We're a SourceForge Top Performer for Digital Credential Management.Read the announcement

Last updated on Jul 24, 2026

Data Processing Addendum

Details Wauld's data protection obligations and security measures when processing customer data.

This Data Processing Addendum (the "DPA") forms an integral part of the separate commercial agreement(s) between you, the User (the "Controller" or "Data Controller") and Wauld LLC (the "Processor" or "Data Processor"), each on behalf of themselves and their Affiliates (together, the "Parties") that pertains to the Terms of Use (the "Principal Agreement"). This DPA governs the processing of any personal information that Controller may make accessible to the Processor and is effective as of the last signature hereto ("Effective Date").

1. Definitions

Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:

"Anonymization" means the irreversible process by which Personal Data is altered in such a way that the data subject is no longer identifiable, directly or indirectly, particularly by reference to an identifier or any other means.

"Controller Personal Data" means any Personal Data Processed by the Processor on behalf of Controller pursuant to or in connection with the Principal Agreement.

"Data Protection Law" means all data protection laws applicable to the Processing of Personal Data under this DPA, including local, state, national, and/or foreign laws, treaties, and/or regulations, including without limitation the GDPR and implementations of the GDPR into national law, and the California Consumer Privacy Act ("CCPA"), in each case as amended, repealed, consolidated, or replaced from time to time.

"Data Breach" means a security incident that involves the exposure, loss, theft, destruction, or alteration of Personal Data or Sensitive Information, whether intentional or accidental.

"Europe or European" means the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland.

"GDPR" means (a) the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "EU GDPR"); and (b) the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of Section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR").

"Personal Data or Personal Information" means any information relating to (i) an identified or identifiable natural person and (ii) an identified or identifiable legal entity (where such information is protected similarly as Personal Data or personally identifiable information under applicable Data Protection Laws), where for each (i) or (ii), such data is Controller's Personal Data. Data Controllers shall take necessary permissions from the Data Subjects prior to gathering and sending their data to the Data Processor.

"Principal Agreement" means the MSA, the Professional Services Agreement, and Order Forms, including any exhibits or attachments applicable to the Service provided by the Processor.

"Process or Processing" means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data.

"Processor Product" means the services being offered by the Processor to the Controller.

"Restricted Transfer" means any export of Controller Personal Data by Controller to the Processor from its country of origin, either directly or via onward transfer, to a third country in the course of Processor's provision of the Services under the Agreement that is prohibited under Applicable Laws, unless (a) the destination has been recognized as providing an adequate level of data protection by a competent data protection authority, or otherwise in a legally binding way, or (b) Processor has adopted an appropriate adequacy mechanism recognized under Applicable Laws ensuring an adequate level of data protection.

"Sensitive Information" means any religious or philosophical beliefs, trade union membership, medical information, financial information, social security number, health or genetic information, sex life or sexual orientation. In addition, Sensitive Information in accordance with CCPA/CPRA means personal information that reveals the consumer's social security, driver's license, state identification card, or passport number; consumer's account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; consumer's precise geolocation; consumer's racial or ethnic origin, religious or philosophical beliefs, or union membership.

Where the Services involve the processing of Sensitive Information that is included in or associated with a Credential or otherwise necessary to deliver the Services, the Controller is responsible for ensuring that such processing is lawful and that all necessary consents and notices have been obtained. The Controller shall inform the Processor in advance of any intended processing of Sensitive Information that goes beyond what is incidental to the standard credentialing functionality of the Services, so that the Parties may agree on any additional safeguards or contractual terms required.

The Processor processes any Personal Data and Sensitive Information that is included in or associated with a Credential solely for the purpose of providing the Services as instructed by the Controller and for complying with applicable legal obligations. The Processor does not use such Personal Data or Sensitive Information for analytics, advertising, behavioral profiling, marketing, training of artificial intelligence models, or any purpose unrelated to the delivery of the Services. The Processor may use aggregated or de-identified data derived from such Personal Data and Sensitive Information, provided that such data does not identify any individual and cannot reasonably be re-identified, for purposes such as improving the Services, generating internal analytics, and benchmarking, but excluding the training of artificial intelligence models.

"Standard Contractual Clauses" means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as amended or replaced from time to time.

"Security Incident" means a breach of security of the Processor's Services or Processor's systems used to Process Personal Data leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by the Processor in the context of this DPA.

"Services" means the service offering provided by Processor to Controller under the Principal Agreement.

"Sub-Processor" means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Controller in connection with this DPA.

"Supervisory Authority" means an independent public authority responsible for monitoring the application of applicable Data Protection Law, including the Processing of Personal Data covered by this DPA.

