Wumpix Data Processing Addendum
Effective date: 14 July 2026 Brand: Wumpix Platform: Vividor Website: https://wumpix.com Canonical URL: https://wumpix.com/legal/dpa
This Data Processing Addendum, including its Annexes (the “DPA”), forms part of the Wumpix Terms of Service available at https://wumpix.com/legal/terms (the “Agreement”) between Customer and Wumpix.
For purposes of this DPA, “Wumpix” means the commercial brand and the operator of the Wumpix Services at https://wumpix.com, including the Vividor platform. A separate registered legal entity for these Services has not been formed yet. Legal notices are valid when sent to legal@wumpix.com (privacy requests: privacy@wumpix.com). When a legal entity is later incorporated (jurisdiction to be determined), these documents will be updated with the entity’s legal name, registration details, and registered address. These documents do not represent that Wumpix is currently an LLC, limited company, or other registered corporate entity.
This DPA applies when Wumpix processes Personal Data on behalf of Customer in the course of providing the Wumpix / Vividor Services.
If there is any conflict between this DPA and the other parts of the Agreement with respect to the subject matter of Personal Data protection, this DPA prevails.
By accepting the Agreement, or by using the Services, Customer enters into this DPA.
1. Definitions
1.1 Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1.2 In this DPA:
“Controller” means the natural or legal person that determines the purposes and means of Processing of Personal Data (and, where applicable under US state privacy laws, the analogous “business”).
“Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including: (a) Regulation (EU) 2016/679 (“GDPR”); (b) the United Kingdom General Data Protection Regulation and Data Protection Act 2018 (“UK GDPR”); (c) the Swiss Federal Act on Data Protection (“FADP”); and (d) US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (“CCPA”), to the extent applicable.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“Personal Data” means any information relating to an identified or identifiable natural person that is protected as personal data or personal information under Data Protection Laws and that Wumpix Processes on behalf of Customer in providing the Services.
“Processing” (and “Process”) means any operation or set of operations performed on Personal Data, whether or not by automated means, as defined in GDPR.
“Processor” means the natural or legal person that Processes Personal Data on behalf of the Controller (and, where applicable under US state privacy laws, the analogous “service provider” or “contractor”).
“SCCs” means Module Two (Controller-to-Processor) of the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended or replaced.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Wumpix or its Subprocessors in connection with the Services.
“Subprocessor” means any Processor engaged by Wumpix to Process Personal Data on behalf of Customer.
“UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner’s Office to the SCCs, as amended or replaced.
2. Roles of the parties
2.1 Customer is the Controller. Wumpix is the Processor with respect to Personal Data contained in Customer Data.
2.2 Each party will comply with the obligations applicable to it under Data Protection Laws.
2.3 This DPA does not apply to Personal Data that Wumpix Processes as an independent Controller (including Account registration data, billing contacts, Website analytics, Wumpix’s own marketing lists, and abuse-prevention data about Users), which is described in the Privacy Policy at https://wumpix.com/legal/privacy.
2.4 Customer is solely responsible for: (a) the accuracy and lawfulness of Personal Data it provides or collects through the Services; (b) providing required notices to Data Subjects; (c) obtaining and documenting required consents or establishing another lawful basis; and (d) ensuring that its instructions to Wumpix comply with Data Protection Laws.
3. Customer instructions
3.1 Wumpix will Process Personal Data only:
(a) to provide, maintain, secure, and support the Services; (b) in accordance with the Agreement, this DPA, Customer’s configuration of the Services, and Customer’s documented instructions; and (c) as required by applicable Law to which Wumpix is subject. In that case, Wumpix will inform Customer of that legal requirement before Processing, unless the Law prohibits such information on important grounds of public interest.
3.2 The Agreement, this DPA, and Customer’s use and configuration of the Services (including API calls, integrations, and feature settings) constitute Customer’s complete and final documented instructions to Wumpix for the Processing of Personal Data. Additional instructions require prior written agreement and may be subject to additional fees.
3.3 Wumpix will immediately inform Customer if, in Wumpix’s opinion, an instruction infringes GDPR or UK GDPR. Wumpix is not obligated to perform a comprehensive legal assessment of Customer’s instructions.
