating the team inbox, chatbot canvas, message templates, broadcast campaigns, Dolores AI features, analytics (Mumble Tracker), and integrations with third-party systems on the Customer’s instructions.
Categories of Data Subjects: (i) the Customer’s end-users and customers (e.g., individuals who message the Customer on WhatsApp); (ii) the Customer’s employees, agents and contractors who use the Service.
Categories of Personal Data: contact identifiers (name, phone number, email), WhatsApp profile information, message content (text, media, attachments), conversation metadata (timestamps, delivery/read receipts), custom fields and tags created by the Customer, click and event data from Mumble Tracker, and account/user data for the Customer’s team.
Special categories: Mumble does not require, and asks Customers not to send through the Service, special categories of Personal Data (Art. 9 GDPR) unless strictly necessary and lawfully justified. The Customer is responsible for any such Processing.
4. Customer Instructions and Obligations
4.1 Documented instructions. The Agreement, this DPA, and the Customer’s documented use of the Service constitute the Customer’s complete and final instructions to Mumble for Processing Customer Personal Data. Any additional or different instructions must be agreed by the parties in writing.
4.2 Compliance. The Customer warrants that (a) it has provided all required notices to, and obtained all required consents and opt-ins from, Data Subjects; (b) its instructions to Mumble comply with Applicable Data Protection Law and with Meta’s WhatsApp Business Policy, Commerce Policy, and Messaging Policy; and (c) it has a valid lawful basis for each instance of Processing.
4.3 Mumble’s right to flag. Mumble will notify the Customer if, in Mumble’s reasonable opinion, an instruction infringes Applicable Data Protection Law, and may decline to comply until the instruction is amended.
5. Mumble’s Obligations as Processor
Mumble will:
(a) Process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to third countries, unless required to do so by law (in which case Mumble will notify the Customer in advance, unless prohibited by law);
(b) ensure that personnel authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality;
(c) implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex B;
(d) engage Sub-processors only in accordance with Section 6;
(e) taking into account the nature of the Processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligations to respond to Data Subject requests under Chapter III of the GDPR and equivalent rights under other Applicable Data Protection Law;
(f) assist the Customer in ensuring compliance with the obligations in Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment, prior consultation), taking into account the nature of the Processing and information available to Mumble;
(g) at the choice of the Customer, return or delete all Customer Personal Data after the end of the provision of the Services, as set out in Section 11;
(h) make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and allow for audits as set out in Section 10.
6. Sub-processors
6.1 General authorization. The Customer provides general authorization for Mumble to engage Sub-processors, subject to this Section 6.
6.2 Current Sub-processors. Mumble’s current Sub-processors are listed in Annex A and on the Mumble website. Mumble maintains an updated list and will provide the Customer with reasonable means of being informed of changes.
6.3 Changes. Mumble will notify the Customer at least thirty (30) days before authorizing a new Sub-processor or replacing an existing Sub-processor that Processes Customer Personal Data. If the Customer reasonably objects to the change on legitimate data-protection grounds, the parties will work in good faith to resolve the concern. If the parties cannot resolve it, the Customer’s exclusive remedy is to terminate the affected portion of the Agreement on written notice.
6.4 Sub-processor terms. Mumble enters into a written contract with each Sub-processor that imposes data-protection obligations no less protective than those in this DPA. Mumble remains liable to the Customer for the acts and omissions of its Sub-processors to the same extent Mumble would be liable for performing the services itself.
7. International Transfers
7.1 Geographic location of Processing. Mumble may Process Customer Personal Data in Israel, the European Economic Area, the United Kingdom, the United States, and other countries where its Sub-processors operate.
7.2 EEA transfers. Where Mumble transfers Customer Personal Data from the EEA to a country that does not benefit from an adequacy decision under Article 45 GDPR, the parties incorporate the Standard Contractual Clauses by reference into this DPA. The Customer (as data exporter) and Mumble (as data importer) are deemed to have signed Module Two (Controller to Processor) of the SCCs. The optional clauses and completion details are set out in Annex C.
7.3 UK transfers. Where Customer Personal Data is transferred from the United Kingdom, the UK IDTA is incorporated by reference and applies to such transfers.
7.4 Swiss transfers. Where Customer Personal Data is transferred from Switzerland, the SCCs apply with the modifications required by the Swiss Federal Act on Data Protection.
7.5 Onward transfers. Mumble will ensure that any Sub-processor receiving Customer Personal Data is subject to equivalent transfer safeguards.
8. Personal Data Breach Notification
8.1 Mumble will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification will, to the extent known at the time and on a rolling basis as further information becomes available, include: (a) a description of the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the breach and to mitigate its possible adverse effects; and (d) the contact point at Mumble for further information.
8.3 Mumble will cooperate with the Customer’s reasonable requests and provide reasonable assistance in connection with the Customer’s obligations to notify supervisory authorities and affected Data Subjects.
9. Data Subject Requests
9.1 Mumble will, without undue delay, forward to the Customer any request it receives from a Data Subject concerning Customer Personal Data, including requests to access, rectify, erase, restrict, port, or object to Processing.
9.2 Taking into account the nature of the Processing and the information available to Mumble, Mumble will provide reasonable assistance to enable the Customer to respond to such requests within the timeframes required by Applicable Data Protection Law.
10. Audits and Inspections
10.1 Mumble will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including (a) the most recent third-party certifications and audit reports Mumble holds (e.g., ISO 27001 or SOC 2, where applicable), and (b) responses to a reasonable security questionnaire once per year.
