LEGAL

Data Processing Agreement

Last updated: September 9, 2026

Draft for review — not yet reviewed by a solicitor

This template is provided for review. It has not yet been reviewed by a solicitor — request a countersigned copy at hello@wrenda.ai. Please read it as a statement of how Wrenda actually processes data and as the starting point for a signed agreement, not as legally verified drafting. If your organisation requires its own DPA or the standard UK IDTA/SCC modules, send them to us and we will work from those instead.

1. Parties, Scope and Roles

This Data Processing Agreement (“DPA”) forms part of, and is subject to, the Terms of Service between Wrenda of 33 John Ireland Way, Pulborough, West Sussex, United Kingdom (“Wrenda”, “we”, the Processor) and the customer that subscribes to the Service (“you”, the Controller).

It applies where Wrenda processes personal data on your behalf in providing the Service. It is written against the UK GDPR (as retained by the Data Protection Act 2018) and, where the EU GDPR applies to you, is intended to satisfy the equivalent Article 28 requirements. Where Wrenda decides the purposes of processing — your own account and billing data, our own marketing site — Wrenda is the controller and the Privacy Policy governs instead. In the event of a conflict on data protection matters, this DPA prevails over the Terms of Service.

2. Subject Matter, Duration, Nature and Purpose (Art. 28(3))

  • Subject matter: Wrenda's provision of the Service — an intelligent reverse proxy that detects AI and search crawlers, optimizes and pre-renders web page content for them, caches the results, exposes a Model Context Protocol (MCP) endpoint on your domains, and reports on crawler and AI-citation activity.
  • Duration: for as long as your subscription is in effect, plus the retention periods in clause 10 and any period required by law.
  • Nature of processing: collection, transient transmission and proxying, transformation and enrichment by AI models, headless-browser rendering, caching, structured storage, aggregation, display in a dashboard, email reporting, deletion.
  • Purpose: solely to deliver, secure, support and improve the Service for you, as instructed by you through your configuration and this DPA.
  • Your obligations and rights: you remain the controller, are responsible for the lawfulness of the data you route through the Service, for your own privacy notices and lawful bases, and for the instructions you give us. Your rights are set out in this DPA, in particular clauses 4, 9, 10, 11 and 12.

3. Categories of Data Subjects and Personal Data

Wrenda is deliberately narrow here, and the list below is exhaustive for processing carried out on your behalf. Notably, Wrenda does not store the IP addresses of ordinary human visitors to your website: that traffic is proxied and handled transiently at the edge, and no log record is written for it.

3.1 Categories of data subjects

  • Your personnel who hold Wrenda accounts (administrators, team members you invite)
  • End users and operators of AI agents that call the MCP endpoint published on your domain
  • Individuals whose personal data happens to appear in the content of your own web pages that you configure for optimization or pre-rendering

3.2 Categories of personal data

  • MCP endpoint caller records: IP address, user agent, timestamp, the tool invoked and its arguments — retained 14 days
  • Account-holder contact and administrative data: name, work email, role, tenant membership, and — in administrative audit logs only — the IP address from which an administrative action was taken, retained 14 days
  • Your web page content: processed transiently for optimization and pre-rendering, and cached in its optimized form. It may incidentally contain personal data that you have published, such as author names, staff biographies, testimonials or contact details
  • Crawler telemetry: bot user agent, URL path, timestamp, action taken and cache metadata. This does not identify individuals and contains no IP address, but is listed for completeness — retained 14 days raw, 13 months in weekly aggregate

No special category data. The Service is not designed for and must not be used to route special category data under Art. 9, criminal offence data under Art. 10, or children's data as a primary audience, unless separately agreed in writing.

4. Processing on Documented Instructions — Art. 28(3)(a)

Wrenda will process personal data only on your documented instructions, including in relation to transfers to a third country, unless required to do otherwise by UK or EU law — in which case we will tell you before processing, unless that law prohibits it on important grounds of public interest.

Your documented instructions consist of: this DPA, the Terms of Service, and the configuration you set in the Service (domains, serving modes, crawler and content rules, pre-render settings and scripts, MCP tools, tracked prompts, report and alert settings). Instructions outside these must be agreed in writing and may attract additional charges. Wrenda will inform you if, in its opinion, an instruction infringes data protection law. Wrenda does not use your data, or any content processed on your behalf, to train AI models, and does not sell it.

5. Confidentiality — Art. 28(3)(b)

Wrenda ensures that every person authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality — contractual for personnel and contractors, or a statutory duty — that survives the end of their engagement. Access is granted on a need-to-know, least-privilege basis and is removed promptly when no longer required.

6. Security Measures — Art. 28(3)(c) and Art. 32

Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to individuals, Wrenda implements and maintains at least the following:

  • Encryption of personal data in transit (TLS) and at rest, provided by the underlying Cloudflare platform
  • Logical tenant isolation — every query and cache key is scoped to a single customer account
  • Authentication delegated to Google sign-in; scoped, least-privilege API tokens for every internal integration; API keys stored hashed and shown once
  • Role-based access control and administrative audit logging of privileged actions
  • Data minimisation and short retention windows as the primary risk control — see clause 10
  • Dependency vulnerability auditing and secret scanning in the continuous-integration pipeline on every change; secrets held in the platform secret store, never in source control
  • Point-in-time database recovery and nightly encrypted backups, supporting timely restoration of availability after an incident
  • Periodic review of the effectiveness of these measures, and of the access rights granted under them

Wrenda may update these measures over time provided the level of security is not reduced.

