1. Parties
This Agreement is entered into between:
- Customer (the data controller)
- UAB “Wantly” (Wantly) (the data processor)
This Data Processing Agreement (“Agreement”) forms part of the Terms of Service and applies when Wantly processes personal data on behalf of the Customer.
This Agreement is entered into between:
This Agreement governs the processing of personal data by Wantly on behalf of the Customer in connection with the provision of the Service.
For the purposes of GDPR:
The Customer determines the purposes and means of processing personal data.
Wantly processes personal data to provide the Service, including:
We do not control these cookies directly. Please refer to their privacy policies:
Wantly processes personal data for the duration of the agreement under which the Service is provided, and thereafter only for as long as is necessary to delete or return the data in accordance with the section on Data Retention and Deletion, or for as long as retention is required by applicable law.
Wantly shall:
The Customer grants Wantly general authorisation to engage sub-processors to process personal data on the Customer’s behalf for the purpose of providing the Service.
The sub-processors engaged by Wantly for the processing of Customer Data are:
Wantly uses the business or API services of its AI sub-processors. Under those services, the contents of Customer Data submitted for processing are not used to train the providers’ models. Wantly has entered into data processing agreements with each AI sub-processor.
Wantly enters into a written agreement with each sub-processor imposing data protection obligations no less protective than those set out in this Agreement, and remains responsible for its sub-processors’ performance of those obligations.
Wantly will notify the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or in-app notification. The Customer may object on reasonable grounds relating to data protection within 14 days of the notice. If the Customer objects and the parties cannot agree on a solution, the Customer may terminate the affected part of the Service without penalty.
Third-party services that the Customer connects to the Service, for example the Customer’s own CRM, ERP, accounting, e-commerce, e-signature, or payment provider, are not Wantly’s sub-processors. Where the Customer instructs Wantly to transmit personal data to such a service, the Customer is responsible for its own relationship with that provider, including any data processing agreement required with it.
Where personal data is transferred outside the EEA, including to AI sub-processors and support and CRM providers established in the United States, Wantly ensures appropriate safeguards, including:
Wantly implements appropriate technical and organizational measures, including:
Wantly shall assist the Customer in:
Wantly will make available to the Customer the information reasonably necessary to demonstrate compliance with this Agreement and Article 28 of the GDPR, including responses to reasonable data protection questionnaires and any security documentation or third-party certifications Wantly holds.
Where that information is not sufficient, the Customer may request an audit of the processing activities relevant to the Service. Such audits:
The Customer may appoint an independent auditor, provided that the auditor is not a competitor of Wantly and is bound by confidentiality obligations.
In the event of a personal data breach affecting Customer Data in systems operated by Wantly, Wantly shall notify the Customer without undue delay after becoming aware of it, and in any event within 72 hours.
Where a personal data breach occurs at a sub-processor, Wantly shall notify the Customer without undue delay after establishing that Customer Data is affected.
The notification shall include, to the extent available:
Wantly shall cooperate with the Customer and provide reasonable assistance in the Customer’s own notification obligations under Articles 33 and 34 of the GDPR.
Forwarding of a proposal link by the Customer or by a recipient of that link is not a personal data breach on Wantly’s part.
Upon termination or expiry of the agreement under which the Service is provided, the Customer may export Customer Data from the Service for 30 days.
After that period, Wantly will delete Customer Data from active systems within 30 days and from backups within 90 days, or return it to the Customer where the Customer so requests before the end of the export period.
Wantly may retain personal data where, and for as long as, retention is required by applicable law, including accounting and tax obligations, and will continue to protect any retained data in accordance with this Agreement.
Each party shall be responsible for its own compliance with applicable data protection laws.
This Agreement shall be governed by the laws of the Republic of Lithuania.
V. Nageviciaus str. 3, LT-08237 Vilnius, Lithuania
Company code 307039973