Legal

Data Processing Addendum

Our processor commitments for customer data — CCPA/CPRA and GDPR-ready, with SCCs, security measures, and subprocessors.

Last updated: July 14, 2026 (July 14, 2026)

This Data Processing Addendum ("DPA") forms part of, and is subject to, the Terms of Service between Willder, operated by Tri Nguyen (pending incorporation as Willder, Inc.) ("Willder", "Processor") and the customer organization agreeing to the Terms ("Customer", "Controller") (together, the "Agreement"). It governs Willder's processing of Personal Data on Customer's behalf in providing the Service.

This DPA is designed to satisfy the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss FADP, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA). If any provision conflicts with the Agreement, this DPA controls for the subject matter of data protection.

Signature. Because the Service is in beta and typically self-served, this DPA takes effect automatically as part of the Agreement when Customer uses the Service. Customer may also request a countersigned copy at legal@willder.ai.

1. Definitions

  • "Personal Data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings in the GDPR. "Business", "service provider", "sell", "share", and "consumer" have the meanings in the CCPA/CPRA.
  • "Customer Personal Data" means Personal Data within Customer Content that Willder processes on Customer's behalf under the Agreement.
  • "Data Protection Laws" means all privacy and data protection laws applicable to a party's processing under the Agreement, including the GDPR, UK GDPR, Swiss FADP, and CCPA/CPRA.
  • "Subprocessor" means a third party engaged by Willder to process Customer Personal Data.
  • "SCCs" means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914.

2. Roles and scope

  • Customer is the controller (or a processor acting for another controller) of Customer Personal Data; Willder is the processor. Under the CCPA/CPRA, Customer is the business and Willder is a service provider.
  • Willder will process Customer Personal Data only to provide, secure, and support the Service under the Agreement, on Customer's documented instructions (including through the Service's configuration), and as this DPA permits. The Agreement, this DPA, and Customer's use of the Service constitute Customer's complete and final instructions.
  • Willder will notify Customer if, in its opinion, an instruction violates Data Protection Laws (without obligation to give legal advice), and may decline instructions that would do so.
  • Details of processing — the subject matter, duration, nature and purpose, types of Personal Data, and categories of data subjects are described in Annex I.

3. Confidentiality and personnel

Willder will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and process it only as needed to perform under the Agreement.

4. Service-provider / processor commitments

Willder will not:

  • sell or share Customer Personal Data (as "sell" and "share" are defined under CCPA/CPRA);
  • retain, use, or disclose Customer Personal Data for any purpose other than providing the Service under the Agreement, or outside the direct business relationship, except as permitted by Data Protection Laws;
  • combine Customer Personal Data with data from other sources except as permitted by the CCPA/CPRA (e.g. to provide the Service); or
  • use Customer Personal Data to train generalized AI/ML models.

Willder certifies that it understands and will comply with these restrictions. Customer may take reasonable steps to remediate unauthorized use.

5. Security

Willder will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the risk. These measures are described in Annex II and may be updated so long as security is not materially reduced.

6. Subprocessors

  • Customer provides general authorization for Willder to engage Subprocessors to process Customer Personal Data. The current Subprocessors are listed in Annex III and maintained at willder.ai/subprocessors.
  • Willder will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for its Subprocessors' performance.
  • Willder will give Customer notice before adding or replacing a Subprocessor (by updating the list at willder.ai/subprocessors and/or by email, where Customer subscribes to notifications). Customer may object on reasonable data-protection grounds within 14 days; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected part of the Service.

7. Data subject requests

Taking into account the nature of the processing, Willder will assist Customer with appropriate technical and organizational measures, insofar as possible, to respond to data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). Much of this is self-service: Customer can access, correct, export, and delete Customer Personal Data directly in the Service. If Willder receives a request directly from a data subject, it will not respond except to direct them to Customer, unless legally required.

8. Personal data breach

Willder will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations. Notice of a breach is not an acknowledgment of fault or liability.

9. Data protection impact assessments

Taking into account the nature of processing and information available to Willder, Willder will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities.

10. Deletion and return

On termination or expiry of the Agreement, Willder will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, except to the extent retention is required by law. Customer can also delete Customer Personal Data during the term using the Service. Residual copies in routine backups are deleted on a rolling basis and remain protected by this DPA until deleted.

11. Audits

Willder will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates. To limit disruption, Willder may satisfy audit requests by providing existing reports, certifications, or a completed security questionnaire; on-site audits are limited to once per year (absent a breach or regulator requirement), on reasonable notice, during business hours, subject to confidentiality.

