Wondeya Data Processing Agreement

Last updated: August 30, 2026 · Version: 1.0

This Data Processing Agreement (the "DPA") forms part of the Wondeya Terms of Service or of another written agreement that incorporates this DPA (the "Main Agreement") between the Customer and Woku SpA, a company incorporated in Chile, domiciled at Calle 120 39 Dp 14 B, Hualpén, Chile 4600150 ("Woku"). Wondeya is a product of Woku operated by Woku SpA.

The DPA takes effect when the Customer accepts the Main Agreement or when both parties sign it, and it applies when Woku processes Customer Personal Data on the Customer's behalf in providing Wondeya.

1. Definitions

The terms "personal data", "processing", "controller", "processor", "subprocessor", "data subject" and "personal data breach" shall have the meaning given in the applicable Data Protection Legislation.

For this DPA:

2. Roles and Scope

The Customer acts as controller and Woku as processor with respect to Customer Personal Data. If the Customer acts as a processor for a third party, the Customer is the processor and Woku is the subprocessor; the Customer represents that it has authority to give instructions and to incorporate this DPA.

Woku acts as an independent controller with respect to data necessary to:

The Privacy Policy governs those own activities. Paddle is the merchant of record and an independent controller for the checkout page, taxes, fraud prevention, and billing; by virtue of that function it is not a Subprocessor of the conversations or of other Customer Content.

3. Documented Instructions

Woku will process Customer Personal Data only:

  1. to provide, protect, and maintain the Services in accordance with the Main Agreement, this DPA, and the Customer's configuration;
  2. according to other documented and lawful instructions agreed by the parties;
  3. when an applicable law requires it, in which case Woku will inform the Customer before the processing, unless legally prohibited.

The Main Agreement, the use and configuration of the Service, authorized support requests, and the Customer's written instructions constitute documented instructions.

Woku will inform the Customer if, in its reasonable opinion, an instruction infringes the Data Protection Legislation. It may suspend the affected instruction while the parties review it, without being obligated to provide legal advice to the Customer.

4. Customer Obligations

The Customer warrants that it:

The Customer must not use Wondeya to deliberately solicit or process health, biometric, or genetic data, trade union membership, political opinions, beliefs, sex life or sexual orientation, criminal records, government identifiers, data of minors, or other sensitive categories, unless there is a specific written addendum with Woku, a valid legal basis, and appropriate controls. Even with an addendum, the Customer must never enter passwords, secrets, authentication codes, or full payment card numbers into the Service.

Conversations are free text and a person may disclose sensitive data without the Customer or Woku soliciting it. The Customer must configure the Agent to discourage such disclosure, minimize collection, and communicate to Woku any special instructions needed.

5. Woku Obligations

Woku shall:

6. Authorized Personnel and Confidentiality

Woku will limit access to personnel and contractors who need the data to provide, secure, or support the Service. Such personnel will be subject to contractual or legal confidentiality obligations and will receive instructions appropriate to their role.

Human administrative access to Customer Content will be limited to authorized support, incident investigation, legal compliance, or maintenance that cannot reasonably be performed otherwise, and is subject to Woku's internal access controls and confidentiality obligations.

7. Security

Woku will maintain technical and organizational measures proportionate to the nature, scope, context, and risk of the processing. Annex II describes the technical and organizational measures Woku maintains.

The Customer acknowledges that no measure eliminates all risk and that it is responsible for configuring Users, roles, domains, integrations, and content securely.

Woku may update the measures to respond to threats or improve the Service, provided that it does not materially reduce the overall level of protection during the term.

8. Subprocessors

8.1 Initial Specific Authorization

By accepting this DPA, the Customer specifically authorizes the Subprocessors named in Annex III for the purposes described there. Woku will not enable a provider to process Customer Personal Data until appropriate data protection conditions are in place.

8.2 Authorization for New Subprocessors

Where the Data Protection Legislation permits a general written authorization, the Customer authorizes the addition or replacement of Subprocessors subject to this procedure. Woku will notify the account contact at least 30 days before the new Subprocessor processes Customer Personal Data. The notice will describe the name, purpose, and relevant location.

Where applicable law requires specific authorization, Woku will obtain an affirmative acceptance, written or electronic, before enabling the new Subprocessor. If a legal or security emergency prevents prior notice, Woku will limit the processing to what is strictly necessary and will inform the Customer as soon as it is legally and reasonably possible.

The Customer may object on reasonable data protection grounds within the following 15 days. The parties will try to agree on a solution, such as disabling the feature or applying additional measures. If there is no reasonable solution, the Customer may terminate the affected part of the Service before the change takes effect and receive, where applicable, a proportional refund of the unused prepaid period for that part.

