This DPA applies when Wolf visibility processes personal data on a business customer's documented instructions in connection with the service. It is designed to support GDPR, UK GDPR, and comparable US state processor or service-provider requirements.
1. Application and roles
This Data Processing Addendum forms part of the agreement between the customer (“Customer”) and Wolf visibility. It applies to personal data contained in customer content that Wolf visibility processes on Customer's behalf (“Customer Personal Data”). Customer is the controller or business; Wolf visibility is the processor or service provider. Each party remains independently responsible for personal data it processes for its own purposes.
Terms such as controller, processor, data subject, personal data, processing, sell, share, and supervisory authority have the meanings given by applicable data-protection law.
2. Documented instructions
Wolf visibility will process Customer Personal Data only to provide, secure, support, and improve the service under the agreement; comply with Customer's documented use and configuration; and comply with law. The agreement, this DPA, order forms, and Customer's authorised use are the documented instructions. Wolf visibility will notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
Wolf visibility will not sell Customer Personal Data, share it for cross-context behavioural advertising, retain or use it outside the direct business relationship, or combine it with personal data from unrelated sources except as permitted for a service provider by applicable law.
3. Customer responsibilities
Customer will provide lawful instructions; give required notices; obtain required consents; respond to data subjects; and ensure that its use, prompts, and Customer Personal Data comply with law and the agreement. Customer will not submit sensitive or regulated data unless the order form expressly authorises it and specifies additional safeguards.
4. Confidentiality and security
Wolf visibility will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations. Taking account of the state of the art, cost, scope, context, purposes, and risk, Wolf visibility will maintain appropriate technical and organisational measures designed to protect confidentiality, integrity, availability, and resilience.
- Access controls based on role and need to know, with authentication protections appropriate to the service.
- Encryption in transit and provider-supported encryption at rest.
- Secure software development, dependency maintenance, vulnerability handling, and change controls appropriate to the service.
- Logging, abuse prevention, backup, recovery, and incident-response practices proportionate to risk.
- Vendor diligence and written data-protection obligations for subprocessors.
- Periodic review and testing of relevant safeguards.
5. Subprocessors
Customer generally authorises Wolf visibility to use subprocessors to provide the service. Subprocessors may include hosting and compute providers, Neon database services, authentication, payment, email, support, security, and the AI or search providers selected for Customer's checks. Wolf visibility will impose data-protection obligations that are no less protective in substance than those required by applicable law and remains responsible for subprocessor performance to the extent required by law.
Wolf visibility will make a current subprocessor list available before the paid service launches and provide reasonable advance notice of a new subprocessor. Customer may object on reasonable data-protection grounds within the notice period. The parties will work in good faith on a reasonable solution; if none is available, Customer may stop the affected feature or terminate it as the agreement permits.
6. Assistance and incidents
Taking account of the nature of processing and information available, Wolf visibility will reasonably assist Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and consultations with authorities. Customer is responsible for its own compliance and any extraordinary assistance costs agreed in advance.
Wolf visibility will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and provide available information reasonably needed for Customer's legal obligations. Notification is not an admission of fault. Customer is responsible for notices to individuals and regulators unless law assigns that duty to Wolf visibility.
7. Return and deletion
During the service term, Customer may export supported Customer Personal Data. On termination or written request, Wolf visibility will delete or return Customer Personal Data within a commercially reasonable period, ordinarily 30 days, unless law requires retention. Data may remain temporarily in protected backups until overwritten under normal cycles and will not be used for another purpose.
8. Information and audits
Wolf visibility will provide information reasonably necessary to demonstrate compliance, such as security summaries, policies, or independent reports when available. If that information is insufficient, Customer may request one audit per year by an independent auditor, on reasonable notice, during business hours, under confidentiality, without accessing other customers' data or disrupting the service. Customer bears its audit costs unless the audit identifies a material breach by Wolf visibility.
9. International transfers
Where an applicable restricted transfer requires safeguards, the current European Commission Standard Contractual Clauses are incorporated by reference using the controller-to-processor module as applicable, with Customer as exporter and Wolf visibility as importer. The UK International Data Transfer Addendum applies to restricted UK transfers. The agreement and this DPA supply the relevant annex information. If a transfer mechanism is invalidated, the parties will cooperate to implement a lawful replacement.
10. Processing details
- Subject matter and purpose: providing AI visibility measurement, project storage, reporting, support, security, and related service functions selected by Customer.
- Duration: the agreement term plus the limited return, deletion, backup, and legal-retention periods described above.
- Nature: collection, transmission, storage, organisation, retrieval, analysis, display, export, deletion, and other processing initiated through the service.
- Data subjects: Customer's authorised users, personnel, clients, prospects, website representatives, and people mentioned in Customer-submitted content.
- Personal data: business identifiers, contact data, account identifiers, domains, prompts, project configuration, engine responses, source URLs, usage and diagnostic data, and support content.
- Sensitive data: not intended or authorised unless expressly listed in an order form with additional safeguards.
- Frequency: continuous or on demand, depending on Customer's configuration.
11. Priority and contact
If this DPA conflicts with the service agreement on personal-data protection, this DPA controls. The liability terms in the service agreement apply to this DPA unless prohibited by law. Contact privacy@wolfvisibility.com about this DPA. A signature-ready version naming both legal entities and the final subprocessor list must be completed before relying on this DPA for paid enterprise processing.