4. Confidentiality of processing personnel
Wumpix will ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive appropriate training on data protection and information security.
5. Security
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Wumpix will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, as described in Annex A (Security Measures).
5.2 Customer is responsible for securely administering its Account, Users, credentials, API keys, endpoint devices, and Customer-managed integrations, and for applying available security settings.
6. Subprocessors
6.1 Customer provides a general authorization for Wumpix to engage Subprocessors to Process Personal Data. The current list of Subprocessors is set out in Annex B and at https://wumpix.com/legal/subprocessors.
6.2 Wumpix will enter into a written agreement with each Subprocessor imposing data-protection obligations that are no less protective with respect to Personal Data than those imposed on Wumpix under this DPA, to the extent applicable to the nature of the services provided by the Subprocessor.
6.3 Wumpix remains fully liable to Customer for the performance of the Subprocessor’s data-protection obligations under this DPA.
6.4 Wumpix will provide Customer with notice of the addition or replacement of any Subprocessor by updating https://wumpix.com/legal/subprocessors and, for material changes affecting active paid Customers, by email or in-product notice at least fifteen (15) days before the new Subprocessor begins Processing Personal Data (except in emergency security or continuity situations, in which case notice will be given as soon as practicable).
6.5 Customer may object to a new Subprocessor on reasonable data-protection grounds by written notice to privacy@wumpix.com within fifteen (15) days of notice. The parties will cooperate in good faith to resolve the objection. If they cannot resolve it before the planned change, Customer may terminate the affected Services by written notice as its exclusive remedy, and Wumpix will refund prepaid unused fees for the terminated portion of the Subscription Term.
7. Assistance with Data Subject rights
7.1 Taking into account the nature of the Processing, Wumpix will assist Customer by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Customer’s obligation to respond to requests by Data Subjects to exercise their rights under Data Protection Laws.
7.2 If Wumpix receives a request from a Data Subject relating to Personal Data Processed under this DPA, Wumpix will promptly forward the request to Customer and will not respond substantively except as instructed by Customer or required by Law.
7.3 Customer is responsible for verifying the identity of Data Subjects and for the content of responses to Data Subject requests regarding Customer Data.
8. Assistance with compliance
Taking into account the nature of Processing and the information available to Wumpix, Wumpix will assist Customer with:
(a) security of Processing under Article 32 GDPR; (b) notification of a Security Incident to a supervisory authority and communication to Data Subjects, where Customer is legally required to notify; (c) data protection impact assessments under Article 35 GDPR; and (d) prior consultation with a supervisory authority under Article 36 GDPR,
in each case to a reasonable extent and, for assistance beyond Wumpix’s standard support and documentation, subject to reasonable fees if the volume of work is extraordinary.
9. Security Incidents
9.1 Wumpix will notify Customer without undue delay after becoming aware of a Security Incident, and where feasible within seventy-two (72) hours.
9.2 The notification will describe, to the extent then known: (a) the nature of the Security Incident, including where possible the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the name and contact details of the Wumpix contact point; (c) the likely consequences of the Security Incident; and (d) the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.
9.3 Wumpix will take commercially reasonable steps to contain, investigate, and remediate the Security Incident and will reasonably cooperate with Customer’s investigation and any required notifications. Notification under this Section is not an acknowledgement of fault or liability.
9.4 Customer is responsible for Security Incident notifications to regulators and Data Subjects that are legally Customer’s responsibility as Controller.
10. Return and deletion of Personal Data
10.1 During the Subscription Term, Customer may export Customer Data using the export / API features described in the Documentation.
10.2 Upon termination or expiry of the Services, or upon Customer’s written request, Wumpix will, at Customer’s choice: (a) return a copy of Personal Data then retained in production systems in a commonly used machine-readable format; or (b) delete Personal Data from production systems, and delete existing copies, except where storage is required by applicable Law or for the establishment, exercise, or defense of legal claims.
10.3 Residual copies in encrypted backups will be isolated from production Processing and overwritten in accordance with Wumpix’s backup rotation cycle, not to exceed ninety (90) days after production deletion, unless Law requires longer retention.
