Data Processing Addendum
How Writ processes personal data on your behalf under GDPR: roles, subprocessors, and safeguards.
Effective June 22, 2026 · Version 2.0
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer", the data controller) and Benjamin Garcia, carrying on business as “Logiciels Writ”, NEQ 2282397514 ("Writ", "we", "us", the data processor) and applies where we process personal data on your behalf in connection with the Service. Where applicable data protection law (including the EU GDPR and UK GDPR) governs the processing, this DPA sets out the parties' obligations under, among others, Article 28.
1. Scope and roles
You are the controller and Writ is the processor of personal data processed to provide the Service. Writ is the API and MCP layer for sites that have no API; it records, stores, executes, and monitors the workflows and Monitors you create, and manages your account and prepaid balance billing.
2. Subject matter and duration
We process personal data only to provide the Service, for the duration of your account and as instructed by you. Processing ends when your account is deleted, subject to the retention windows in our Privacy Policy.
3. Nature and purpose of processing
The nature of processing is the operation of an automation and monitoring platform: recording, storing, and executing workflows; running Monitors and automations; managing accounts and authentication; metering usage; and processing prepaid-wallet billing. The purpose is limited to delivering the Service and complying with law.
4. Categories of data and data subjects
Personal data may include account information (name, email, organization), technical data (IP addresses, user agents, timestamps), billing metadata, and any personal data contained within the workflows, inputs, credentials, or results you choose to process through the Service. Data subjects are your authorized users and any individuals whose data you process through the Service.
5. Customer instructions
We process personal data only on your documented instructions, including with regard to transfers, unless required by law. If we believe an instruction violates applicable data protection law, we will inform you.
6. Confidentiality
We ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations.
7. Security measures
We implement appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, tenant isolation, access controls, hashed credentials (Argon2), an encrypted credential vault for secrets and personas, and signed, expiring tokens with refresh rotation. See the "Data security" section of the Privacy Policy for detail.
8. Sub-processors
You authorize us to engage the sub-processors below to process personal data on your behalf. We impose data protection obligations on each that are no less protective than those in this DPA, and we remain responsible for their performance. We will give reasonable notice of any new sub-processor.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing for subscriptions and prepaid-wallet top-ups. | United States / EU |
| DigitalOcean | Cloud hosting, compute, and the managed run fleet; object storage where DigitalOcean Spaces is used. | United States / EU |
| Anthropic | Managed AI model inference for AI sessions, navigation, and assistive features. | United States |
| OpenAI | Managed AI model inference for AI sessions, streaming, and assistive features. | United States |
| Google (Gemini) | Managed AI model inference and grounded web-search for AI features. | United States |
| Email delivery (SMTP) | Transactional email and email notifications - verification, alerts, and billing. | United States / EU |
| Sentry | Backend error and diagnostic reporting. | EU / United States |
| Cloudflare | Edge / CDN in front of the API, Turnstile bot-defense captcha, and the edge-resolved country header for the sanctions/embargo gate. | Global edge |
| hCaptcha | Alternative bot-defense captcha (a drop-in replacement for Turnstile). | United States / EU |
| Twilio | SMS notification delivery (and WhatsApp where configured) for alerts you set up. | United States / EU |
| S3-compatible object store | Storage of tenant file assets, run artifacts, and backups. | Provider / region-dependent |
| PostHog | Privacy-first product analytics for the marketing site and app, consent-gated. | EU (self-hostable) |
9. International transfers
Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on an appropriate transfer mechanism such as the Standard Contractual Clauses or an adequacy decision.
10. Assistance to the Customer
Taking into account the nature of processing, we provide reasonable assistance with your obligations to respond to data subject requests and to ensure security, data protection impact assessments, and consultation with supervisory authorities.
11. Data subject requests
If we receive a request from a data subject regarding data we process on your behalf, we will, where legally permitted, direct the request to you rather than respond directly. Self-serve access, export, and deletion tools are available in your account.
12. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data and provide the information reasonably necessary for you to meet your notification obligations.
13. Deletion and return
Upon termination of the Service, we delete personal data in accordance with the retention windows in our Privacy Policy, except where retention is required by law (for example, billing and wallet records).
14. Audits
We make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits in line with applicable law, subject to reasonable confidentiality and security constraints.
15. Contact
For DPA or data protection questions, contact [email protected]. See all policies in the legal index.