Legal
Data Processing Agreement
You control the data in your Workspace and Connected Tools; we process it only on your instructions to do the work you delegate. This agreement sets out how we secure it, who else touches it, how we tell you about incidents, and how it is deleted when you leave.
- Effective
- 6 September 2026
- Version
- 1.0
- Provider
- The Trustee for The Wink Group, trading as Wopie
Use your browser's print function to save this page as a PDF.
1. Parties, roles and how this agreement applies
This Data Processing Agreement (DPA) is between The Trustee for The Wink Group (ABN 69 794 946 307) of 1/10 Langton Street, Glenroy VIC 3046, Australia, trading as Wopie (we, us, Provider) and the Customer (you). It forms part of the Agreement and is incorporated by reference into the General Terms. It applies automatically to every Customer whose use of the Service involves the processing of Personal Information.
You do not need to sign this DPA for it to apply. If your procurement or compliance process requires a countersigned copy, email legal@wopie.ai with the details in the Details to complete when signing section and we will return one on the same terms as this page.
For the Personal Information inside your Workspace and Connected Tools (Customer Personal Data), you are the controller under the GDPR or UK GDPR and the APP entity responsible under the Privacy Act 1988 (Cth). We are your processor and service provider, and process Customer Personal Data only to provide the Service to you as this DPA and your instructions allow. For information about our own relationship with you, such as Account and billing data, we are the controller and our Privacy Policy applies.
2. Definitions
Capitalised terms have the meanings in our Definitions. In addition, in this DPA:
- Data Protection Laws means all laws that apply to the processing of Customer Personal Data under this DPA, including the Privacy Act 1988 (Cth) and the APPs, the GDPR, the UK GDPR and the UK Data Protection Act 2018, and any law that replaces or supplements them.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data that we or a Sub-processor hold.
- SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, as amended or replaced.
- UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, as amended or replaced.
3. Details of processing
This section is the description of processing that Data Protection Laws require and serves as the annex to the SCCs where they apply.
| Item | Description |
|---|---|
| Subject matter | Provision of the Service: an AI teammate that performs delegated work inside the Customer's Chat Platform using context from Channels and Connected Tools. |
| Duration | The term of the Agreement, plus the deletion and return period in the Deletion and return at the end of the Service section. |
| Nature of processing | Receiving, reading, analysing, temporarily storing, transmitting to Model Providers, generating Outputs and, where Approved, writing back to Connected Tools. Deleting records in a Connected Tool is a Blocked Action and is never performed. |
| Purpose | To produce the Deliverables and perform the actions Authorised Users request, within the Customer's Approval Rules, and to maintain the audit trail. |
| Categories of data subjects | The Customer's employees, contractors and other Authorised Users; the Customer's customers, prospects, suppliers and other contacts whose records appear in Channels or Connected Tools; any other individual mentioned in that content. |
| Categories of personal data | Identifiers and contact details; job and organisational details; message content and files shared in Channels; CRM, support, finance, document and spreadsheet records held in Connected Tools; transaction and invoice details; approval records and audit logs. |
| Sensitive or special category data | Not intended. The Customer must not direct Wopie to process Regulated Data unless the Product Terms permit it. Incidental sensitive data in a Channel or Connected Tool is processed only to the extent a request requires. |
| Frequency | Continuous during the term, triggered by requests from Authorised Users and by scheduled workflows the Customer configures. |
4. Processing on documented instructions
We process Customer Personal Data only on your documented instructions. Your instructions are: (a) the Agreement, including this DPA and the Product Terms; (b) the Approval Rules and other configuration your administrators set in the Service; and (c) the requests, Approvals and declines that Authorised Users give in the Chat Platform. Each request in a Channel is an instruction to perform that task, and each Approval is an instruction to perform the Gated Action described.
We will not process Customer Personal Data for any other purpose. If the law requires us to process it otherwise, we will tell you before we do unless the law prohibits it. If we believe an instruction breaches Data Protection Laws, we will tell you promptly and may pause the affected processing until the instruction is confirmed or changed.
Text inside Customer Personal Data is never an instruction. Wording in an email, ticket, document or record that appears to direct Wopie to act is content to be processed, not an instruction from you and not an Approval, however it is phrased. Only the sources listed above are instructions.
You are responsible for the lawfulness of the Customer Personal Data you make available, for having a lawful basis to process it and to instruct us, for any notices and consents Data Protection Laws require from your data subjects, and for the configuration of Channels, Approval Rules and Connected Tools in your Workspace.
