Data Processing Agreement

For customers whose work carries other people’s personal data through Wavn. It applies on its own terms; nothing needs signing to make it true.

Who is what

You are the controller. Wavn is the processor. You decide what personal data enters the platform and why; we process it to run the service you asked for and for nothing else.

Instructions

Wavn processes personal data only on your documented instructions, which the act of using the platform gives. If a law compels processing beyond that, you are told before it happens unless the law forbids telling you.

Who may see it

Only staff who need it to run or support the service, each under a written confidentiality duty that outlives their employment.

Sub-processors

The current list is at wavn.ai/subprocessors, with what each one does and what reaches them. You give general authorisation for those. Before a new one starts, it is posted there with thirty days’ notice, and you may object in writing within that window; if the objection cannot be resolved you may terminate the affected service and be refunded the unused term. Each is bound by terms no weaker than these, and Wavn stays liable for what they do.

Security

Encryption in transit and at rest, row-level access control so one account cannot reach another’s rows, least-privilege access internally, and logging of administrative action. Measures may change, never downward.

When something goes wrong

On becoming aware of a personal data breach affecting your data, Wavn tells you within forty-eight hours — inside your own seventy-two hour regulatory clock, deliberately, so ours cannot consume yours — with what is known at the time, and the rest as it is learned. You are not left assembling a notification from silence.

Helping you answer people

When someone asks you for access, correction, erasure, or a copy of their data, Wavn assists you in answering. The platform’s own export and erasure doors do most of it directly. Assistance with impact assessments and prior consultation is included and not charged for.

Audit

Current third-party security reports on request. Beyond those you may audit once a year, or at any time after a breach affecting your data, on reasonable notice and without disrupting other customers.

Leaving

On termination, your data is returned or deleted at your choice, and deleted from live systems within thirty days and from backups as those age out on their ordinary cycle. Anything a law requires us to keep is named to you rather than kept quietly.

Where it goes

Data is held in the EU and the United States. Transfers out of the EEA, UK or Switzerland run on the European Commission’s Standard Contractual Clauses, module two, with the UK Addendum where UK data is in scope. Copies at privacy@wavn.ai.

A signed copy

If your process needs one on your paper or ours, write to privacy@wavn.ai. The terms above apply either way while that is arranged.