WPWriter Data Processing Agreement (DPA)
Last updated: September 27, 2026
This Data Processing Agreement ("DPA") forms part of the WPWriter Terms of Service between YLabs, the operator of WPWriter ("WPWriter", "we", "Processor"), and the customer using WPWriter ("Customer", "Controller"). It applies whenever WPWriter processes personal data on the Customer's behalf and the EU General Data Protection Regulation (GDPR), the UK GDPR or the Swiss FADP applies to that processing.
1. How this DPA becomes binding
This DPA is incorporated into the Terms of Service. It applies automatically to every Customer to whom the GDPR applies, from the moment the Customer uses WPWriter, including the WPWriter connector for Claude and ChatGPT. No signature is required. A countersigned copy is available on request from info@wpwriter.com.
2. Roles and scope
The Customer is the controller of the personal data on its WordPress site. WPWriter acts as a processor and processes that data only to provide the service the Customer uses: reading, creating and editing content and settings on the Customer's WordPress site, and the related account, support and billing functions.
Details of the processing are set out in Annex 1.
3. Processor obligations (GDPR Article 28(3))
WPWriter will:
- process personal data only on the Customer's documented instructions. The Customer's use and configuration of the service are those instructions. WPWriter will tell the Customer if it believes an instruction infringes data protection law;
- ensure that everyone authorised to process the personal data is bound by confidentiality;
- apply the technical and organisational measures in Annex 2;
- engage subprocessors only as described in section 4;
- assist the Customer, taking into account the nature of the processing, in responding to data subject requests (Articles 12 to 23 GDPR);
- assist the Customer with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR);
- notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide the information the Customer reasonably needs to meet its own obligations;
- at the end of the service, delete the Customer's personal data within 30 days of account deletion, unless law requires retention. On request before deletion, WPWriter will return the data it holds in a common format. Content on the Customer's own WordPress site stays on that site and is not affected;
- make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits. These are carried out by written questionnaire in the first instance, or by the Customer or an auditor it appoints, with reasonable notice and at the Customer's cost.
4. Subprocessors
The Customer gives general authorisation for WPWriter to use subprocessors. The current list, with purposes and locations, is published at www.wpwriter.com/subprocessors.
WPWriter imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for its subprocessors.
WPWriter will update the list at least 14 days before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for it.
5. International transfers
WPWriter's servers and database are hosted in the European Union: DigitalOcean, Frankfurt, Germany. Where a subprocessor processes personal data outside the EEA, the transfer is covered by one of the following:
- an adequacy decision of the European Commission;
- the EU-U.S. Data Privacy Framework, where the recipient is certified;
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with supplementary measures where needed.
WPWriter is operated from Israel, which benefits from an EU adequacy decision.
6. AI assistants chosen by the Customer
When the Customer uses WPWriter through an AI assistant such as Claude or ChatGPT, that assistant's provider is engaged by the Customer directly, under the Customer's own agreement with that provider. It is not a subprocessor of WPWriter.
WPWriter's own AI generation features use the AI providers listed on the subprocessor page. They are used only when the Customer uses those features.
7. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service, as far as the law permits. If this DPA conflicts with the Terms of Service regarding the processing of personal data, this DPA prevails.
Annex 1 - Details of processing
- Subject matter and purpose: providing WPWriter, which covers content management on the Customer's WordPress site (reading, creating and editing posts, pages, media and SEO settings), AI-assisted writing when used, account management, support and billing.
- Duration: for as long as the Customer uses WPWriter, plus up to 30 days after account deletion.
- Nature of processing: retrieval, storage, modification, transmission and deletion.
- Categories of data subjects: the Customer's account users, and people whose personal data appears in the Customer's WordPress content, such as authors, commenters or people named on pages.
- Categories of personal data:
- account data: name, email, login data;
- WordPress connection data, stored encrypted;
- website content and metadata processed at the Customer's instruction;
- technical logs: IP address, request metadata.
- Special categories: none are intended. The Customer decides what content its site contains.
Annex 2 - Technical and organisational measures
- Encryption in transit: HTTPS with TLS 1.2 or higher on all wpwriter.com endpoints.
- Encryption at rest of stored credentials, such as WordPress application passwords and connector tokens.
- EU hosting (Frankfurt) with managed database backups.
- Database access only over authenticated, encrypted connections.
- Least-privilege access to production systems, limited to authorised personnel who are bound by confidentiality.
- Access to the Customer's WordPress site only through the connection the Customer creates, which the Customer can revoke at any time from wp-admin.
- Logging of administrative actions performed through the connector.
- Deletion of personal data within 30 days of account deletion.
- A process for handling and notifying personal data breaches.
Contact for data protection matters: info@wpwriter.com