WorkWise HR Solutions

Data Processing Agreement

Article 28 GDPR · Standard terms · v1.0

This Data Processing Agreement ("DPA") forms part of the WorkWise Terms of Service between WorkWise (the "Processor") and the customer ("Controller"). It governs Processor's handling of Personal Data on Controller's behalf.

1. Subject matter & duration

Processor will process Personal Data only on documented instructions from Controller, for the duration of the subscription, to provide the WorkWise Policy Assistant service.

2. Nature & purpose of processing

Storing HR policy documents, generating embeddings, returning grounded answers, escalating sensitive questions, and maintaining administrative audit trails.

3. Categories of data subjects & data

Employees and HR administrators of the Controller; account credentials, names, work emails, questions submitted to the assistant, answers generated, escalation metadata.

4. Sub-processors

Controller authorises the sub-processors listed at /sub-processors. Processor will notify Controller before adding or replacing a sub-processor; Controller may object on reasonable grounds.

5. International transfers

Personal Data is stored within the European Economic Area (default region: eu-west-1, Ireland). Any onward transfer outside the EEA is covered by the EU Standard Contractual Clauses (2021/914) Module 3 (processor-to-processor).

6. Security measures (Art. 32)

7. Data subject rights

Processor provides self-service tools for export, deletion and rectification, and assists Controller in responding to data-subject requests within 30 days.

8. Personal data breach

Processor will notify Controller without undue delay and within 48 hours of becoming aware of a personal data breach affecting Controller's data, with the information required by Art. 33(3) GDPR.

9. Return or deletion

On termination Processor will, at Controller's option, return or delete all Personal Data within 30 days, except where Union or Member State law requires retention.

10. Audits

Processor will make available all information necessary to demonstrate compliance and will permit audits, including inspections, conducted by Controller or a mandated auditor, subject to confidentiality and reasonable scheduling.

11. Governing law

This DPA is governed by the laws of Ireland. Supervisory authority: Irish DPC.

Questions about this DPA, our sub-processors or a data-protection request? Contact our Data Protection Officer.