Data Processing Addendum (DPA)
Last updated: July 19, 2026 · Version 3.2 (Enterprise Readiness) · Effective December 26, 2025
Draft — pending legal counsel review. This Data Processing Addendum is a professional draft published so the public /dpa link advertised in our Terms and signup flow resolves to living text. It is not approved by counsel and must not be treated as final legal advice or a counsel-signed instrument until counsel review completes.
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Service between BIT FOUNDRY AI FZC LLC ("Workweaver," "we," "us," or "our") and you ("Customer," "you," or "your"). This DPA governs the processing of personal data in connection with the Workweaver AI workforce platform services.
Table of Contents
- 1. Definitions and Interpretation
- 2. Data Processing Roles
- 3. Customer Instructions and Approvals
- 4. Processor Obligations
- 5. AI Features Requiring Explicit Approval
- 6. Customer Control and Opt-Out Rights
- 7. Data Subject Rights
- 8. Security Measures
- 9. Sub-Processing
- 10. Cross-Border Data Transfers
- 11. Data Breach Notification
- 12. Audit and Transparency
- 13. Data Deletion and Return
- 14. Term and Termination
- 15. Governing Law
- 16. HIPAA / Business Associate (BAA) — Draft
1. Definitions and Interpretation
1.1 Definitions
Capitalized terms used in this DPA have the meanings set forth below:
| Term | Definition |
|---|---|
| "Approved AI Feature" | Any AI-driven capability that you have explicitly enabled through your account settings, onboarding process, or written confirmation. Current AI features are documented at www.workweaver.ai/features. |
| "Customer Content" | All data, information, and materials you provide to us or that we collect from your customers in connection with the Services. |
| "Customer Rules" | The workflows, automations, templates, scripts, configurations, and AI settings you create or approve within your account dashboard or through our onboarding process. |
| "Data Controller" | The natural or legal person who alone determines the purposes and means of the processing of personal data. For all processing under this DPA, you are the Data Controller. |
| "Data Processor" | The natural or legal person who processes personal data on behalf of the Data Controller. Workweaver acts as your Data Processor for all processing activities. |
| "DecisionTrace" | Our immutable audit logging system that captures evidence of AI decisions executed pursuant to your Customer Rules, including inputs, outputs, and performance metrics. |
| "Personal Data" | Any information relating to an identified or identifiable natural person. |
| "Processing" | Any operation or set of operations performed on personal data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction. |
| "Standard Mode" | The default operational mode that enables Approved AI Features you have explicitly enabled. |
| "Strict Mode" | The restricted operational mode where all AI decisions follow your explicit Customer Rules without any autonomous optimization. |
| "Sub-Processor" | Any third party engaged by us to process personal data on your behalf. |
1.2 Interpretation
- Singular/Plural: Words in the singular include the plural and vice versa.
- Headers: Section headers are for convenience only and do not affect interpretation.
- Hierarchy: In case of conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict regarding data processing.
2. Data Processing Roles
2.1 Our Role: Data Processor
Workweaver acts as your Data Processor for all processing of personal data under this DPA.
We process personal data solely on your instructions as documented in:
- Your Customer Rules configured in Workweaver
- Your account settings and dashboard configurations
- Your explicit approvals during the onboarding process
- Your written instructions provided to us
2.2 Your Role: Data Controller
You are the Data Controller for all personal data processed through the Services.
