Data Processing Addendum

How Winglo processes
personal data for you.

Version 2026-08-22. Effective 22 August 2026. This DPA is the public processor agreement for Customers subject to the GDPR, UK GDPR, Swiss FADP, or equivalent law.

For counsel and procurement

Winglo is the processor. You (the Customer) are the controller of Personal Data you submit to the Service. This DPA is incorporated into the Winglo Terms of Service and becomes binding when you accept the Terms. A countersigned original is available for Enterprise customers on request.

SCCs included

Module 2 (Controller to Processor), 2021/914

UK Addendum

ICO International Data Transfer Addendum, incorporated

HIPAA BAAs

Not available. Do not submit PHI.

1. Parties and incorporation

This Data Processing Addendum ("DPA") is between the Customer and Winglo ("Winglo", "we", "us"). It forms part of the Winglo Terms of Service (the "Terms") and any Order Form or enterprise agreement that incorporates the Terms (together, the "Agreement").

If you use the Service on behalf of an organization, you represent that you have authority to bind that organization. "Customer" then means that organization.

If there is a conflict between this DPA and the rest of the Agreement, this DPA controls for the processing of Personal Data. An executed Order Form or countersigned DPA controls over this public text for the points it expressly varies.

2. Definitions

  • "Personal Data" has the meaning in GDPR Article 4(1) and includes equivalent terms under UK GDPR and the Swiss FADP.
  • "Processing" has the meaning in GDPR Article 4(2).
  • "Controller" and "Processor" have the meanings in GDPR Article 4(7) and 4(8).
  • "Customer Data" means data the Customer (or its users) submits to the Service, including Personal Data.
  • "Service" means the Winglo platform described in the Terms.
  • "Sub-processor" means a third party engaged by Winglo to Process Personal Data on behalf of the Customer.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Winglo.
  • "Standard Contractual Clauses" or "SCCs" means the clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2 (Controller to Processor), as amended or replaced.
  • "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner and laid before Parliament in accordance with s119A of the Data Protection Act 2018, as revised.
  • "Applicable Data Protection Law" means the GDPR, UK GDPR, Swiss FADP, and any other law that applies to the Processing under this DPA.

3. Scope and roles

This DPA applies when Winglo Processes Personal Data on behalf of the Customer in the course of providing the Service. For that Processing, the Customer is the Controller and Winglo is the Processor.

Winglo acts as an independent Controller for account administration, billing, security of the Service, and the marketing website. That Processing is described in the Privacy Policy and is outside this DPA.

Details of the Processing (subject matter, duration, nature, purpose, types of Personal Data, and categories of data subjects) are set out in Schedule A.

4. Customer instructions

Winglo shall Process Personal Data only on documented instructions from the Customer, including this DPA, the Agreement, and configuration of the Service by the Customer's authorized users (connecting a source, starting a job, exporting or deleting a workspace). Winglo shall not Process Personal Data for its own purposes, for advertising, or to train a foundation model.

If Applicable Data Protection Law requires Winglo to Process Personal Data other than on the Customer's instructions, Winglo shall inform the Customer before that Processing, unless the law prohibits that notice.

The Customer is responsible for the lawfulness of the Personal Data it submits, for the instructions it gives, and for informing data subjects where required. The Customer shall not instruct Winglo to Process protected health information or other data for which the Service is not configured (see Section 17).

5. Winglo's obligations

Winglo shall:

  • Process Personal Data only on documented Customer instructions, as set out in Section 4
  • Ensure that persons authorized to Process Personal Data are bound by confidentiality
  • Implement the technical and organizational measures in Section 7 and Schedule C, and maintain a level of security appropriate to the risk (GDPR Article 32)
  • Engage Sub-processors only as Section 11 allows, and remain liable to the Customer for their performance of this DPA
  • Assist the Customer, taking into account the nature of the Processing, with data-subject requests (Section 9) and with DPIAs and prior consultation (Section 10)
  • Notify the Customer of a Security Incident as Section 8 requires
  • Delete or return Personal Data at the end of the provision of services, as Section 13 requires
  • Make available the information reasonably necessary to demonstrate compliance with GDPR Article 28, and allow for audits as Section 14 requires

6. Confidentiality

Winglo shall treat Personal Data as the Customer's confidential information. Access by Winglo personnel is limited to what is needed to operate, secure, or support the Service, is logged, and is subject to written confidentiality obligations that survive the end of the engagement.

7. Security measures

Winglo implements and maintains the measures in Schedule C. Those measures include encryption in transit and at rest, per-workspace isolation, access control, logging, and an incident-response process.

Winglo may update the measures as long as the update does not materially reduce the overall security of the Processing. A current description is also published at winglo.ai/security.

8. Security incidents

Winglo shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of a Security Incident affecting Personal Data Winglo Processes for the Customer.

The notice shall include, to the extent then known: the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Winglo shall provide further information as it becomes available and shall reasonably cooperate with the Customer's investigation and any notification the Customer is required to make.

