Wennov Connect
Data Processing Agreement (DPA)
Last updated: August 2026. The Art. 28 GDPR terms governing the relationship between the customer (controller) and Wennov Connect (processor).
APPLICABILITY
This Data Processing Agreement ("DPA") forms an integral part of the Wennov Connect Terms and Conditions and applies automatically to any customer who uses the platform to process personal data of their own contacts. No separate signature is required for it to take effect; for a countersigned copy, write to office@wennov.ro.
In this DPA: the "Controller" is the customer; the "Processor" is Glo Wennov SRL, the company operating the Wennov Connect platform; "Customer Data" is the personal data the Controller uploads to or generates through the platform.
1. SUBJECT MATTER, DURATION AND NATURE OF PROCESSING
Subject matter: provision of the omnichannel communication platform. Duration: the term of the contract, plus the retention periods in section 8. Nature and purpose: storing, organising, segmenting, transmitting and reporting on communications initiated by the Controller.
Categories of data subjects: the Controller contacts (customers, prospects, subscribers) and the users of the Controller account.
Categories of data: name, phone number, email address, tags and custom fields defined by the Controller, consent and opt-out status, content of messages sent and received, delivery and engagement metadata.
The Controller must not upload special categories of data (Art. 9 GDPR) or criminal conviction data. The platform is not configured for such data and the Controller is responsible if it is uploaded.
2. CONTROLLER INSTRUCTIONS
We process Customer Data solely on the documented instructions of the Controller. Use of the platform and the configuration made in the interface constitute documented instructions. If an instruction appears to us to infringe GDPR or Romanian law, we will inform you without delay and may suspend its execution.
3. CONFIDENTIALITY
Our personnel with access to Customer Data are bound by contractual confidentiality obligations and receive data protection training. Access is granted on a need-to-know basis.
4. SECURITY MEASURES (ART. 32)
We apply: encryption in transit (TLS); full-disk encryption of the storage infrastructure; application-level AES-256 encryption for provider credentials, SMTP passwords and DKIM private keys; passwords stored as hashes; two-factor authentication, enforceable for privileged roles; IP allowlisting; scoped API keys with expiry and rotation; audit logging; request rate limiting; logical separation of customer data (multi-tenancy); regular backups and tested restore procedures.
5. SUBPROCESSORS
The Controller gives general authorisation for the subprocessors listed in section 5 of the Privacy Policy (/privacy), which states the category, purpose and location of each. We impose on every subprocessor data protection obligations at least equivalent to those in this DPA and remain fully liable to the Controller for their performance.
We give the Controller at least 30 days notice before adding or replacing a subprocessor. The Controller may object on reasonable grounds within that period; if no reasonable solution is found, the Controller may terminate the affected services without penalty.
6. INTERNATIONAL TRANSFERS
Primary data is stored on EU/EEA infrastructure. Certain subprocessors process data outside the EEA (notably in the United States). Those transfers rely on the European Commission Standard Contractual Clauses, on EU-US Data Privacy Framework certification where applicable, and on supplementary technical and organisational measures.
7. ASSISTANCE WITH DATA SUBJECT RIGHTS
The platform gives the Controller the tools to respond to requests directly: contact search and export, editing, deletion, opt-out management and data export. If a data subject contacts us directly, we do not respond on the Controller behalf: we forward the request to the Controller without undue delay and assist them, to the extent reasonable, in handling it.
8. DELETION AND RETURN OF DATA
During the contract, the Controller can export or delete data from the platform at any time. On termination, Customer Data is deleted within 30 days, except for: (a) data we are legally required to keep – in particular billing documents, 10 years; (b) backup copies, which are overwritten in the normal rotation cycle.
The automatic operational retention periods (campaign messages 60 days, individual messages 30 days, send tracking 60 days, audit logs 365 days, the rest in section 7 of the Privacy Policy) apply throughout the contract. IMPORTANT: if you need proof of sending for longer periods, export the data before those periods expire.
9. PERSONAL DATA BREACH NOTIFICATION
We notify you without undue delay after becoming aware of a security breach affecting Customer Data, providing the information you need to meet your obligations under Art. 33 and 34 GDPR. Notification is not an acknowledgement of liability.
10. AUDIT AND INSPECTION
On written request and with reasonable notice, we make available the information necessary to demonstrate compliance with Art. 28 GDP
Contact
Tell us your use case and we will recommend the best setup.
Email: office@wennov.ro
Phone: +40 731 177 744
Location: București, România