Data processing agreement (WireWhy Pro)
Draft awaiting legal review before WireWhy Pro goes on sale.
This agreement under Article 28 of the GDPR is between the firm that uses WireWhy Pro (the controller, "you") and DevUnit.pl Mateusz Hinca, ul. Arcangela Corellego 17/12, 03-289 Warszawa, Polska, NIP 839-312-42-45, REGON 368565464 (the processor, "we"). It is part of the WireWhy Pro terms. You accept it when you create your Pro workspace; we record the version you accepted and when.
1. Subject matter and duration
We process, on your behalf, the personal data you put into Pro about your customers and the people connected with your jobs, so that we can provide Pro to you. This agreement lasts as long as we process such data for you: from the creation of your workspace until its data has been deleted (section 11).
2. Nature and purpose
Storing, organising, and retrieving the data; using it in planning, counting, and pricing; producing quotes and their PDFs; making the customer’s page available to whoever holds the link you sent; recording the customer’s answers; reminding you of what a job is waiting for; exporting it for you; and deleting or anonymising it. The only purpose is to provide Pro to you, keep it secure, and help you when you ask.
When you ask: sending the quote, a reminder about it, or your own answer to your customer by e-mail (from WireWhy’s address mail@wirewhy.com, with your firm’s name and a reply address of the job’s own) or by SMS (from the sender "WireWhy", to Polish and German numbers); receiving your customer’s e-mail answers, with their attachments, into the job’s conversation; and, if you switch it on, sending you a copy of each answer. All through Brevo (Sendinblue SAS).
3. Types of personal data
- The customer’s name, phone number, and email address; whether they are a private person or a company, and a company’s tax number; their billing address and the addresses of their sites; and the notes you keep about them (as far as you enter them).
- The site’s address and what you record about the job: its status, the description of the installation (including the names you give rooms), and the existing installation.
- The quotes: their scope, rows, prices, terms, and title, and the PDFs made from them.
- From the customer’s page: when the link was first opened, whether and when the quote was accepted, and the text of any question the customer sends.
- Technical data from the customer’s page: the IP address, used to deliver the page and to limit requests per connection and turned into an approximate location (country and city) in the request log, after which the address is discarded.
- Photos and documents you add to a job, with their captions. Photos may show the customer’s home, property, or people; their metadata (camera, time, GPS position) is removed when they are uploaded, before anything is stored.
- The reminders you set on a job, with their notes.
- Any other personal data you type into Pro’s free-text fields.
- The conversation on each job: the messages you send through Pro (the quote, reminders, your answers) and your customer’s answers by e-mail and questions on the quote page, with the e-mail address or phone number of the recipient or sender, the sender’s name, the subject, the text, the attachments (kept among the job’s files, hidden from the customer, photos without their metadata), whether a message was delivered and when (in the job’s record the recipient is partly hidden, for example +48 600 *** 200), and whether you have read it.
Special categories of data (Article 9 GDPR) are not needed for Pro; do not enter them.
4. Data subjects
Your customers and prospective customers, the people you name as contacts on a job, and anyone who opens a customer link you sent.
5. Your instructions
We process the data only on your documented instructions: this agreement, the Pro terms, and what you do in Pro (for example creating a job, sending a link, withdrawing it, deleting a job, or exporting, anonymising, or deleting a customer), including as regards any transfer outside the European Economic Area. If we believe an instruction infringes data protection law, we tell you. If EU or Polish law requires us to process the data otherwise, we tell you first, unless that law forbids it.
6. Confidentiality
Today only the operator of WireWhy has access to the data, and is bound to keep it confidential. Anyone we authorise in the future will commit to confidentiality in writing before getting access, and will have only the access their work needs.
7. Security (Article 32 GDPR)
- Hosting in the European Union: Microsoft Azure, region Poland Central, for the application, the PostgreSQL database, and the files (Azure Blob Storage).
- Encryption in transit everywhere (HTTPS; TLS required by the database and by the file storage), and Azure’s encryption at rest.
- Photos added to a job are decoded and encoded again on upload: no metadata, the GPS position included, is stored or shown; every file is checked by its content, served with its own type only, and a document opened on its own can run nothing.
- Files (quote PDFs, logos, the photos and documents of jobs) in a private container without public access and without account keys: only the application reaches it, through its managed identity, and serves a file only after its own access checks.
- Firms kept apart in three layers: the application finds the workspace from the signed-in account, never from the address; every query is filtered by workspace; and the database enforces row-level security on every Pro table, so one firm’s rows can be neither read nor written in another firm’s session. A request for another firm’s data answers "not found". Automated tests cover every route.
- Customer links: 128 random bits, stored only as a SHA-256 hash; the page shows only the copy of the quote you chose to share, never your price list, margin, or hours; links expire after 7 to 60 days, can be withdrawn, are not indexed by search engines, send no referrer, and are rate-limited.
- Logs: link codes are replaced by a placeholder in every request record, IP addresses are discarded after the approximate location is worked out, no customer data is written to telemetry, and quote contents are never logged.
- Sign-in through Microsoft Entra External ID (authorisation code flow with PKCE); the session cookie is HttpOnly.
- Administrative access to production is limited to the operator’s own accounts, protected by multi-factor authentication.