8.3 Responsibility for Subprocessors

Woku will enter into a written contract with each Subprocessor that imposes substantially equivalent obligations for the delegated processing. Woku will remain responsible to the Customer for the Subprocessor's compliance to the extent required by law and the Main Agreement.

9. Data Subject Rights

Taking into account the nature of the processing, Woku will assist the Customer through appropriate technical and organizational measures to respond to requests for access, correction, erasure, objection, blocking, restriction, portability, or rights relating to automated decisions.

If Woku receives a request related to Customer Personal Data:

Woku will normally acknowledge and act on a sufficiently detailed request within 10 business days, or sooner where a legal deadline requires.

Extraordinary, repetitive, or technically complex assistance may be subject to reasonable costs disclosed in advance, unless the need arises from Woku's breach.

10. Return, Retention, and Deletion

10.1 During the Service

The Customer can delete content through the available features. For the records that contain Customer Personal Data processed on the Customer's behalf, the following retention applies:

Account, security, billing, content-free metrics, and business-relationship data that Woku processes as controller are governed by the retention table in the Privacy Policy, not by the instructions in this DPA.

10.2 Termination or Deletion Instruction

Following a valid return or deletion instruction, or upon termination of the Main Agreement when Woku ceases to provide the Service and process the data, Woku will, at the Customer's documented choice, return a copy in a reasonably portable format or delete Customer Personal Data in active systems within 30 days, unless the law requires retaining a limited copy. Woku will only anonymize as a substitute for deletion when the Customer expressly instructs or agrees to it. On request, Woku will provide written confirmation of the completed actions and of any legal exceptions or pending backups. Woku will also instruct its Subprocessors to delete the Customer Personal Data they hold in accordance with their agreements.

Backups will be isolated, will not serve traffic, and will be deleted upon rotation in accordance with the documented period. In S3, the purge must remove access to the active object and create the corresponding delete marker; non-current versions are deleted upon rotation at 30 days according to the documented rotation period. If a backup is restored, Woku must re-apply the deletions that occurred after that backup before returning the system to service.

Cancellation of the subscription, by itself, may downgrade the workspace to the Free plan and does not constitute a deletion instruction.

10.3 Legal Retention

If Woku must retain data for legal reasons, security, fraud, or defense of claims, it will isolate it from ordinary use, limit access, and delete it when the obligation ends.

11. Security Incidents

Woku will notify the Customer without undue delay and, unless legally prevented, no later than within 48 hours of becoming aware of a security breach affecting Customer Personal Data.

The initial notification will include, to the extent known:

If the information is not available in the first notice, Woku will provide it in phases without unjustified delay. Woku will cooperate reasonably so that the Customer can assess and meet its notification duties. A notification does not constitute an admission of fault or liability.

The Customer is responsible for notifying authorities and data subjects when it is required to as controller, unless otherwise agreed or legally required.

12. Audits and Compliance Information

Woku will make available information reasonably necessary to demonstrate compliance with this DPA. The process will follow this order:

  1. questionnaire, documentation, or available evidence;
  2. a remote meeting with relevant personnel;
  3. an independent or on-site audit only when the prior evidence is insufficient, an authority requires it, or there is a material incident reasonably connected to Woku.

Except in cases of urgency or an authority's mandate, the Customer will give 30 days' notice, conduct at most one audit per 12 months, use an independent auditor bound by confidentiality, not access other customers' data, and avoid affecting operations. The Customer will bear its own costs, unless the audit reveals a material breach by Woku.

Woku does not claim to hold certifications, audits, or reports that are not current and available.

13. Assessments and Authorities

Woku will provide reasonable assistance with impact assessments, prior consultations, and requests from authorities when the processing through the Service makes it necessary and the Customer provides sufficient information.

Each party will inform the other, when legally possible, of a binding request that affects Customer Personal Data. Woku will review the legality of the request and will limit disclosure to what is required.

14. International Transfers

The Customer authorizes processing in Chile, the United States, and the locations of the Subprocessors in Annex III, subject to valid mechanisms.

14.1 Data Subject to the GDPR

When the GDPR applies and a transfer requires safeguards:

If there is a conflict between the SCCs and this DPA, the SCCs prevail with respect to the covered transfer.

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs applies. Unless an order states otherwise, the governing law of the SCCs is that of Ireland and the competent supervisory authority is the Irish Data Protection Commission. Woku applies the SCCs or an equivalent recognized mechanism with each Subprocessor in Annex III where a transfer requires it.

14.2 Chile and Other Jurisdictions

Woku will apply the transfer and subcontracting rules of the Chilean Data Protection Legislation from its entry into force, in addition to any mandatory safeguard of the Customer's jurisdiction agreed in writing.

