Data Processing Addendum
Effective date: September 22, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between [Company legal name] (operating as Windlass) ("Windlass") and the customer identified in the account ("Customer"). It applies where Windlass processes Personal Data on Customer's behalf in providing the Windlass hosted AI agent workspace (the "Service") and prevails over the Agreement for that processing.
1. Definitions
1.1 "Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other law applicable to the processing of Personal Data under the Agreement.
1.2 "Customer Data" means Personal Data in Customer's workspace content, including files, prompts, attachments, session transcripts and voice recordings.
1.3 "Sub-processor" means a third party engaged by Windlass to process Customer Data.
1.4 "SCCs" means the standard contractual clauses in European Commission Implementing Decision (EU) 2021/914 and, for UK transfers, the UK International Data Transfer Addendum (the "UK Addendum").
1.5 Other capitalized terms have the meanings given in the GDPR.
2. Scope and Roles
2.1 Customer is the controller of Customer Data (or a processor, where Customer acts for another controller). Windlass is Customer's processor (or sub-processor). Annex 1 describes the processing.
2.2 Windlass is an independent controller of account data, billing records, usage metering records and technical logs, as described in the Privacy Policy. This DPA does not apply to that processing.
3. Processing Instructions
3.1 Windlass will process Customer Data only on Customer's documented instructions: the Agreement, this DPA, Customer's use of the Service (including the prompts, files and connector configurations Customer provides and the actions Customer directs the agent to take), and any further written instructions agreed by the parties.
3.2 Windlass will inform Customer if, in its opinion, an instruction infringes Data Protection Law, or if the law requires it to process Customer Data other than on Customer's instructions, unless the law prohibits such notice.
3.3 Windlass will not use Customer Data to train machine learning models, sell it, or process it for any purpose other than providing the Service.
4. Confidentiality
Personnel authorized to process Customer Data are bound by written confidentiality obligations and access Customer Data only to the extent needed to provide, secure and support the Service.
5. Security
Windlass will implement and maintain appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as described in Annex 2. Windlass may update these measures provided the overall level of protection is not materially reduced.
6. Sub-processors
6.1 Customer authorizes Windlass to engage the Sub-processors listed in Annex 3.
6.2 Windlass will give at least 30 days' notice, by email or in the Service, before a new Sub-processor processes Customer Data. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved in good faith, Customer may terminate the Agreement and receive a pro-rata refund of prepaid fees for the remaining term.
6.3 Windlass will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains liable for its Sub-processors' performance.
7. Assistance
7.1 Taking into account the nature of the processing, Windlass will assist Customer with appropriate technical and organizational measures in responding to data subject requests. If Windlass receives such a request directly, it will forward it to Customer without responding unless legally required to respond.
7.2 Windlass will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, and may charge reasonable fees for assistance beyond what Data Protection Law requires.
8. Personal Data Breach
8.1 Windlass will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data.
8.2 The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Windlass may provide information in phases and will cooperate with Customer to contain and remediate the breach.
9. Audits
On written request, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, Windlass will make available the information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, Customer or an independent auditor bound by confidentiality may audit Windlass's relevant systems and processes on at least 30 days' notice, during business hours, without disrupting the Service or compromising the security of other customers.
10. Deletion and Return
Customer may export workspace files at any time from the account settings. On termination of the Agreement or deletion of the account, Windlass will delete Customer Data within 30 days and purge copies in backups within 30 days after that, unless applicable law requires retention. Windlass will confirm deletion in writing on request.
11. International Transfers
11.1 Windlass hosts the Service with [Hosting provider] in [Hosting location]. Model inference is performed by DeepSeek in China. Customer acknowledges that Customer Data sent to the model (prompts, attachments and outputs) is transferred to China, and that Customer controls what content is sent.
11.2 Where Customer Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the SCCs (Module Two or Module Three, as applicable) are incorporated into this DPA with Customer as data exporter and Windlass as data importer. Windlass will ensure onward transfers to Sub-processors are covered by the SCCs or another valid transfer mechanism and will implement supplementary measures where needed.
11.3 For the SCCs: Clause 9 uses Option 2 with 30 days' notice; the governing law and forum are those of the EU Member State in which Customer is established, or Ireland if Customer is not established in the EU; and Annexes 1, 2 and 3 of this DPA serve as Annexes I, II and III. For UK transfers, the UK Addendum applies with the information in this DPA.
12. Liability
Each party's liability under this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, except that nothing limits liability to data subjects under the SCCs or liability that cannot be limited under Data Protection Law.
13. Term and General
13.1 This DPA takes effect when Customer accepts the Agreement or first places Customer Data in the Service, whichever is earlier, and remains in force for as long as Windlass processes Customer Data.
13.2 Windlass may update this DPA to reflect changes in Data Protection Law or the Service on at least 14 days' notice, without materially reducing Customer's protections.
13.3 This DPA is governed by the governing law of the Agreement except where the SCCs require otherwise. Notices: [legal email]. Privacy queries: [privacy email].
Annex 1: Details of Processing
- Subject matter. A hosted AI agent workspace in which Customer stores files, runs an AI agent and keeps session history.
- Duration. The term of the Agreement plus the deletion period in Section 10.
- Nature and purpose. Hosting, storage, transmission to the model for inference, transcription of voice input, execution of code and commands at Customer's direction, and related support.
- Data subjects. Customer's personnel and users, and any individuals whose Personal Data Customer includes in workspace content, such as clients, contacts, employees or end users.
- Categories of Personal Data. Any Personal Data Customer places in files, prompts, attachments or voice input, such as names, contact details, identifiers and professional information. Special categories are not required by the Service and are processed only if Customer includes them.
- Frequency. Continuous, as directed by Customer.
Annex 2: Technical and Organizational Measures
- Isolation. Each customer's workspace runs in a separate container, isolated from other customers.
- Encryption in transit. Connections between users, the Service and Sub-processors use TLS.
- Access control. Production access is limited to authorized personnel on a need-to-know basis. Passwords are stored as hashes; sessions are protected by session cookies and CSRF protection.
- Data minimization. Metering records hold token counts, model and timestamps only, never prompt text; voice recordings are deleted once transcribed.
- Logging and deletion. Technical logs are retained for 90 days; Customer Data is deleted within 30 days of account deletion and backups purged within 30 days after that.
- Incident response. A documented process for detecting, assessing, containing and notifying security incidents.
Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. (DeepSeek) | Model inference (prompts, attachments sent to the model, outputs) | China |
| [Hosting provider] | Hosting of workspaces, databases and backups | [Hosting location] |
| [Payment processor] | Payment processing and invoicing | As published by the provider |
| [Email provider] | Transactional email delivery | As published by the provider |
| our speech-to-text provider | Voice transcription | As published by the provider |
The current list is maintained at 195.58.146.102 and updated in accordance with Section 6.