- Database backups for 7 days; deleted files recoverable for 7 days, then gone.
- E-mail and SMS through Brevo, with the data hosted in the European Union: e-mails go from the domain wirewhy.com authenticated with SPF, DKIM, and DMARC, without tracking of opens or clicks; the API key and the webhooks’ secret are kept as secrets of the application, and Brevo’s calls are accepted only with that secret (and only from Brevo’s addresses where set); a customer’s answer reaches only its own job, through a reply address unique to the job’s conversation (a 128-bit code stored only as a hash), automatic replies, bounces, and spam are discarded, and attachments are checked and cleaned as uploads are; messages are shown as text, never as the e-mail’s own HTML; at most 50 SMS and 200 e-mails a day per firm and 3 messages a day per recipient.
We review these measures as Pro develops and may change them, as long as the level of protection does not fall.
8. Subprocessors
You authorise us to use Microsoft Ireland Operations Limited (Microsoft Azure: hosting, database, file storage, and Application Insights for technical logs, all in the European Union) as a subprocessor, under Microsoft’s data protection addendum, which imposes on Microsoft obligations no weaker than ours under this agreement.
You also authorise us to use Sendinblue SAS (Brevo), 17 rue Salneuve, 75017 Paris, France, as a subprocessor to send the e-mails and SMS you send to your customers and to receive their e-mail answers, under Brevo’s data processing agreement (its terms of service, appendix 3), which imposes on Brevo obligations no weaker than ours under this agreement. Brevo hosts the data in the European Union (France and Belgium); its own subprocessors, among them the partners that route SMS to mobile networks, are listed in that agreement.
An e-mail or SMS you send passes through the recipient’s mail provider or mobile network on its way, as any e-mail or SMS does; they deliver it to the recipient and are not our subprocessors.
Microsoft Entra External ID signs you in to your own account and Paddle handles your payments; neither receives your customers’ data, so neither is a subprocessor under this agreement (we and Paddle process your own account and billing data as described in the Privacy notice).
We tell you by email and on this page at least 30 days before we add or replace a subprocessor. You may object in that time; if we cannot meet a reasonable objection, you may end the contract and we refund the unused part of a period you paid for.
9. Help with data subjects’ requests
You answer your customers’ requests (access, rectification, erasure, restriction, objection, portability). Pro lets you see and correct a customer’s details, delete a job, withdraw a link, and download the PDFs; for anything you cannot do yourself, we help within a reasonable time and without charge. If a data subject writes to us, we pass the request on to you without undue delay and answer them only to say so.
10. Personal data breaches and other help
We tell you without undue delay, and where possible within 48 hours, after we become aware of a personal data breach affecting your data: what happened, the categories and approximate number of people and records concerned, the likely consequences, and what we have done and propose to do. We add what we learn later, and help you notify the supervisory authority and the people concerned. We also help, in proportion to our role, with data protection impact assessments and prior consultation.
11. End: deletion or return
Before your workspace is deleted, you can download the quote PDFs and ask for a full copy of the workspace’s data (Pro terms, section 10). When you delete a job, or the workspace is deleted (Pro terms, sections 10 and 12), we delete its personal data from the live systems at once, from the backups within 7 days, and from the technical logs within 90 days, unless the law requires us to keep it. The end of a Pro subscription alone does not delete anything.
The job’s conversation (the messages’ words, their delivery, and the answers’ attachments among the job’s files) is kept with the job and deleted with it, or with the customer; anonymising a customer clears the words and names in their jobs’ conversations and ends their reply addresses, so nothing new reaches those jobs. Brevo keeps a message and its delivery events only as its agreement and the account’s settings provide, to deliver it and report on it; the link between a message and its delivery report is kept 7 days, and a received e-mail’s fingerprint (a hash of its Message-ID, to take it only once) 30 days.
12. Information and audits
We give you the information you need to show that this agreement is kept: this agreement, the description of the measures in section 7, and Microsoft’s and Brevo’s certifications and audit reports for their services. If written answers are not enough, or a supervisory authority asks for it, you or an auditor bound to confidentiality may audit us at most once a year, with 30 days’ notice, during working hours, remotely where possible, and at your cost; an audit never gives access to another firm’s data or to Microsoft’s or Brevo’s facilities.
13. Transfers outside the European Economic Area
None are planned: the data is stored and processed in the European Union. Microsoft may access data from outside it only as its data protection addendum allows (the EU Data Boundary, the European Commission’s standard contractual clauses, and the EU–US Data Privacy Framework). We tell you before anything about this changes. For firms in Brazil: the European Union and Brazil recognise each other’s protection as adequate.
Brevo keeps the messages’ data in the European Union. Some of the partners that route SMS to mobile networks are outside it; Brevo’s agreement names them and covers them with the European Commission’s standard contractual clauses or the EU–US Data Privacy Framework.
14. Your obligations
You make sure you have a lawful basis for the data you enter and that your customers are informed (the customer’s page links to Privacy on quote pages, which names you as responsible); you keep your sign-in safe; and you tell us at once if you notice anything that could be a breach.
15. Liability and precedence
Liability under this agreement follows Article 82 GDPR and section 11 of the Pro terms. Where this agreement and the Pro terms differ on data protection, this agreement applies. It is governed by Polish law.