legal ▸ dpa LEGAL

Data Processing Addendum

How Writ processes personal data on your behalf under GDPR: roles, subprocessors, and safeguards.

Effective June 22, 2026 · Version 2.0

Template, not legal advice. This Data Processing Addendum is a generated template and must be reviewed by qualified counsel before you rely on it. For a countersigned DPA, contact legal@usewrit.app.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer", the data controller) and Benjamin Garcia, carrying on business as “Logiciels Writ”, NEQ 2282397514 ("Writ", "we", "us", the data processor) and applies where we process personal data on your behalf in connection with the Service. Where applicable data protection law (including the EU GDPR and UK GDPR) governs the processing, this DPA sets out the parties' obligations under, among others, Article 28.

1. Scope and roles

You are the controller and Writ is the processor of personal data processed to provide the Service. Writ is the API and MCP layer for sites that have no API; it records, stores, executes, and monitors the workflows and Monitors you create, and manages your account and prepaid balance billing.

2. Subject matter and duration

We process personal data only to provide the Service, for the duration of your account and as instructed by you. Processing ends when your account is deleted, subject to the retention windows in our Privacy Policy.

3. Nature and purpose of processing

The nature of processing is the operation of an automation and monitoring platform: recording, storing, and executing workflows; running Monitors and automations; managing accounts and authentication; metering usage; and processing prepaid-wallet billing. The purpose is limited to delivering the Service and complying with law.

4. Categories of data and data subjects

Personal data may include account information (name, email, organization), technical data (IP addresses, user agents, timestamps), billing metadata, and any personal data contained within the workflows, inputs, credentials, or results you choose to process through the Service. Data subjects are your authorized users and any individuals whose data you process through the Service.

5. Customer instructions

We process personal data only on your documented instructions, including with regard to transfers, unless required by law. If we believe an instruction violates applicable data protection law, we will inform you.

6. Confidentiality

We ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations.

7. Security measures

We implement appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, tenant isolation, access controls, hashed credentials (Argon2), an encrypted credential vault for secrets and personas, and signed, expiring tokens with refresh rotation. See the "Data security" section of the Privacy Policy for detail.

8. Sub-processors

You authorize us to engage the sub-processors below to process personal data on your behalf. We impose data protection obligations on each that are no less protective than those in this DPA, and we remain responsible for their performance. We will give reasonable notice of any new sub-processor.

Sub-processorPurposeLocation
StripePayment processing for subscriptions and prepaid-wallet top-ups.United States / EU
DigitalOceanCloud hosting, compute, and the managed run fleet; object storage where DigitalOcean Spaces is used.United States / EU
AnthropicManaged AI model inference for AI sessions, navigation, and assistive features.United States
OpenAIManaged AI model inference for AI sessions, streaming, and assistive features.United States
Google (Gemini)Managed AI model inference and grounded web-search for AI features.United States
Email delivery (SMTP)Transactional email and email notifications - verification, alerts, and billing.United States / EU
SentryBackend error and diagnostic reporting.EU / United States
CloudflareEdge / CDN in front of the API, Turnstile bot-defense captcha, and the edge-resolved country header for the sanctions/embargo gate.Global edge
hCaptchaAlternative bot-defense captcha (a drop-in replacement for Turnstile).United States / EU
TwilioSMS notification delivery (and WhatsApp where configured) for alerts you set up.United States / EU
S3-compatible object storeStorage of tenant file assets, run artifacts, and backups.Provider / region-dependent
PostHogPrivacy-first product analytics for the marketing site and app, consent-gated.EU (self-hostable)

9. International transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on an appropriate transfer mechanism such as the Standard Contractual Clauses or an adequacy decision.

10. Assistance to the Customer

Taking into account the nature of processing, we provide reasonable assistance with your obligations to respond to data subject requests and to ensure security, data protection impact assessments, and consultation with supervisory authorities.

11. Data subject requests

If we receive a request from a data subject regarding data we process on your behalf, we will, where legally permitted, direct the request to you rather than respond directly. Self-serve access, export, and deletion tools are available in your account.

12. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data and provide the information reasonably necessary for you to meet your notification obligations.

13. Deletion and return

Upon termination of the Service, we delete personal data in accordance with the retention windows in our Privacy Policy, except where retention is required by law (for example, billing and wallet records).

14. Audits

We make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits in line with applicable law, subject to reasonable confidentiality and security constraints.

15. Contact

For DPA or data protection questions, contact privacy@usewrit.app. See all policies in the legal index.