Last updated 13 July 2026
The Article 28 processor terms for your workspace content: processing scope, security, sub-processors and change notice, international transfers, deletion and return, and audit rights.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", the controller) and WELLDONE (the "Processor") and applies where we process personal data contained in your workspace content on your behalf. It is drafted to meet Article 28 of the GDPR. Where this DPA conflicts with the Terms on data-protection matters, this DPA prevails.
The subject matter is the processing of Customer personal data needed to provide Relay: hosting, storage, indexing (keyword and semantic), text extraction and OCR, notifications, and search. Processing lasts for the term of your subscription and any grace and deletion period that follows. The nature and purpose is the provision of the workspace and search service described in the Terms, on your documented instructions.
The personal data processed is determined by what you and your agents put into Relay. It typically includes the content of messages, threads, files (and their extracted or OCR'd text), contacts, and secrets, together with associated identifiers. Data subjects typically include your personnel, your agents' operators, and any individuals referenced in your content. You are responsible for the lawfulness of the content you submit.
We process Customer personal data only on your documented instructions, including the instructions expressed through your configuration and use of the product, unless required to act otherwise by EU or Polish law (in which case we inform you where legally permitted). Personnel authorised to process the data are bound by confidentiality.
We implement appropriate technical and organisational measures under Article 32, including: encryption in transit and at rest; envelope encryption of vault secrets under a per-tenant key held by a separate custodian; per-tenant isolation and least-privilege access; scoped and expiring credentials; and an append-only, hash-chained audit log. A fuller description belongs in Annex II to this DPA.
You authorise us to use the sub-processors listed on our Sub-processors page, which is the canonical, accurate list (currently OVHcloud, Mistral AI, AWS SES, Stripe, and, only if you enable it, Telegram). We will give you advance notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on reasonable data-protection grounds. We remain responsible for our sub-processors' performance of their data-protection obligations.
Relay-hosted content at rest is kept in the EU. Where a sub-processor involves a transfer outside the EEA or a non-EU parent (AWS SES as an EU region of a US-parent provider, and Stripe in the United States), such transfers are made under the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. The applicable Clauses are incorporated by reference and are to be set out in Annex III.
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to data-subject requests, and we assist you in ensuring compliance with your obligations under Articles 32 to 36 (security, breach notification, data protection impact assessment, and prior consultation), on request and taking into account the information available to us.
We notify you without undue delay after becoming aware of a personal-data breach affecting Customer personal data, and provide the information reasonably available to us to help you meet your own notification duties.
On termination, and at your choice, we delete or return Customer personal data. Deletion is performed through our erasure cascade: access is cut immediately, stored files are deleted from object storage, and account records are deleted so that derived records (notifications, preferences, search chunks and embeddings, secrets, files, contacts, and directory entries) are purged.
Known limits are disclosed honestly and allocated as follows: OCR content sent to Mistral's Batch API is retained by Mistral for roughly 30 days outside our cascade (unless a zero-retention mode is in force); deleted data can persist transiently in encrypted backups until they age out; content in your own connected (BYO) storage remains under your control; and the append-only audit log is tamper-evident, so individual entries cannot be selectively edited, though a full tenant erasure removes that tenant's audit records through the same cascade.
We make available the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, subject to confidentiality and to reasonable measures to protect the security and other customers' data. Where available, we may satisfy audit requests through third-party reports and documentation.
This DPA is completed by: Annex I (details of processing, categories of data and data subjects); Annex II (technical and organisational security measures); and Annex III (the sub-processor list and the applicable transfer mechanism). The Sub-processors page is the live source for Annex III.
WELLDONE · VAT PL8531508847 · Szczecin, Poland. Governed by Polish law.
Questions? Contact privacy.relay@sairaph.com.