10.4 Upon request, Wumpix will provide written confirmation of deletion.
11. Audits and information
11.1 Wumpix will make available to Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, including responses to security questionnaires and available summaries of independent audits or certifications when Wumpix maintains them.
11.2 Customer may exercise audit rights no more than once in any twelve (12) month period, unless a Security Incident has occurred or a supervisory authority requires an additional audit.
11.3 Audits must: (a) be on at least thirty (30) days’ prior written notice (except for urgent Security Incident follow-up); (b) be conducted during business hours; (c) not unreasonably interfere with Wumpix’s business; (d) be subject to confidentiality obligations; and (e) be limited to systems and records relevant to Personal Data Processed for Customer.
11.4 Before any on-site audit, Customer will first review Wumpix’s available documentation and audit reports. On-site audits are permitted only if Customer reasonably demonstrates that documentation is insufficient. Customer bears its own costs. Wumpix may charge reasonable fees for personnel time beyond standard questionnaire support.
11.5 Wumpix may require audits to be performed by an independent third-party auditor bound by confidentiality, mutually agreed (agreement not to be unreasonably withheld).
12. International transfers
12.1 Customer authorizes Wumpix to transfer Personal Data internationally as necessary to provide the Services, including to Wumpix Affiliates and Subprocessors, subject to this Section 12 and Data Protection Laws.
12.2 EEA transfers. Where Wumpix Processes Personal Data subject to GDPR and transfers that Personal Data to a country not recognized by the European Commission as providing an adequate level of protection, the SCCs (Module Two) are incorporated by reference into this DPA and apply between Customer (as “data exporter”) and Wumpix (as “data importer”), completed as follows:
(a) Clause 7 (Docking clause): included; (b) Clause 9 (Use of subprocessors): Option 2 (General Written Authorization), with the notice period stated in Section 6.4 of this DPA; (c) Clause 11 (Redress): the optional language is not included; (d) Clause 17 (Governing law): the laws of Ireland; (e) Clause 18 (Choice of forum and jurisdiction): the courts of Ireland; (f) Annex I to the SCCs: completed by Annex C of this DPA; (g) Annex II to the SCCs: completed by Annex A of this DPA; (h) Annex III to the SCCs: completed by Annex B of this DPA.
12.3 UK transfers. Where UK GDPR applies to a restricted transfer, the SCCs as completed above are used with the UK Addendum, which is incorporated by reference. For the UK Addendum Tables: Table 1 parties are Customer and Wumpix; Table 2 selected SCCs are those in Section 12.2; Table 3 Appendix information is Annexes A–C of this DPA; Table 4 importer may end the Addendum as set out therein.
12.4 Swiss transfers. Where FADP applies, references in the SCCs to GDPR are interpreted to include references to FADP, references to EU Member State are interpreted to include Switzerland, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority where required.
12.5 If any transfer mechanism is amended, replaced, or invalidated, the parties will promptly adopt a valid alternative mechanism that enables lawful continuation of the Services, and this DPA will be deemed amended accordingly.
13. US state privacy terms (service provider / contractor)
To the extent CCPA or similar US state privacy laws apply to Personal Data Processed under this DPA:
(a) Wumpix will Process Personal Data only for the limited and specified business purposes of providing the Services under the Agreement and this DPA, and for purposes permitted of a service provider / contractor under those laws; (b) Wumpix will not “sell” or “share” Personal Data as those terms are defined under those laws; (c) Wumpix will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship with Customer, except as permitted by those laws; (d) Wumpix will not combine Personal Data with personal information received from or on behalf of another person, or collected from Wumpix’s own interactions, except as permitted for service-provider purposes under those laws; (e) Wumpix will comply with applicable obligations under those laws and provide the same level of privacy protection as required of businesses by those laws with respect to Personal Data; (f) Customer may take reasonable and appropriate steps to help ensure that Wumpix uses Personal Data in a manner consistent with Customer’s obligations under those laws, including through the audit rights in Section 11; (g) Wumpix will notify Customer if Wumpix determines it can no longer meet its obligations under this Section 13; and (h) upon notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
14. Liability
The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent Data Protection Laws prohibit such limitation (in which case the limitation applies only to the maximum extent permitted).
