Skip to main content
Wysera

Legal · DPA

Data Processing
Addendum.

When you put personal data into Wysera, you are the controller and we are the processor. This document sets out what that means in practice: what we may do with the data, how we secure it, who else touches it, what happens in a breach, and how you get it back or have it deleted.

Last updated · 2026-09-11PrivacySecurityTerms

Roles and scope

This Addendum (the DPA) forms part of the Terms of Service between you (Controller) and Wysera HQ Ltd, 8 The Green, Suite A, Dover, DE 19901, USA (Processor).

It applies whenever we process personal data on your behalf as part of providing the Service. In that processing, you decide the purposes and means and we act on your instructions.

We are a controller, not a processor, for our own limited purposes: account and billing records, product telemetry, and marketing to our own contacts. That processing is governed by the Privacy Policy, not by this DPA.

Definitions

Data Protection Laws means the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss FADP, the CCPA/CPRA and comparable US state privacy laws, and any other applicable privacy law.

Personal Data, processing, data subject, controller, processor and supervisory authority carry the meanings given in the GDPR.

Customer Personal Data means personal data contained in Customer Data, as that term is defined in the Terms.

SCCs means the Standard Contractual Clauses approved by the European Commission in Decision (EU) 2021/914.

Your instructions

We process Customer Personal Data only on your documented instructions. Your use of the Service, together with the Terms and this DPA, constitutes those instructions. Additional instructions need to be agreed in writing and may carry a cost if they require work outside the Service.

We will tell you if, in our opinion, an instruction infringes Data Protection Laws. We may also process where required by law, in which case we will notify you first unless the law forbids it.

We will not sell Customer Personal Data, share it for cross-context behavioural advertising, or use it for our own purposes outside this agreement.

Personnel

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, has access only on a need-to-know basis under the least-privilege model described on /security, and receives guidance appropriate to their role.

Access to customer workspace content is not part of normal operations. Where support requires it, it is logged.

Security measures

We implement appropriate technical and organisational measures under Article 32 of the GDPR. The specifics are in Annex II, and the operational detail behind them is on /security.

We may update these measures as the product and the threat landscape change, provided we do not materially reduce the overall level of protection during your subscription.

Subprocessors

You give general authorisation for us to engage subprocessors. The current list, with each one's purpose and region, is maintained at /trust and summarised in Annex III.

  • We impose data protection obligations on each subprocessor that are no less protective than those in this DPA.
  • We remain liable to you for a subprocessor's performance as if it were our own.
  • We give notice before adding or replacing a subprocessor. Enterprise customers may object in writing within 30 days on reasonable data protection grounds.
  • If we cannot resolve a reasonable objection, you may terminate the affected part of the Service and receive a refund of the unused prepaid portion.

Data subject requests

The Service gives you controls to access, correct, export, and delete Customer Personal Data yourself, which is usually the fastest route.

Where a data subject contacts us directly about data we process for you, we will not respond to the substance ourselves. We will refer them to you and tell you promptly. Where you cannot fulfil a request through the Service, we will provide reasonable assistance, taking into account the nature of the processing.

Breach notification

We will notify you of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it.

Our notice will describe, as far as we know at the time:

  • the nature of the breach and the categories and approximate number of records affected;
  • the likely consequences;
  • the measures taken or proposed to address it and mitigate harm;
  • a contact point for further information.

We will not delay the initial notice in order to complete our investigation. Where facts are still being established we will say so and follow up as they firm up. Notice goes to your account admins.

Notifying a supervisory authority or affected data subjects is your decision as controller. We will give you the information you reasonably need to make it and to meet your own deadlines.

DPIAs and prior consultation

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and with any prior consultation of a supervisory authority. Annex II and /trust are written to answer most of what a DPIA asks for without needing to contact us.

Deletion and return

You can export Customer Personal Data in a machine-readable format at any time while the account is active, and for 30 days after termination.

After that we delete it. Workspace data is hard-deleted within 30 days, and encrypted backups containing it are purged on the rolling 30-day backup cycle described on /security. The practical effect is that a deletion is fully flushed from backups within 60 days of termination at the outside.

We keep data beyond that only where law requires, such as tax invoices retained for seven years. Anything retained stays subject to this DPA for as long as we hold it.

Audits

To demonstrate compliance we will make available the information in this DPA, on /trust, and on /security, and will respond to reasonable security questionnaires.

We do not have a SOC 2 Type II report yet; the audit is underway with Vanta-led control monitoring and a letter of engagement is available on request. We would rather say that here than let a reference to third-party reports imply one exists.

Where the above is genuinely insufficient for your legal obligations, you may audit once in any 12-month period, on 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own costs and ours if the audit is not triggered by a breach or a supervisory authority.

International transfers

Primary infrastructure is in AWS us-east-1 (Virginia). EU residency in eu-central-1 (Frankfurt) is available on Pro Bundle and Enterprise, and Enterprise customers can request dedicated deployments in Australia, the UK, or Canada with a typical lead time of 30 to 60 days.

RegionMechanism
EU / EEAWhere personal data leaves the EEA, the SCCs (Decision (EU) 2021/914) apply, Module Two (controller to processor), with Annex I and Annex II of this DPA populating their annexes.
United KingdomThe SCCs as supplemented by the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018.
SwitzerlandThe SCCs with the amendments required by the Swiss FADP, with the Swiss FDPIC as supervisory authority and references to Swiss law read accordingly.
Transfer assessmentsWe conduct transfer impact assessments where required and will share the relevant outcome with you on request.