10.2 Where required by Applicable Data Protection Law, the Customer (or a qualified independent auditor mutually agreed by the parties, bound by confidentiality) may, on reasonable advance written notice and at the Customer’s expense, conduct an on-site audit no more than once in any twelve-month period, during business hours, in a manner that does not interfere with Mumble’s operations or compromise the security of other customers’ data.
11. Return and Deletion of Data
11.1 During the Term, the Customer may export Customer Personal Data through the features made available in the Service.
11.2 Upon termination or expiry of the Agreement, Mumble will, at the Customer’s choice, return or delete all Customer Personal Data, subject to the grace period and retention practices set out in the Agreement and Mumble’s Privacy Policy. Following the grace period, deletion from Mumble’s active systems will be completed within thirty (30) days, except where retention is required to comply with legal, tax, accounting, or regulatory obligations or to resolve disputes and enforce the Agreement.
11.3 Mumble’s Sub-processors apply their own retention windows for incidental copies (e.g., backups). Mumble will ensure that any such residual copies are protected from active use and are deleted in accordance with each Sub-processor’s standard retention cycle.
12. Israeli Privacy Protection Law
To the extent the Israeli PPL applies, the parties intend this DPA to satisfy the contractual requirements imposed on a “holder” of a database that Processes Personal Information on behalf of another. Mumble will comply with the operative provisions of the Israeli PPL and the Privacy Protection (Data Security) Regulations, 5777-2017, and will cooperate with the Customer in responding to inquiries or instructions from the Israeli Privacy Protection Authority.
13. CCPA / CPRA (California)
For Customer Personal Data that constitutes “personal information” of California residents under the CCPA/CPRA, Mumble acts as a “Service Provider” or “Contractor”. Mumble will not (a) sell or share such personal information; (b) retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement and this DPA; or (c) combine it with personal information received from other sources, except as permitted by the CCPA/CPRA. Mumble grants the Customer the rights to take reasonable and appropriate steps to ensure Mumble’s use of the personal information is consistent with the Customer’s obligations under the CCPA/CPRA.
14. Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is part of the Agreement and any reference to “Agreement” in the liability provisions of the Agreement includes this DPA.
15. Term and Order of Precedence
15.1 This DPA enters into force on the Effective Date and continues for the duration of the Agreement, plus any period required for return or deletion of data under Section 11.
15.2 In the event of a conflict between this DPA and the Agreement on matters relating to data protection, this DPA prevails. In the event of a conflict between this DPA and the SCCs (where incorporated), the SCCs prevail.
Annex A — Sub-processors
The following Sub-processors Process Customer Personal Data in connection with the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. (WhatsApp Business API / Cloud API) | Message transmission and storage in the WhatsApp ecosystem; Facebook services where applicable | United States / Ireland |
| Google LLC (Sign-in, Drive, Analytics, Google Workspace / Gmail) | Authentication, document storage, website analytics, and operational email | United States / European Union |
| Stripe, Inc. | Payment processing for subscriptions and invoices | United States / Ireland |
| DigitalOcean, LLC | Infrastructure hosting of the Service | Frankfurt, Germany (FRA1 region) |
| OpenAI, L.L.C. | AI/LLM services powering Dolores AI conversational features | United States |
The current Sub-processor list is also available at https://mumble.co.il/sub-processors/.
Annex B — Technical and Organizational Security Measures
Mumble implements and maintains the following measures, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risks to the rights and freedoms of natural persons:
• Access control. Role-based access to production systems, multi-factor authentication for administrative access, least-privilege principles, and regular access reviews.
• Network and infrastructure security. Encrypted communications using TLS 1.2 or higher, network segmentation, firewall controls, and regular vulnerability scanning of internet-facing systems.
• Encryption. Customer Personal Data is encrypted in transit and at rest using industry-standard algorithms.
• Identity management. Centralized identity provider with credential rotation policies and audit logging.
• Application security. Secure development lifecycle, code review, dependency scanning, and periodic penetration testing of the Service.
• Logging and monitoring. Security event logging, intrusion detection, and alerting on anomalous activity.
• Backups and resilience. Regular backups of production data, with restoration testing; documented business continuity and disaster recovery procedures.
• Personnel. Background checks where lawful; confidentiality undertakings for all personnel; mandatory security and data-protection training.
• Incident response. Documented Personal Data Breach response procedure with defined roles and notification timelines.
• Vendor management. Security and data-protection due diligence on all Sub-processors, with contractual obligations matching those in this DPA.
• Physical security. Hosting in data centers with industry-standard physical access controls and environmental safeguards.
Annex C — Standard Contractual Clauses (Completion)
Where the SCCs are incorporated under Section 7:
• Module: Module Two (Controller to Processor).
• Clause 7 (Docking clause): applies. Additional parties may accede to the SCCs with the consent of all parties.
• Clause 9 (Sub-processors): Option 2 (general written authorization) applies. The thirty (30)-day notice period under Section 6.3 of this DPA applies.
• Clause 11 (Redress): Optional language does not apply unless required.
• Clause 17 (Governing law): The law of the jurisdiction specified in the Agreement, or where no such law is specified, the law of Israel.
• Clause 18 (Forum and jurisdiction): The courts of the jurisdiction specified in the Agreement.
• Annex I.A (List of parties): Data exporter — the Customer (as identified in the Agreement). Data importer — MUMBLE GROUP, INC.
• Annex I.B (Description of transfer): As described in Section 3 and Annex A of this DPA.
• Annex I.C (Competent supervisory authority): Determined under Clause 13 of the SCCs.
• Annex II (Technical and organizational measures): As set out in Annex B of this DPA.
• Annex III (Sub-processors): As set out in Annex A of this DPA.
Contact
For any questions about this DPA, please email support@mumble.co.il.