15. Term and survival
This DPA takes effect on the Effective Date above (or on the date Customer first accepts the Agreement, if later) and continues until Wumpix ceases Processing Personal Data on behalf of Customer. Sections that by their nature should survive (including confidentiality, security incident cooperation for closed incidents, liability, and deletion confirmation) survive termination.
16. Contact points
| Topic | Contact |
|---|---|
| Privacy / DPA inquiries | privacy@wumpix.com |
| Security Incidents | security@wumpix.com |
| Legal notices | legal@wumpix.com |
Annex A — Security Measures
(also completes Annex II of the SCCs)
Wumpix maintains a security program that includes the following measures, as applicable to the Services:
A.1 Organization of information security
- Assigned security and privacy responsibility
- Confidentiality obligations for personnel with access to Personal Data
- Security awareness expectations for personnel
- Vendor security review for Subprocessors Processing Personal Data
A.2 Physical access control
- Production infrastructure hosted in professionally managed data centers or cloud regions with physical access controls, environmental safeguards, and monitored facilities (implemented by infrastructure Subprocessors under contract)
A.3 System access control
- Unique user identifiers for administrative access
- Role-based access control and least-privilege principles
- Multi-factor authentication for privileged access where supported
- Secure credential storage (passwords hashed; secrets managed via restricted configuration)
- Session management and account lockout / abuse controls for Customer-facing authentication
A.4 Data access control
- Logical separation of Customer Data by Account / tenant identifiers
- Authorization checks within application layers for User actions
- Restriction of production data access to personnel with a need to know
A.5 Transmission control
- Encryption of data in transit using TLS for public HTTPS endpoints and secured channels for service interconnects
- Secure remote administration practices
A.6 Input control / integrity
- Logging of security-relevant administrative and authentication events
- Application and infrastructure monitoring for anomalous activity
- Change management practices for production deployments
A.7 Availability and resilience
- Regular backups of critical Service data
- Disaster-recovery and backup-restoration procedures
- Redundancy and restart procedures appropriate to the deployment architecture
- Continuity planning for material outages
A.8 Separation
- Separation of production and non-production environments
- Controls designed to prevent unauthorized use of production Customer Data in non-production environments (use of anonymized or synthetic data where practicable)
A.9 Job control / Subprocessors
- Written agreements with Subprocessors
- Flow-down of confidentiality and data-protection terms
- Maintenance of the Subprocessor list in Annex B
A.10 Vulnerability and malware management
- Timely application of security updates for systems under Wumpix control
- Vulnerability intake via security@wumpix.com
- Malware protection on relevant administrative systems
A.11 Incident response
- Documented incident response process
- Security Incident assessment, containment, remediation, and Customer notification workflow consistent with Section 9 of this DPA
Annex B — Subprocessors
(also completes Annex III of the SCCs and the public list at https://wumpix.com/legal/subprocessors)
Wumpix engages the following categories and providers to Process Personal Data in connection with the Services. Exact regional endpoints may vary by Account configuration and product module.
| Subprocessor | Location of processing | Purpose |
|---|---|---|
| Infrastructure hosting provider(s) engaged by Wumpix for compute, storage, networking, and managed database services used to operate the Vividor / Wumpix platform | European Economic Area and/or other regions selected for the Account’s hosting footprint | Hosting and operating the Services; storage of Customer Data |
| Object / backup storage provider(s) engaged for encrypted backups and durable object storage | Same hosting footprint as primary infrastructure | Backup, restore, and object storage |
| Transactional email delivery provider | EEA and/or United States (provider network) | Delivery of Service emails (account, billing, notifications) and, where Customer uses email send features, Customer-directed email transmission |
| Payment processing provider | United States and/or EEA (provider network) | Subscription billing and payment processing (controller billing data; limited Customer Data if included on invoices) |
| Error monitoring and application performance provider | United States and/or EEA | Application diagnostics, crash and error telemetry |
| Customer support ticketing / messaging provider | United States and/or EEA | Handling Customer support requests |
| Analytics provider for product usage (Account / Website controller telemetry; limited Customer metadata as needed for product metrics) | United States and/or EEA | Product analytics and service improvement |
| LLM / AI API provider(s) enabled when Customer uses AI Features | United States and/or EEA (provider network) | Processing prompts and content submitted to AI Features under Customer’s configuration |
| Content delivery / DNS / edge security provider | Global anycast network | CDN, DNS, DDoS protection, edge TLS termination |
| Identity / SSO provider (if Customer enables SSO) | Per provider region | Authentication for Users |
Wumpix Affiliates, if any, that assist in Support, engineering, or operations may Process Personal Data under the same confidentiality and security standards as Wumpix, in the locations where those personnel work.
