This Data Processing Agreement (“DPA”) governs WeMachines' processing of personal data contained in your workspace. It forms part of the Terms of Service and applies automatically to every customer, with no need to sign or request anything. If you need a countersigned copy for your records, email [email protected].
It is written to satisfy Article 28(3) of the EU General Data Protection Regulation and the equivalent provision of the UK GDPR. Where it uses terms such as “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach”, they carry the meaning given in the GDPR.
1. Parties and roles
This DPA is between Decisive Network, Inc., a Delaware corporation with its registered office at 2810 N Church St STE 89498, Wilmington, DE 19802, United States (“WeMachines”, “we”), and the customer that accepted the Terms of Service (“you”, “Customer”).
You are the controller of the personal data your team submits to a workspace: the messages, tasks, documents, discussions, comments, files, and the personal data of your members and of anyone your team writes about. WeMachines is your processor for that data and processes it only to provide the Service.
WeMachines is a separate and independent controller for the data it needs to run its own business, which this DPA does not cover: account and profile records, billing, support correspondence, product analytics and diagnostic logs. Our Privacy Policy describes that processing and the legal bases for it.
You are responsible for having a lawful basis for the personal data your team puts into a workspace and for meeting your own transparency obligations to the people it concerns.
2. Scope of processing
Annex I describes the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects, as Article 28(3) requires.
3. Our instructions
We process workspace content only on your documented instructions, which consist of this DPA, the Terms of Service, the configuration choices your administrators make in the product, and the actions your members take when they use it. Using a feature is an instruction to perform the processing that feature requires, including sending relevant content to the AI providers listed in Annex III when a member uses an AI feature.
We do not use workspace content for our own purposes. Specifically, we do not sell it, we do not use it to train or fine-tune AI models, we do not use it to build features or profiles for other customers, and we do not use it for advertising. We do not use session replay, so no recording of what is on screen in a workspace is ever made.
If we believe an instruction infringes the GDPR or other applicable data protection law, we will tell you rather than act on it. If law requires us to process your data otherwise than on your instructions, we will inform you before doing so unless that law forbids it on important grounds of public interest.
4. Confidentiality
Everyone we authorise to process workspace content is bound by an obligation of confidentiality that survives the end of their engagement, and access is limited to the people who need it to operate, support or secure the Service.
5. Security
We implement appropriate technical and organisational measures to protect workspace content, as required by Article 32. Annex II sets out the measures in force. We may change them as the Service evolves, provided the level of protection is not reduced. Our Security page describes the architecture behind them in more detail.
6. Sub-processors
You give general authorisation for WeMachines to engage sub-processors. The current list, and what each one does, is published and kept up to date at wemachines.com/privacy#subprocessors. It is maintained in one place so it cannot fall out of step with what we actually run.
Each sub-processor is bound by a written contract imposing data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
Before adding or replacing a sub-processor we will give at least 30 days' notice by updating that list and emailing workspace administrators. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees for the unused period, which is your exclusive remedy.
7. International transfers
WeMachines is established in the United States and several of our sub-processors process data outside the European Economic Area. Where workspace content is transferred out of the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, incorporated into this DPA by reference and completed with the information in Annexes I to III. Where the UK GDPR applies, the UK International Data Transfer Addendum applies to those clauses. Where an adequacy decision covers the destination, we rely on it instead.
In the SCCs, you are the data exporter and WeMachines is the data importer; the optional docking clause applies; the governing law and forum are those of Ireland unless your establishment requires another EEA member state; and the time period for Clause 9(a) notice of sub-processor changes is the 30 days stated in clause 6 above.
8. Assisting you with data subject requests
The product is built so most requests need no involvement from us. A workspace administrator can export the workspace's full contents at any time from Settings, and members can correct their own profile and edit or delete their own content directly.
Where a data subject contacts us about workspace content, we will not respond substantively ourselves. We will refer them to you, and tell you promptly, because you are the controller and the response is yours to give. Taking account of the nature of the processing, we will assist you with appropriate technical and organisational measures in meeting your obligations under Chapter III of the GDPR, including access, rectification, erasure, restriction, portability and objection. This assistance is included at no charge for requests in normal volumes.
9. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting workspace content. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact, to the extent that information is available at the time. Where it is not all available at once, we will provide it in phases as it becomes known rather than delay the first notification.
The 48-hour commitment is deliberately shorter than the 72 hours the GDPR gives you to notify your supervisory authority, so that the clock you are held to does not start with an unexplained gap. Notifying your supervisory authority and affected data subjects remains your decision as controller, and we will provide the information you reasonably need to make it.
