Data Processing Agreement
Article 28 GDPR · Standard terms · v1.0
This Data Processing Agreement ("DPA") forms part of the WorkWise Terms of Service between WorkWise (the "Processor") and the customer ("Controller"). It governs Processor's handling of Personal Data on Controller's behalf.
1. Subject matter & duration
Processor will process Personal Data only on documented instructions from Controller, for the duration of the subscription, to provide the WorkWise Policy Assistant service.
2. Nature & purpose of processing
Storing HR policy documents, generating embeddings, returning grounded answers, escalating sensitive questions, and maintaining administrative audit trails.
3. Categories of data subjects & data
Employees and HR administrators of the Controller; account credentials, names, work emails, questions submitted to the assistant, answers generated, escalation metadata.
4. Sub-processors
Controller authorises the sub-processors listed at /sub-processors. Processor will notify Controller before adding or replacing a sub-processor; Controller may object on reasonable grounds.
5. International transfers
Personal Data is stored within the European Economic Area (default region: eu-west-1, Ireland). Any onward transfer outside the EEA is covered by the EU Standard Contractual Clauses (2021/914) Module 3 (processor-to-processor).
6. Security measures (Art. 32)
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Tenant isolation via Row Level Security in Postgres.
- Role-based access control; least-privilege admin access; MFA on internal accounts.
- Immutable audit log of administrative actions.
- Vulnerability scans and dependency monitoring.
- Documented incident-response playbook with 72-hour DPC notification window.
7. Data subject rights
Processor provides self-service tools for export, deletion and rectification, and assists Controller in responding to data-subject requests within 30 days.
8. Personal data breach
Processor will notify Controller without undue delay and within 48 hours of becoming aware of a personal data breach affecting Controller's data, with the information required by Art. 33(3) GDPR.
9. Return or deletion
On termination Processor will, at Controller's option, return or delete all Personal Data within 30 days, except where Union or Member State law requires retention.
10. Audits
Processor will make available all information necessary to demonstrate compliance and will permit audits, including inspections, conducted by Controller or a mandated auditor, subject to confidentiality and reasonable scheduling.
11. Governing law
This DPA is governed by the laws of Ireland. Supervisory authority: Irish DPC.
Questions about this DPA, our sub-processors or a data-protection request? Contact our Data Protection Officer.