"Third Parties" means the other organizations or individuals who may be involved in the processing of Personal Data by a personal information controller.

"UK Addendum" means the International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner's Office, in force as of 21 March 2022, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf.

2. General Terms and Scope

2.1 The purpose of this DPA is to describe the work to be carried out by the Processor in relation to the Agreement. This DPA shall be deemed to take effect from the Effective Date and shall continue in full force and effect until termination of the Agreement.

2.2 This DPA applies to all activities in which employees of the Processor or Sub-Processor commissioned by the Processor process Personal Data of the Controller on its behalf.

2.3 This DPA applies to the Processing of Personal Data, including under local, state, national, and/or foreign laws, treaties, and/or regulations, including without limitation the GDPR and implementations of the GDPR into national law, and the CCPA, in each case as amended, repealed, consolidated, or replaced from time to time, by the Processor on behalf of the Controller.

2.4 This DPA does not limit or reduce any data protection commitments relating to Processing of Data previously negotiated by the Processor in the Agreement (including any existing data processing addendum to the Principal Agreement).

2.5 The Processor's role depends on the type of Personal Data being processed: (a) the Processor acts as a Processor with respect to Personal Data that the Controller or its authorized users upload or that is included in or associated with a Credential issued through the Services, including data relating to Recipients ("Credential Data"); and (b) the Processor acts as an independent Controller with respect to Personal Data collected directly from the Controller's administrators, billing contacts, support contacts, and other users who interact with the Processor directly, including in connection with account registration, billing, support, product analytics, and marketing of the Processor's own services ("Account Data"). This DPA governs the Processor's processing of Credential Data. The Processor's processing of Account Data is governed by the Processor's Privacy Policy and is outside the scope of this DPA.

2.6 Processing listed in Annex I is in scope of this DPA. Processing where Wauld acts as an independent Controller (including platform analytics, product telemetry, feature usage logs, and Processor-generated support data) is outside the scope of this DPA and is governed by Wauld's Privacy Policy.

3. Processing of Personal Data

3.1 The Parties acknowledge that the Processor may process Personal Data on behalf of the Controller during the term of this Agreement. A description of the Personal Data and the processing activities (including the subject matter, nature, and purpose of the Processing, the types of Personal Data, and categories of Data Subjects) undertaken by the Processor is set out in Annex I.

3.2 Both Parties will comply with all applicable requirements of the Data Protection Law. This clause is in addition to, and does not relieve, remove, or replace a Party's obligations or rights under the Data Protection Law.

3.3 The Controller instructs the Processor to Process Personal Data for the following purposes:

  • Processing in accordance with the Principal Agreement and applicable orders;
  • Processing to comply with other reasonable instructions provided by the Controller where such instructions are consistent with the terms of the Principal Agreement;
  • Processing pursuant to additional written instructions issued by Controller, if they are consistent with the terms and scope of the Agreement; and
  • Processing of Personal Data required under applicable law to which the Processor or Processor's Affiliate is subject, including but not limited to applicable Data Protection Laws, in which case the Processor or the relevant Affiliate shall, to the extent permitted by applicable law, inform the Controller of such legally required processing.

4. Processor Personnel

4.1 Processor shall take reasonable steps to ensure the reliability of any employee, agent, or contractor of any Sub-Processor who may have access to the Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Personal Data, as strictly necessary for the purposes of providing Services according to the Principal Agreement, and to comply with applicable laws in the context of that individual's duties to the Sub-Processor. All such individuals shall be subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

4.2 The Processor shall ensure that its personnel and all Sub-Processors engaged in the processing of Personal Data have received appropriate training on their responsibilities and shall handle the data in adherence to the security measures provided under Annex III.

5. Duties of Processor

5.1 The Processor confirms that it is aware of the legal provisions of the applicable Data Protection Laws and observes the principles of correct data processing.

5.2 The Processor undertakes to maintain strict confidentiality during Processing.

5.3 Processor shall comply with all Data Protection Laws applicable to the Processor in its role as a Processor Processing Personal Data. Controller shall comply with all Data Protection Laws applicable to Controller as a Controller and shall obtain all necessary consents, and provide all necessary notifications, to Data Subjects to enable the Processor to carry out lawfully the Processing contemplated by this DPA. Controller will ensure that any instruction it issues to the Processor complies with applicable Data Protection Laws. The Processor shall inform Controller without undue delay if, in its reasonable opinion, an instruction issued by Controller violates applicable European Data Protection Laws.

5.4 If the Controller is subject to inspection by supervisory authorities or other bodies, or if data subjects assert rights against it, the Processor undertakes to support the Controller to the extent necessary insofar as the Processing is concerned.

