Data Processing Addendum
This Data Processing Addendum (“DPA”) is part of the Terms of Service or accepted order under which WrenFoundry provides a Service to a customer. It governs personal data that the customer submits to a Service for WrenFoundry to process on the customer’s behalf (“Customer Personal Data”). A signed or product-specific DPA controls where it differs. DueFiles publishes its own DPA.
1. Roles and instructions
The customer is the controller or a processor acting for a controller; WrenFoundry is the processor or subprocessor. Each party complies with the data protection law applicable to its role. The customer determines the purposes of processing and provides the notices, authority, and lawful basis required for Customer Personal Data. WrenFoundry processes that data only on the customer’s documented instructions in the agreement, this DPA, product settings, and authorized support requests, unless law requires other processing. We notify the customer of a legal instruction unless law prohibits notice and promptly flag an instruction that infringes applicable data protection law.
2. Processing details
Subject matter: Customer Personal Data submitted to or generated through the covered Service. Duration: The service term and the deletion period below. Nature and purpose: Hosting, storage, retrieval, transmission, display, feature execution, support, security, and deletion in accordance with the customer’s use of the Service. Data subjects: Customer personnel, users, customers, vendors, contacts, and other people whose information the customer submits. Data types: Contact and account details, content and documents, communications, identifiers, activity records, and other personal data that the customer chooses to process through the Service. The customer must not submit data prohibited by the product documentation or applicable order.
3. Confidentiality and security
WrenFoundry restricts access to personnel bound by confidentiality who need the data to operate, support, or secure the Service. WrenFoundry maintains technical and organizational measures appropriate to the risk, including access control, encryption in transit, separation of customer access, logging, backups, vulnerability response, and personnel access review. The Security page describes the public controls. The customer controls its user permissions, exports, connected accounts, and instructions.
4. Subprocessors
The customer authorizes the subprocessors listed on the service providers page or the applicable product list. WrenFoundry binds each subprocessor to data protection duties consistent with this DPA and remains responsible for its processing. We post a material addition or replacement at least 15 days before it takes effect. The customer can object during that period on documented data protection grounds by emailing privacy@wrenfoundry.com. If the parties cannot resolve the objection, the customer can terminate the affected Service and receive a prorated refund of prepaid unused fees for that Service.
5. Assistance and requests
WrenFoundry assists the customer with data subject requests, security inquiries, impact assessments, and regulator consultations to the extent relevant to the Service and information available to us. We direct requests concerning Customer Personal Data to the customer unless law requires a direct response. The customer remains responsible for its response and decisions as controller.
6. Personal data incidents
WrenFoundry notifies the customer without undue delay, and within 72 hours after becoming aware, of a confirmed personal data breach affecting Customer Personal Data. We provide available facts about the incident, affected information, measures taken, and contact channel, and continue to provide material updates as the investigation progresses.
7. Return and deletion
At the end of the Service, the customer can export its data through available product controls. On written request, WrenFoundry deletes Customer Personal Data from active systems within 30 days, except information law requires us to retain. Backup copies expire under the normal backup cycle and remain protected during that period. We confirm completion on request.
8. International transfers
WrenFoundry puts a lawful transfer mechanism in place before a restricted international transfer of Customer Personal Data. Where the parties use the European Commission’s 2021/914 Standard Contractual Clauses, the applicable controller-to-processor or processor-to-processor module, required annexes, and UK or Swiss terms become part of the customer agreement. Request signed transfer terms from privacy@wrenfoundry.com.
9. Audit and precedence
On reasonable written notice, WrenFoundry supplies information needed to demonstrate compliance with this DPA. The customer can conduct one audit in a 12-month period, with additional audits after a confirmed breach or regulator demand. Audits occur during business hours under confidentiality, protect other customers’ data, and are at the customer’s expense unless an audit establishes a material breach by WrenFoundry. This DPA controls over general Terms on data processing; executed transfer clauses control over this DPA for the transfer they govern. Liability follows the applicable customer agreement.