Draft for legal review. Nothing here is final until this notice is gone; items in [brackets] are still to be decided.
Data processing addendum.
For organisations that pay for Wonder for their people and need a data processing agreement under [UK GDPR and the EU GDPR]. It forms part of the terms between [legal entity name] (“Wonder”, the processor) and the organisation (the controller) once both have signed it. [Signature process: email [privacy contact email] for a countersigned copy.]
1. What’s processed
- Subject matter and duration: providing Wonder to the controller’s users, for as long as the subscription lasts.
- Nature and purpose: storing and syncing users’ end-to-end encrypted journals; account and billing administration; the AI features users switch on.
- Personal data: account details (name, email, sign-in records); the journal, which Wonder holds only as ciphertext it cannot read; the material users choose to send to AI features, processed transiently.
- Data subjects: the controller’s users, and people named in what they write or in calendars and meeting notes they connect.
2. Wonder’s commitments
- Process personal data only on the controller’s documented instructions (these terms, and how users configure Wonder), unless the law requires otherwise, in which case we’ll say so first if we may.
- Everyone with access is bound to confidentiality.
- Keep the technical and organisational measures in Security and What we can read, above all end-to-end encryption of the journal.
- Use only the subprocessors listed, under written terms at least as protective as these, with [30] days’ notice of any change and a right to object.
- Help the controller answer data subjects’ requests. Users can export and delete their own data at any time.
- Tell the controller without undue delay, and within [48] hours, of a personal data breach affecting their users, with what we know.
- Help with data protection impact assessments and consultations with supervisory authorities, as far as our processing goes.
- At the end of the service, delete the controller’s users’ data (users can export first), except where the law requires us to keep it. Backups age out within [backup retention period].
- Make available what’s needed to show compliance, and allow audits [once a year, on 30 days’ notice, or by a recognised third-party report].
3. International transfers
Where personal data leaves [the UK / the EEA], transfers rely on [adequacy decisions / the standard contractual clauses and the UK addendum], incorporated by reference.
4. Liability and precedence
[Liability as in the terms. Where this addendum and the terms conflict on data protection, this addendum wins.]
Last updated [date of publication].