5.5 The Processor may provide information to Third Parties, Sub-Processors, or data subjects only after obtaining prior written consent from the Controller. The Processor shall immediately forward requests received directly to the Controller.

5.6 The Processor maintains a designated Privacy Officer who serves as the primary point of contact for the Controller and Data Subjects on matters relating to the processing of Personal Data under this DPA. The Privacy Officer is responsible for receiving and coordinating responses to inquiries, complaints, data subject rights requests, and breach notifications. The current contact details of the Privacy Officer are available at /legal/privacy-policy and will be updated in this DPA or the Privacy Policy in the event of any change. The Processor has determined that it does not currently meet the thresholds requiring designation of a formal Data Protection Officer under Article 37 of the GDPR; should this determination change, the Processor will designate a Data Protection Officer who satisfies the requirements of Articles 37, 38, and 39 of the GDPR and will promptly inform the Controller of such designation.

5.7 The Processor will make reasonable efforts to notify the Controller of any legally binding request for disclosure of Personal Data by a law enforcement authority, unless legally prohibited from doing so (e.g., under national security laws).

6. Sub-Processors

6.1 Controller authorizes the Processor to engage Sub-Processors and agrees that Processor may disclose Personal Data to its Sub-Processors for purposes of providing the Processor Product, provided that Processor shall:

  • enter into an agreement with its Sub-Processors that imposes on the Sub-Processors obligations regarding the Processing of Personal Data that are consistent with those obligations that apply to Processor hereunder; and
  • remain fully liable for all obligations subcontracted to the Sub-Processors. Processor shall provide a detailed list of current Sub-Processors attached with this DPA, as set forth in Annex II.

6.2 The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors, and the Controller will have an opportunity to object to such changes on reasonable grounds within thirty (30) days after being notified of the engagement of the Sub-Processor.

6.3 If the Controller objects to a new Sub-Processor, as permitted in Section 6.2 of this DPA, the Processor shall use reasonable efforts to make available to the Controller a change in the Processor's Services or recommend a commercially reasonable change to Controller's configuration or use of the Processor's Services to avoid processing of Personal Data by the objected-to new Sub-Processor without unreasonably burdening the Controller.

6.4 If Processor is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, the Controller may terminate the component of the Processor Product which cannot be provided by the Processor without the use of the objected-to new Sub-Processor by providing written notice to the other Party.

6.5 The Processor will refund Controller any prepaid fees covering the remainder of the term of Controller's subscription following the effective date of termination with respect to such terminated component of the Processor Product, without imposing a penalty for such termination on Controller.

7. Data Anonymization

7.1 Subject to the Privacy Policy and the Principal Agreement, Processor undertakes to use industry-accepted anonymization techniques to ensure that Personal Data, as shared by the Controller, is anonymized prior to any use, processing, sale, or distribution for the Processor product or service enhancement or to any third-party entity.

7.2 Liability for Inadequate Anonymization. In the event the Processor fails to adequately anonymize the Personal Data, as evidenced by the identification of any individual directly or indirectly, the Processor shall:

  • promptly notify the Controller upon becoming aware of such failure; and
  • take immediate remedial measures to prevent further disclosures and to properly anonymize the data.

8. Security

8.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall, in relation to the Personal Data, implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.

8.2 In assessing the appropriate level of security, the Processor shall take account in particular of the risks that are presented by Processing, in particular from a Data Breach.

8.3 Upon Controller's written request at reasonable intervals (and no more than once in any twelve-month period absent reasonable cause), the Processor shall make available to the Controller such information as is reasonably necessary to demonstrate compliance with this DPA, including: (a) audit reports and certifications then available, which may include pass-through certifications of the Processor's infrastructure providers (such as Google Cloud Platform's SOC 2, ISO 27001, ISO 27017, and ISO 27018 certifications); (b) a description of the Processor's information security program; and (c) responses to reasonable written questions regarding the Processor's processing of Personal Data under this DPA. Subject to the Parties' agreement on reasonable scope and confidentiality protections, the Controller or an independent auditor mandated by the Controller may conduct a written audit of the Processor's compliance with this DPA, provided that any such audit will be conducted (i) at the Controller's expense, (ii) during regular business hours, (iii) with reasonable advance notice, and (iv) in a manner that does not disrupt the Processor's operations or the security of other customers' data.

8.4 The Processor shall not create copies or duplicates of Personal Data outside of those reasonably required for the provision of the Services, including those required for backups, disaster recovery, redundancy, and routine system operations. Such operational copies are protected by the same technical and organizational measures applicable to the primary Personal Data, as set forth in Annex III to this DPA. The Processor shall not create copies of Personal Data for any purpose other than providing the Services without the Controller's prior written consent.