Where the SCCs apply, the docking clause is available, the governing law is Ireland, and the supervisory authority is the one with jurisdiction over you as data exporter. In any conflict between the SCCs and this DPA, the SCCs prevail.

California

For personal information subject to the CCPA/CPRA, we act as a service provider. We do not sell or share it as those terms are defined, do not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service, and do not combine it with personal information from other sources except as permitted.

We certify that we understand these restrictions and will comply with them. Equivalent terms apply under the Colorado, Virginia, Connecticut, and comparable state privacy laws.

AI processing

Wyse processes Customer Personal Data only to deliver the Service to your workspace. Four commitments are contractual here, not just policy:

  • Customer Personal Data is never used to train public AI models or included in fine-tuning datasets for public release.
  • What Wyse learns from your team's edits stays scoped to your tenant and does not benefit other customers.
  • Upstream model providers act as our subprocessors, receive only the prompt content needed for the task, and operate under zero-data-retention contracts, so prompts are not retained beyond the inference request.
  • Prompt and output logs are retained 90 days by default and can be configured down to 7 days on Pro Bundle and Enterprise.

Fields containing PHI or special-category data can be flagged for field-level redaction before Wyse processes them. Healthcare customers processing PHI need a Business Associate Agreement in place; ask us for one before putting PHI into the Service.

Liability and precedence

Each side's liability under this DPA is subject to the limitation of liability in the Terms, and the caps there are aggregate across the Terms and this DPA rather than cumulative.

Order of precedence, where documents conflict: the SCCs first, then this DPA, then the Terms, then the Privacy Policy. A signed order form takes precedence over all of them where it says so.

How to execute this DPA

This DPA is incorporated into the Terms and applies automatically when we process personal data on your behalf. You do not need to sign anything for it to be in force.

If your procurement process needs a countersigned copy, or you need the SCCs executed as a standalone document, email hi@wysera.ai with the subject DPA and the entity name and address to use. If your own DPA template must be used, send it and we will review it.

Annex I — Details of processing

ItemDetail
Data exporterThe customer, acting as controller, as identified in the account or order form.
Data importerWysera HQ Ltd, 8 The Green, Suite A, Dover, DE 19901, USA, acting as processor.
Subject matterProvision of the Wysera platform, including PostWyse, OpsWyse, BrandWyse, HireWyse, and the Wyse AI.
DurationThe term of the subscription, plus the deletion periods set out above.
Nature and purposeHosting, storage, transmission, display, backup, and AI-assisted drafting and analysis, all to deliver the Service to the controller.
Categories of data subjectThe customer's employees and users; the customer's own contacts, leads, candidates, and customers whose records are put into the workspace.
Categories of personal dataIdentity and contact details, employment and role data, communication content, notes and files, integration content synced on the customer's instruction, and usage and device data associated with users.
Special categoriesNot required by the Service and not requested. Where a customer chooses to process them, field-level redaction is available, and PHI additionally requires a BAA.
FrequencyContinuous, for the duration of the subscription.
RetentionActive workspace data for the life of the account; backups 30 days; AI prompt and output logs 90 days by default, configurable to 7; deletion within 30 days of account deletion, subject to legal retention.
Subprocessor processingAs set out in Annex III, for the purpose and duration stated for each.

Annex II — Technical and organisational measures

MeasureImplementation
Encryption at restAES-256 for all customer data, keys managed by AWS KMS, backups encrypted with separate keys held in a different region.
Encryption in transitTLS 1.3 on customer-facing endpoints with HSTS enforced; mutual TLS internally where appropriate.
Key managementKMS master keys rotated annually; application keys rotated every 90 days; per-tenant keys on Pro Bundle and Enterprise.
Access controlSSO-gated production access, hardware-key MFA, least-privilege role assignment, no shared or local production accounts.
Credential storageAccount passwords stored as Argon2 hashes and never recoverable.
Tenant isolationWorkspaces are logically isolated; one customer's data does not cross into another's.
PseudonymisationField-level redaction available for PHI and PII before AI processing; redacted data does not leave the storage layer.
LoggingPrivileged actions, authentication events, and AI prompt/output pairs logged; error tracking PII-scrubbed before leaving our systems.
ResilienceMulti-AZ deployment with cross-region backup replication; us-east-1 to us-west-2, or eu-central-1 to eu-west-1 for EU residency.
RestorationEncrypted backups retained 30 days with restore capability; deletion flushed through the backup cycle.
Secure developmentChange control through version-controlled pull requests, code review, automated static analysis including CodeQL, and dependency advisory tracking.
Incident managementDocumented detect, contain, notify, resolve process with the 48-hour customer notification commitment above.
Vendor managementSubprocessors bound to obligations no less protective than this DPA, with regions and purposes published.
GovernanceContinuous control monitoring through Vanta; SOC 2 Type II audit in progress; no report issued yet.

Annex III — Subprocessors

The authoritative, current list lives at /trust, which is updated when a subprocessor is added or removed. As at the date of this DPA:

SubprocessorPurpose and region
AWSInfrastructure hosting. US-East, EU-Central.
AnthropicUpstream LLM, Claude family. US, EU.
OpenAIUpstream LLM, GPT family. US.
StripePayment processing. US, EU.
CloudflareCDN and DDoS protection. Global.
ResendTransactional email. US, EU.
SentryError tracking, PII-scrubbed. US, EU.
VantaCompliance monitoring. US.
To be notified when this list changes, email hi@wysera.ai with the subject Subprocessor notice and we will add you to the notification list for your account.