Legal
Data Processing Addendum
Last updated: 2026-07-11
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between MB "Wetapoint" (the “Processor”) and the customer organisation that subscribes to the Service (the “Controller”). It governs the processing of personal data we carry out on your behalf.
If you are subject to the EU GDPR, UK GDPR, or equivalent data-protection law, these terms apply automatically. Your continued use of the Service is acceptance.
1. Scope
Processing consists of collecting, recording, organising, storing, retrieving, transmitting, making available, securing, exporting, and deleting personal data as needed to provide account management, operational coordination, communications, location-enabled features, media handling, notifications, support, and security. Processing lasts for the subscription and the deletion periods stated in the Terms and Privacy Policy, unless law requires longer retention.
2. Processor obligations (Art. 28 GDPR)
- Process personal data only on your documented instructions (the Terms, your configuration of the Service, or additional written instructions), including for international transfers, unless law requires otherwise. Where legally permitted, we will inform you of that requirement before processing.
- Ensure authorised personnel are under an appropriate confidentiality obligation.
- Implement the technical and organisational security measures described in Section 7.
- Assist you in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection).
- Assist with your obligations under Articles 32–36 GDPR (security, breach notification, impact assessments).
- At termination, delete or return all personal data as you choose, except where retention is required by law.
- Inform you promptly if, in our opinion, an instruction infringes applicable data-protection law.
3. Categories of data
- Identifiers (name, email, phone, role, organisation).
- Authentication data (password hash, MFA secret).
- Real-time location data (latitude, longitude, altitude, accuracy, heading, speed, network type, time recorded, related operation or event identifier(s), device identifier).
- Operational content (tasks, incidents, messages, push-to-talk radio transmissions, live video streams, camera feeds, media uploads).
- Device and session telemetry (IP, user-agent, app version, device push tokens for APNs and Firebase Cloud Messaging).
Data subjects: your employees, contractors, volunteers, and other personnel who use the Service; other individuals whose data your personnel record in the system.
4. Sub-processors
You grant us general authorisation to engage sub-processors. The current list is published at /legal/subprocessors.
We will notify you at least 7 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if we cannot accommodate your objection, you may terminate with a pro-rated refund.
We remain responsible for the acts and omissions of our sub-processors as if they were our own and impose on each sub-processor, by contract, data-protection obligations that provide at least the same level of protection required by this DPA for the processing it performs.
5. International transfers
Primary processing of customer data takes place in the EEA. Where a sub-processor receives data through a restricted transfer, we require the applicable lawful safeguard in that provider's data-processing terms, such as an adequacy decision or recognised framework, or the European Commission's Standard Contractual Clauses. The UK Addendum and proportionate supplementary measures apply where required.
6. Breach notification
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting your data. The notification will include the information required by Article 33(3) GDPR to the extent then available.
7. Security measures
We maintain measures appropriate to the risk, including access and confidentiality controls; protection of data in transit and where appropriate at rest; account and credential safeguards; separation of customer data; logging and monitoring; backup, restoration, and continuity controls; vulnerability and change management; incident response; personnel confidentiality; and periodic review of these measures. We may update the measures without materially reducing the overall level of protection.
We do not currently hold a third-party security certification (SOC 2, ISO 27001 or equivalent). If that changes we will say so on this page and link the relevant report.
8. Audits
We will make available the information necessary to demonstrate compliance with this DPA. The standard route is a proportionate written security questionnaire covering the measures in section 7, which we will answer on reasonable written notice.
In addition, you (or an independent auditor you mandate, provided it is not a competitor of ours and is bound by confidentiality) may conduct audits, including inspections, where required by applicable data-protection law. Audits are subject to reasonable prior written notice, confidentiality undertakings, and normal business hours; they may take place at most once per 12 months, unless a supervisory authority requires otherwise or an audit follows a personal-data breach affecting your data. You bear the costs of audits you initiate.
9. Return / deletion at termination
After termination or deactivation, your organisation's administrators retain export-only access to your data through in-product tools for 30 days. When that window ends, an automated process permanently deletes your data from primary storage, keeping only a minimal billing and audit record. The retained audit records are pseudonymised, not anonymised: identifiers are removed from them on the categorised schedule described in the Privacy Policy, and the records are used only for security investigations, compliance with applicable law, and the establishment, exercise or defence of legal claims. Copies in encrypted off-site backups age out on the rolling snapshot schedule described in the Privacy Policy (up to approximately six months) and are not restored except for disaster recovery. If a backup is restored, our retention and deletion processes are re-applied to the restored data.
During the subscription, removal of individual users follows the layered model in the Privacy Policy: disabling a user revokes access immediately without deleting historical activity; deleting a user's profile removes profile data while content contributed to your workspace remains under your retention instructions and may be displayed as contributed by a deleted user. For workspace content you remain the controller and we delete it on your documented instructions; we act as controller only for our own account, billing, and platform-security records.
10. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service.
11. Contact
Data Protection contact: privacy@wetapoint.com.
MB "Wetapoint", Papiškių g. 19-1, LT-06282 Vilnius, Lithuania.