As Data Controller, you:
- Determine the purposes and means of all processing
- Provide lawful, documented instructions for all processing activities
- Obtain all necessary consents from your customers (end users)
- Ensure compliance with UAE PDPL, India DPDP Act, and applicable data protection laws
- Maintain records of processing activities where required by law
- Handle data subject rights requests from your customers
2.3 Processing Activities
We process personal data on your behalf for the following purposes:
| Purpose | Description | Legal Basis |
|---|---|---|
| Service Provision | Providing AI workforce platform, messaging, CRM integration, and automation services | Your Instructions |
| AI Feature Execution | Executing Approved AI Features you have explicitly enabled | Your Instructions |
| Data Storage | Storing Customer Content on AWS servers in the United States (us-east-1); UAE-resident tenants requiring data residency are stored in the United Arab Emirates (me-central-1), according to your retention settings | Your Instructions |
| Workflow Execution | Executing Workweaver flows and automations configured by you | Your Instructions |
| Communications | Sending template-based messages, reminders, and notifications | Your Instructions |
| CRM/Calendar Sync | Synchronizing data with third-party CRMs and calendars per your configurations | Your Instructions |
| Analytics | Providing usage analytics and performance reports to you | Your Instructions |
| Support | Providing customer support and troubleshooting | Your Instructions |
| Audit Logging | Maintaining DecisionTrace logs for transparency and accountability | Your Instructions |
3. Customer Instructions and Approvals
3.1 Your Instructions
We process personal data only according to your instructions, which include:
- Customer Rules: Workflows, automations, templates, scripts, and configurations you create
- Account Settings: AI feature toggles, retention periods, recording settings you configure
- Onboarding Approvals: Explicit approvals you provide during the onboarding process
- Written Instructions: Any additional instructions you provide via email, support tickets, or API
We will not process personal data outside the scope of your documented instructions.
3.2 Onboarding Approval Process
During the onboarding process, we will:
- Explain Each AI Feature: Clearly describe what each AI feature does and what data it processes
- Request Your Approval: Ask you to explicitly enable or disable each AI feature
- Document Your Choices: Record your approval decisions in your account settings
- Provide Control: Ensure you can disable any feature at any time through your dashboard
You are not required to enable any AI feature. All AI features are optional and may be disabled.
3.3 Default Settings
AI features have varying default settings as documented at www.workweaver.ai/features. Many AI features are DISABLED (OFF) by default and require your explicit opt-in before activation.
Key Principles:
- Opt-In Requirement: Features that process Customer Content using AI typically require explicit opt-in
- Customer Control: You may enable or disable AI features through your dashboard at any time
- Feature Documentation: Current AI features, their default settings, and opt-in requirements are documented at www.workweaver.ai/features
If you do not enable an AI feature, the Services will function using deterministic rules only (workflows, templates, scripts you configure).
4. Processor Obligations
4.1 Our General Obligations
When acting as your Data Processor, we:
- Process Only on Your Instructions: We process personal data only based on your documented instructions (Customer Rules, account settings, onboarding approvals)
- Maintain Confidentiality: All personnel processing personal data are bound by confidentiality obligations
- Implement Security Measures: We maintain appropriate technical and organizational security measures (Section 8)
- Assist with Data Subject Rights: We assist you in fulfilling your obligations regarding data subject rights requests (Section 7)
- Enable Data Portability: We provide you with the ability to export Customer Content at any time (Section 13)
- Notify of Breaches: We notify you of personal data breaches without undue delay (Section 11)
- Allow Audits: We make available to you all information necessary to demonstrate compliance with this DPA
- Respect Feature Preferences: We process data only according to the AI features you have explicitly enabled
- Enable Opt-Out: We allow you to disable any AI feature at any time through your dashboard
4.2 Restrictions on Processing
We will not:
- Process personal data outside the scope of your instructions
- Process personal data for purposes incompatible with the Services
- Sell, rent, or license personal data to third parties
- Transfer personal data to countries without appropriate safeguards (Section 10)
- Enable AI features without your explicit approval
- Use your Customer Content to train or improve our general AI models for use with other customers, except as follows:
- You have explicitly enabled a named "Continuous Learning" feature (Phase 2, not yet available), AND
- Such training is limited to anonymized and aggregated data, OR
- Such training is performed solely within your tenant environment for your benefit only
- Access your data for purposes other than providing the Services to you
- Use your Customer Content to develop new features or products for other customers
4.3 Sub-Processor Engagement
We may engage sub-processors to provide the Services. All sub-processors are subject to data processing agreements with appropriate safeguards. A list of our sub-processors is available in Section 9.
You may object to new sub-processors by terminating your account before the change takes effect.
5. AI Features Requiring Explicit Approval
5.1 AI Features Overview
Many AI features are DISABLED (OFF) by default. You must explicitly opt-in to enable such features.
Current AI Features: For a complete list of current AI features, their descriptions, default settings, and opt-in requirements, please visit www.workweaver.ai/features.