15. Liability

Each party's liability under this DPA is subject to the exclusions and limits of the Main Agreement, except to the extent that the Data Protection Legislation or the SCCs prohibit limiting them. This DPA does not duplicate indemnities for the same event.

16. Term, Changes, and Termination

This DPA remains in force for as long as Woku processes Customer Personal Data. Obligations that by their nature must survive will continue until deletion or anonymization is complete.

We may update the DPA to reflect legal or Service changes. We will notify material changes at least 30 days in advance, except in cases of legal or security urgency. A change of Subprocessor also follows the process in section 8.

We will not materially reduce the protection of Customer Personal Data during a paid period without offering a reasonable solution or right of termination where the law requires it.

17. Precedence and Governing Law

If there is a conflict regarding data processing:

  1. the SCCs prevail for the transfer they cover;
  2. then this DPA;
  3. then the Main Agreement.

Outside the mandatory scope of the SCCs or a mandatory foreign law, this DPA is governed by the law of Chile and the dispute clause of the Main Agreement.

18. Contact

Annex I: Processing Details

A. Parties

Exporter or initial controller/processor

The Customer identified in the account, order, or signature of the Main Agreement.

Importer or processor/subprocessor

Woku SpA, operator of the Wondeya product, with the contact details in section 18.

B. Subject Matter, Nature, and Purpose

ElementDescription
Subject matterProvision of Wondeya's sites, pages, agents, chat, embeddable component, SDK, API, MCP, custom domains, knowledge, leads, and support
DurationTerm of the Main Agreement and applicable deletion/retention periods
NatureCollecting, receiving, transmitting, organizing, structuring, storing, querying, extracting, chunking, indexing, vectorizing, retrieving, combining, translating, transcribing, analyzing, generating outputs, displaying, backing up, restricting, and deleting
PurposeProviding the features configured by the Customer, responding to Visitors, publishing content, capturing leads, maintaining security, diagnosing, and carrying out instructions
FrequencyContinuous or as determined by the Customer's and its Visitors' use

C. Categories of Data Subjects

D. Categories of Data

E. Sensitive Data

Deliberate processing of sensitive data is not contemplated as a standard purpose. The Customer must not configure it without a written addendum. If such data appears incidentally in free text, Woku will process it under the same instructions and measures, and the Customer may instruct its deletion.

F. Retention

Section 10 and the table in the Privacy Policy describe the periods. When an enterprise order sets a shorter period and the product supports it, that period will prevail.

Annex II: Technical and Organizational Measures

The following are the technical and organizational measures Woku maintains for the processing of Customer Personal Data.

1. Governance and Access

2. Isolation and Authorization

3. Encryption and Transmission

4. AI and Content Security

5. Availability and Abuse

6. Logging and Monitoring

Pattern-based redaction reduces exposure but does not guarantee removal of all personal data present in free text. For this reason, Woku limits sampling, access, and retention.

7. Incidents and Continuity

8. Deletion

Annex III: Authorized Subprocessors

Provider / entityService and purposePotential dataKnown relevant location
Amazon Web Services, Inc.Compute, S3 storage, CloudFront, CloudWatch, SES, caching, and secrets managementContent, files, leads, logs, identifiers, and communicationsPrimary infrastructure us-east-1; global distribution network
MongoDB, Inc. (MongoDB Atlas)Database, search, and vector representationsWorkspace content, conversations, leads, knowledge, vectors, and metadataAWS us-east-1
OpenAI, L.L.C.Chat, vector representations, translation, enrichment, drafting, vision, and transcriptionPrompts, relevant history, chunks, text, images, and audio sent to each featureUnited States, global depending on the service
Cloudflare, Inc.DNS/proxy, edge network, security, Turnstile, and domainsIP, headers, browser signals, host, and technical trafficGlobal network
LangChain, Inc. (LangSmith)Sampled traces and diagnostics of the AI flow, only when activePrompts/outputs with partial redaction, customer, and conversationUnited States
Functional Software, Inc. (Sentry)Errors and technical traces; required and active in the production environmentExceptions, technical tags, and incidental dataUnited States

Paddle does not appear on this list because it acts as an independent controller for the checkout page and the buyer's data. Stytch, Woku's own analytics, and the mailbox provider also do not appear by default: they process data for which Woku is the controller for accounts, security, support, or the business relationship. Analytics tools that the Customer configures, such as Google Tag Manager, Microsoft Clarity, Meta Pixel, or PostHog, are considered providers chosen by the Customer unless a specific agreement determines another role. If any of those providers comes to process Customer Personal Data on the Customer's behalf, it must be added to this list before that processing.