Data Processing Addendum
The Article 28 addendum governing Wavn’s processing of personal data on a customer’s behalf. It incorporates the Standard Contractual Clauses for international transfers and completes their Annex I and Annex II at sections 11 and 12. It takes effect automatically with the Terms of Service; no signature is required.
- Instrument
- Data Processing Addendum
- Version
- 2.0
- Effective
- 28 August 2026
- Last updated
- 28 August 2026
- Supersedes
- Version 1.0, effective 8 August 2026
1.Incorporation, parties and precedence
This Data Processing Addendum (the DPA) forms part of the Terms of Service between Wavn, Inc. (Wavn, the Processor) and the customer accepting them (Customer, the Controller), and applies wherever Wavn processes Personal Data on Customer’s behalf in connection with the Service.
It takes effect automatically, without signature, when Customer accepts the Terms. A countersigned copy is available on request at legal@wavn.ai for customers whose procurement requires one.
Precedence. In the event of conflict, the order of precedence is: (a) the Standard Contractual Clauses incorporated by clause 7; (b) this DPA; (c) the Terms of Service; (d) any other agreement between the parties.
Definitions. Personal Data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in Regulation (EU) 2016/679 (the GDPR). Data Protection Law means the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the United States state privacy laws applicable to the processing. Sub-processor means a processor engaged by Wavn to process Personal Data on Customer’s behalf.
Roles. For Personal Data contained in Customer Content, Customer is the controller and Wavn is the processor. For account, billing and website data described in the Privacy Notice, Wavn is a controller in its own right and this DPA does not apply.
2.Processing on documented instructions
Wavn shall process Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law to which Wavn is subject. Where such a requirement applies, Wavn shall inform Customer of that legal requirement before processing, unless the law prohibits that information on important grounds of public interest. (Art. 28(3)(a).)
What counts as an instruction. The Terms, this DPA, and Customer’s use of the features of the Service constitute Customer’s complete documented instructions. Additional instructions require written agreement and may attract reasonable charges where they exceed the Service as offered.
Unlawful instructions. Wavn shall inform Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is amended or confirmed. (Art. 28(3), final paragraph.)
Customer’s warranties. Customer warrants that it has a lawful basis for the processing it instructs, has provided all notices and obtained all consents required, and that its instructions comply with Data Protection Law. Customer is responsible for the accuracy and lawfulness of the Personal Data it submits.
No training. Wavn shall not use Personal Data contained in Customer Content to train, retrain or fine-tune any machine learning model, and shall ensure by contract that no Sub-processor does so. The Free Plan training described in the Privacy Notice operates on the basis of an account holder’s own consent and is outside the scope of this DPA.
3.Confidentiality and personnel
Wavn shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. (Art. 28(3)(b).)
Wavn shall limit access to Personal Data to those personnel who require it to perform the Service, shall apply least-privilege access, and shall ensure those personnel receive appropriate data protection training.
4.Security of processing
Wavn shall implement the technical and organisational measures required by Article 32, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures in force are set out in Annex II (clause 12). (Art. 28(3)(c).)
Wavn may update the measures in Annex II provided the update does not materially reduce the overall level of security.
5.Sub-processors
General authorisation. Customer grants Wavn general authorisation to engage Sub-processors. The current list is published at wavn.ai/subprocessors, naming each Sub-processor, what it does, the country it operates in, and what Personal Data reaches it. (Art. 28(2).)
Notice of change. Wavn shall publish an intended addition or replacement on that page before the Sub-processor begins processing. Customers may subscribe to email notice at privacy@wavn.ai.
Objection. Customer may object to an intended change on reasonable grounds relating to data protection, by written notice within thirty (30) days of publication. The parties shall discuss the objection in good faith. If Wavn cannot accommodate it without disproportionate effort, Customer may terminate the affected subscription on written notice and receive a pro-rata refund of prepaid unused fees, which is Customer’s sole remedy.
Flow-down and liability. Wavn shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and shall remain fully liable to Customer for the performance of each Sub-processor’s obligations. (Art. 28(4).)
6.Assistance to the Controller
Data subject rights. Taking into account the nature of the processing, Wavn shall assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR. The Service provides self-service export, correction and deletion; where those do not suffice, Wavn shall provide reasonable additional assistance. (Art. 28(3)(e).)
Requests received directly. Where Wavn receives a request from a data subject relating to Personal Data processed on Customer’s behalf, Wavn shall not respond to it on the merits, and shall without undue delay direct the data subject to Customer and inform Customer of the request.