Feature Categories: AI capabilities within the Services may include:
- Language Processing: Language detection, transcription, translation
- Conversation Analysis: Sentiment detection, intent classification, lead scoring
- Automation: Workflow triggers, decision routing, dynamic responses
- Quality Assurance: Call recording, conversation logging, compliance monitoring
Feature Availability: Specific features may vary based on:
- Geographic region
- Service tier
- Third-party service integrations
- Regulatory requirements
5.2 How Approval Works
To enable an AI feature, you will:
- Receive Feature Explanations: We will explain each AI feature, what data it processes, and how it benefits you
- Provide Explicit Opt-In: You must explicitly opt-in to enable each feature through your dashboard or during onboarding
- Configure Settings: You will configure feature parameters (e.g., thresholds, retention periods) through your account settings
- Document Your Decisions: Your approval choices will be recorded in your account settings with timestamps for audit purposes
You can change your mind at any time:
- Disable any feature through your dashboard
- Modify feature settings through your account settings
- Contact support for assistance
5.3 What Happens Without Your Approval
If you do not approve an AI feature:
- The feature remains DISABLED
- The Services will function using deterministic rules only (workflows, templates, scripts)
- We will not use AI for that processing activity
- You retain full control over the processing logic
Example: If you disable AI lead scoring, leads will not be automatically categorized. You can still use workflows to categorize leads based on rules you define.
5.4 Feature-Specific Information
For detailed information about specific AI features, including:
- Data processed by each feature
- Configuration options
- Retention policies
- Opt-in requirements
Please visit: www.workweaver.ai/features
6. Customer Control and Opt-Out Rights
6.1 Your Control Rights
You have the following control rights:
- Enable or Disable Any Feature: Toggle any AI feature on or off through your dashboard at any time
- Modify Feature Settings: Change thresholds, parameters, and configurations for enabled features
- Export Your Data: Download all your data at any time (Section 13)
- Delete Your Data: Request deletion of your data (Section 13)
- Access DecisionTrace: View logs of AI decisions executed according to your settings
- Contact Support: Request human review of any AI decision
6.2 How to Exercise Control Rights
Through your dashboard:
- Log in to your account
- Navigate to "Settings" → "AI Features"
- Toggle features on or off
- Adjust parameters and thresholds
- Save your changes
Via support:
- Email: contact@bitfoundry.ai
- Subject line: "AI Feature Control Request"
- We will respond within 3 business days
6.3 Effect of Disabling Features
When you disable an AI feature:
- The feature stops processing data immediately
- No data is processed for that feature going forward
- Historical data processed while the feature was enabled remains in accordance with your retention settings
- The Services continue to function using deterministic rules (Workweaver flows, templates, scripts)
You can re-enable any feature at any time.
7. Data Subject Rights
7.1 Your Responsibilities
As Data Controller, you are responsible for:
- Handling Rights Requests: Responding to data subject rights requests from your customers (end users)
- Response Timeframes: Responding within statutory timeframes (30 days under UAE PDPL and India DPDP Act)
- Providing Access: Providing access, rectification, erasure, and portability as required by law
- We Will Assist: We will assist you by providing the relevant Customer Content upon your written request
7.2 How We Assist
To support your fulfillment of data subject rights requests, we will:
- Provide Data Exports: Export relevant Customer Content within 7-14 business days of your written request
- Delete Data: Delete data as requested in accordance with retention policies
- Provide DecisionTrace: Provide audit logs documenting processing activities
- Document Processing: Provide documentation of processing activities where required
Submit requests to: contact@bitfoundry.ai with subject line "Data Subject Rights Request"
7.3 Rights Request Process
To exercise data subject rights:
- Submit Written Request: Send an email to contact@bitfoundry.ai with the subject line "Data Rights Request"
- Provide Identification: Include sufficient information to verify your identity as Data Controller
- Specify Scope: Clearly state which rights you wish to exercise and the personal data involved
- Response Time: We will respond within 30 days, with possibility of extension for complex requests
8. Security Measures
8.1 Technical Security Measures
We implement the following technical security measures:
| Measure | Description |
|---|---|
| Encryption | TLS 1.2+ for data in transit, AES-256 for data at rest |
| Access Controls | Role-based access controls (RBAC) with principle of least privilege |
| Authentication | Multi-factor authentication (MFA) for administrative access |
| Tenant Isolation | Per-tenant AWS resources with dedicated ECS Fargate services |
| Session Isolation | Unique session_id per call/conversation prevents cross-tenant leakage |
| S3 WORM Storage | Write-Once-Read-Many storage for immutable DecisionTrace logs |
| Network Security | Firewalls, intrusion detection, and prevention systems |
8.2 Organizational Security Measures
We implement the following organizational security measures:
| Measure | Description |
|---|---|
| Employee Training | All employees receive data protection training annually |
| Background Checks | We conduct background checks for employees with access to personal data |
| Confidentiality Agreements | All employees sign confidentiality agreements |
| Security Policies | We maintain comprehensive information security policies |
| Incident Response | We have a data breach incident response plan |
| Vendor Due Diligence | We conduct due diligence on all sub-processors before engagement |
8.3 No Absolute Security
Despite our security measures, no system is completely secure. You acknowledge that you provide personal data at your own risk. We cannot guarantee absolute security of personal data.