12. International transfers

Where Willder processes Customer Personal Data originating from the EEA, UK, or Switzerland in a country without an adequacy decision:

  • the EU SCCs are incorporated by reference and apply, with Willder as "data importer" and Customer as "data exporter." Module Two (controller-to-processor) applies (or Module Three, controller-to-processor-to-processor, where Customer is itself a processor). Docking clause: optional. Clause 9: Option 2 (general authorization), with the notice period in Section 6. Clause 11 optional redress: not selected. Clause 17 governing law and Clause 18 forum: the EU Member State identified in Annex I, or Ireland if none is specified. Annexes I–III of this DPA populate the SCC Annexes.
  • for UK transfers, the UK International Data Transfer Addendum to the SCCs applies, and the SCCs are read as amended by it;
  • for Swiss transfers, the SCCs apply with references to the GDPR read as the FADP and to the Swiss FDPIC as supervisory authority.

If the SCCs are invalidated or superseded, the parties will work in good faith to adopt a valid transfer mechanism.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.

14. Term

This DPA takes effect when the Agreement does and remains in effect until Willder has ceased all processing of Customer Personal Data.

Annex I — Details of processing

Data exporter / ControllerCustomer (the organization using the Service)
Data importer / ProcessorWillder, operated by Tri Nguyen (pending incorporation as Willder, Inc.)
Subject matterProvision of the Willder governed-memory and access-control Service
DurationFor the term of the Agreement, plus deletion period per Section 10
Nature and purposeHosting, storage, retrieval, and processing of Customer Content in a memory graph; access control, audit logging, and AI-agent features; optional mailbox sending/receiving and enrichment
FrequencyContinuous, as directed by Customer's use of the Service
Categories of data subjectsCustomer's members and users; Customer's contacts, prospects, customers, and collaborators; individuals referenced in Customer Content, uploaded files, or connected mailboxes
Categories of Personal DataNames, business contact details (email, title, company), professional/organizational information, memory facts and context authored by or about individuals, email content and metadata (if a mailbox is connected), usage and audit metadata
Special categoriesNot intended or required by the Service; Customer should not submit special-category data unless it has a lawful basis. Any such data is subject to the safeguards in Annex II.
Competent supervisory authority (SCC Clause 13)Determined by Customer's EEA place of establishment; if none, Ireland

Annex II — Technical and organizational security measures

  • Access control: default-deny authorization enforced at a single check() checkpoint in front of every memory read/write; role-, scope-, and grant-based permissions modeled on an ltree scope tree; time-bounded and revocable access grants.
  • Agent/machine access: non-human actors authenticate with scoped, expiring capability tokens; only token hashes are stored at rest; every agent action is subject to the same authorization checks.
  • Tenant isolation: all data keyed by organization; memory partitioned per scope; cross-tenant access structurally prevented.
  • Auditing: append-only audit log of access decisions and memory read/write/delete events (actor, scope, allow/deny), for security and accountability.
  • Encryption: TLS/HTTPS for data in transit; encryption of sensitive stored credentials (e.g. mailbox OAuth tokens) using authenticated encryption; storage on managed providers with encryption at rest.
  • Input handling: input sanitization and prompt-injection defenses on memory ingest and chat.
  • Secrets and keys: provider and application secrets stored in environment configuration, not in code or Customer-accessible surfaces.
  • AI providers: LLM inference performed under contracts prohibiting model training on Customer Personal Data and providing no/limited retention.
  • Operational: least-privilege access to production systems; logging and monitoring; rate limiting; security headers (HSTS, CSP, and related).

Measures may evolve as the Service matures; Willder will not materially reduce overall security during the term.

Annex III — Subprocessors (snapshot as of July 14, 2026)

The authoritative, current list is maintained at willder.ai/subprocessors.

SubprocessorPurposeData processedLocation
ClerkAuthentication and identity / organization managementAccount identifiers, names, emailsUnited States
NeonManaged Postgres — application data and access-control treeCustomer Content (app data), account and audit dataUnited States
Neo4j (self-hosted on Railway)Memory graph storageCustomer Content (memory facts and episodes)United States
VercelApplication hosting and serverless computeAll data processed by the Service (in transit / in memory)United States
OpenAI and/or Microsoft Azure OpenAILLM inference for memory extraction and agent featuresContent sent for inference (no training; no/limited retention)United States
InngestBackground job orchestrationJob payloads that may include Customer ContentUnited States
LangfuseLLM observability / tracingPrompts and outputs that may include Customer ContentUnited States / EU
Google (Gmail API) — only if mailbox connectedSending/receiving email on Customer's behalfEmail content and metadataUnited States
Microsoft (Microsoft Graph) — only if mailbox connectedSending/receiving email on Customer's behalfEmail content and metadataUnited States
Exa, Firecrawl, Apollo — only if enrichment usedWeb/company/firmographic enrichment for agentsSearch queries and returned business dataUnited States
Stripe — if/when billing is enabledPayment and billing processingBilling contact and payment metadataUnited States

Contact for this DPA: legal@willder.ai