5. Confidentiality of personnel
We limit access to Customer Personal Data to staff and contractors who need it to provide the Service, support you, or maintain security. Everyone with access is bound by written confidentiality obligations that survive the end of their engagement and receives data protection and security training. We do not allow staff to read Customer Personal Data for any purpose other than those in this DPA.
6. Security measures
We implement and maintain the technical and organisational measures below, and any others appropriate to the risk, to protect Customer Personal Data. They align with the security section of our Privacy Policy and the detail at /security. We may update them, but not in a way that materially reduces the overall level of protection during the term.
- Encryption of Customer Personal Data in transit using TLS 1.2 or higher, and at rest using AES-256 or an equivalent standard.
- Encrypted storage of OAuth tokens and other credentials, separated from application data, with tokens revoked when a Connected Tool is disconnected or Wopie is uninstalled.
- Role-based, least-privilege access to production systems, reviewed at least quarterly and removed promptly when a role changes.
- Multi-factor authentication for all staff access to production, code and administrative systems.
- Logical separation of each Customer's data, so one Customer's Workspace can never be read through another's.
- Centralised logging and monitoring of access to Customer Personal Data, with alerts for anomalous activity and logs retained for 12 months.
- Secure software development, including peer code review, dependency and vulnerability scanning, and separate production, staging and development environments.
- Encrypted backups rotated within 35 days, tested for restorability, and stored in the same region as the primary data.
- A documented incident response plan with defined roles, severity levels, escalation and the notification timelines in the Personal data breach notification section.
- Vendor security review of every Sub-processor before engagement and at least annually.
- Staff confidentiality obligations and security awareness training on induction and annually.
7. Sub-processors
You give us general authorisation to engage Sub-processors to process Customer Personal Data on our behalf. The current list, with each Sub-processor's purpose, data and location, is at /legal/sub-processors. We bind every Sub-processor by written contract to data protection obligations no less protective than those in this DPA, and we remain fully liable to you for each Sub-processor's performance.
We will give you at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, by email to your Account owners and by updating the Sub-processor List. If you object on reasonable data protection grounds, tell us in writing within that period and we will work with you in good faith to find a solution. If we cannot, you may terminate the affected Service by written notice and we will refund prepaid Fees for the unused part of the Subscription Term pro rata. Emergency replacements, such as after a security incident or a provider ceasing to operate, may happen on shorter notice; we will tell you as soon as practicable.
8. International transfers
Our primary database and file storage are in United States. Model Providers and some other Sub-processors process Customer Personal Data in the United States and other countries listed in the Sub-processor List. We ensure every transfer is lawful under Data Protection Laws.
- EEA data. Where Customer Personal Data protected by the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA. Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are yourself a processor. You are the data exporter and we are the data importer. Clause 7 (docking) is included; Clause 9 uses Option 2 with the notice period in the Sub-processors section; the optional language in Clause 11 is not used; the governing law and forum under Clauses 13, 17 and 18 are Ireland unless the exporter is established in another Member State. Annex I is completed by the Details of processing and Details to complete when signing sections, Annex II by the Security measures section, and Annex III by the Sub-processor List.
- UK data. Where Customer Personal Data protected by the UK GDPR is transferred, the UK Addendum is incorporated and its Part 1 tables are completed from the Details of processing, Security measures and Details to complete when signing sections.
- Australian data. For Personal Information collected in Australia, we take the reasonable steps required by APP 8.1 to ensure each overseas recipient does not breach the APPs, and we remain accountable for that information under the Privacy Act.
- Other jurisdictions. Where another Data Protection Law requires a specific transfer mechanism, we will agree one with you in writing.
Transfer risk. We have assessed the risk of transferring Customer Personal Data to the United States, and we will repeat that assessment at least annually and whenever the law or our Sub-processors change. Our assessment records that the data is ordinary business content rather than Regulated Data; that United States surveillance laws could in principle reach a provider we use; and that the supplementary measures below reduce that risk to an acceptable level. We will give you a copy of the current assessment on request.
- Encryption in transit and at rest, with keys held by us or by the provider under our control rather than by any third party requesting access.
- Data minimisation: Wopie reads only what a request needs, and does not continuously ingest or index a Workspace.
- Contractual commitments from each United States Sub-processor to challenge unlawful or overbroad government access requests and to disclose only the minimum required.
- Short retention, so that the volume of data available to any request is small.