8.5 The Processor shall implement and adhere to the technical and organizational security measures set forth in Annex III to this DPA, which describes the Processor's information security program in detail.

8.6 The Processor and Controller shall use reasonable efforts to identify the cause of any Security Incident, and the Processor shall promptly and without undue delay: (a) investigate the Security Incident; (b) provide the Controller with the information described in Section 11.1 of this DPA within the timeframes set forth therein; and (c) take reasonable steps to mitigate the effects of and to minimize any damage resulting from the Security Incident to the extent the remediation is within the Processor's reasonable control.

9. Security Incident

9.1 In the event that the Processor becomes aware of a Security Incident, the Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours after becoming aware. The notification requirements set out in Section 11.1 apply to such notifications.

9.2 In the event of such a Security Incident, the Processor shall provide Controller with a detailed description of the Security Incident and the type of Personal Data concerned, unless otherwise prohibited by law or otherwise instructed by a law enforcement or supervisory authority.

9.3 In the course of any Security Incident, the Controller is responsible for communicating the Personal Data Breach to the Data Subjects without undue delay under Article 34 of the GDPR. The Processor's liability extends to providing the cause along with reasonable investigation within the Processor's scope for the Data Breach to the Controller. At Controller's request, the Processor shall provide reasonable assistance and cooperation with respect to any notifications that Controller is legally required to send to affected Data Subjects and regulators.

10. Rights of Data Subjects

10.1 Taking into account the nature of the Processing, the Processor shall assist the Controller by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligations, as reasonably understood by the Controller, to respond to requests to exercise Data Subject rights under the Data Protection Laws.

10.2 The Processor shall:

  • promptly notify the Controller if it receives a request from a Data Subject under any Data Protection Law in respect of the Personal Data; and
  • ensure that it does not respond to that request except on the documented instructions of the Controller or as required by Applicable Laws to which the Processor is subject, in which case the Processor shall, to the extent permitted by Applicable Laws, inform the Controller of that legal requirement before the Processor responds to the request.

Compliance with FERPA and COPPA

10.3 Where the Controller is an educational institution subject to the Family Educational Rights and Privacy Act (FERPA), the Controller represents and warrants that it has the necessary authority to share educational records with the Processor and that such disclosure complies with FERPA.

10.4 Where the Controller uploads Personal Data relating to children under 13 years of age, the Controller represents and warrants that it has obtained verifiable parental or guardian consent in compliance with the Children's Online Privacy Protection Act (COPPA) and other applicable laws. The Processor shall not be responsible for verifying the age of data subjects uploaded by the Controller.

11. Personal Data Breach

11.1 The Processor shall notify the Controller without undue delay upon becoming aware of a Personal Data Breach affecting Personal Data, and in any event within seventy-two (72) hours. The notification shall include, to the extent then known: (a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; (c) the measures the Processor has taken or proposes to take to address the Personal Data Breach, including, where applicable, measures to mitigate its possible adverse effects; and (d) the name and contact details of the Processor's data protection contact from whom the Controller may obtain further information. Where it is not possible to provide all the information at the same time, the Processor will provide an initial notification with the information then available and will follow up with additional information without further undue delay.

12. Data Protection Impact Assessment and Prior Consultation

12.1 The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with Supervisory Authorities or other competent data privacy authorities, which the Controller reasonably considers to be required by Article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of the Personal Data by, and taking into account the nature of the Processing and information available to, the Processor.

13. Information and Audit

13.1 The Processor may make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by Controller.

13.2 Where the Processor has obtained third-party audit reports and certifications for its Services ("Audit Reports and Certifications"), the Processor shall, at Controller's request and subject to the confidentiality terms set forth in the Principal Agreement, make its most recent Audit Reports and Certifications available to Controller for the applicable covered service.

14. Data Transfer

14.1 The Processor's primary data storage infrastructure is located in the United States. The Processor and its Sub-Processors may process Personal Data in the United States, the European Union, and other jurisdictions as described in Annex II to this DPA. The Controller authorizes the Processor to engage Sub-Processors located outside the Controller's country of residence, including outside the European Economic Area, in connection with the provision of the Services. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction not recognized as providing an adequate level of data protection, the Parties shall ensure that the Personal Data is adequately protected through appropriate safeguards, including the Standard Contractual Clauses as described in Annex IV to this DPA.

14.2 When Personal Data is accessed or processed by Wauld HQ Private Limited (an affiliate of Wauld LLC based in India) for the purpose of providing support or development services, such transfer is governed by the applicable provisions of Indian data privacy laws. The Parties acknowledge that Wauld LLC and Wauld HQ Private Limited have established an intercompany agreement to ensure compliance with these regulations.