Winglo's notice under this Section is not an admission of fault or liability.

9. Data-subject rights

Taking into account the nature of the Processing, Winglo shall provide reasonable assistance to enable the Customer to respond to requests from data subjects exercising rights of access, rectification, erasure, restriction, portability, and objection, or the right not to be subject to automated decision-making.

If Winglo receives a request directly, it shall redirect the data subject to the Customer and notify the Customer promptly, unless applicable law prohibits that notice. The Customer remains responsible for the response.

Requests may also be sent to privacy@winglo.ai. Winglo responds to the Customer within 30 days.

10. Data-protection impact assessments

Winglo shall provide reasonable assistance to the Customer with data-protection impact assessments and prior consultation with a supervisory authority, in each case taking into account the nature of the Processing and the information available to Winglo.

11. Sub-processors

The Customer grants Winglo a general written authorization to engage the Sub-processors listed in Schedule B, and to engage new Sub-processors under this Section.

Winglo shall impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, so far as they apply to that Sub-processor's Processing. Winglo remains liable to the Customer for the Sub-processor's performance.

Winglo shall give the Customer at least 14 days' notice before a new Sub-processor starts Processing Personal Data for the Customer (email to the account owner, or an in-product notice). The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service without penalty for that objection.

Schedule B on this page is the current list. There is no separate sub-processor directory. Customer-authorized connectors are engaged only when the Customer connects them.

12. International transfers

Customer Data at rest is stored in the European Union. The primary database and authentication currently run on Supabase in Ireland (AWS eu-west-1).

Application compute and object storage run on Cloudflare's network. Model inference is sent to the providers in Schedule B. Those transfers may involve Processing outside the EU or the UK. Winglo does not claim that no Personal Data ever leaves the EU.

For any Restricted Transfer, the parties incorporate the SCCs (Module 2: Controller to Processor). The Customer is the data exporter. Winglo is the data importer. The SCCs prevail over this DPA if they conflict. Schedule A completes Annex I. Schedule C completes Annex II. The competent supervisory authority for the exporter is the authority of the Customer's EU or UK establishment, or of its representative, as applicable.

For transfers subject to UK GDPR, the UK Addendum is incorporated and applies to those transfers. For transfers subject to the Swiss FADP, the SCCs are interpreted so that references to the GDPR include the FADP and the competent authority includes the Federal Data Protection and Information Commissioner.

Winglo shall not make a new Restricted Transfer of Customer Personal Data except as this Section and Schedule B describe, or on further documented Customer instruction.

13. Return and deletion

During the term, the Customer may export or delete workspace data from the Service, or request an export and erasure by emailing privacy@winglo.ai.

When the Agreement ends, or on the Customer's written request, Winglo shall delete Personal Data, or return it in a reasonable machine-readable form and then delete remaining copies, unless Union, Member State, or UK law requires storage.

Operational Customer Data is deleted within 30 days of a valid deletion request or account closure. Audit logs are deleted within 90 days, unless a longer retention is required by law or the Customer has contracted a longer retention.

14. Audits

Winglo shall make available information reasonably necessary to demonstrate compliance with GDPR Article 28, including this DPA, the Security overview, and, when they exist, third-party audit reports or certificates.

The Customer (or a mandated auditor bound by confidentiality) may audit Winglo's relevant Processing, on at least 30 days' written notice, no more than once in any twelve-month period unless a Security Incident or a supervisory authority requires more. The audit shall avoid unreasonable disruption. Winglo may satisfy the request with current documentation and independent reports under NDA where those reasonably address the questions asked. If they do not, the parties shall agree a scoped inspection.

SOC 2 Type II and a third-party penetration test are on the roadmap. They are not live. Winglo will not describe a planned audit as complete.

15. Records

Winglo shall maintain the records of Processing required of a processor under GDPR Article 30(2), and shall make those records available to the Customer or a supervisory authority on request where they relate to this DPA.

16. AI processing and training

The Service uses third-party models to generate drafts, reports, and other output. That inference is Processing of Customer Data on the Customer's instructions.

Winglo contractually requires its model providers not to use Customer Data to train or fine-tune a foundation model. Winglo does not use Customer Data to train a model of its own.

Each inference is logged with the model identifier, timestamp, workspace, and a record of the input and output sufficient for the Customer's audit. Logs are retained for the subscription plus 90 days, unless the Customer has contracted a different retention.

17. HIPAA and regulated data Winglo does not accept

Winglo does not offer HIPAA-compliant infrastructure or Business Associate Agreements. The Customer shall not submit protected health information to the Service.

HIPAA-ready infrastructure and BAA capability are on the product roadmap. Enterprise customers who need that capability should contact legal@winglo.ai. Until Winglo confirms it in writing, those workloads are out of scope.

18. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except that nothing in the Agreement limits liability that Applicable Data Protection Law does not allow to be limited, including a data subject's rights under GDPR Article 82.

Winglo's processor obligations in this DPA are in addition to, and do not reduce, any duty Winglo has as a Controller under the Privacy Policy.