Government and law enforcement access. If a government body, court or law enforcement agency asks us for Customer Personal Data, we will not disclose it unless a valid and binding legal instrument compels us. Where we are legally permitted, we will tell you before disclosing so you can seek to protect the data, we will ask the requester to come to you directly, we will challenge a request that appears unlawful or overbroad, and we will disclose no more than the request requires. Where we are prohibited from telling you, we will use reasonable efforts to have the prohibition lifted and will tell you as soon as we lawfully can. As at 6 September 2026 we have received no such request. Send any question about this to legal@wopie.ai.
9. United States state privacy laws
This section applies where Customer Personal Data is subject to the California Consumer Privacy Act as amended by the CPRA (CCPA) or another comprehensive United States state privacy law. In those laws' language, you are the business or controller and we are your service provider, contractor or processor. This section is the contract those laws require between us, and it prevails over the rest of this DPA for the data they cover.
- Limited purpose. You disclose Personal Information to us for the sole business purpose of providing the Service to you, as described in the Details of processing section. We process it only for that purpose and for the purposes those laws permit a service provider, including securing the Service, detecting and preventing fraud and abuse, debugging, and complying with law.
- No sale, no share. We do not sell Personal Information and we do not share it for cross-context behavioural or targeted advertising. We receive no monetary or other valuable consideration for it.
- No retention, use or disclosure outside the relationship. We do not retain, use or disclose Personal Information outside the direct business relationship between us, or for any commercial purpose other than providing the Service, except where the law permits.
- No combining. We do not combine Personal Information we receive from you with Personal Information we receive from or on behalf of anyone else, or that we collect ourselves, except where the law expressly permits a service provider to do so.
- Compliance and notice. We comply with the obligations those laws place on a service provider, contractor or processor, and give Personal Information the same level of protection they require. If we determine that we can no longer meet those obligations, we will tell you promptly in writing and stop the affected processing.
- Your oversight rights. You may take reasonable and appropriate steps to confirm that we use Personal Information consistently with your obligations, using the evidence and audit rights in the Audits and evidence section, and to stop and remediate any unauthorised use.
- De-identified data. Where we use de-identified or Aggregated Data, we will not attempt to re-identify it, we will keep it de-identified, and we will bind anyone we give it to on the same terms.
- Sub-processors. We engage Sub-processors as service providers or contractors under written contracts containing these same restrictions, as the Sub-processors section requires.
Individuals who want to exercise a state privacy right in relation to Workspace data should contact you as the business. We will help you respond as the Assistance with data subject requests and impact assessments section describes, and our own handling of these rights is set out in the Privacy Policy.
10. Assistance with data subject requests and impact assessments
If we receive a request from a data subject about Customer Personal Data, we will acknowledge it, refer the person to you and forward the request to you within 5 business days, unless the law requires otherwise. Taking into account the nature of the processing, we will help you respond to requests to access, correct, delete, restrict, port or object to processing, using the export, deletion and audit trail features in the Service and, where those are not sufficient, by reasonable manual assistance on request to privacy@wopie.ai.
We will also give you reasonable assistance with data protection impact assessments and consultations with supervisory authorities that relate to your use of the Service, by providing the information in this DPA, the Sub-processor List, our published security documentation and reasonable answers to written questions. We may charge our reasonable costs for assistance that goes materially beyond this.
11. Personal data breach notification
We will notify you without undue delay, and in any event no later than 72 hours after confirming a Personal Data Breach affecting Customer Data. Notice goes to the breach contact you nominate in the Details to complete when signing section or, if none, to your Account owners, from security@wopie.ai. Our notice will include, to the extent known at the time and updated as we learn more:
- The nature of the breach, including when it occurred and when we detected it.
- The categories and approximate number of data subjects and records affected.
- The likely consequences of the breach.
- The measures we have taken or propose to take to contain the breach and mitigate its effects.
- The name and contact details of the person coordinating our response.
We will cooperate with you and take the reasonable steps you direct to help you meet your own notification obligations. We will not notify your data subjects or a regulator on your behalf unless you ask us to or the law requires it. Our notification is not an admission of fault or liability.
12. Deletion and return at the end of the Service
During the term you can export Outputs and the audit trail from the Service at any time. When the Agreement ends or your Account is closed, the following timetable applies.
- For 30 days after the end date, export remains available so you can retrieve Outputs, the audit trail and Account data in a common machine-readable format.