14.3 The Processor will transfer Personal Data of Controller only for the provision of Services to Controller under the Agreement. Controller hereby authorizes the Processor to make routine transfers of Personal Data to the Sub-Processors of the Processor.

14.4 The Processor shall ensure that any international transfers of Personal Data comply with applicable Data Protection Legislation. In the event that Personal Data is transferred from the European Economic Area to outside the European Economic Area, either directly or via onward transfer, to any country or recipient not recognized by the European Commission as providing an adequate level of protection for personal data, then the Standard Contractual Clauses approved by the European Commission in Decision 2021/914/EU (the "SCCs") shall apply.

14.5 To the extent that Processing relates to Personal Data originating from or in a jurisdiction which has any mandatory requirements in addition to those in this DPA, including Standard Contractual Clauses, the Parties may agree to any additional measures required to ensure compliance with applicable Privacy Laws as an annexure to this DPA or in a duly executed written addendum or amendment. If any variation is required to this DPA as a result of a change in Privacy Laws, either Party may provide written notice to the other Party of that change in law. The Parties will discuss and negotiate in good faith any necessary variations to this DPA to address such changes.

15. Deletion or Return of the Personal Data

15.1 The Processor shall promptly (but in any event not later than sixty (60) calendar days) return all Personal Data transferred and any copies to the Controller, or delete any particular or all Personal Data in its possession, and certify in writing to the Controller that it has complied with the requirements of this Section.

15.2 In any situation, the Processor shall not retain Personal Data except in accordance with the Processor's standard data retention policies and the deletion or return obligations set forth in Section 15.1 of this DPA.

16. General Terms

16.1 Confidentiality

Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement ("Confidential Information") confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party, except to the extent that: (a) disclosure is required by law; or (b) the relevant information is already in the public domain. The Processor may disclose Confidential Information to Sub-Processors bound by written confidentiality obligations.

16.2 Notices

All notices and communications given under this DPA must be in writing and will be delivered personally, sent by post, or sent by email to the address or email address set out in the Principal Agreement, or such other address as notified from time to time by the Parties changing address.


Annex I: Details of Processing

A. List of Parties

Data Importer (Processor)

FieldDetail
NameWauld LLC
Address1021 E Lincolnway, Suite #8406, Cheyenne, Wyoming 82001, United States
Contact PersonWill be provided upon request.
ActivitiesSee Annex I(B) below and the Agreement.
Signature and DateThis Annex I shall automatically be deemed executed when the DPA is executed by Controller.
RoleProcessor

Data Exporter (Controller)

FieldDetail
NameThe party identified as the "Controller" in this DPA.
AddressReference is made to the Agreement.
Contact PersonReference is made to the Agreement.
ActivitiesSee Annex I(B) below and the Agreement.
Signature and DateThis Annex I shall automatically be deemed executed when the DPA is executed by Controller.
RoleController

B. Description of Processing / Transfer

ItemDetail
Categories of Data SubjectsIssuers (organization admins, designers, and other staff), Recipients (credential holders), Third Parties (credential viewers/verifiers)
Categories of Personal Data TransferredName, contact information, device information, and other information necessary to provide the Services under the Agreement.
Sensitive Data Transferred (if applicable) and Applied Restrictions or SafeguardsThe Services may involve the processing of limited categories of Sensitive Information (which may include, depending on the Controller's use case, government identifiers, health-related data, biometric data, precise geolocation, or similar categories) where such information is included in or associated with a Credential or otherwise necessary to deliver the credentialing functionality the Controller has requested. The Processor processes any Sensitive Information included in or associated with a Credential solely for the purpose of providing the Services and for complying with applicable legal obligations, and does not use such Sensitive Information for analytics, advertising, behavioral profiling, marketing, training of artificial intelligence models, or any purpose unrelated to the delivery of the Services. Sensitive Information is protected by the technical and organizational measures set out in Annex III of this DPA. Where the Controller intends to use the Services in a manner that relies centrally on Sensitive Information, the Controller shall inform the Processor in advance so the Parties may agree on any additional safeguards or contractual terms.
Frequency of TransferContinuous.
Nature and Purpose of the Data Transfer and ProcessingProcessor will process Personal Data to provide and improve the Services under the Principal Agreement.
Retention PeriodPersonal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with Applicable Laws.