9. Sub-Processing
9.1 Authorized Sub-Processors
We engage the following sub-processors to provide the Services:
| Sub-Processor | Purpose | Location | Data Processing Agreement |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, computing, storage | United States (us-east-1); UAE (me-central-1) for UAE-resident tenants | AWS DPA |
| Twilio Inc. | Telephony, SMS messaging, WhatsApp Business Solution Provider | United States | Twilio DPA |
| xAI Corporation (Grok API) | Speech-to-speech AI services (if enabled) | United States | Available upon request |
| Stripe, Inc. | Payment processing | United States | Stripe DPA |
| LiveKit Incorporated | Real-time WebRTC voice/video communications infrastructure and inference data transmission conduit (if voice features enabled) | United States | LiveKit DPA |
| Google Services | Calendar, Speech-to-Text (if enabled) | United States | Google DPA |
| Microsoft Corporation | Outlook, Teams integration (if enabled) | United States | Microsoft DPA |
| Deepgram, Inc. | Speech-to-text transcription (if enabled) | United States | Deepgram DPA |
| Sarvam AI Pvt. Ltd. | Indic language speech services (if enabled) | India | Available upon request |
| Recall.ai Inc. | Meeting bot infrastructure for recording and transcription (if enabled) | United States | Recall.ai DPA |
| Zoom Video Communications | Video meeting integration (if enabled) | United States | Zoom DPA |
| Zoho Corporation | CRM, email, helpdesk, and business app integration (if enabled) | United States / India | Zoho DPA |
9.2 Sub-Processor Engagement
We may:
- Add Sub-Processors: Add new sub-processors with at least 30 days' notice
- Replace Sub-Processors: Replace existing sub-processors with similar services
- Remove Sub-Processors: Discontinue use of sub-processors
You may object to new sub-processors by terminating your account before the change takes effect.
9.3 Sub-Processor Obligations
We require all sub-processors to:
- Implement appropriate technical and organizational security measures
- Comply with applicable data protection laws
- Sign data processing agreements with appropriate safeguards
- Undergo regular security audits (where applicable)
- Process personal data only according to our (and your) instructions
10. Cross-Border Data Transfers
10.1 Data Stored Outside UAE and India
You instruct and authorize cross-border data transfers as part of using our Services.
