Winly Data Processing Agreement (DPA)
Last Updated: April 28, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (“Agreement”) between:
Winly (“Processor”)
and
Customer (“Controller”)
This DPA governs the processing of Personal Data by Winly on behalf of the Customer.
1. Definitions
- “Personal Data”: Any information relating to an identified or identifiable individual.
- “Processing”: Any operation performed on Personal Data (e.g., collection, storage, use).
- “Controller”: The entity that determines the purposes and means of processing.
- “Processor”: The entity that processes data on behalf of the Controller.
- “Subprocessor”: A third party engaged by the Processor.
- “Applicable Data Protection Laws”: Includes GDPR, UK GDPR, CCPA/CPRA, and other relevant laws.
2. Scope & Roles
- The Customer acts as the Controller of Personal Data.
- Winly acts as the Processor.
- This DPA applies when Winly processes Personal Data on behalf of the Customer through its SaaS platform.
3. Nature and Purpose of Processing
Winly processes Personal Data to provide its all-in-one business management platform, including:
- Project and task management
- CRM and client data management
- HR and workforce management
- Financial data (invoices, payments, expenses)
- Communications and collaboration tools
Processing activities include storage, organization, retrieval, transmission, and deletion.
4. Categories of Data Subjects
Personal Data may relate to:
- Customer’s employees and contractors
- Customer’s clients and end-users
- Job applicants and candidates
- Business contacts
5. Types of Personal Data
May include:
- Names, emails, phone numbers
- Business and employment information
- Financial and billing data
- Communications and files
- Login and usage data
6. Processor Obligations (Winly)
Winly shall:
A. Processing Instructions
Winly shall process Personal Data:
- In accordance with the Customer’s documented instructions, as set forth in the Agreement, and
- As necessary to provide, maintain, secure, and improve the Service
Winly may also process Personal Data:
- To comply with applicable laws
- To prevent fraud, abuse, or security threats
- For internal analytics and service improvement, provided such processing does not identify individual data subjects where possible
B. Confidentiality
Ensure personnel with access to Personal Data are bound by confidentiality obligations.
C. Security Measures
Implement appropriate technical and organizational measures, including:
- Encryption (where appropriate)
- Access controls and authentication
- Secure infrastructure
- Monitoring and logging
D. Assistance to Controller
Provide reasonable assistance with:
- Data subject requests (access, deletion, etc.)
- Data protection impact assessments (DPIAs)
- Compliance obligations
7. Subprocessors
Winly may engage subprocessors to deliver the Service, including:
- Cloud hosting providers (e.g., AWS, Cloudflare R2)
- Payment processors (e.g., Stripe)
- Email and communication providers
Requirements
- Subprocessors are bound by data protection obligations
- They process data only as necessary
Updates
- Winly may update subprocessors
- Customers may object on reasonable grounds
8. International Data Transfers
Personal Data may be transferred outside the EEA/UK.
Winly ensures appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- Secure transfer mechanisms
9. Data Subject Rights
Winly shall assist the Customer in responding to requests from data subjects, including:
- Access
- Correction
- Deletion
- Data portability
The Customer remains responsible for responding to such requests.
10. Data Breach Notification
In the event of a Personal Data breach, Winly will:
- Notify the Customer without undue delay
- Provide relevant details (nature, impact, mitigation steps)
- Cooperate in remediation efforts
11. Data Retention & Deletion
Upon termination of the Agreement:
- Personal Data will be deleted within 30–90 days, unless retention is required by law
- Backup copies may persist temporarily
Upon request, Winly may:
- Return data where technically feasible
12. Audit Rights
Customer may request reasonable information to verify Winly’s compliance with this DPA.
Formal audits may be conducted:
- Only upon reasonable prior written notice (e.g., 30 days)
- No more than once per year, unless required by law or following a security incident
- During normal business hours
- In a manner that does not unreasonably disrupt Winly’s operations
Winly may satisfy audit requests by providing:
- Security documentation
- Certifications or reports (if available)
- Responses to security questionnaires
Any on-site or third-party audits:
- Must be conducted at Customer’s expense
- Subject to confidentiality obligations
13. Liability
Liability under this DPA is subject to the limitations set forth in the Terms of Service.
14. Governing Law
This DPA is governed by the laws specified in the Terms of Service.
15. Contact Information
For data protection inquiries:
Email: info@winly.io
Mailing Address: 1968 S Coast Hwy #803 Laguna Beach, CA 92651
