Wondeya Data Processing Agreement
Last updated: August 30, 2026 · Version: 1.0
This Data Processing Agreement (the "DPA") forms part of the Wondeya Terms of Service or of another written agreement that incorporates this DPA (the "Main Agreement") between the Customer and Woku SpA, a company incorporated in Chile, domiciled at Calle 120 39 Dp 14 B, Hualpén, Chile 4600150 ("Woku"). Wondeya is a product of Woku operated by Woku SpA.
The DPA takes effect when the Customer accepts the Main Agreement or when both parties sign it, and it applies when Woku processes Customer Personal Data on the Customer's behalf in providing Wondeya.
1. Definitions
The terms "personal data", "processing", "controller", "processor", "subprocessor", "data subject" and "personal data breach" shall have the meaning given in the applicable Data Protection Legislation.
For this DPA:
- Customer is the person or entity that accepts the Main Agreement and determines the essential purposes and means of the processing of Customer Personal Data.
- Customer Content has the meaning given in the Terms.
- Customer Personal Data is the personal data included in Customer Content that Woku processes on the Customer's behalf, including conversations, leads, knowledge bases, files, and Visitor data. It does not include data for which Woku acts as an independent controller to administer accounts, security, support, or the business relationship.
- Data Protection Legislation comprises the laws applicable to the processing, including Chile's Law No. 19.628 and, from its entry into force, its amendments by Law No. 21.719; Regulation (EU) 2016/679 ("GDPR"); the UK GDPR; and other applicable mandatory rules.
- SCCs are the European Commission's standard contractual clauses approved by Implementing Decision (EU) 2021/914, as updated or replaced.
- Services are the Wondeya features described in the Main Agreement (the "Service" as defined in the Terms).
- Subprocessor is a third party engaged by Woku to process Customer Personal Data on the Customer's behalf.
2. Roles and Scope
The Customer acts as controller and Woku as processor with respect to Customer Personal Data. If the Customer acts as a processor for a third party, the Customer is the processor and Woku is the subprocessor; the Customer represents that it has authority to give instructions and to incorporate this DPA.
Woku acts as an independent controller with respect to data necessary to:
- administer accounts, Users, authentication, and the business relationship;
- protect the security and integrity of the Service;
- comply with its own legal obligations;
- generate aggregated or de-identified metrics that do not allow identifying a person;
- administer the subscription together with Paddle within each party's independent domains.
The Privacy Policy governs those own activities. Paddle is the merchant of record and an independent controller for the checkout page, taxes, fraud prevention, and billing; by virtue of that function it is not a Subprocessor of the conversations or of other Customer Content.
3. Documented Instructions
Woku will process Customer Personal Data only:
- to provide, protect, and maintain the Services in accordance with the Main Agreement, this DPA, and the Customer's configuration;
- according to other documented and lawful instructions agreed by the parties;
- when an applicable law requires it, in which case Woku will inform the Customer before the processing, unless legally prohibited.
The Main Agreement, the use and configuration of the Service, authorized support requests, and the Customer's written instructions constitute documented instructions.
Woku will inform the Customer if, in its reasonable opinion, an instruction infringes the Data Protection Legislation. It may suspend the affected instruction while the parties review it, without being obligated to provide legal advice to the Customer.
4. Customer Obligations
The Customer warrants that it:
- has a legal basis to collect, use, and entrust the processing;
- provides transparent notices to Users and Visitors;
- obtains consents when necessary, including for cookies, analytics, and marketing;
- limits the data to what is necessary and keeps it accurate;
- does not instruct processing that is unlawful or incompatible with the Terms;
- responds to data subject requests and forwards to Woku only those that require assistance;
- has authority over domains, sources, files, and connected tools;
- assesses the suitability of the Service for its industry, territory, and risk.
The Customer must not use Wondeya to deliberately solicit or process health, biometric, or genetic data, trade union membership, political opinions, beliefs, sex life or sexual orientation, criminal records, government identifiers, data of minors, or other sensitive categories, unless there is a specific written addendum with Woku, a valid legal basis, and appropriate controls. Even with an addendum, the Customer must never enter passwords, secrets, authentication codes, or full payment card numbers into the Service.
Conversations are free text and a person may disclose sensitive data without the Customer or Woku soliciting it. The Customer must configure the Agent to discourage such disclosure, minimize collection, and communicate to Woku any special instructions needed.
