Data Processing Agreement

Version 2026-11-02

This Data Processing Agreement governs the processing of personal data by V.P. Labs on behalf of the customer through the wawesome platform. It forms an integral part of the Terms of Service between V.P. Labs and the customer.

1. Scope and statutory roles

When a customer deploys functions, uploads files, and serves end-user traffic through the platform, the customer acts as the Data Controller, and V.P. Labs acts as the Data Processor under Article 28 of Regulation (EU) 2016/679 (GDPR).

Where the customer processes personal data on behalf of its own third-party clients, the customer acts as a processor or joint controller, and wawesome acts as a Subprocessor.

This DPA applies exclusively to Customer Personal Data processed within deployed functions, static assets, invocation metadata, captured function execution logs, and conversations with the dashboard assistant.

Data protection officer and representative. wawesome’s core activities are neither regular and systematic monitoring of data subjects on a large scale nor large-scale processing of special categories of data, so GDPR Article 37 does not require it to appoint a data protection officer. wawesome is established in the Netherlands, so no representative under Article 27 is required. Privacy questions are answered at privacy@wawesome.io.

2. Subject matter and duration of processing

Subject matter: wawesome provides serverless WebAssembly execution, static asset delivery, HTTP routing, automated background scheduling, and execution telemetry for applications deployed by the customer.

Duration: The processing continues for the duration of the customer workspace, until all Customer Personal Data is deleted in accordance with Section 12 of this DPA.

3. Nature and purpose of processing

wawesome processes Customer Personal Data solely to:

  • Execute customer WebAssembly modules upon incoming HTTP requests or scheduled triggers.
  • Route inbound requests to the appropriate application and return generated responses to visitors.
  • Store deployed WebAssembly bundles, static files, and application environment variables.
  • Capture operational execution metadata (timestamps, response status codes, execution duration, and caller IP prefix) to generate usage metrics and measure resource allowances.
  • Capture execution output (standard output and standard error logs) to enable debugging in the customer dashboard.
  • Answer questions from the customer’s workspace members through the dashboard assistant, and propose changes that a member approves. To do this, wawesome sends the question, and what the assistant reads from the workspace, to a model provider listed in Annex A. That can include function source code, execution logs, and the values of environment variables that are not secrets. The assistant cannot read secret values, and it reads execution logs only in a workspace where an owner or admin has allowed it. What a member writes in the chat is sent as written, including a secret the member pastes there. The assistant is optional: a workspace owner can turn it off, or back on, at any time in the workspace settings, and while it is off nothing from the workspace is sent to the model providers.

wawesome does not access, inspect, sell, or use Customer Personal Data for its own independent purposes.

Neither wawesome nor the model providers listed in Annex A use Customer Personal Data, function code, configuration, or what the dashboard assistant sends or receives, to train or improve artificial intelligence or machine learning models.

4. Types of personal data and categories of data subjects

Categories of data subjects: Visitors and end users of customer applications, customer team members, and individuals whose data is processed by code deployed by the customer.

Types of personal data: Any personal data included in HTTP request bodies, headers, URL query parameters, function output payloads, captured execution logs, and conversations with the dashboard assistant: what members write to it, what it reads from the workspace to answer, and what it answers. Invocation records include caller IP addresses, which are processed for rate limiting, security, and traffic metrics.

Prohibition on sensitive data: The platform is a general-purpose serverless hosting environment and is not configured for processing Special Categories of Personal Data under GDPR Article 9 (such as health data, biometric data, religious beliefs, or criminal history) or unencrypted payment cardholder data under PCI-DSS. The customer warrants that its deployed workloads do not process Special Category Data or cardholder data without a separate written agreement with wawesome. The same applies to the dashboard assistant: the customer is responsible for making sure its members do not write Special Category Data, cardholder data, credentials or other secrets in the chat.

5. Controller instructions

wawesome shall process Customer Personal Data only on documented instructions from the customer, including regarding transfers of personal data outside the EEA, unless required to do so by European Union or Member State law.

The customer instructions are set forth in the Terms of Service, this DPA, and the configuration choices made by the customer in the dashboard or via the command-line tool.

A change that a workspace member approves through the dashboard assistant is also a documented instruction of the customer. It runs only within that member’s role and permissions, checked when it runs.

wawesome shall inform the customer immediately if, in its reasonable opinion, an instruction infringes the GDPR or other applicable data protection provisions.