Security, breach, impact assessment and prior consultation. Wavn shall assist Customer in ensuring compliance with Articles 32 to 36, taking into account the nature of processing and the information available to Wavn. (Art. 28(3)(f).)
Personal data breach. Wavn shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Personal Data processed on Customer’s behalf. The notification shall describe, insofar as known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information cannot be provided at once, it shall be provided in phases without undue further delay. Wavn’s notification is not an admission of fault or liability.
Government access requests. Wavn shall notify Customer of any legally binding request from a public authority for disclosure of Personal Data processed on Customer’s behalf, unless prohibited by law. Where prohibited, Wavn shall use reasonable efforts to obtain a waiver, shall challenge requests it assesses to be unlawful or overbroad, and shall disclose only the minimum the request compels.
7.International transfers and the Standard Contractual Clauses
EEA transfers. Where Wavn processes Personal Data transferred from the EEA to a country without an adequacy decision, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA and apply, with Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is itself a processor.
Elections under the Clauses. The parties agree the following:
- Clause 7, the docking clause, applies.
- In Clause 9, Option 2 (general written authorisation) applies, with the notice period stated in clause 5.2 of this DPA.
- In Clause 11, the optional independent dispute-resolution paragraph does not apply.
- In Clause 17, the Clauses are governed by the law of Ireland.
- In Clause 18(b), disputes shall be resolved before the courts of Ireland.
- Annex I and Annex II to the Clauses are completed by sections 11 and 12 of this DPA respectively.
- The list of Sub-processors required by Annex III is published at wavn.ai/subprocessors and is incorporated by reference.
United Kingdom. For transfers subject to the UK GDPR, the International Data Transfer Addendum to the Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is incorporated and applies, with the Clauses above as its Approved EU SCCs; Tables 1 to 3 are completed by clauses 1, 11 and 12 of this DPA, and in Table 4 neither party may end the Addendum as set out in its section 19.
Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the Clauses apply with references to the GDPR read as references to the Swiss Act, the competent authority being the Federal Data Protection and Information Commissioner, and the term “Member State” read so as not to prevent data subjects in Switzerland from suing in their place of habitual residence.
Transfer impact assessment. Wavn has assessed the law and practice of each destination country for its effect on the protection afforded by the Clauses and applies supplementary measures where the assessment requires them, including encryption in transit and at rest, access minimisation and challenge of overbroad requests. The current assessment is available on request.
Precedence. Where the Clauses conflict with any other provision of this DPA or the Terms, the Clauses prevail.
8.Audit and information
Wavn shall make available to Customer all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. (Art. 28(3)(h).)
How the right is exercised. Wavn shall satisfy this obligation in the first instance by providing its then-current security documentation and by responding to a reasonable security questionnaire, once in any twelve-month period. Where that does not reasonably satisfy Customer’s obligations, or following a personal data breach, Customer may conduct an on-site or remote audit on thirty (30) days’ written notice, during business hours, no more than once in any twelve-month period, subject to confidentiality undertakings, conducted so as not to disrupt the Service or compromise the data of other customers, and at Customer’s expense except where the audit reveals material non-compliance.
Wavn does not currently hold SOC 2, ISO/IEC 27001 or any comparable third-party certification, and this DPA makes no such claim. Where one is obtained, the report or certificate will be made available under confidentiality in satisfaction of clause 8.2.
9.Deletion and return
At Customer’s choice, Wavn shall delete or return all Personal Data processed on Customer’s behalf after the end of the provision of the Service, and delete existing copies, unless Union or Member State law requires storage. (Art. 28(3)(g).)
How it happens. Customer may export Customer Content at any time, and for thirty (30) days after termination. Wavn deletes Customer Content from live systems after that period, or earlier on Customer’s written instruction. Residual copies in backups are deleted on the ordinary backup expiry cycle, are not restored to live systems, and are not processed for any other purpose while they persist.
10.Liability, term and general
Liability. Each party’s liability under this DPA is subject to the exclusions and limitations in clause 17 of the Terms, except where Data Protection Law prohibits such limitation, and except as provided in Clause 12 of the Standard Contractual Clauses in respect of data subjects.
Term. This DPA takes effect with the Terms and continues until Wavn has ceased all processing of Personal Data on Customer’s behalf and completed deletion or return under clause 9.