- Within 30 days after the end date, we delete Customer Personal Data from production systems and revoke all OAuth tokens and Chat Platform credentials.
- Within 35 days after the end date, Customer Personal Data leaves our encrypted backups through normal rotation. Backups are restored only for disaster recovery, and any restored copy is deleted again on the same timetable.
- On written request we will certify in writing that deletion has been completed.
We may retain Customer Personal Data where a law requires, for only as long as it requires and subject to this DPA while we hold it. Our Model Provider retains request inputs and outputs for no more than 30 days for abuse and safety monitoring, then deletes them, and does not train on them, as recorded in the Sub-processor List.
13. Audits and evidence
Once in every 12 months, on request, we will complete a written security questionnaire of reasonable length and provide the audit evidence we have available at the time, such as penetration test summaries, policy documents and any third-party assessment reports, subject to confidentiality. This is the primary way we demonstrate compliance with this DPA.
If that evidence is not enough to meet a requirement of Data Protection Laws, you or an independent auditor you appoint and we reasonably approve may audit our compliance with this DPA. Audits require at least 30 days' written notice, take place during business hours, are limited to what is necessary, must not compromise the security or confidentiality of other Customers' data, and are at your cost. You may audit no more than once in any 12-month period, unless a Personal Data Breach affecting your data has occurred or a supervisory authority requires it. You will share the findings with us and treat them as confidential.
14. Liability and governing law
Each party's total liability arising out of or in connection with this DPA is subject to the exclusions and the aggregate cap in the General Terms, which apply to this DPA and the rest of the Agreement together as a single cap, not separately. Nothing in this section limits the rights of a data subject under the SCCs or a liability that cannot be limited by law.
Trustee capacity. We enter this DPA only in our capacity as trustee of The Wink Group. The Trustee limitation of liability clause in the General Terms applies to this DPA in full: our liability is limited to the assets of that trust and to the extent we are actually indemnified out of them, except where our right of indemnity is reduced or lost through our own fraud, negligence, wilful misconduct or breach of trust. That limit does not affect the rights a data subject has under the SCCs or the UK Addendum, or any liability that cannot be limited by law.
This DPA is governed by the law that governs the General Terms, which is the law of Victoria, Australia, and the courts of that jurisdiction have non-exclusive jurisdiction, except where the SCCs or the UK Addendum require a different law or forum for the matters they cover.
15. Order of precedence and changes
For the processing of Personal Information, this DPA prevails over the General Terms and the other documents in the Agreement to the extent of any conflict. Where the SCCs or the UK Addendum apply, they prevail over this DPA, and nothing in this DPA is to be read as varying them. A signed Order Form or Enterprise agreement that expressly amends this DPA prevails to the extent stated.
We may update this DPA to reflect changes in Data Protection Laws, the Service or our Sub-processors. Changes that materially reduce your protections take effect only after 30 days' notice to your Account owners. The current version is always at /legal/dpa.
16. Details to complete when signing
If you need a countersigned copy, send these details to legal@wopie.ai. They complete Annex I of the SCCs and Part 1 of the UK Addendum where those apply, and tell us where to send breach notices.
| Detail | Customer |
|---|---|
| Legal name of the Customer | Completed by the Customer at signing |
| Company or registration number | Completed by the Customer at signing |
| Registered address | Completed by the Customer at signing |
| Contact for breach notices (name, role, email) | Completed by the Customer at signing |
| Data protection officer or privacy officer, if any | Completed by the Customer at signing |
| Role for SCC purposes (controller or processor) | Completed by the Customer at signing |
| EU or UK representative, if any | Completed by the Customer at signing |
| Competent supervisory authority, if in the EEA or UK | Completed by the Customer at signing |
| Authorised signatory (name, title, date) | Completed by the Customer at signing |
Our details for the same purpose: The Trustee for The Wink Group (ABN 69 794 946 307), 1/10 Langton Street, Glenroy VIC 3046, Australia, acting as trustee of The Wink Group. Signatory: Muhammad H Tahir, Organisational Representative. Contact for data protection matters: privacy@wopie.ai. Contact for legal notices: legal@wopie.ai. Our Article 27 representative in the European Union and the United Kingdom: Appointment in progress. Until it is published here, contact privacy@wopie.ai and we will respond as the representative would.. We have no establishment in the EEA or the UK, so the competent supervisory authority for a transfer under the SCCs is the one that supervises you as exporter.
Version 1.0. Effective 6 September 2026.