Version 2026-09-15Effective September 15, 2026

Effective 2026-09-15 · replaces version 2026-04-24-draft · published at /legal/dpa · accepted at signup

1. Roles and scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer") and Desk Plus LLC d/b/a WYN Studio ("WYN Studio"). It applies to personal information contained in Customer Data ("Customer Personal Data"). Customer is the business, controller or equivalent; WYN Studio is the service provider, processor or equivalent. Where Customer acts as a processor for its own clients, Customer represents that its instructions are authorized by the relevant controller. In case of conflict, this DPA prevails over the Terms for its subject matter.

2. Processing details

  • Subject matter: provision of the WYN Agent Portal to Customer.
  • Duration: the term of the Terms plus the closure period and any retention required by section 12.
  • Nature and purpose: hosting, storage, retrieval, display, transmission, communication (email, SMS, voice), recording and transcription where enabled, AI-assisted drafting, summarization, extraction and scoring, automation, e-signature, reporting, backup and support.
  • Categories of data subjects: Customer's employees, contractors and Authorized Users; Customer's clients, insureds, prospects, leads and their dependents; signers; carrier and vendor contacts; client portal users.
  • Categories of personal data: identifiers and contact details; dates of birth; addresses; driver, vehicle and property information; policy, premium, coverage, claims and service information; financial information related to premiums and commissions; health and life risk information collected for insurance; government identifiers on forms; documents and files; signatures; communications content, call recordings, voicemail, transcripts and summaries; usage and device data.
  • Sensitive data: may include health information, government identifiers and precise financial information, as determined by Customer's use.

3. Instructions and permitted use

WYN Studio will process Customer Personal Data only on Customer's documented instructions, which are the Terms, this DPA, Customer's configuration of the Service, and other written instructions Customer gives. WYN Studio will inform Customer if it believes an instruction violates applicable law. WYN Studio will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in section 2, or combine it with personal data from other sources except as the Service requires and the law permits.

4. CCPA and state privacy law terms

To the extent the California Consumer Privacy Act or a similar state law applies, WYN Studio is a service provider or processor, certifies that it understands and will comply with the restrictions in section 3, will notify Customer if it can no longer meet its obligations, will allow Customer to take reasonable steps to stop and remediate unauthorized use, and will pass equivalent obligations to its subprocessors. Customer may audit compliance as described in section 11.

5. Gramm-Leach-Bliley and Safeguards assistance

Customer may be a financial institution subject to the Gramm-Leach-Bliley Act, the FTC Safeguards Rule and state insurance privacy rules. WYN Studio will maintain the safeguards in Annex A, use nonpublic personal information only to provide the Service, and assist Customer with information reasonably needed for Customer's own information security program and vendor oversight.

6. Confidentiality and personnel

WYN Studio will ensure that persons authorized to process Customer Personal Data are bound by confidentiality, receive appropriate training, and access data only as needed for their role.

7. Security

WYN Studio will implement and maintain the technical and organizational measures in Annex A, will not materially reduce them during the term, and will assist Customer in meeting its own security obligations taking into account the nature of the processing.

8. Subprocessors

Customer authorizes WYN Studio to engage subprocessors. Current subprocessors are listed by category, with purpose, data and hosting region, at /legal/subprocessors; the legal names of subprocessors are available to Customer on request under confidentiality. Customer pre-authorizes the subprocessors listed at the effective date. WYN Studio will post any new subprocessor to that page, with a dated change entry, at least 15 days before it processes Customer Personal Data, and will notify Customer by email if Customer subscribes to notices on that page. Customer may object on reasonable data-protection grounds within the notice period; if the parties cannot resolve the objection, Customer may stop using the affected feature or terminate the affected Service and receive a refund of prepaid unused fees for it. WYN Studio will impose data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Services that Customer connects with its own credentials are not subprocessors.

9. Data subject requests

WYN Studio will promptly forward to Customer any request it receives from a data subject about Customer Personal Data and will not respond except to refer the person to Customer, unless the law requires otherwise. WYN Studio will assist Customer with tools in the Service and, where needed, reasonable additional assistance within 30 days of request, at no charge unless requests are excessive.

10. Security incidents

WYN Studio will notify Customer without undue delay, and no later than 72 hours after confirming, of any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. The notice will describe the nature of the incident, the categories and approximate volume of data and data subjects affected as then known, the likely consequences, the measures taken or proposed, and a contact. WYN Studio will provide updates as information becomes available and will cooperate with Customer's own notification obligations. Notice of an incident is not an admission of fault.

11. Audit and assurance

On request, no more than once per year, WYN Studio will provide written responses to Customer's reasonable security questionnaire and summaries of its security program and any third-party assessments it holds. If that is insufficient to meet a legal requirement, Customer may conduct or commission an audit on 30 days' written notice, during business hours, under confidentiality, at Customer's expense, scoped to Customer Personal Data and no more than once per year unless required by a regulator or following a security incident.

12. Return and deletion

During the term Customer may export Customer Data using the Service's export features. On closure of the account, the Service enters a 30-day read-only period for export, after which WYN Studio deletes Customer Personal Data from active systems, except data that Customer has placed under a legal hold, data subject to a retention period configured by Customer for regulatory record-keeping, and data WYN Studio must retain by law. Data in backups is deleted on the normal backup expiry schedule and remains protected until then. On written request, WYN Studio will confirm deletion.

13. International transfers

WYN Studio processes Customer Personal Data in the United States. If Customer Personal Data is subject to the GDPR or UK GDPR and is transferred to WYN Studio, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two or Three as applicable) and the UK International Data Transfer Addendum, with Customer as data exporter, WYN Studio as data importer, and the details in section 2 and Annex A completing the annexes. This section applies only if such a transfer occurs.

14. Liability and general

Each party's liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the law and dispute terms in the Terms. It is written in English; the English text controls. WYN Studio may update this DPA to reflect changes in law or the Service in the manner set out for amendments in the Terms, without reducing the protections it gives.

Annex A. Security measures

  • Encryption in transit using TLS for all connections.
  • Field-level encryption at rest for sensitive personal data fields using AES-256-GCM with per-customer data keys wrapped by a cloud key-management service; blind indexes for search without plaintext.
  • Encrypted storage of connected-service credentials.
  • Logical tenant isolation enforced in the database and in application code; every query scoped to the customer's organization.
  • Role-based access control with seven roles and per-user scope restriction; owner and administrator roles require multi-factor authentication; customers may require it for any role.
  • Tamper-evident, hash-chained audit logs of privileged and data-changing actions.
  • Read-only, logged support access; no support write access to customer data.
  • API keys with scopes, per-key rate limits and optional IP allowlists.
  • Secrets held in a managed secrets service; production database access restricted and logged.
  • Error monitoring configured to exclude personal data.
  • Backups with point-in-time recovery; retention and purge processes with legal-hold override.
  • Secure development practices including code review, automated tests and dependency monitoring.

Questions about this document? hello@wynstudio.io