Trust · DPA · Agentic Revenue Operating System

Data Processing Agreement

Self-serve template for security review, plus a request flow for a countersigned copy. Aligned with GDPR / DPDP processing and our Security control pillars.

Email legalSecurity architecture

What the DPA covers

01RolesCustomer is Controller. Wavly is Processor for workspace Graph data, integration metadata, and webhook payloads processed to operate the Agentic Revenue OS.
02Subject matterAccount and opportunity entities, CRM/product sync metadata, agent drafts under governance, attributed outcomes in Revenue Memory, and conversion webhook payloads — as described in the Privacy Policy.
03Security measuresRLS tenancy, TLS in transit, encrypted secrets, HMAC webhook verification, audit logging, and human approval tiers for high-risk agent actions.
04Sub-processorsHosting (Vercel), database/auth (Supabase), model API (OpenAI), email (Resend), billing (Stripe / Razorpay). Updated list with the countersigned package.
05Retention & deletionPer Controller instruction. Workspace deletion workflow in-app with a 30-day grace period before hard delete of Graph rows.
06AssistanceData-subject request support, breach notification assistance, and questionnaire responses for Scale within 2 business days.

Download or request

Download template

Standard DPA covering Controller / Processor roles, Graph · Memory · agent processing, subprocessors, retention, incident notice, and security measures aligned with /security.

Need a countersigned copy or custom schedules? Submit the form or email legal@thewavly.com.

Request signed DPA

Signed-in users get a tracked request. We respond within 2 business days for Scale.

Sign in to attach this request to your workspace audit log.

Next

Need a human on the packet?

Talk to Closer for Scale procurement — governed intake, reply in one business day.

Start freeTalk to Closer