6. Technical and organizational security measures

wawesome implements technical and organizational measures under GDPR Article 32 to ensure a level of security appropriate to the risk. These measures include:

  • Sandbox isolation: Guest code runs inside sandboxed WebAssembly runtimes with isolated linear memory and enforced instruction fuel limits. A guest function cannot read host memory or access other tenants’ execution environments.
  • Envelope encryption for secrets: Environment variables and secret configurations are encrypted using envelope encryption before storage. Decryption keys (DEKs) are protected by a versioned master key ring.
  • Per-tenant storage separation: Object storage buckets for code bundles, assets, artifacts, and logs enforce isolation by tenant identifier and cryptographic content hashes.
  • Encrypted transport: All incoming and outgoing network traffic across public endpoints is encrypted in transit using TLS 1.2 or TLS 1.3.
  • Database backups: Managed database clusters include automated daily snapshots and point-in-time recovery (PITR) to ensure availability can be restored in a timely manner.
  • Access control: Production infrastructure access is restricted to authorized operations personnel using multi-factor authentication, key-based access, and least-privilege principles.
  • Confidentiality of personnel: Every person authorized by wawesome to process Customer Personal Data is bound by a written confidentiality obligation that outlives their engagement, and reaches only what their work requires.

7. Subprocessors

General authorization

The customer grants wawesome general written authorization to engage subprocessors to support platform operations. The subprocessors currently authorized are listed in Annex A of this DPA.

Notice of changes

wawesome shall provide the customer with at least 30 days prior written notice before engaging a new subprocessor or replacing an existing subprocessor. Notice will be sent by email to registered workspace owners.

Objection mechanism

The customer may object to a new subprocessor on reasonable data protection grounds by notifying privacy@wawesome.io within 30 days of receiving the notice.

If the customer objects and wawesome cannot reasonably accommodate the objection or provide an alternative without using the subprocessor, the customer may terminate the affected workspace without penalty before the effective date of the subprocessor appointment. wawesome will issue a pro-rata refund for any prepaid, unused service fees for the remainder of the monthly billing period.

Flow-down obligations

wawesome imposes data protection obligations on every subprocessor that are no less protective than those set out in this DPA. wawesome remains fully liable to the customer for the performance of each subprocessor’s obligations.

8. International data transfers

wawesome hosts primary customer compute workloads, databases, and storage buckets within the European Union (initially Frankfurt, Germany, with provision for additional facilities within the European Union).

Where the engagement of a subprocessor involves a transfer of Customer Personal Data outside the European Economic Area, wawesome ensures that the transfer complies with Chapter V of the GDPR by:

  1. Entering into European Commission Standard Contractual Clauses (Module 3: Processor-to-Processor) with every recipient outside the EEA, whether or not it holds a certification; and
  2. Recording in Annex A whether the recipient is also certified under the EU-US Data Privacy Framework (adequacy decision under GDPR Article 45).

9. Personal data breach notification

wawesome shall notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a confirmed personal data breach affecting Customer Personal Data.

Notification will be sent by email to registered workspace owners and will include, to the extent known:

  • A description of the nature of the breach, including the categories of data and approximate number of records affected.
  • The likely consequences of the breach.
  • The mitigation and remediation measures taken or proposed to address the incident.

wawesome shall provide reasonable cooperation to help the customer fulfill its breach notification obligations under Articles 33 and 34 of the GDPR.

The obligation to report an incident does not apply to unsuccessful attempts or benign activities that do not compromise data security, such as pings, routine port scans, blocked denial-of-service attempts, or failed rate-limited requests.

10. Assistance to the customer

The customer is responsible for responding to requests from data subjects seeking to exercise their rights under Chapter III of the GDPR.

Because wawesome does not index guest logs or execution payloads by end-user identity, wawesome cannot directly identify an individual visitor in operational logs.

Assistant conversations are different. Each one belongs to the workspace member who started it, so wawesome can find a member’s conversations. A member can read and delete their own conversations in the dashboard, and wawesome helps the customer with any other request about them.

If wawesome receives a request directly from an end user of a customer app, wawesome will promptly advise the requester to contact the customer, and will notify the customer. wawesome will provide reasonable technical assistance to help the customer respond to data subject requests, taking into account the nature of the processing.

Impact assessments and prior consultation. Taking into account the nature of the processing and the information available to it, wawesome assists the customer with data protection impact assessments under GDPR Article 35 and with prior consultation of a supervisory authority under Article 36.

11. Audits and inspections

wawesome makes available all information necessary to demonstrate compliance with GDPR Article 28:

  • wawesome satisfies customer audit and review requests by providing relevant third-party security certifications (such as SOC 2 Type II or ISO 27001 reports) held by our infrastructure subprocessors, architecture documentation, and written responses to reasonable security questionnaires. Written questionnaires may be submitted no more than once per 12-month period.
  • If the provided documentation reasonably fails to demonstrate compliance, or if an audit is formally ordered by a competent data protection supervisory authority, the customer may conduct an audit at customer expense. Such audit must occur upon at least 30 business days prior written notice, during normal business hours, without disrupting operations, and subject to strict confidentiality. The audit must not provide access to any other tenant’s data or infrastructure secrets.

12. Deletion and return of data

The workspace owner closes the workspace from the dashboard. It closes fourteen days after the request, and the owner can cancel until then. When it closes:

  • Deployed function code, every version of it, the modules compiled from it, and static assets are deleted. Static assets are removed after the platform reclamation grace window. Older copies kept for recovery, including backups, expire about 31 days after the workspace closes, so about 45 days after the owner asks to close it.
  • Invocations metadata is automatically deleted after 35 days under the platform retention sweep.
  • Captured function log bodies stored in object storage are automatically deleted after 14 days.
  • Any workspace export is deleted.
  • Assistant conversations are deleted.