Changes. Wavn may amend this DPA where required to reflect a change in Data Protection Law, a supervisory authority decision, or a new or replacement transfer mechanism, on thirty (30) days’ notice, provided the amendment does not materially reduce the protection afforded to data subjects.
Severability and governing law. If a provision is unenforceable it shall be severed and the remainder continues. Except as clause 7 provides for the Clauses, this DPA is governed by the law stated in clause 19.6 of the Terms.
11.Annex I: description of the processing
Completing Annex I to the Standard Contractual Clauses.
A. List of parties. Data exporter: the Customer accepting the Terms of Service, acting as controller (Module Two) or processor (Module Three), whose identity and contact details are those on its Account; activities relevant to the transfer: use of the Service. Data importer: Wavn, Inc., a Delaware corporation, acting as processor; contact legal@wavn.ai; activities relevant to the transfer: provision of the Service. Signature and date: as at acceptance of the Terms.
B. Description of the transfer.
- Categories of data subjects. Customer’s personnel and authorised users; Customer’s clients, counterparties and prospects; and any individual whose personal data appears in material Customer submits. Customer determines this by what it submits.
- Categories of personal data. Identification and contact data; professional and employment data; the content of documents, correspondence, prompts and files submitted; and any other personal data contained in Customer Content.
- Sensitive data. Not permitted. Clause 13.4 of the Terms and clause 5.2 of the Acceptable Use Policy prohibit submitting special category data, health data, payment card data, biometric identifiers and children’s data without Wavn’s prior written agreement. The Service is not configured to receive it and no restrictions or safeguards for it are represented.
- Frequency. Continuous, for the duration of the Service.
- Nature and purpose. Hosting, storage, retrieval, organisation, analysis and generation of material at Customer’s direction, for the purpose of providing the Service.
- Retention. For the duration of the Account, then as set out in clause 9 and in section 6 of the Privacy Notice.
- Sub-processors. As published at wavn.ai/subprocessors, for the duration and purpose stated there.
C. Competent supervisory authority. For Module Two and Module Three transfers, the supervisory authority of the Member State in which the data exporter is established; where the exporter is not established in the EEA but has an Article 27 representative, the authority of the Member State where that representative is established; failing which, the authority of the Member State in which the data subjects whose personal data is transferred are located.
12.Annex II: technical and organisational measures
Completing Annex II to the Standard Contractual Clauses. These are the measures actually in force. Where a measure is not implemented, it is stated as not implemented rather than omitted.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS for all connections to the Service and between the Service and its sub-processors. |
| Encryption at rest | Database and object storage encrypted at rest by the managed platform provider. |
| Access control (data) | Row-level security enforced at the database as the default, so a query cannot reach another account’s rows even if application logic is wrong. |
| Access control (personnel) | Least-privilege access, limited to personnel who require it to operate the Service; administrative access is logged. |
| Authentication | Managed identity provider; email-based authentication with session management. Credentials are not stored by Wavn in plaintext. |
| Segregation | Separation between the marketing site, the application and the build engine, each with its own credentials and scope. |
| Pseudonymisation and minimisation | Aggregated and de-identified data is used for operational analysis; personal data is not used for analytics where aggregate data suffices. |
| Logging and monitoring | Application and security event logging, an alerts ledger for failures, and health checks on the public surfaces. |
| Resilience and restoration | Managed platform backups with restoration procedures maintained by the platform providers. |
| Vendor assurance | Written data processing agreements with every sub-processor, review before engagement, and a published sub-processor list maintained in advance of change. |
| Incident response | Defined breach notification path with the 72-hour commitment in clause 6.4, and an alerts ledger recording failures with their verbatim cause. |
| Secure development | Type checking and automated test suites required before release; changes reviewed before merge; releases dated on a public changelog. |
| Third-party certification | None held. Wavn does not hold SOC 2, ISO/IEC 27001 or comparable certification and makes no such claim. |
| Independent penetration testing | Not yet conducted. This row will state the date and scope when it is. |
Measures for transfers to Sub-processors. Each Sub-processor is bound by written terms imposing obligations no less protective than these, is restricted to documented instructions, is prohibited from training on Personal Data, and is listed with its country at wavn.ai/subprocessors before it begins processing.
Wavn, Inc. Questions about this document go to legal@wavn.ai. The other instruments that bind alongside it are the Terms of Service, Acceptable Use Policy, Privacy Notice, Cookie Notice, Data Processing Addendum, the Sub-processor List and the Refund Policy.