Legal, Last updated: 2026-05-18

Data Processing Addendum.

Governs wrxstack's processing of personal data on behalf of Customers under GDPR, UK GDPR, CCPA, the Swiss FADP, and similar laws.

Effective date: 2026-05-18.

Background

This Data Processing Addendum (the "DPA") forms part of the agreement between wrxstack ("wrxstack") and the customer ("Customer") for the provision of the wrxstack AI work platform (the "Services"). It reflects the parties' agreement on the processing of Personal Data in connection with the Services. To the extent of conflict between this DPA and the underlying agreement, this DPA controls with respect to Personal Data processing.

1. Definitions

Terms used in this DPA have the meanings given to them in the GDPR, UK GDPR, CCPA, FADP, or LGPD, as applicable. In addition:

  • Customer Personal Data means Personal Data processed by wrxstack on behalf of Customer in connection with the Services.
  • Data Protection Laws means all data-protection and privacy laws applicable to the processing of Customer Personal Data, including the EU GDPR, the UK GDPR, the Swiss FADP, the CCPA (as amended by the CPRA), and other US state privacy laws.
  • EU SCCs means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 of 4 June 2021.
  • UK IDTA means the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office in 2022.
  • Sub-processor means a third party engaged by wrxstack to process Customer Personal Data.

2. Roles & subject matter

With respect to Customer Personal Data, Customer is the controller (or processor on behalf of a third-party controller) and wrxstack is the processor (or sub-processor). Where wrxstack processes personal data of Customer's account contacts and billing contacts for its own corporate purposes, it acts as an independent controller and the Privacy Policy governs.

3. Duration, nature & purpose

The duration of processing is the term of the underlying subscription plus the deletion/return period in Section 11. The nature of processing is the provision of the Services (storage, retrieval, hosting, transmission, search, indexing, AI inference, backup, security monitoring, support). The purpose is to enable Customer to use the Services for its internal business operations.

4. Categories of data subjects

Customer Personal Data may relate to the following categories of data subjects, as determined by Customer: Customer's employees, contractors, and agents; Customer's customers, prospects, and business contacts; meeting participants; senders and recipients of email handled by Customer through the Services; and form respondents.

5. Categories of personal data

Customer determines the categories of Personal Data it processes through the Services. They may include: name, email address, phone number, postal address, employer, job title, profile photo, IP address, device and browser identifiers, login records, content of communications and documents, meeting recordings and transcripts, contract content, signature blocks, CRM records, billing identifiers, and any other information Customer chooses to upload. Customer is responsible for not submitting categories of Personal Data that the Services are not designed to receive without first contacting wrxstack.

6. Sub-processing

Customer authorizes wrxstack to engage Sub-processors to process Customer Personal Data, subject to this DPA. wrxstack publishes a current list of Sub-processors at /legal/subprocessors and updates that page before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds; if the parties cannot agree on a resolution, Customer may terminate the affected Services and receive a pro-rata refund of pre-paid, unused fees. wrxstack will impose data-protection obligations on Sub-processors no less protective than those in this DPA, and remains liable for Sub-processors' performance.

7. Security measures

wrxstack implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II. wrxstack regularly tests, assesses, and evaluates the effectiveness of those measures.

8. International transfers

For transfers of Customer Personal Data from the EEA, the UK, or Switzerland to a country that the European Commission, UK government, or Swiss Federal Council has not deemed adequate, the parties incorporate by reference:

  • For controller-to-processor transfers, the EU SCCs Module 2;
  • For processor-to-processor transfers, the EU SCCs Module 3;
  • For UK transfers, the UK IDTA with the EU SCCs;
  • For Swiss transfers, the EU SCCs as modified by the Swiss FDPIC guidance (references to the GDPR replaced with the FADP; the FDPIC as supervisory authority; "Member State" interpreted to include Switzerland).

The parties select Option 2 for Clause 9 (general written authorization for Sub-processors). Annexes I and II to the SCCs are completed as set out in Annex I and Annex II of this DPA.