10. Impact assessments and prior consultation
Taking account of the nature of the processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that relates to your use of the Service.
11. Deletion and return
Throughout the term, and without asking us, a workspace administrator can export the workspace's complete contents from Settings, on every plan, in both machine-readable and human-readable form. We will not place that behind a paywall, a request form, or a notice period, and it is how the return of your data is intended to work.
On termination, or on your written request at any time, we will delete workspace content within 30 days, and instruct our sub-processors to do the same, unless law requires us to keep it. Backups are overwritten on a rolling 30-day cycle, and content awaiting that cycle is not restored to live systems. We will confirm deletion in writing if you ask.
If we discontinue the Service, the Terms commit us to at least 60 days' notice with export available throughout.
12. Audit
We will make available the information necessary to demonstrate compliance with Article 28, which in practice means our published security documentation, completed security questionnaires, and any third-party audit reports or certifications once issued. Our current certification status is stated plainly on the Security page; we hold no certification today and do not describe ourselves as certified before an auditor has issued a report.
Where that is genuinely insufficient for your compliance obligations, you may request an audit no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or the security and privacy of other customers. A supervisory authority exercising its own powers is not limited by this clause.
13. General
This DPA takes effect when you accept the Terms of Service and continues for as long as we process workspace content on your behalf. Clauses that by their nature should survive termination, including deletion, confidentiality and audit, do so.
If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the rest of the Terms of Service, in each case only on the subject of data protection. Everything else in the Terms, including the limitations of liability, applies to this DPA and is not increased by it. If a provision is held invalid, the rest stands.
Data protection questions, countersignature requests, and security questionnaires go to [email protected]. A suspected vulnerability goes to [email protected].
Annex I: description of the processing
| Subject matter | Provision of the WeMachines workspace: team chat, tasks, documents, discussions, huddles, AI features, and the coding agent. |
|---|---|
| Duration | The term of your subscription, plus the deletion window in clause 11. |
| Nature and purpose | Hosting, storage, transmission, display, backup, synchronisation and search of workspace content; generating AI responses, summaries and proposed code changes on request; real-time audio and video; transcription of huddles and voice sessions; email notification; and support. |
| Types of personal data | Identification and contact data (name, email address, profile picture, job title); workspace content submitted by your team, which may contain personal data about anyone your team writes about; audio and video streams and their transcripts; connected-account identifiers for integrations your team enables; and technical data such as IP address and device information. |
| Special categories | None. The Service is not designed for special-category data under Article 9, and protected health information must not be stored in a workspace. |
| Categories of data subjects | Your workspace members and administrators; people invited to a workspace; and any individual your team refers to in workspace content, which may include your own customers, candidates and contacts. |
| Frequency | Continuous, for as long as the workspace is in use. |
Annex II: technical and organisational measures
These are the measures in force under clause 5. They are described in more detail on the Security page.
- Tenant isolation. Separation between workspaces is enforced in Postgres by row-level security rather than in application code, so a defect in the front end cannot reach another team's data. Automated regression tests fail the build if a policy weakens.
- Encryption. TLS for all data in transit. Sensitive credentials, including AI provider API keys and connected-account tokens, are encrypted at rest with AES-GCM under a key held outside the database. Data at rest is encrypted by our infrastructure providers.
- Access control. Passwordless authentication, administrator and member roles enforced at the database, and single-use invitations consumed transactionally. Internal access to production is limited to those who need it.
- Least-privilege credentials for automated processing. The coding agent runs in an isolated container that never receives a shared or long-lived platform secret. Model access is proxied with a short-lived token scoped to a single run, and repository access is scoped to the one repository the workspace has bound.
- Continuous adversarial auditing. The architecture and codebase are audited on a recurring basis using frontier AI models directed at defeating tenant isolation, escalating privilege and extracting credentials. Every confirmed finding is remediated and converted into an automated regression test.
- Supply chain. Secret scanning on every commit, static analysis, dependency review, and hash-pinned build steps.
- Logging and accountability. An append-only audit log, readable by workspace administrators on every plan, records access and configuration changes, every AI and coding-agent run, and data exports. No client of any role can edit or delete an entry.
- Availability and resilience. Managed, replicated infrastructure with automated backups, and a public status page publishing measured uptime.
- Data minimisation in diagnostics. No session replay. Product analytics record which pages and features are used, not screen contents, and request and response bodies and browser console output are excluded from diagnostics.
- Portability. Self-serve full workspace export on every plan, at any time.
Annex III: sub-processors
The current list of sub-processors, and what each one processes, is published at wemachines.com/privacy#subprocessors and forms part of this DPA. Changes are notified as described in clause 6.