Annex II: List of Sub-Processors

Sub-Processor NameActivityProcessing Location
Google Cloud Platform (GCP)Cloud hosting, infrastructure, data storage, and backups for the Wauld platformUnited States
PostHogProduct analytics and event trackingUnited States
FeaturebaseSupport, feedback, changelog, and user engagement servicesUnited States and European Union
StripePayment processing and billingUnited States
LinearInternal issue tracking and bug management (may incidentally include limited support-related data)United States and European Union
FramerWebsite hosting and form submissionsUnited States
Google WorkspaceBusiness email, file storage, and collaborationGlobal
PostmarkTransactional and notification email deliveryUnited States
SlackInternal communication and collaboration (may incidentally include limited support-related data)United States
DevMarq Solutions Private LimitedContracted technical and development support personnel who may have controlled access to systems containing customer dataIndia

Annex III: Processor's Data Security Requirements

The Processor maintains a comprehensive, written information security program containing administrative, technical, and physical safeguards appropriate to (a) the size, scope, and type of the Processor's business; (b) the categories of Personal Data processed; and (c) the level of security and confidentiality required for such Personal Data. The Processor's security program is described below and is reviewed periodically to address evolving risks, technologies, and regulatory requirements.

1. Security Awareness and Training

The Processor maintains a mandatory security awareness and training program for all personnel (including management) covering:

  • Training on how to implement and comply with the Processor's information security program, including data protection requirements applicable to the Services;
  • Periodic communications from senior leadership reinforcing a culture of security awareness;
  • Role-specific training for personnel with elevated privileges or access to Personal Data; and
  • Acknowledgment of security policies and confidentiality obligations as part of personnel onboarding.

2. Access Controls

The Processor implements logical access controls designed to:

  • Limit access to information systems containing Personal Data to authorized personnel with a legitimate business need;
  • Prevent persons who should not have access from obtaining access, through authentication, authorization, and audit mechanisms;
  • Remove access on a timely basis when a person's role changes, employment ends, or a security risk is identified; and
  • Provide for periodic reviews of access privileges to confirm continued legitimate need.

3. Technical and Organizational Measures

The Processor implements the following technical and organizational measures:

  • Encryption. All Personal Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption.
  • Information Security Program Documentation. The Processor maintains a written Information Security Policy, Incident Response Plan, and Business Continuity Plan, each reviewed periodically.
  • Role-Based Access Control. RBAC is implemented across all systems, with regular access reviews.
  • Logging and Monitoring. Data access and changes are logged, monitored, and periodically reviewed for anomalies. Administrative actions (such as credential edits, account changes, and access grants) are logged for auditability.
  • Environment Segregation. Production, staging, and testing environments are logically segregated. Personal Data is not used in non-production environments except where necessary for legitimate testing and subject to equivalent safeguards.
  • Authentication. Authentication mechanisms include strong password requirements and, where available, multi-factor authentication for personnel access to systems containing Personal Data.
  • Network Security. Network-level controls, including firewalls, network segmentation, and intrusion detection, are maintained to protect against unauthorized access.

4. Security Incident Management

The Processor maintains documented procedures to detect, investigate, contain, and respond to potential security incidents:

  • Security incidents are identified through monitoring, alerts, personnel reports, and third-party notifications;
  • The Processor's Incident Response Plan defines the roles, escalation procedures, and remediation steps for security incidents;
  • In the event of a Personal Data Breach affecting Controller Data, the Processor will notify the Controller in accordance with Section 11.1 of this DPA; and
  • The Processor will conduct post-incident reviews to identify and implement improvements.

5. Data Integrity and Secure Disposal

The Processor maintains policies and procedures to ensure the confidentiality, integrity, and availability of Personal Data:

  • Personal Data is securely deleted, anonymized, or rendered unreadable when no longer required for processing, in accordance with applicable retention policies and the deletion and return obligations set forth in this DPA;
  • Storage media is securely disposed of in a manner that prevents reconstruction of Personal Data;
  • Pseudonymization and anonymization techniques are applied where appropriate; and
  • Cryptographic protocols are reviewed periodically to ensure continued effectiveness.

6. Physical and Environmental Security

The Processor's primary data storage and processing infrastructure is operated by Google Cloud Platform (GCP), which maintains physical and environmental security controls at its data centers in accordance with industry-leading certifications, including SOC 2, ISO 27001, ISO 27017, and ISO 27018. GCP's certifications are available for the Controller's review upon request. The Processor does not maintain its own physical data center; physical security of personnel workstations and remote access is maintained through endpoint security controls, including device encryption, screen lock requirements, and access restrictions.

7. Business Continuity and Disaster Recovery

The Processor maintains a documented Disaster Recovery Plan (DRP) covering the Services:

  • Personal Data is backed up regularly, with backups stored within the United States;
  • Backup integrity is periodically verified, and recovery procedures are tested in accordance with the Processor's internal cadence;
  • The Processor maintains defined Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) appropriate to the Services; and
  • The Disaster Recovery Plan is reviewed periodically and updated to address evolving risks and changes to the Services.

