Wantly logo
Product
Product catalog
Keep product codes, pricing, suppliers and details in one place.
Pricing & CPQ
Margins, discounts and minimum quantities - calculated automatically.
Proposal editor
Create professional proposals using templates, products and content blocks.
Interactive proposals
Clients can select products, change quantities and approve proposals online.
Tracking & analytics
See when clients open, view, approve or sign your proposals.
E-signature & contracts
Turn an approved proposal into a signed contract in one flow.
AI assistant
Analyze requests, create content and prepare proposals with AI.
Integrations
Connect Wantly with your ERP, CRM, accounting, payment and other systems.

What's new

AI offer drafts
from a one-line brief
Paste an RFQ. Get a structured proposal with the right products, prices and margins.
Read announcement  →
80 features across nine product areas.
See all features
Industries
Built for your industry
Don’t see yours? We probably still fit.
Interior & furnishing
Live
Furniture, decor & fit-out sellers
Wholesale & distribution
Live
Distributors, importers & resellers
Manufacturing
Live
Made-to-order & configured products
Equipment & machinery
Live
Industrial & technical equipment
Construction & building materials
Live
Merchants, contractors & supply
Promotional products & gifts
Live
Branded merchandise & business gifts
Professional services
Live
Scoped, quote-based engagements
IT & software
Live
Licenses, subscriptions & bundles
Food & catering
Live
Catering, supply & event quotes
More industries are on the way.
All industries
Pricing
ENG
Englishen
Lithuanianlt
Log in
Book a demo
Home
›
Legal
›
Data Processing Agreement (DPA)
Legal

Data Processing Agreement (DPA)

Last updated: 2026-03-25  ·  UAB Wantly, company code 307039973
Print / save as PDF

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service and applies when Wantly processes personal data on behalf of the Customer.

On this page
01.
Parties
02.
Subject Matter
03.
Roles
04.
Nature and Purpose of Processing
05.
Categories of Data
06.
Categories of Data Subjects
07.
Duration of Processing
08.
Processor Obligations
09
Sub-processors
10
International Transfers
11.
Security Measures
12.
Assistance to Controller
13.
Audits and Inspections
14.
Data Breach
15.
Data Retention and Deletion
16.
Liability
17.
Governing Law
18.
Contact

1. Parties

This Agreement is entered into between:

  • Customer (the data controller)
  • UAB “Wantly” (Wantly) (the data processor)

2. Subject Matter

This Agreement governs the processing of personal data by Wantly on behalf of the Customer in connection with the provision of the Service.

3. Roles

For the purposes of GDPR:

  • The Customer is the Data Controller
  • Wantly is the Data Processor

The Customer determines the purposes and means of processing personal data.

4. Nature and Purpose of Processing

Wantly processes personal data to provide the Service, including:

  • managing product and service catalogs
  • creating and sharing commercial proposals
  • tracking engagement and interactions
  • storing contracts and related documents
  • facilitating integrations (e.g. payments, communication tools)

5. Categories of Data

We do not control these cookies directly. Please refer to their privacy policies:

  • contact details (name, email, phone)
  • business information
  • proposal interaction data (behavior, engagement, scoring)
  • contract-related data
  • technical data (device, browser)

6. Categories of Data Subjects

  • Customer’s clients (B2B and/or B2C)
  • Customer’s employees or representatives

7. Duration of Processing

Wantly processes personal data for the duration of the agreement under which the Service is provided, and thereafter only for as long as is necessary to delete or return the data in accordance with the section on Data Retention and Deletion, or for as long as retention is required by applicable law.

8. Processor Obligations

Wantly shall:

  • process personal data only on documented instructions from the Customer
  • ensure persons authorized to process data are bound by confidentiality
  • implement appropriate technical and organizational measures
  • assist the Customer in fulfilling GDPR obligations
  • notify the Customer of personal data breaches without undue delay
  • delete or return personal data upon termination (unless legally required to retain it)

9. Sub-processors

General authorisation

The Customer grants Wantly general authorisation to engage sub-processors to process personal data on the Customer’s behalf for the purpose of providing the Service.

Current sub-processors

The sub-processors engaged by Wantly for the processing of Customer Data are:

Sub-processor
Purpose
Location
AWS
Hosting and infrastructure
EU
HubSpot
CRM and email communication
EU / US
Intercom
Support and in-app messaging
EU / US
OpenAI
AI processing: import, translation, drafting
US
Anthropic
AI processing: import, translation, drafting
US
Google (Gemini)
AI processing: import, translation, drafting
EU / US

AI sub-processors

Wantly uses the business or API services of its AI sub-processors. Under those services, the contents of Customer Data submitted for processing are not used to train the providers’ models. Wantly has entered into data processing agreements with each AI sub-processor.

