Legal
Data processing terms
Draft — pending legal counsel. This document sets out our intended terms and the structure of the final agreement. It is not yet the binding version; the wording below will be replaced once reviewed. Dated commitments and definitions are marked as placeholders.
How Wrenna processes personal information on behalf of a business — the terms a controller needs before trusting a processor with a caller’s data.
1. Roles and scope
The business as controller, Wrenna as processor, and the caller data these terms govern.
[Full clause to be supplied by counsel.]
2. Instructions and purpose
Wrenna processes caller content only to provide the service and on the business’s documented instructions — never for our own ends.
[Full clause to be supplied by counsel.]
3. Confidentiality
The confidentiality obligations on everyone at Wrenna who could reach the data, and the access controls behind them.
[Full clause to be supplied by counsel.]
4. Security measures
Tenant isolation enforced at the database, encryption of recordings, per-request access to audio, and an audit trail for sensitive actions.
[Full clause to be supplied by counsel.]
5. Sub-processors
The list of sub-processors, the commitment to bind them to equivalent terms, and how we notify you of changes.
[Full clause to be supplied by counsel.]
6. Data subject requests and breach notice
How we help you answer a caller’s request, and how quickly we tell you if something goes wrong.
[Full clause to be supplied by counsel.]
7. Deletion and return
What happens to caller content when the agreement ends, and the retention windows in the meantime.
[Full clause to be supplied by counsel.]
8. International transfers
Where data is processed and the safeguards applied to any transfer, to be confirmed by counsel.
[Full clause to be supplied by counsel.]