Wiseen

Data Processing Addendum

This Data Processing Addendum ("DPA") applies when the Customer's use of the Service involves personal data contained in customer content, for which the Customer is the controller and Wiseen ([LEGAL ENTITY NAME]) is the processor under Art. 28 GDPR.

1. Subject matter and duration

Processing of personal data included in customer content, for the duration of the subscription and the deletion period that follows it.

2. Nature and purpose

Hosting, storage, display and processing strictly necessary to provide the Wiseen features the Customer uses (KPIs, improvement actions, analyses, boards, audits, optional AI assistance).

3. Categories of data and data subjects

  • Data subjects: the Customer's employees and collaborators.
  • Data: names and work emails of users; names of employees in rosters (responsibles, auditors, attendance); and any personal data the Customer chooses to include in free-text content. The Service does not require special categories of data, and the Customer agrees not to upload them.

4. Instructions

Wiseen processes personal data only on the Customer's documented instructions — using the Service is the instruction — and informs the Customer if an instruction appears to infringe the GDPR.

5. Confidentiality and security (Art. 32)

  • Encryption in transit (TLS) and at rest.
  • Per-organization isolation enforced at the database layer (row-level security).
  • Least-privilege internal access; server-side secrets never exposed to clients.
  • Rate limiting, bot protection and audit logging on sensitive operations.

6. Subprocessors

The Customer authorizes the subprocessors listed in the Privacy Policy §6 (Supabase, Vercel, Stripe, OpenAI, Google, Resend, Upstash, Cloudflare). Wiseen will announce subprocessor changes with at least 30 days' notice, during which the Customer may object on reasonable data-protection grounds. Wiseen remains liable for its subprocessors. Transfers outside the EEA rely on Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

7. AI processing

AI features are optional and per-request: when used, the minimum necessary content is transmitted to OpenAI's API to generate the response. Per OpenAI's API terms, that data is not used to train their models. The Customer controls AI availability through its plan and its users' actions.

8. Assistance

Taking into account the nature of the processing, Wiseen assists the Customer with data subject requests (access, deletion, export), with Art. 32–36 obligations, and provides the information reasonably necessary to demonstrate compliance. Audits are satisfied in the first instance by documentation; on-site audits require reasonable notice and scope.

9. Personal data breaches

Wiseen notifies the Customer without undue delay after becoming aware of a personal data breach affecting customer content, with the information reasonably available at that time.

10. Deletion and return

During the subscription, the Customer can export its content using the Service's export features. After termination, customer content is deleted within 90 days (backups within a further 30 days), unless retention is legally required.