An assistant conversation is also deleted 30 days after its last message, or earlier when its member deletes it or leaves the workspace. Text the assistant read from execution logs is removed from the conversation after 14 days. The model providers keep nothing after answering, except as Annex A describes: Scaleway may keep a request that causes errors for up to 14 days to investigate it.

Return of data. The workspace owner may export the workspace at any time before it closes, the fourteen days included, from the dashboard, the command-line tool, or an MCP client. The export is one archive holding, for each deployed function, the version it serves with its static assets and schedules; every environment variable, with the value of each secret one left out; the records wawesome keeps about the workspace, its members, its plans and the invocations of the last 35 days; and the assistant conversations of the owner who asks for the export. Other members’ conversations are left out, since only the member who started a conversation can read it. The archive is deleted seven days after it is built.

The export is wawesome’s answer to a request for data portability under GDPR Article 20. It is not a complete answer to a request for access under Article 15, and does not hold everything wawesome keeps about a person. Access requests go to privacy@wawesome.io and are answered as the Privacy Policy describes.

wawesome does not retain Customer Personal Data beyond these windows, unless required to do so by European Union or Member State law, or where a target is subject to a statutory preservation order (Legal Hold). Where a Legal Hold is active, deletion is suspended on the affected target until the order is formally released by operations personnel.

13. Liability and governing law

This DPA is governed by Dutch law, and disputes are subject to the exclusive jurisdiction of the competent court in Amsterdam, the Netherlands.

Any liability arising out of or related to this DPA is subject to the aggregate limitations of liability set forth in Section 13 of the Terms of Service. Nothing in this section limits direct statutory liability toward data subjects under GDPR Article 82.

Annex A: Subprocessor List

The following third-party entities are authorized subprocessors for the wawesome platform:

Subprocessor Entity & Headquarters Service Provided Data Transferred Processing Location Transfer Mechanism
DigitalOcean DigitalOcean, LLC (United States) Cloud hosting, App Platform compute, Managed PostgreSQL database, Spaces object storage Deployed code bundles, static assets, invocation metadata, execution log bodies Frankfurt, Germany (EU region fra1), and facilities within the European Union EU-US Data Privacy Framework; Standard Contractual Clauses (Module 3)
Cloudflare Cloudflare, Inc. (United States) Anycast DNS routing, DDoS mitigation, TLS termination, edge caching Inbound HTTP request headers, caller IP addresses, static web assets Global edge network (transient routing) EU-US Data Privacy Framework; Standard Contractual Clauses (Module 3)
Supabase Supabase, Inc. (United States) User authentication, identity provider, OAuth token validation User email addresses, account identifiers, session tokens Stockholm, Sweden (AWS eu-north-1), with support access from the United States Standard Contractual Clauses (Module 3). Supabase is not certified under the EU-US Data Privacy Framework
Stripe Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (United States) Payment processing, subscription management, Merchant of Record Customer billing address, VAT/tax details, transaction identifiers Ireland (EU) and United States EU establishment (Stripe Payments Europe); EU-US Data Privacy Framework; Standard Contractual Clauses
Resend Resend, Inc. (United States) Transactional email delivery for platform notifications (send.wawesome.io) Recipient name, recipient email address, notification subject, message body United States EU-US Data Privacy Framework; Standard Contractual Clauses (Module 3)
Grafana Labs Raintank, Inc., dba Grafana Labs (United States) Log storage and search for the platform gateway (Grafana Cloud Logs) Gateway operational log lines: Tenant, App and Function identifiers, invocation identifiers, error messages, and caller IP addresses where a line records one. No guest log bodies or request bodies Frankfurt, Germany (AWS eu-central-1) EU-US Data Privacy Framework; Standard Contractual Clauses (Module 3)
Sentry Functional Software, Inc., dba Sentry (United States) Error reporting for the wawesome dashboard Dashboard error diagnostics: error messages, stack traces, the page path without its query or fragment, the browser’s user agent, and the active Tenant identifier. No request bodies, cookies, other headers, or user names and email addresses European Union (Sentry EU data region) EU-US Data Privacy Framework; Standard Contractual Clauses (Module 3)
Mistral AI Mistral AI SAS (France) Language model inference for the dashboard assistant Members’ questions to the assistant, and the workspace content it reads to answer them: function source code, invocation records, execution logs, environment variable names and the values of those that are not secrets, and what members write in the chat. The assistant cannot read secret values European Union EU establishment. Zero Data Retention: inputs and outputs are not kept after the response. Not used for training
Scaleway Scaleway SAS (France) Language model inference for the dashboard assistant Same as Mistral AI Paris, France EU establishment. Not kept after processing, except a request that causes errors, which may be kept up to 14 days to investigate it. Not used for training