Legal
Data processing addendum
Last updated 16 September 2026
This addendum is part of the Terms of service and applies whenever woble processes personal data on your behalf under the GDPR or the UK GDPR. It is written so that you can hand it to your legal or compliance team as it stands. It applies automatically; you do not need to sign anything. If your organisation needs a countersigned copy, write to privacy@woble.ai.
Parties and roles
This addendum is between the customer that runs a woble workspace ("Customer", "you") and woble ("we", "us"). For the personal data inside your workspace ("Customer data"), you are the controller and we are the processor. Where you are yourself a processor for another organisation, you are our controller for the purposes of this addendum and you warrant that your own controller has authorised us as a subprocessor.
For your account data and for our own website, billing and support records, we are an independent controller and the Privacy policy applies instead.
Subject matter, duration and nature of the processing
We process Customer data in order to provide woble: a team chat in which AI agents read channels, answer messages, remember rules, run routines and workflows, and act in connected services on your instructions. The processing consists of storing, displaying, transmitting to model providers and integrated services, and deleting the data, and lasts for as long as you have a workspace with us plus the deletion period described under the heading Deletion and return of data.
The data may concern your employees, contractors, customers, suppliers and any other people mentioned in your channels or in the services you connect. The categories depend on what you put into woble and typically include names, contact details, job titles, message content, files and business records. You must not use woble to process special categories of data (health, biometric, criminal, political, religious, sexual orientation, trade union membership) unless you have told us in writing and we have agreed.
Your instructions
We process Customer data only on your documented instructions. Your instructions are: the Terms of service, this addendum, your configuration of the workspace (which agents exist, what they are told, which integrations are connected, who may approve what), and the messages your members and agents send in the ordinary use of the product.
If we believe an instruction breaks the GDPR or other data protection law, we will tell you before acting on it. If the law requires us to process Customer data otherwise than on your instructions, we will tell you before doing so unless the law prevents it.
Your obligations
As controller you are responsible for:
- having a lawful basis for the personal data you put into woble and for the instructions you give agents;
- telling the people whose data you process what you do with it, including that AI agents may read and act on it;
- configuring agents, approvals, roles and integrations in a way that fits the sensitivity of the data;
- answering data subject requests that come to you, with our help as described under the heading Assistance with data subject requests;
- making sure your members keep their accounts secure.
Confidentiality
Everyone we allow to process Customer data, whether staff or contractor, is bound by a written confidentiality obligation and is given access only to the extent their role requires. Access to production systems is logged. Our staff do not browse customer workspaces; access to Customer data happens only to fix a fault you reported, to investigate abuse, or to answer a support request that includes the data.
Security measures
We implement the technical and organisational measures described on the Security page, which forms part of this addendum. In summary:
- encryption of all data in transit (TLS 1.2 or newer) and at rest (AES-256);
- separate encryption of integration credentials with keys held outside the database, decrypted only inside the worker at the moment of use;
- isolation of every workspace's data, with every query scoped to a workspace;
- human approval before agents take irreversible or outward-facing actions;
- a network guard that blocks outbound calls to private, internal and cloud metadata addresses;
- role-based access inside workspaces, multi-factor authentication and logged access for our staff;
- continuous encrypted backups retained for 30 days, and an audit log on the Business plan.
We may update these measures from time to time, but will not reduce the overall level of protection during the term of this addendum.
Subprocessors
You give us general authorisation to use subprocessors to provide the service. At the date of this addendum they fall into four categories: hosting and storage (EU regions), model providers (to generate agent answers), email delivery (sign-in links, notifications and receipts), and payments (card processing). A current list with company names and locations is available on request at privacy@woble.ai and is provided to you when this addendum starts.
Every subprocessor is bound by a written contract that imposes data protection obligations no less protective than this addendum. We remain responsible to you for their performance. Model providers in particular are barred from using Customer data to train models and from retaining it beyond what is needed to serve the request and detect abuse.
We will give you at least 30 days' notice by email to the workspace owner before adding or replacing a subprocessor that will process Customer data. If you object on reasonable data protection grounds and we cannot resolve the objection, you may end the affected workspace before the change takes effect and we will refund any prepaid fees for the remaining period.
Assistance with data subject requests
If a person contacts us directly to exercise rights over data in your workspace (access, correction, deletion, restriction, portability, objection), we will not answer on your behalf. We will pass the request to you within five working days and tell the person we have done so.
The product lets you export channels, delete messages, edit or delete agent memories, remove members and delete a workspace, which covers the common cases. Where a request needs something the product cannot do, we will help you within a reasonable time and may charge for unusual effort.
Assistance with your other obligations
Taking into account the nature of the processing and the information available to us, we will help you meet your obligations under Articles 32 to 36 of the GDPR: keeping the data secure, notifying breaches, carrying out data protection impact assessments and consulting supervisory authorities. This page, the Security page and the Privacy policy are intended to give you most of what an impact assessment needs; if you need more, ask at privacy@woble.ai.
Personal data breaches
If we become aware of a personal data breach affecting Customer data, we will notify the workspace owner without undue delay and in any case within 72 hours of confirming it. The notice will describe the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, the measures we have taken or propose, and a contact point. Where we cannot provide everything at once, we will provide it in stages.
We will cooperate with you and take reasonable steps to contain and remedy the breach. Notification is not an admission of fault.
Deletion and return of data
You can export your data from the workspace at any time while the workspace exists. When a workspace is deleted, or when this addendum ends, we delete all Customer data in it, including channels, messages, files, agents, memories, routines, workflow runs and stored integration credentials, within 30 days, and encrypted backups roll off within a further 30 days at most.
We keep only what the law requires us to keep (for example invoices) and only for as long as it requires. On request we will confirm deletion in writing.
International transfers
Customer data is stored in the European Union. Some subprocessors, in particular model providers and email delivery, may process data outside the EU or UK. Where they do, the transfer is made under the European Commission's standard contractual clauses (and the UK International Data Transfer Addendum where relevant), an adequacy decision, or another mechanism valid under Chapter V of the GDPR, and only the data needed for that subprocessor's role is sent.
We will not transfer Customer data to a country without an adequate level of protection except under such a mechanism.
Audits
We will make available the information reasonably necessary to demonstrate our compliance with this addendum, including this page, the Security page, our subprocessor list and, where we hold them, summaries of independent security assessments.
If that is not enough to meet a legal obligation you have, you may audit us once in any twelve-month period, or more often after a breach or when required by a supervisory authority. Audits must be agreed at least 30 days in advance, take place during business hours, not disturb other customers, and be conducted by you or an independent auditor bound by confidentiality. You bear the cost of the audit and we may charge for our time beyond one working day.
Liability, term and precedence
The limits and exclusions of liability in the Terms of service apply to this addendum. Each party is liable for its own breaches of data protection law, and nothing here limits a person's rights against either party under the GDPR.
This addendum starts when you first use woble and lasts until all Customer data has been deleted as described under the heading Deletion and return of data. If it conflicts with the Terms of service or the Privacy policy on a matter of data protection, this addendum wins. Where the UK GDPR applies, references to the GDPR include the UK GDPR and references to the European Commission's standard contractual clauses include the UK addendum.