7. Sub-processors — Art. 28(3)(d), 28(2) and 28(4)

You give Wrenda general written authorisation to engage the sub-processors listed below. Wrenda imposes on each of them data protection obligations no less protective than those in this DPA, and remains fully liable to you for their performance.

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting, edge proxy, D1 and KV storage, Workers AI, Browser RenderingUS / global edge
Google LLC (Google APIs)OAuth sign-in; Search Console and Analytics data where the customer connects themUS / EU
Stripe, Inc.Payment and subscription processingUS / EU
Microsoft Corporation (Microsoft Graph)Transactional email deliveryUS / EU
Resend, Inc.Alert email deliveryUS
Bright Data Ltd.Submitting prompts to AI platforms and collecting responses for citation trackingIsrael / US
OpenRouter, Inc. and Anthropic PBCAI text generation for content optimization and generated content featuresUS
OpenAI, L.L.C. (contingent)Configured as a fallback AI text-generation provider; not in active use. We will give notice under clause 7 before activating it.US

Change notice. Wrenda will give you at least 30 days' notice by email to your account administrators before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none can be found, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees.

8. Assistance with Data Subject Rights — Art. 28(3)(e)

Taking into account the nature of the processing, Wrenda will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise data subject rights under Chapter III of the UK GDPR.

In practice: the dashboard provides self-service export and deletion of account data; the short retention windows in clause 10 mean most log data has already been erased; and for anything not covered, we will respond to a written request for assistance within 5 working days and in any event in time for you to meet your one-month deadline. If a data subject contacts Wrenda directly about data we process on your behalf, we will not respond substantively but will refer them to you and tell you promptly.

9. Breach Notification and Wider Assistance — Art. 28(3)(f)

Wrenda will notify you without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting personal data processed on your behalf, so that you can meet your own 72-hour obligation under Art. 33. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — providing information in phases where it is not all available at once.

Wrenda will also assist you, taking into account the nature of processing and the information available to it, with your obligations under Articles 32 to 36 — security of processing, breach notification to the ICO and to data subjects, data protection impact assessments and prior consultation.

10. Deletion or Return on Termination — Art. 28(3)(g)

At your choice, Wrenda will delete or return all personal data processed on your behalf at the end of the provision of the Service, and delete existing copies, unless UK or EU law requires storage.

  • You can export your data at any time from Settings → General; account deletion there is an immediate hard delete, not a soft delete.
  • Unless you request otherwise, account and configuration data is deleted within 30 days of termination.
  • Short-lived logs erase themselves on a nightly schedule regardless of termination: crawler telemetry, audit logs, event and MCP records, MCP tool executions and agent-test records after 14 days.
  • Weekly aggregates, AI-citation history and page-optimization history are held for 13 months; email notification records for 12 months; billing records for as long as UK tax law requires, typically 7 years.
  • Cached optimized pages expire on their configured TTL and are purged when the domain or rule is removed.

11. Audit and Information Rights — Art. 28(3)(h)

Wrenda will make available to you all information necessary to demonstrate compliance with the obligations in Art. 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance we will answer written security and privacy questionnaires and provide the relevant certifications and reports of our sub-processors. Where that is not sufficient, you may conduct an audit on at least 30 days' written notice, no more than once in any 12-month period (unless required by a supervisory authority or following a personal data breach), during business hours, subject to confidentiality, and in a way that does not unreasonably disrupt the Service. Each party bears its own costs for the first such audit in any 12-month period.

12. International Transfers

Wrenda is established in the United Kingdom. Several sub-processors listed in clause 7 are established outside the UK, principally in the United States. Where personal data is transferred out of the UK to a country without UK adequacy regulations, the transfer is made under the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, or — for EU-origin data — the EU Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor), in each case as incorporated into the data processing terms published by that sub-processor and accepted by Wrenda when using their service. Where a recipient is certified under the UK Extension to the EU-US Data Privacy Framework, that mechanism may be relied on instead. We can point you to each sub-processor's published data processing terms on request. Wrenda has not carried out its own transfer risk assessment for each recipient and does not hold separately executed transfer instruments.

13. Liability, Term and Governing Law

This DPA takes effect when you begin using the Service and continues for as long as Wrenda processes personal data on your behalf. The limitations and exclusions of liability in the Terms of Service apply to this DPA, except where data protection law does not permit them to. If any provision of this DPA is found unenforceable, the remainder continues in effect.

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to any mandatory rights of data subjects or the powers of a supervisory authority.

14. Contact and Signed Copies

To request a countersigned copy of this DPA, to raise a data protection question, or to send us your own DPA to review:

hello@wrenda.ai

Wrenda, 33 John Ireland Way, Pulborough, West Sussex, United Kingdom

See also our Privacy Policy and Terms of Service.