9. Data subject requests

Taking into account the nature of the processing, wrxstack will provide reasonable assistance through appropriate technical and organizational measures to enable Customer to respond to requests from data subjects exercising their rights under Data Protection Laws. wrxstack will, without undue delay, forward to Customer any data-subject request received directly relating to Customer Personal Data and will not respond to such requests except on Customer's documented instructions or as required by law.

10. Personal data breach

wrxstack will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will include, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. wrxstack will provide reasonable assistance to Customer in fulfilling Customer's own notification obligations.

11. Deletion & return

On termination or expiration of the underlying agreement, or earlier on Customer's written request, wrxstack will, at Customer's election, delete or return all Customer Personal Data in its possession. Deletion from the live database is prompt; copies held in our hosting provider's backups age out on that provider's ordinary backup rotation and are then removed. wrxstack may retain Customer Personal Data to the extent and for the period required by applicable law, subject to the confidentiality obligations of this DPA.

12. Audit rights

wrxstack will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. wrxstack does not hold any audit report or security certification. In place of an audit report, wrxstack will answer Customer's written questions about its data-protection practices directly and within a reasonable time. If written answers are not sufficient, Customer may, no more than once per 12 months and on at least 30 days' prior written notice, conduct an audit by an independent, mutually-agreed auditor bound by confidentiality, at Customer's expense, during business hours and in a manner that does not unreasonably disrupt wrxstack's operations. Customer will share audit results with wrxstack on a confidential basis.

13. CCPA / CPRA, service provider terms

With respect to Personal Information of California residents, wrxstack acts as a "Service Provider" or "Processor" as those terms are defined in the CCPA. wrxstack will not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than the specific business purpose of providing the Services; (c) retain, use, or disclose Personal Information outside the direct business relationship with Customer; or (d) combine Personal Information received from Customer with Personal Information from another source, except as permitted by the CCPA. wrxstack certifies that it understands and will comply with these obligations.

14. Order of precedence

In the event of a conflict between this DPA and any other agreement between the parties, this DPA controls with respect to the processing of Personal Data. In the event of a conflict between this DPA and the SCCs, the SCCs control.


Annex I, List of parties & processing

A. List of parties

RoleIdentityContact
Data exporter (controller / processor)The Customer named on the Order Form.As provided in the Order Form.
Data importer (processor / sub-processor)wrxstack, an independent product operated by the individual who runs it, based in the United States.contact@wrxstack.com

B. Description of transfer

Categories of data subjectsCustomer's employees, contractors, business contacts, customers, prospects, meeting participants, form respondents.
Categories of personal dataIdentifiers (name, email, phone), professional information, online identifiers (IP, device), content of documents, meetings, contracts, and communications, and any other data Customer chooses to submit.
Special categoriesNone routinely required by the Services. Customer must not submit special-category data without first contacting wrxstack to confirm fit. wrxstack does not offer a HIPAA Business Associate Agreement and the Services are not intended for protected health information.
FrequencyContinuous, throughout the Subscription Term.
Nature of processingHosting, storage, transmission, indexing, search, AI inference, backup, support, security monitoring.
PurposeProvision of the Services to Customer.
RetentionDuration of the Subscription Term plus the deletion period in Section 11.
Transfers to sub-processorsAs described in the sub-processor list.

C. Competent supervisory authority

The Irish Data Protection Commission (for EEA exporters), the UK Information Commissioner's Office (for UK exporters), or the Swiss FDPIC (for Swiss exporters).

Annex II, Technical & organizational measures

These are the technical and organizational measures wrxstack applies. We list only what is actually in place. wrxstack holds no security or compliance certification and has not undergone a third-party audit or penetration test.

MeasureDescription
Encryption in transitTLS 1.3 is used for connections to the Services.
Encryption at restData at rest is encrypted using the encryption provided by our managed hosting provider.
Model trainingCustomer Content is not used to train any model. This is enforced by the model provider's API terms.

Annex III, Sub-processors

The current Sub-processor list is published at /legal/subprocessors and is updated as required by Section 6 of this DPA.