8. Continuous Improvement

The Processor reviews and updates its information security program periodically to address evolving risks, technologies, regulatory requirements, and customer feedback. Changes to the program that materially affect the Controller's Personal Data will be reflected in updates to this Annex III or in other contractually appropriate communications.


Annex IV: International Transfers of European Personal Data

1. Definitions

"Data Privacy Framework" means the EU-U.S., Swiss-U.S., and UK-U.S. Extension to the Data Privacy Framework maintained by the United States Department of Commerce, determined to provide an adequate level of protection for Personal Data transfers to certified commercial organizations in the United States under (i) the European Commission's Adequacy Decision 2023/4745 of 10 July 2023 and (ii) other applicable Data Protection Laws.

"Restricted Transfer" means (i) where the EU GDPR applies, a transfer of Personal Data from the EEA to a country or commercial organization outside of the EEA which is not subject to a valid adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data from the UK to a country or commercial organization outside the UK which is not based on adequacy regulations pursuant to section 17A of the UK Data Protection Act 2018 ("UK DPA"); and (iii) where the Swiss Federal Act on Data Protection of June 19, 1992 ("Swiss FADP") applies, a transfer of Personal Data from Switzerland to a country or commercial organization outside Switzerland which has not been recognized to provide an adequate level of protection by the Federal Data Protection and Information Commissioner.

"SCCs" means (i) where the EU GDPR applies, the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 ("EU SCCs"); and (ii) where the UK GDPR applies, the "International Data Transfer Addendum to the EU Commission Standard Contractual Clauses" issued by the Information Commissioner under s.119A(1) of the UK DPA (version B1.0 of 21 March 2022) as updated or amended ("UK Addendum").

2. Transfer Mechanisms

To the extent Controller's use of the Services requires a transfer mechanism to lawfully transfer Personal Data from Europe, the following terms will apply:

2.1 Where more than one transfer mechanism applies, the transfer of Personal Data will be subject to a single transfer mechanism in accordance with the following order of precedence: (i) the Data Privacy Framework; and (ii) the SCCs.

2.2 Data Privacy Framework. The Processor is self-certified to and complies with the Data Privacy Framework and will remain certified for the term of the Agreement.

2.3 Standard Contractual Clauses

2.3.1 Processor-to-Processor SCCs. Where Controller is contracting with the Processor, all Restricted Transfers of Personal Data will be governed by SCCs Module 3 implemented between the Processor (as "data exporter") and its Sub-Processors (as "data importers").

2.3.2 Controller-to-Processor SCCs. Where the transfer from Controller to the Processor is a Restricted Transfer, the SCCs will apply to such Restricted Transfers between Controller (as "data exporter") and the Processor (as "data importer") as follows:

EU Personal Data

In relation to Personal Data protected by the EU GDPR, the EU SCCs will apply (and are incorporated into this DPA by this reference) completed as follows:

i. Module 2 applies unless the Controller is a Processor, in which case Module 3 applies; ii. in Clause 7, the optional docking clause will not apply; iii. in Clause 9(a), option 2 (general written authorization) is implemented, and the time period for prior notice of Sub-Processor changes is thirty (30) days; iv. in Clause 11, the optional redress clause permitting data subjects to lodge complaints with an independent dispute resolution body will not apply; v. in Clause 17, option 1 is implemented and the governing law is the laws of Ireland; vi. in Clause 18(b), disputes will be resolved before the courts of Ireland; vii. Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; and viii. Annex II of the EU SCCs shall be deemed completed with the technical and organizational security measures set out in Annex III to this DPA.

UK Personal Data

In relation to Personal Data protected by the UK GDPR ("UK Personal Data"), the UK Addendum will apply as follows:

  • for the purpose of Table 1 of Part 1, the exporter is Controller and the importer is Processor, and the table is deemed to be completed with the information set out in Annex I;
  • for the purpose of Table 2 of Part 1, the "Approved EU SCCs" which the UK Addendum is appended to are the Standard Contractual Clauses incorporated into this DPA and completed as set out in the foregoing paragraph; and
  • for the purpose of Table 3 of Part 1, the information requested in Annex I and II of the Standard Contractual Clauses is provided in Annex I and Annex II to this DPA respectively, and the list of Sub-Processors is available at Annex II.

Swiss Personal Data

In relation to Personal Data protected by the Swiss FADP, the EU SCCs will apply amended and adapted as follows:

  • the Swiss Federal Data Protection and Information Commissioner is the exclusive supervisory authority;
  • the term "member state" must not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18; and
  • references to the GDPR in the EU SCCs shall also include the reference to the equivalent provisions of the Swiss FADP.