Obligations

Wantly enters into a written agreement with each sub-processor imposing data protection obligations no less protective than those set out in this Agreement, and remains responsible for its sub-processors’ performance of those obligations.

Changes to sub-processors

Wantly will notify the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or in-app notification. The Customer may object on reasonable grounds relating to data protection within 14 days of the notice. If the Customer objects and the parties cannot agree on a solution, the Customer may terminate the affected part of the Service without penalty.

Customer-initiated integrations

Third-party services that the Customer connects to the Service, for example the Customer’s own CRM, ERP, accounting, e-commerce, e-signature, or payment provider, are not Wantly’s sub-processors. Where the Customer instructs Wantly to transmit personal data to such a service, the Customer is responsible for its own relationship with that provider, including any data processing agreement required with it.

10. International Transfers

Where personal data is transferred outside the EEA, including to AI sub-processors and support and CRM providers established in the United States, Wantly ensures appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • supplementary technical and organisational measures where required
  • reliance on an adequacy decision where one applies to the recipient

11. Security Measures

Wantly implements appropriate technical and organizational measures, including:

  • encryption in transit (HTTPS)
  • secure cloud infrastructure (AWS)
  • access controls and role-based permissions

12. Assistance to Controller

Wantly shall assist the Customer in:

  • responding to data subject requests
  • ensuring compliance with security obligations
  • conducting data protection impact assessments (where applicable)

13. Audits and Inspections

Wantly will make available to the Customer the information reasonably necessary to demonstrate compliance with this Agreement and Article 28 of the GDPR, including responses to reasonable data protection questionnaires and any security documentation or third-party certifications Wantly holds.

Where that information is not sufficient, the Customer may request an audit of the processing activities relevant to the Service. Such audits:

  • may be carried out no more than once in any 12-month period, unless required by a supervisory authority or following a personal data breach
  • require at least 30 days’ prior written notice
  • shall be conducted during normal business hours and without unreasonable disruption to Wantly’s operations
  • are subject to confidentiality obligations
  • shall be carried out at the Customer’s own cost

The Customer may appoint an independent auditor, provided that the auditor is not a competitor of Wantly and is bound by confidentiality obligations.

14. Data Breach

In the event of a personal data breach affecting Customer Data in systems operated by Wantly, Wantly shall notify the Customer without undue delay after becoming aware of it, and in any event within 72 hours.

Where a personal data breach occurs at a sub-processor, Wantly shall notify the Customer without undue delay after establishing that Customer Data is affected.

The notification shall include, to the extent available:

  • the nature of the breach and the categories and approximate number of data subjects and records concerned
  • the likely consequences of the breach
  • the measures taken or proposed to address the breach and mitigate its effects
  • a contact point for further information

Wantly shall cooperate with the Customer and provide reasonable assistance in the Customer’s own notification obligations under Articles 33 and 34 of the GDPR.

Forwarding of a proposal link by the Customer or by a recipient of that link is not a personal data breach on Wantly’s part.

15. Data Retention and Deletion

Upon termination or expiry of the agreement under which the Service is provided, the Customer may export Customer Data from the Service for 30 days.

After that period, Wantly will delete Customer Data from active systems within 30 days and from backups within 90 days, or return it to the Customer where the Customer so requests before the end of the export period.

Wantly may retain personal data where, and for as long as, retention is required by applicable law, including accounting and tax obligations, and will continue to protect any retained data in accordance with this Agreement.

16. Liability

Each party shall be responsible for its own compliance with applicable data protection laws.

17. Governing Law

This Agreement shall be governed by the laws of the Republic of Lithuania.

18. Contact

UAB Wantly

V. Nageviciaus str. 3, LT-08237 Vilnius, Lithuania
Company code 307039973

Data protection:
privacy@wantly.eu
Related policies

Terms of Service

How the Service may be used
Read
→

Privacy Policy

What personal data we process and why
Read
→

Cookie Policy

Cookies and similar technologies
Read
→

Data Processing Agreement

Controller–processor terms and sub-processors
You are here
Ready when you are

See how your team would build, send and track proposals in Wantly.

📅  Book a demo
wantly-full-white logo

Built for distributors, manufacturers, wholesalers and teams that need accurate products, pricing and margins in every offer.

GDPR
EU hosted
SSL protected
Product
Product CatalogProposal EditorInteractive ProposalsTracking & AnalyticsAI in WantlyAll features →
Solutions
Wholesale & DistributionManufacturingEquipment & MachineryConstruction & MaterialsInterior & FurnishingAll industries →
Explore
PricingAboutSuccess StoriesResourcesAPI documentationContact
Legal
Legal & policiesTerms of ServicePrivacy PolicyCookie PolicyData Processing Agreement
© 2026 Wantly. All rights reserved.
All systems operational
·
English