- Our Services are hosted on AWS servers located primarily in the United States (us-east-1 region). UAE-resident tenants requiring data residency under UAE PDPL are deployed on AWS servers in the United Arab Emirates (me-central-1 region)
- Personal data will be transferred, stored, and processed in the United States, and in the United Arab Emirates for UAE-resident tenants, as well as other countries where our service providers operate
- These countries may have different data protection laws than your home country
You represent and warrant that:
- You have the lawful authority to instruct transfers to these locations
- You have provided required notices to data subjects regarding cross-border transfers
- You have obtained any necessary consents required under applicable provisions of UAE PDPL, India DPDP Act cross-border transfer rules, and other applicable laws
- You are responsible for compliance with all cross-border transfer regulations
10.2 Safeguards for Cross-Border Transfers
To protect personal data during cross-border transfers, we implement:
- Standard Contractual Clauses (SCCs):
- For transfers from EEA: We use European Commission-approved Standard Contractual Clauses:
- Module 2 (Controller to Processor): Covers transfers where you (as Data Controller) transfer personal data to us (as Data Processor)
- Module 3 (Processor to Processor): Covers transfers where we (as Data Processor) engage sub-processors for processing on your behalf
- For transfers from UAE and India: We use equivalent contractual clauses incorporating the same data protection safeguards as the EC SCCs
- These SCCs are available at: EU Standard Contractual Clauses (Module 2) and Module 3
- Upon written request to contact@bitfoundry.ai, we will provide an executed copy of these SCCs for your records
- For transfers from EEA: We use European Commission-approved Standard Contractual Clauses:
- AWS Data Processing Addendum: Our agreement with AWS includes contractual commitments for data protection.
- Sub-Processor Vetting: We conduct due diligence on all sub-processors.
- Security Measures: We implement encryption and security measures during transfer.
10.3 Obtaining SCCs
The Standard Contractual Clauses referenced above (EU SCCs Module 2 and Module 3) govern our cross-border data transfers. Upon written request, we will provide you with a copy of the executed SCCs for your records.
Submit requests to: contact@bitfoundry.ai with subject line "SCC Request"
Official SCC Sources:
11. Data Breach Notification
11.1 Our Notification Obligations
We will notify you without undue delay and, in any event, within 72 hours of becoming aware of a personal data breach that poses a risk to your rights and freedoms.
11.2 Breach Notification Content
Our breach notification will include:
- Description of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate amount of personal data concerned
- Likely consequences of the breach
- Measures taken or proposed to address the breach
11.3 Your Notification Obligations
As Data Controller, you are responsible for:
- Notifying relevant authorities (UAE Data Office, India Data Protection Board)
- Notifying affected data subjects where required by law
- We will provide you with all information necessary to fulfill these obligations
12. Audit and Transparency
12.1 DecisionTrace
DecisionTrace is our immutable audit logging system that captures metadata about AI decisions for security, dispute resolution, and accountability.
What DecisionTrace Captures:
- Event ID: Unique identifier for each decision
- Timestamp: When the decision occurred
- Decision Type: Category of action (e.g., lead score, transfer)
- Performance Metrics: Latency, cost, success rates
- Session ID: Reference to the call or conversation
What DecisionTrace Does NOT Contain:
- Call recordings or audio content
- Full transcript content
- Personal data beyond metadata (event IDs, timestamps)
Retention: DecisionTrace logs are retained for the period you configure in your account settings (default: up to 12 months). You may shorten this period at any time through your dashboard.
Legal Exception: Workweaver may retain limited records where required by applicable law or to establish, exercise, or defend legal claims, regardless of your configured retention period.
You may access DecisionTrace logs through:
- Your account dashboard (real-time access)
- Written request to contact@bitfoundry.ai (for historical logs)
12.2 Audit Rights
You (or your designated auditor) may:
- Request Information: Request information necessary to demonstrate our compliance with this DPA
- Inspect Records: Inspect DecisionTrace logs
- Verify Safeguards: Request documentation of our security measures
- Conduct Site Audits: Conduct audits with reasonable notice (30 days) during business hours
Audit requests must be submitted to: contact@bitfoundry.ai with subject line "Audit Request"
Costs: You bear the costs of audits unless a breach or non-compliance is found.
13. Data Deletion and Return
13.1 Data Retention Periods
We retain different types of data for different periods. Detailed information about specific retention periods for each data type is available in our Privacy Policy at www.workweaver.ai/privacy and in your account settings.
Key Retention Categories:
- Configurable Retention: Many data types allow you to configure retention periods through your account settings
- Standard Retention: Some data types have fixed retention periods based on service requirements
- Legal Exceptions: Payment and billing records are retained for the period required by applicable law (e.g., 7 years under UAE tax law)
Exception: Payment records cannot be deleted earlier due to UAE tax law requirements.
13.2 Data Export
You may export all your Customer Content at any time.