Customer-instructed Third-Party Products that Customer connects to the Services (messengers, CRMs, ad platforms, and similar) are not Wumpix Subprocessors; they Process data under Customer’s separate relationship with those providers.
Updates to this Annex B are published at https://wumpix.com/legal/subprocessors.
Annex C — Description of Processing
(completes Annex I of the SCCs)
C.1 List of parties
Data exporter (Controller): Customer, as identified in the applicable Order or Account record. Contact: the Account administrative email; privacy contact as designated by Customer. Activities: use of Wumpix / Vividor Services for business lead generation, outreach, dialogue, campaign operations, and related workflows. Role: Controller.
Data importer (Processor): Wumpix — the commercial brand and operator of https://wumpix.com (including the Vividor platform). A separate registered legal entity has not been formed yet; notices: privacy@wumpix.com; security@wumpix.com; legal@wumpix.com. Contact: privacy@wumpix.com; security@wumpix.com; legal@wumpix.com. Activities: provision of the cloud Services and Support. Role: Processor.
C.2 Description of transfer / processing
| Item | Description |
|---|---|
| Categories of Data Subjects | Customer’s Users; Customer’s leads, prospects, customers, partners, and other contacts whose data Customer submits to or collects through the Services |
| Categories of Personal Data | Identification and contact data (e.g., name, email, phone, messenger IDs, company, title); communication content and metadata; campaign and workflow data; technical logs associated with outreach; any other Personal Data Customer chooses to upload or sync |
| Sensitive data | Not intended. Customer must not submit special categories of Personal Data or other restricted data except as permitted under the Agreement and AUP |
| Frequency | Continuous / ongoing during the Subscription Term |
| Nature of Processing | Collection, storage, hosting, organization, retrieval, transmission, erasure, and other operations necessary to provide messaging, campaign, analytics, orchestration, AI Features (if enabled), and Support |
| Purpose | Provision of the Wumpix / Vividor Services to Customer under the Agreement |
| Retention | For the Subscription Term and thereafter as stated in Section 10 of this DPA |
| Subprocessors | As listed in Annex B |
C.3 Competent supervisory authority
Where GDPR applies, the competent supervisory authority is determined in accordance with Clause 13 of the SCCs (for many exporters, the authority of the EU Member State in which the exporter is established, or as otherwise provided in Clause 13). Where UK GDPR applies, the UK Information Commissioner’s Office is the competent authority for UK-restricted transfers. Where FADP applies, the Swiss FDPIC is the competent authority as applicable.
Annex D — Details for operational completeness
D.1 Subject matter and duration
The subject matter of Processing is Personal Data uploaded to or generated in the Services under Customer’s Account. Duration equals the Subscription Term plus the deletion / backup residual period in Section 10.
D.2 Customer configuration controls
Customer may apply available administrative controls, including User roles, API keys, integration scopes, retention settings (where offered), export tools, and AI Feature toggles. Those controls form part of Customer’s instructions.
D.3 Related documents
- Terms of Service: https://wumpix.com/legal/terms
- Privacy Policy: https://wumpix.com/legal/privacy
- Acceptable Use Policy: https://wumpix.com/legal/aup
- Subprocessors (public mirror of Annex B): https://wumpix.com/legal/subprocessors
End of Data Processing Addendum