Framework only; not yet effective. This draft is not a signed DPA and is not ready for customer acceptance. The final document requires the contracting entity, transfer mechanism, jurisdiction-specific terms, security annex review, and legal approval.
1. Parties and scope
This Data Processing Addendum will supplement the agreement between the organization using Wildflower (“Customer”) and the Wildflower contracting entity. It applies only when Wildflower processes personal data contained in Customer Content on Customer’s behalf to provide the Services.
Customer is the controller or business, and Wildflower is the processor or service provider, unless applicable law assigns different labels. Account, security, service, and business data that Wildflower handles for its own operational purposes remains governed by the Privacy Notice.
2. Customer instructions
Wildflower will process Customer Personal Data only to provide, secure, support, and improve the contracted Services; follow documented Customer configuration and requests; comply with the agreement; and meet legal obligations. The agreement, API calls, provider selections, project configuration, and written support instructions together form Customer’s documented instructions.
If Wildflower believes an instruction violates applicable data-protection law, it may suspend the affected processing while the parties resolve the issue. Wildflower will not sell Customer Personal Data, use it for cross-context behavioral advertising, or use Customer sandbox content to train AI models.
3. Customer responsibilities
Customer is responsible for the lawfulness of Customer Personal Data and its instructions; required notices and consents; provider and region selection; user permissions; credential scope; workload configuration; and responding to data-subject requests where Customer controls the data.
Customer must not submit regulated or highly sensitive personal data unless the parties have agreed in writing that the Services, providers, locations, and safeguards support that use.
4. Confidentiality and security
Wildflower will limit access to people and service providers who need it to perform the Services and who are subject to appropriate confidentiality obligations. Wildflower will maintain technical and organizational measures appropriate to the current risk and service design.
Current measures include transport encryption; hashed project API keys; role- and project-scoped authorization; encryption of stored provider credentials; bounded inputs; redaction of secrets from errors and logs; content-minimized operational telemetry; protected database backups; and recovery procedures. The final security annex will document the reviewed production controls. This draft makes no certification or audit-report claim.
5. Subprocessors and customer-directed providers
Customer authorizes Wildflower to engage the subprocessors identified on the Service Providers and Subprocessorspage. Wildflower will require subprocessors handling Customer Personal Data on its behalf to provide data-protection obligations appropriate to their services.
In customer-connected or BYOK mode, a sandbox provider selected and contracted by Customer is ordinarily a customer-directed third-party service rather than Wildflower’s subprocessor. Customer is responsible for its agreement, data location, configuration, and instructions to that provider. If Wildflower later selects or resells a provider for Customer, the applicable schedule and subprocessor list will identify that different relationship.
6. Assistance
Taking into account the nature of processing and information available to Wildflower, Wildflower will provide reasonable assistance with data-subject requests, security assessments, impact assessments, regulatory consultations, and Customer compliance obligations. Customer remains responsible for deciding how to respond and for using available account, project, provider, and deletion controls first.
7. Security incidents
Wildflower will notify Customer without undue delay after confirming a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Wildflower. Notice will include information reasonably available to Wildflower and may be provided in phases. Customer is responsible for notifications it must give to individuals or regulators.
8. Return and deletion
At the end of the Services, Wildflower will delete or return Customer Personal Data as required by the agreement and Customer’s available instructions, unless law requires retention. Deletion may wait for sandbox cleanup and protected backup rotation. Organization-owned data is not deleted merely because an individual member leaves or deletes a User Profile.
9. Reviews and audits
Wildflower will make information reasonably necessary to demonstrate compliance available under appropriate confidentiality protections. The final DPA will define a proportionate audit process, including the use of current independent reports when available, advance notice, scope, timing, security constraints, and responsibility for extraordinary costs.
10. International transfers
The final DPA will identify applicable data locations and lawful transfer mechanisms, including standard contractual clauses or an alternative where required. Customer remains responsible for the regions and providers it selects in customer-directed mode.
11. Processing details
| Topic | Description |
|---|---|
| Subject matter | Provider-neutral creation and management of isolated compute environments. |
| Duration | The service term plus deletion and protected-backup rotation, unless law requires longer retention. |
| Nature and purpose | Receiving, transmitting, operating on, securing, troubleshooting, and deleting Customer Content according to Customer instructions. |
| Data subjects | Customer personnel, users of Customer applications, and other people whose data Customer chooses to process. |
| Personal data | Data contained in code, commands, environment values, files, input, output, logs, and configuration submitted by Customer. |
| Sensitive data | Not required for the service. Customer must not submit it without written agreement and suitable configuration. |
| Frequency | As initiated by Customer through API and account operations. |
12. Term and precedence
The final DPA will remain in effect while Wildflower processes Customer Personal Data and will state its order of precedence with the Terms, an Order Form, and service-specific schedules. Until then, this page is a product and legal-readiness framework rather than an agreement.
13. Questions
For questions about data processing terms, email legal@wildflower.computer. Do not include Customer Personal Data, credentials, or sandbox content in the message.