- Submit Request: Send email to contact@bitfoundry.ai with subject line "Data Export Request"
- Specify Format: Indicate preferred format (JSON, CSV, PDF)
- Timeline: We will provide the export within 7-14 business days, depending on data volume
We recommend regularly exporting your Customer Content for your own records.
13.3 Data Deletion Upon Termination
Upon termination of the Terms of Service:
- Option 1 - Return: Return all Customer Content to you in a standard machine-readable format
- Option 2 - Delete: Delete all Customer Content in accordance with retention policies
You may indicate your preference during the termination process.
13.4 Your Responsibility
Since we delete data according to retention periods, you are responsible for:
- Exporting any data you need before retention periods expire
- Maintaining your own backups of important Customer Content
- Exporting data regularly through your account dashboard
We are not obligated to provide data exports after retention periods have expired.
14. Term and Termination
14.1 Term
This DPA remains in effect for so long as we process personal data on your behalf as your Data Processor.
14.2 Termination
Upon termination of the Terms of Service:
- Processor Obligations Survive: Our processor obligations survive until all personal data is deleted or returned
- SCCs Survive: Standard Contractual Clauses survive until all data is deleted
14.3 Return or Deletion
Upon termination, we will:
- Return or Delete: Return or delete all personal data as per your instructions (Section 13)
15. Governing Law
15.1 Governing Law
This DPA is governed by the laws of the Emirate of Ajman, United Arab Emirates, without regard to its conflict of laws principles. To the extent Ajman law is silent on any matter, UAE federal law applies.
15.2 Dispute Resolution
Disputes arising under this DPA are subject to the tiered dispute resolution process in the Terms of Service (Section 15).
16. HIPAA / Business Associate (BAA) — Draft
Draft — counsel review required. This Section 16 is a scaffold for procurement and architecture alignment. It is not a signed Business Associate Agreement (BAA), does not constitute a signed BAA, and must not be treated as evidence that Workweaver or any sub-processor has executed a HIPAA BAA. Human BAA negotiation and signature remain a launch / counsel gate (not completed by publication of this draft).
16.1 Scope of Protectable Surface
When a Customer configures the Services for a HIPAA-covered use case (and only after a counsel-approved BAA is executed), the Workweaver protectable surface that may contain Protected Health Information (PHI) includes, without limitation:
- Voice and meeting transcripts produced or stored by enabled transcription / meeting features
- WorkMemory and related memory stores that persist Customer Content derived from conversations, documents, or integrations
- DecisionTrace and operational logs to the extent Customer Content or identifiers are present
- Inference prompts and model outputs when Customer Content containing PHI is sent to an Approved AI Feature
16.2 Sub-Processors and Model Providers (BAA Status Register)
Model providers and other sub-processors that may process Customer Content in connection with AI features are listed in the machine-readable register docs/legal/subprocessors.yaml. Each row includes an honest baa_status of yes, no, or unknown. A value of yes means the vendor publicly offers a BAA path — not that a BAA has been signed for the Customer's tenancy.
16.3 No Implied HIPAA Authorization
Until a separate, counsel-approved BAA is executed between Workweaver and the Customer (and any required downstream BAAs with sub-processors are in place), publication of this draft Section 16 does not authorize HIPAA-covered processing, and UI, marketing, or API copy must not claim that a BAA is signed.
Acceptance
Once this draft is counsel-reviewed and published as final, clicking "I Agree," using the Services, or executing an order form referencing this DPA will constitute agreement to the then-current Data Processing Addendum.
Until counsel review completes, treat this page as a draft for transparency and procurement preview — not a final instrument approved by counsel.
Last Updated: July 19, 2026 (Version 3.2, Enterprise Readiness; Effective December 26, 2025). Draft pending legal counsel review. When finalized, this Data Processing Addendum is incorporated into and forms part of the Workweaver Terms of Service. In case of conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict regarding data processing.
Disclaimer: This Data Processing Addendum is a draft pending legal counsel review. It is provided for informational purposes only and does not constitute legal advice. It is not approved by counsel. Workweaver recommends that you consult with qualified legal counsel in your jurisdiction to ensure compliance with all applicable data protection laws and regulations, including the UAE PDPL, India DPDP Act, and (where applicable) HIPAA. Section 16 is a draft scaffold and does not constitute a signed Business Associate Agreement.