Legal

Data processing terms

Draft — pending legal counsel. This document sets out our intended terms and the structure of the final agreement. It is not yet the binding version; the wording below will be replaced once reviewed. Dated commitments and definitions are marked as placeholders.

How Wrenna processes personal information on behalf of a business — the terms a controller needs before trusting a processor with a caller’s data.

1. Roles and scope

The business as controller, Wrenna as processor, and the caller data these terms govern.

[Full clause to be supplied by counsel.]

2. Instructions and purpose

Wrenna processes caller content only to provide the service and on the business’s documented instructions — never for our own ends.

[Full clause to be supplied by counsel.]

3. Confidentiality

The confidentiality obligations on everyone at Wrenna who could reach the data, and the access controls behind them.

[Full clause to be supplied by counsel.]

4. Security measures

Tenant isolation enforced at the database, encryption of recordings, per-request access to audio, and an audit trail for sensitive actions.

[Full clause to be supplied by counsel.]

5. Sub-processors

The list of sub-processors, the commitment to bind them to equivalent terms, and how we notify you of changes.

[Full clause to be supplied by counsel.]

6. Data subject requests and breach notice

How we help you answer a caller’s request, and how quickly we tell you if something goes wrong.

[Full clause to be supplied by counsel.]

7. Deletion and return

What happens to caller content when the agreement ends, and the retention windows in the meantime.

[Full clause to be supplied by counsel.]

8. International transfers

Where data is processed and the safeguards applied to any transfer, to be confirmed by counsel.

[Full clause to be supplied by counsel.]