SCC Clarifications

The SCCs will be subject to the following clarifications:

  • Processor will allow Controller to conduct audits as described in the SCCs in accordance with Section 13 of this DPA.
  • Controller authorizes the Processor to appoint Sub-Processors in accordance with Section 6 of this DPA, and Controller may exercise its right to object to Sub-Processors under the SCCs in the manner set out in Section 6.
  • The Processor shall return and delete Controller's data in accordance with Section 15 of this DPA.
  • Nothing in this Annex IV varies or modifies the SCCs nor affects any supervisory authority's or Data Subject's rights under the SCCs. If any provision of this DPA contradicts, directly or indirectly, the SCCs, the SCCs shall prevail.

For the text of the SCCs, please visit https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.


Annex V: California Privacy Law

This California Privacy Law ("Addendum") supplements the DPA to which it is attached. Any term not defined in this Addendum shall have the meaning assigned to it, if any, in the DPA or the Agreement. To the extent the Agreement and this Addendum conflict, the terms of this Addendum shall take precedence with respect to Processing of Personal Information under the CCPA.

When Processor (Wauld) processes Personal Information on behalf of a Controller/Issuer, Processor acts solely as a "Service Provider" (as defined in the CCPA/CPRA). In this role, Processor shall not sell or share Controller Personal Information, and shall not retain, use, or disclose such information for any purpose other than providing or improving the Services.

When Wauld acts as an independent "Business" under the CCPA/CPRA (for example, when it collects information directly from users of wauld.com or users who create Wauld-managed accounts), Wauld will comply with all obligations and applicable Privacy laws.

To the extent the Processor processes Personal Information under the CCPA, the following supplemental terms shall apply:

  • Definitions. The terms "Business," "Business Purpose," "Consumer," "Sell," "Service Provider," and "Share" shall have the same meanings as provided in the CCPA. The term "Personal Information" shall refer to any Personal Data that constitutes Personal Information under the CCPA.
  • Roles of the Parties. Controller, as a Business under the CCPA, is disclosing Personal Information to the Processor, and the Processor is Processing the disclosed Personal Information solely as a Service Provider.
  • Business Purpose. The Processor will Process Personal Information for the purpose of providing the Services described in the Agreement, including in the associated Order Forms.
  • Service Provider Processing Limitations. The Processor will not (i) Sell Personal Information or (ii) retain, use, or disclose Personal Information outside the direct business relationship with Controller or for any purpose other than to provide the Services as articulated in the Agreement, including this Addendum, or as permitted by the CCPA.
  • No Combining Personal Information. The Processor will not combine Personal Information that it receives from, or on behalf of, Controller with Personal Information that it receives from, or on behalf of, another person or persons, or collects from its own interaction with a consumer, except as otherwise permitted by the CCPA.
  • Consumer Requests. The Processor shall provide reasonable support to Controller to enable Controller to respond to Consumer requests to exercise their rights under the CCPA, as set forth in Section 10 of this DPA.
  • Security of Processing. The Processor shall maintain technical and organizational measures to protect Personal Information as set forth in this DPA and as required by the CCPA.
  • Ongoing Compliance. The Processor agrees to comply with all applicable requirements of the CCPA pertaining to its role under the Principal Agreement, including by providing the same level of privacy protection for Personal Information as required under the CCPA.
  • Limited and Specified Purposes. The Processor will Process Personal Information only for the limited and specified business purposes set forth in this Annex V and the Principal Agreement. The Processor will not Process Personal Information for any purpose other than these limited and specified purposes.
  • Sub-Processors and Service Providers. The Processor will engage Sub-Processors to Process Personal Information only pursuant to a written agreement that imposes obligations on the Sub-Processor that are equivalent to the obligations the Processor undertakes in this Annex V, including the restrictions on Selling, Sharing, retaining, using, and disclosing Personal Information. The Processor remains responsible for its Sub-Processors' compliance with these obligations.
  • Notice of Inability to Comply. The Processor will notify the Controller without undue delay if the Processor determines that it can no longer meet its obligations under the CCPA with respect to Personal Information Processed under the Principal Agreement. Upon receipt of such notice, the Controller may take reasonable and appropriate steps to stop and remediate the unauthorized Processing of Personal Information, in accordance with the CCPA and applicable regulations.
  • Acknowledgment of CCPA Restrictions. The Processor acknowledges that it understands the restrictions imposed by the CCPA on Service Providers, including the prohibitions on Selling or Sharing Personal Information and on retaining, using, or disclosing Personal Information for purposes other than the business purposes specified in this Annex V and the Principal Agreement. The Processor will comply with these restrictions.