Data Processing Addendum

The terms under which Windlass processes personal data on behalf of customers as a processor under the GDPR and UK GDPR. · Last updated Sep 22, 2026

Effective date: September 22, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between [Company legal name] (operating as Windlass) ("Windlass") and the customer identified in the account ("Customer"). It applies where Windlass processes Personal Data on Customer's behalf in providing the Windlass hosted AI agent workspace (the "Service") and prevails over the Agreement for that processing.

1. Definitions

1.1 "Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other law applicable to the processing of Personal Data under the Agreement.

1.2 "Customer Data" means Personal Data in Customer's workspace content, including files, prompts, attachments, session transcripts and voice recordings.

1.3 "Sub-processor" means a third party engaged by Windlass to process Customer Data.

1.4 "SCCs" means the standard contractual clauses in European Commission Implementing Decision (EU) 2021/914 and, for UK transfers, the UK International Data Transfer Addendum (the "UK Addendum").

1.5 Other capitalized terms have the meanings given in the GDPR.

2. Scope and Roles

2.1 Customer is the controller of Customer Data (or a processor, where Customer acts for another controller). Windlass is Customer's processor (or sub-processor). Annex 1 describes the processing.

2.2 Windlass is an independent controller of account data, billing records, usage metering records and technical logs, as described in the Privacy Policy. This DPA does not apply to that processing.

3. Processing Instructions

3.1 Windlass will process Customer Data only on Customer's documented instructions: the Agreement, this DPA, Customer's use of the Service (including the prompts, files and connector configurations Customer provides and the actions Customer directs the agent to take), and any further written instructions agreed by the parties.

3.2 Windlass will inform Customer if, in its opinion, an instruction infringes Data Protection Law, or if the law requires it to process Customer Data other than on Customer's instructions, unless the law prohibits such notice.

3.3 Windlass will not use Customer Data to train machine learning models, sell it, or process it for any purpose other than providing the Service.

4. Confidentiality

Personnel authorized to process Customer Data are bound by written confidentiality obligations and access Customer Data only to the extent needed to provide, secure and support the Service.

5. Security

Windlass will implement and maintain appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as described in Annex 2. Windlass may update these measures provided the overall level of protection is not materially reduced.

6. Sub-processors

6.1 Customer authorizes Windlass to engage the Sub-processors listed in Annex 3.

6.2 Windlass will give at least 30 days' notice, by email or in the Service, before a new Sub-processor processes Customer Data. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved in good faith, Customer may terminate the Agreement and receive a pro-rata refund of prepaid fees for the remaining term.

6.3 Windlass will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains liable for its Sub-processors' performance.

7. Assistance

7.1 Taking into account the nature of the processing, Windlass will assist Customer with appropriate technical and organizational measures in responding to data subject requests. If Windlass receives such a request directly, it will forward it to Customer without responding unless legally required to respond.

7.2 Windlass will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, and may charge reasonable fees for assistance beyond what Data Protection Law requires.

8. Personal Data Breach

8.1 Windlass will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data.

8.2 The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Windlass may provide information in phases and will cooperate with Customer to contain and remediate the breach.

9. Audits

On written request, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, Windlass will make available the information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, Customer or an independent auditor bound by confidentiality may audit Windlass's relevant systems and processes on at least 30 days' notice, during business hours, without disrupting the Service or compromising the security of other customers.

10. Deletion and Return

Customer may export workspace files at any time from the account settings. On termination of the Agreement or deletion of the account, Windlass will delete Customer Data within 30 days and purge copies in backups within 30 days after that, unless applicable law requires retention. Windlass will confirm deletion in writing on request.

11. International Transfers

11.1 Windlass hosts the Service with [Hosting provider] in [Hosting location]. Model inference is performed by DeepSeek in China. Customer acknowledges that Customer Data sent to the model (prompts, attachments and outputs) is transferred to China, and that Customer controls what content is sent.

11.2 Where Customer Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the SCCs (Module Two or Module Three, as applicable) are incorporated into this DPA with Customer as data exporter and Windlass as data importer. Windlass will ensure onward transfers to Sub-processors are covered by the SCCs or another valid transfer mechanism and will implement supplementary measures where needed.

11.3 For the SCCs: Clause 9 uses Option 2 with 30 days' notice; the governing law and forum are those of the EU Member State in which Customer is established, or Ireland if Customer is not established in the EU; and Annexes 1, 2 and 3 of this DPA serve as Annexes I, II and III. For UK transfers, the UK Addendum applies with the information in this DPA.

12. Liability

Each party's liability under this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, except that nothing limits liability to data subjects under the SCCs or liability that cannot be limited under Data Protection Law.

13. Term and General

13.1 This DPA takes effect when Customer accepts the Agreement or first places Customer Data in the Service, whichever is earlier, and remains in force for as long as Windlass processes Customer Data.

13.2 Windlass may update this DPA to reflect changes in Data Protection Law or the Service on at least 14 days' notice, without materially reducing Customer's protections.

13.3 This DPA is governed by the governing law of the Agreement except where the SCCs require otherwise. Notices: [legal email]. Privacy queries: [privacy email].

Annex 1: Details of Processing

Annex 2: Technical and Organizational Measures

Annex 3: Sub-processors

Sub-processor Purpose Location
Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. (DeepSeek) Model inference (prompts, attachments sent to the model, outputs) China
[Hosting provider] Hosting of workspaces, databases and backups [Hosting location]
[Payment processor] Payment processing and invoicing As published by the provider
[Email provider] Transactional email delivery As published by the provider
our speech-to-text provider Voice transcription As published by the provider

The current list is maintained at 195.58.146.102 and updated in accordance with Section 6.