5. Woku Obligations
Woku shall:
- process the data only under documented instructions and to provide the Services;
- ensure that authorized persons are bound by confidentiality;
- implement the security measures in Annex II;
- reasonably assist with rights, incidents, assessments, and regulatory consultations;
- maintain records required by the Data Protection Legislation;
- allow audits in accordance with section 12;
- return or delete data in accordance with section 10;
- impose substantially equivalent protection obligations on its Subprocessors;
- not sell Customer Personal Data or use it for its own behavioral advertising;
- not use Customer Content to train or fine-tune Woku's models, nor voluntarily authorize model providers to use it to train theirs.
6. Authorized Personnel and Confidentiality
Woku will limit access to personnel and contractors who need the data to provide, secure, or support the Service. Such personnel will be subject to contractual or legal confidentiality obligations and will receive instructions appropriate to their role.
Human administrative access to Customer Content will be limited to authorized support, incident investigation, legal compliance, or maintenance that cannot reasonably be performed otherwise, and is subject to Woku's internal access controls and confidentiality obligations.
7. Security
Woku will maintain technical and organizational measures proportionate to the nature, scope, context, and risk of the processing. Annex II describes the technical and organizational measures Woku maintains.
The Customer acknowledges that no measure eliminates all risk and that it is responsible for configuring Users, roles, domains, integrations, and content securely.
Woku may update the measures to respond to threats or improve the Service, provided that it does not materially reduce the overall level of protection during the term.
8. Subprocessors
8.1 Initial Specific Authorization
By accepting this DPA, the Customer specifically authorizes the Subprocessors named in Annex III for the purposes described there. Woku will not enable a provider to process Customer Personal Data until appropriate data protection conditions are in place.
8.2 Authorization for New Subprocessors
Where the Data Protection Legislation permits a general written authorization, the Customer authorizes the addition or replacement of Subprocessors subject to this procedure. Woku will notify the account contact at least 30 days before the new Subprocessor processes Customer Personal Data. The notice will describe the name, purpose, and relevant location.
Where applicable law requires specific authorization, Woku will obtain an affirmative acceptance, written or electronic, before enabling the new Subprocessor. If a legal or security emergency prevents prior notice, Woku will limit the processing to what is strictly necessary and will inform the Customer as soon as it is legally and reasonably possible.
The Customer may object on reasonable data protection grounds within the following 15 days. The parties will try to agree on a solution, such as disabling the feature or applying additional measures. If there is no reasonable solution, the Customer may terminate the affected part of the Service before the change takes effect and receive, where applicable, a proportional refund of the unused prepaid period for that part.
8.3 Responsibility for Subprocessors
Woku will enter into a written contract with each Subprocessor that imposes substantially equivalent obligations for the delegated processing. Woku will remain responsible to the Customer for the Subprocessor's compliance to the extent required by law and the Main Agreement.
9. Data Subject Rights
Taking into account the nature of the processing, Woku will assist the Customer through appropriate technical and organizational measures to respond to requests for access, correction, erasure, objection, blocking, restriction, portability, or rights relating to automated decisions.
If Woku receives a request related to Customer Personal Data:
- it will forward it to the Customer without responding substantively, unless authorized or legally required;
- it will not identify or disclose data from another workspace;
- it will provide reasonable assistance without undue delay and with enough time for the Customer to meet the applicable legal deadline.
Woku will normally acknowledge and act on a sufficiently detailed request within 10 business days, or sooner where a legal deadline requires.
Extraordinary, repetitive, or technically complex assistance may be subject to reasonable costs disclosed in advance, unless the need arises from Woku's breach.
10. Return, Retention, and Deletion
10.1 During the Service
The Customer can delete content through the available features. For the records that contain Customer Personal Data processed on the Customer's behalf, the following retention applies:
- public conversations: retained while the workspace exists, so the Customer can review what its Visitors asked, and deleted when the workspace is deleted or upon a valid deletion instruction, subject to the following periods;
- AWS application logs that incidentally contain this data: 30 days;
- sampled LangSmith traces containing this data: retained for up to 14 days when the integration is active;
- OpenAI may retain abuse-monitoring logs that include inputs and outputs for up to 30 days under its standard configuration; data sent to the API is not used for training by default;
- leads, knowledge, pages, resources, and vectors: for as long as the workspace exists or until a valid instruction, subject to the following periods.