19. Term

This DPA starts when the Customer first accepts the Terms or first uses the Service, whichever is earlier, and continues for as long as Winglo Processes Personal Data for the Customer.

Sections that by their nature should survive (confidentiality, deletion, liability, and audit of residual records) survive termination.

20. Notices and changes

Notices under this DPA may be sent to the Customer's account-owner email and to legal@winglo.ai or privacy@winglo.ai.

Winglo may update this public DPA as the Service evolves. Material changes will be notified at least 14 days before they take effect, except where a change is required sooner by law or a supervisory authority. The version and effective date appear at the top of this page.

21. Governing law

This DPA follows the governing law and dispute process in the Terms, except that mandatory provisions of Applicable Data Protection Law continue to apply to the Processing they cover, and the SCCs are governed as those clauses require.

22. Contact

Privacy and data-subject requests: privacy@winglo.ai

Legal and countersigned DPA: legal@winglo.ai

Security incidents and review: security@winglo.ai

Schedule A — Details of processing (Annex I)

Subject matter
Personal Data submitted to the Service so Winglo can operate AI employees, workflows, and connected tools for the Customer
Duration
The term of the Agreement, plus the deletion periods in Section 13
Nature and purpose
Storage, retrieval, analysis, inference, reporting, communication, and deletion as required to provide the Service on the Customer's instructions
Types of Personal Data
Account identifiers, business contact details, operational content the Customer connects or types, usage logs, and any other Personal Data the Customer submits. Winglo does not define a closed list because the Customer chooses what to connect
Categories of data subjects
The Customer's personnel and users, and third parties whose data the Customer inputs or connects (customers, leads, site visitors, and similar)
Frequency of transfer
Continuous, for as long as the Customer uses the Service
Retention
As Section 13. Default: operational data 30 days after deletion or closure; audit logs 90 days, unless law or a contracted retention requires longer

Schedule B — Sub-processors

Platform Sub-processors are used to operate the Service. Instructed Sub-processors receive Personal Data only when the Customer (or an AI employee acting on the Customer's configuration) uses that capability.

Platform

Cloudflare, Inc.
United States / global edge
Application compute (Workers), content delivery, object storage (R2), queues, and DNS
Supabase, Inc.
Ireland (AWS eu-west-1)
Primary database, authentication, and file storage for Customer Data at rest
Anthropic, PBC
United States
Model inference. Inputs are not used to train models. Abuse-monitoring retention is at most 30 days
OpenAI, L.L.C.
United States
Model inference when a workspace selects an OpenAI model. Inputs are not used to train models under Winglo's provider terms
Resend, Inc.
United States
Transactional email (account alerts, briefs, and notifications the Customer configures)
PostHog, Inc. (EU Cloud)
European Union
Product analytics when the visitor or Customer has accepted analytics cookies
Firecrawl (Mendable, Inc.) and Apify
United States / European Union
Page retrieval for research jobs the Customer or an AI employee starts
Orshot
As notified
Image rendering of marketing designs produced in the Service

On Customer instruction

Postiz (operated by Winglo)
As hosted by Winglo
Social publishing when the Customer connects channels
Customer-authorized connectors
As selected by the Customer
Tools the Customer connects (for example Slack, HubSpot, Google Analytics 4, Search Console). Processed only on that instruction

Schedule C — Technical and organizational measures (Annex II)

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Per-workspace isolation at the database, application, and inference layers. Cross-workspace access is denied
  • Role-based access control. SSO is available on Enterprise. An AI employee's access can be revoked in one action
  • Logging of each run: input, output, model identifier, timestamp, and the workflow that started it
  • Personnel access to Customer Data is limited, logged, and subject to confidentiality
  • Vulnerability management and periodic internal security review. A third-party penetration test is planned before general availability and is not yet complete
  • Incident-response procedures, including the notice in Section 8
  • Deletion and export as Section 13 describes
  • No use of Customer Data to train foundation models, contractually enforced with model providers

Schedule D — SCC particulars

Clause 7 (docking)
The docking clause applies
Clause 9 (Sub-processors)
Option 2, general written authorization, 14 days' notice, as Section 11
Clause 11 (redress)
The optional independent dispute-resolution body is not designated in this public DPA
Clause 13 (supervision)
The exporter's competent supervisory authority, as Section 12
Clause 17 (governing law)
Option 1. The law of an EU Member State that allows third-party beneficiary rights. If the parties do not specify one in an Order Form, the law of Ireland
Clause 18 (forum)
The courts of the Member State whose law applies under Clause 17
Annex I.A
Exporter: the Customer. Importer: Winglo. Contact: privacy@winglo.ai
Annex I.B
As Schedule A
Annex I.C
As Section 12 (competent authority)
Annex II
As Schedule C
Annex III
As Schedule B

Countersigned DPA

This page is the binding public DPA. Enterprise customers who need a countersigned copy, a vendor-security packet, or a named security contact should write to legal@winglo.ai or use the form. We respond within 5 business days.

Contact legal