Customer data protection

Data-processing terms summary

This page explains the processor terms Wazzl expects to address with workspace customers. It is information, not a signed data processing agreement.

Summary effective 24 August 2026Request an agreement: [email protected]

Not an executed contract. This public summary does not by itself amend the Terms of Service or create negotiated audit, notice, liability, transfer, or deletion commitments. A customer that requires a DPA should request a reviewable agreement and have it signed by authorised parties.

1. Roles and scope

For account, support, security, and service-operation data, Wazzl can act as controller. For contacts, phone numbers, messages, media, notes, assignments, and other content a workspace customer places in Wazzl for its own business purposes, the customer normally acts as controller and Wazzl acts as processor.

The processing is for providing and securing the shared inbox and related workspace functions during the customer’s authorised use, plus the deletion or return period set out in an applicable agreement.

2. Documented instructions

Wazzl processes customer content to deliver, secure, support, and maintain the service, follow settings and actions submitted by authorised workspace users, and comply with applicable law. If Wazzl cannot follow an instruction lawfully or safely, it should inform the customer where legally permitted and pause the affected processing where appropriate.

3. Authorised people and confidentiality

Access to customer content is limited according to operational need and workspace permissions. Personnel or contractors authorised to process customer content should be subject to appropriate confidentiality obligations and security expectations.

4. Security measures

Measures currently include workspace-scoped access checks, defined member roles, password hashing, protected and rotated sessions, production HTTPS, API validation and rate limiting, Meta webhook signature validation, error and availability monitoring, backups, recovery procedures, and restricted infrastructure access. The security page describes current controls and honest limitations.

5. Subprocessors

Wazzl uses providers for hosting, messaging, email, error diagnostics, support, and availability monitoring. The current provider list explains their functions and potential data. Any contractual notice, objection, or replacement process must be stated in a signed DPA; the public list does not create a negotiated notice period.

6. International transfers

Providers can process data in multiple countries. Where applicable law requires a specific transfer mechanism, the signed agreement should identify the parties’ roles, the appropriate mechanism, and any required supplementary measures.

7. Customer assistance

Taking account of the nature of processing and information available, Wazzl expects to provide reasonable assistance with data-subject requests, security incidents, impact assessments, regulator enquiries, and information needed to demonstrate processor obligations. Scope, cost, timing, and legal limits should be addressed in the signed agreement.

8. Incident communication

Wazzl investigates suspected security incidents and provides affected customers with information required by applicable law and a signed agreement. This summary does not state a fixed notification deadline; any contractual deadline must be agreed in the DPA and measured from the defined awareness point.

9. Return and deletion

At the end of authorised processing, customer data should be returned or deleted as agreed, subject to identity and authority checks, customer instructions, backup limitations, and lawful retention. Wazzl’s public deletion workflow targets eligible active-system content within 24 hours only after the required identity and authority verification has completed.

Backup snapshots can retain earlier content until expiry. A restore can reintroduce snapshot content, so verified deletion handling must be reapplied before or while restored data returns to active use. The current system does not promise an automatic re-purge. A signed DPA should identify any customer-specific return format, deletion evidence, and retention schedule.

10. Information and review

Wazzl can provide reasonable information needed for a customer’s processor review, subject to security, confidentiality, availability, and proportionality. Any audit right, frequency, method, third-party report, cost allocation, or onsite access requires a signed agreement and must avoid exposing another customer’s data or weakening security.

11. Request a signed DPA

Need contractual processor terms?
Include the customer organisation, expected use, and applicable data-protection regime. Do not attach production data.

Request DPA review