Account, security, billing, content-free metrics, and business-relationship data that Woku processes as controller are governed by the retention table in the Privacy Policy, not by the instructions in this DPA.
10.2 Termination or Deletion Instruction
Following a valid return or deletion instruction, or upon termination of the Main Agreement when Woku ceases to provide the Service and process the data, Woku will, at the Customer's documented choice, return a copy in a reasonably portable format or delete Customer Personal Data in active systems within 30 days, unless the law requires retaining a limited copy. Woku will only anonymize as a substitute for deletion when the Customer expressly instructs or agrees to it. On request, Woku will provide written confirmation of the completed actions and of any legal exceptions or pending backups. Woku will also instruct its Subprocessors to delete the Customer Personal Data they hold in accordance with their agreements.
Backups will be isolated, will not serve traffic, and will be deleted upon rotation in accordance with the documented period. In S3, the purge must remove access to the active object and create the corresponding delete marker; non-current versions are deleted upon rotation at 30 days according to the documented rotation period. If a backup is restored, Woku must re-apply the deletions that occurred after that backup before returning the system to service.
Cancellation of the subscription, by itself, may downgrade the workspace to the Free plan and does not constitute a deletion instruction.
10.3 Legal Retention
If Woku must retain data for legal reasons, security, fraud, or defense of claims, it will isolate it from ordinary use, limit access, and delete it when the obligation ends.
11. Security Incidents
Woku will notify the Customer without undue delay and, unless legally prevented, no later than within 48 hours of becoming aware of a security breach affecting Customer Personal Data.
The initial notification will include, to the extent known:
- the nature and approximate scope;
- the categories of data and data subjects affected;
- the estimated date or period;
- the likely consequences;
- the measures taken or proposed;
- a contact for coordination.
If the information is not available in the first notice, Woku will provide it in phases without unjustified delay. Woku will cooperate reasonably so that the Customer can assess and meet its notification duties. A notification does not constitute an admission of fault or liability.
The Customer is responsible for notifying authorities and data subjects when it is required to as controller, unless otherwise agreed or legally required.
12. Audits and Compliance Information
Woku will make available information reasonably necessary to demonstrate compliance with this DPA. The process will follow this order:
- questionnaire, documentation, or available evidence;
- a remote meeting with relevant personnel;
- an independent or on-site audit only when the prior evidence is insufficient, an authority requires it, or there is a material incident reasonably connected to Woku.
Except in cases of urgency or an authority's mandate, the Customer will give 30 days' notice, conduct at most one audit per 12 months, use an independent auditor bound by confidentiality, not access other customers' data, and avoid affecting operations. The Customer will bear its own costs, unless the audit reveals a material breach by Woku.
Woku does not claim to hold certifications, audits, or reports that are not current and available.
13. Assessments and Authorities
Woku will provide reasonable assistance with impact assessments, prior consultations, and requests from authorities when the processing through the Service makes it necessary and the Customer provides sufficient information.
Each party will inform the other, when legally possible, of a binding request that affects Customer Personal Data. Woku will review the legality of the request and will limit disclosure to what is required.
14. International Transfers
The Customer authorizes processing in Chile, the United States, and the locations of the Subprocessors in Annex III, subject to valid mechanisms.
14.1 Data Subject to the GDPR
When the GDPR applies and a transfer requires safeguards:
- for a transfer from the Customer as controller to Woku as processor, the parties will incorporate the SCCs of Decision 2021/914, Module 2;
- when the Customer is a processor and Woku a subprocessor, Module 3 will be used;
- Annex I of this DPA will complete the description of the parties and the processing, and Annex II will describe the technical measures;
- the authority and law chosen in the SCCs will be those of a Member State that allows third-party beneficiary rights, as agreed by the parties or the applicable addendum;
- Woku will apply the SCCs or equivalent mechanisms with Subprocessors where applicable.
If there is a conflict between the SCCs and this DPA, the SCCs prevail with respect to the covered transfer.
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs applies. Unless an order states otherwise, the governing law of the SCCs is that of Ireland and the competent supervisory authority is the Irish Data Protection Commission. Woku applies the SCCs or an equivalent recognized mechanism with each Subprocessor in Annex III where a transfer requires it.
14.2 Chile and Other Jurisdictions
Woku will apply the transfer and subcontracting rules of the Chilean Data Protection Legislation from its entry into force, in addition to any mandatory safeguard of the Customer's jurisdiction agreed in writing.
15. Liability
Each party's liability under this DPA is subject to the exclusions and limits of the Main Agreement, except to the extent that the Data Protection Legislation or the SCCs prohibit limiting them. This DPA does not duplicate indemnities for the same event.
16. Term, Changes, and Termination
This DPA remains in force for as long as Woku processes Customer Personal Data. Obligations that by their nature must survive will continue until deletion or anonymization is complete.
We may update the DPA to reflect legal or Service changes. We will notify material changes at least 30 days in advance, except in cases of legal or security urgency. A change of Subprocessor also follows the process in section 8.
We will not materially reduce the protection of Customer Personal Data during a paid period without offering a reasonable solution or right of termination where the law requires it.
17. Precedence and Governing Law
If there is a conflict regarding data processing:
- the SCCs prevail for the transfer they cover;
- then this DPA;
- then the Main Agreement.
Outside the mandatory scope of the SCCs or a mandatory foreign law, this DPA is governed by the law of Chile and the dispute clause of the Main Agreement.
18. Contact
- Privacy, security, and incidents:
[email protected] - Contractual and general inquiries:
[email protected] - Postal mail: Woku SpA, Calle 120 39 Dp 14 B, Hualpén, Chile 4600150
Annex I: Processing Details
A. Parties
Exporter or initial controller/processor
The Customer identified in the account, order, or signature of the Main Agreement.
Importer or processor/subprocessor
Woku SpA, operator of the Wondeya product, with the contact details in section 18.
B. Subject Matter, Nature, and Purpose
| Element | Description |
|---|---|
| Subject matter | Provision of Wondeya's sites, pages, agents, chat, embeddable component, SDK, API, MCP, custom domains, knowledge, leads, and support |
| Duration | Term of the Main Agreement and applicable deletion/retention periods |
| Nature | Collecting, receiving, transmitting, organizing, structuring, storing, querying, extracting, chunking, indexing, vectorizing, retrieving, combining, translating, transcribing, analyzing, generating outputs, displaying, backing up, restricting, and deleting |
| Purpose | Providing the features configured by the Customer, responding to Visitors, publishing content, capturing leads, maintaining security, diagnosing, and carrying out instructions |
| Frequency | Continuous or as determined by the Customer's and its Visitors' use |
C. Categories of Data Subjects
- Users, members, guests, and staff of the Customer only when their data forms part of Customer Content or Woku processes it following the Customer's instructions; account, authentication, security, and business-relationship data processed for Woku's own purposes are governed by the Privacy Policy;
- Visitors to Sites, Pages, and embeddable components;
- the Customer's leads, prospects, and customers;
- individuals identified or mentioned in uploaded documents, messages, files, images, or audio;
- vendors, contacts, and other individuals whose data the Customer is authorized to process.
D. Categories of Data
- identity and contact data included in Customer Content: name, email, phone, company, and job title;
- communications: questions, answers, forms, messages, and thread context;
- technical identifiers: session, conversation, agent, page, approximate country, device, and user agent;
- business content: documents, pages, files, images, audio, video, brands, links, and metadata;
- derived data: chunks, summaries, translations, vector representations, content classification, and usage metrics;
- any data a person enters in free text, which could incidentally and unsolicited include sensitive categories.
E. Sensitive Data
Deliberate processing of sensitive data is not contemplated as a standard purpose. The Customer must not configure it without a written addendum. If such data appears incidentally in free text, Woku will process it under the same instructions and measures, and the Customer may instruct its deletion.
F. Retention
Section 10 and the table in the Privacy Policy describe the periods. When an enterprise order sets a shorter period and the product supports it, that period will prevail.
Annex II: Technical and Organizational Measures
The following are the technical and organizational measures Woku maintains for the processing of Customer Personal Data.
1. Governance and Access
- access on a need-to-know basis and by role within the workspace;
- personnel bound by confidentiality;
- individual accounts and access revocation;
- console sessions that are opaque, revocable, and stored as a hash;
- account authentication through an identity provider; no availability of multi-factor authentication or passkeys is asserted;
- secrets managed outside the repository and rotatable.
2. Isolation and Authorization
- authorization controls at the edge;
- a customer context that denies by default during each request;
- repositories and database controls scoped to the customer;
- per-customer filters in vector search;
- automated cross-access tests for relevant routes;
- private objects and access signed or validated per customer.
3. Encryption and Transmission
- TLS 1.2 or higher on the interfaces controlled by Woku;
- encryption at rest managed by AWS, MongoDB Atlas, and the relevant providers;
- Customer API keys stored as a hash where applicable;
- session-authority cookie set
Secure,HttpOnly, andSameSite=Strict; CSRF cookie deliberately readable by JavaScript, with no authority of its own, alsoSecureandSameSite=Strict.
4. AI and Content Security
- model output limited to JSON validated against a closed catalog;
- the model cannot emit HTML, JavaScript, or arbitrary URLs for rendering;
- resource identifiers and links are resolved server-side;
- Markdown sanitization and text escaping;
- knowledge retrieval filtered per customer;
- the model is not given access to dangerous administrative tools;
- no training or fine-tuning on Customer Content.
5. Availability and Abuse
- layered request limits, cooldown, and session controls;
- Cloudflare Turnstile and allowlists of permitted origins for public surfaces, when active and verified;
- token caps, quotas, per-customer budget, and global circuit breakers;
- degradation that denies by default when a validation or security control fails;
- limits on the size, type, and processing of file uploads.
6. Logging and Monitoring
- customer-scoped audit for the actions the system covers;
- application logs with redaction of secrets and sensitive headers;
- error reporting configured to exclude requests, users, and personal data by default in Sentry, when that integration is active and verified;
- AI traces with sampling capped at 25% in production and partial redaction of common patterns for email, phone, cards, IBAN, and RUT, when LangSmith is active;
- usage/cost metrics separated from message content.
Pattern-based redaction reduces exposure but does not guarantee removal of all personal data present in free text. For this reason, Woku limits sampling, access, and retention.
7. Incidents and Continuity
- incident protocol with defined owners and channels;
- assessment, containment, evidence preservation, and phased communication;
- contractual target to notify the Customer within 48 hours of becoming aware;
- provider-managed backups and versioned objects where configured;
- recovery process aligned with section 10.
8. Deletion
- automatic expiration for temporary telemetry, and deletion of conversations with the workspace or on a valid deletion instruction;
- deletion of related knowledge, chunks, and vector representations;
- customer-scoped purge manifest for local collections and resources;
- removal of active access to S3 objects via a delete marker and rotation of non-current versions at 30 days.
Annex III: Authorized Subprocessors
| Provider / entity | Service and purpose | Potential data | Known relevant location |
|---|---|---|---|
| Amazon Web Services, Inc. | Compute, S3 storage, CloudFront, CloudWatch, SES, caching, and secrets management | Content, files, leads, logs, identifiers, and communications | Primary infrastructure us-east-1; global distribution network |
| MongoDB, Inc. (MongoDB Atlas) | Database, search, and vector representations | Workspace content, conversations, leads, knowledge, vectors, and metadata | AWS us-east-1 |
| OpenAI, L.L.C. | Chat, vector representations, translation, enrichment, drafting, vision, and transcription | Prompts, relevant history, chunks, text, images, and audio sent to each feature | United States, global depending on the service |
| Cloudflare, Inc. | DNS/proxy, edge network, security, Turnstile, and domains | IP, headers, browser signals, host, and technical traffic | Global network |
| LangChain, Inc. (LangSmith) | Sampled traces and diagnostics of the AI flow, only when active | Prompts/outputs with partial redaction, customer, and conversation | United States |
| Functional Software, Inc. (Sentry) | Errors and technical traces; required and active in the production environment | Exceptions, technical tags, and incidental data | United States |
Paddle does not appear on this list because it acts as an independent controller for the checkout page and the buyer's data. Stytch, Woku's own analytics, and the mailbox provider also do not appear by default: they process data for which Woku is the controller for accounts, security, support, or the business relationship. Analytics tools that the Customer configures, such as Google Tag Manager, Microsoft Clarity, Meta Pixel, or PostHog, are considered providers chosen by the Customer unless a specific agreement determines another role. If any of those providers comes to process Customer Personal Data on the Customer's behalf, it must be added to this list before that processing.