wxrks Data Processing Agreement

Between:

  • Bureau Translations Inc., trading as wxrks ("Processor" or "Vendor")
  • Controller ("Controller" or "Client")

Last updated: 18 August 2026 · Version 2.1

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement and/or Software Order Form ("Principal Agreement") between the parties.

1. Introduction and purpose

1.1 This DPA establishes the terms and conditions under which Vendor will process Personal Data on behalf of Client in connection with the services described in the Principal Agreement.

1.2 This DPA applies to all Personal Data processed by Vendor on behalf of Client that is subject to applicable privacy laws.

1.3 In case of conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to data protection matters.

2. Definitions

2.1 "Applicable Privacy Law" means privacy and data protection laws applicable to the processing of Personal Data under this Agreement, including but not limited to the GDPR, UK GDPR, the CCPA as amended by the CPRA, and other similar laws.

2.2 "Personal Data" means any information relating to an identified or identifiable natural person processed by Vendor on behalf of Client.

2.3 "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

2.4 "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, or deletion.

2.5 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2.6 "Subprocessor" means any third party (excluding Vendor's employees) engaged by Vendor to process Personal Data.

3. Roles and responsibilities

3.1 Client acts as the Controller (or a Processor acting on behalf of a Controller) of the Personal Data.

3.2 Vendor acts as the Processor (or Subprocessor) of the Personal Data.

3.3 Each party will comply with their respective obligations under Applicable Privacy Law.

4. Processing of Personal Data

4.1 Scope and purpose. Vendor shall process Personal Data only:

  • to provide the services specified in the Principal Agreement;
  • in accordance with Client's documented instructions;
  • for the duration of the Principal Agreement.

4.2 Details of processing. Details regarding the processing activities are specified in Appendix 1, including categories of Data Subjects, types of Personal Data, nature and purpose of processing, and duration of processing.

4.3 Processing instructions

4.3.1 The Principal Agreement, this DPA, and Client's use of Vendor's services constitute Client's documented instructions.

4.3.2 If Vendor believes an instruction violates Applicable Privacy Law, Vendor shall promptly inform Client.

4.3.3 If Vendor must process Personal Data to comply with applicable law, Vendor shall inform Client before processing, unless prohibited by law.

4.3.4 Client's documented instructions include the use of Client's content in a non-production environment for the purpose of reproducing and resolving a reported defect, or validating a change to the services against representative content. Where Vendor relies on this instruction:

  • the processing is limited to what is necessary for the stated purpose;
  • the content is encrypted and access is restricted to the personnel performing the work;
  • the content is deleted within 60 days and is not retained in the non-production environment beyond 30 days in active form; and
  • Vendor shall maintain a record of such use and make it available to Client on reasonable request.

5. Confidentiality and security

5.1 Confidentiality

5.1.1 Vendor shall ensure that personnel authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.1.2 Vendor shall limit access to Personal Data to those personnel who need access to perform the services.

5.2 Security measures

5.2.1 Vendor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Appendix 2.

5.2.2 In assessing security risks, Vendor shall consider risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Personal Data.

5.2.3 Vendor shall regularly test, assess, and evaluate the effectiveness of its security measures.

6. Subprocessing

6.1 General authorization

6.1.1 Client authorizes Vendor to engage Subprocessors as necessary to provide the services under the Principal Agreement.

6.1.2 The current list of Subprocessors is published at https://wxrks.com/subprocessors and is incorporated into this DPA by reference. It is deliberately not reproduced in this document, so that it can be kept current without amending this DPA.

6.1.3 Vendor shall maintain that list, record the date of each change, and retain previous versions so that Client can identify the Subprocessors engaged at any given time. Any change to the list is subject to clause 6.2.

6.2 Notification of changes

6.2.1 Vendor shall provide Client with 30 days' prior notice before authorizing any new Subprocessor.

6.2.2 If Client reasonably objects to a new Subprocessor within 15 days of notification, Vendor shall make commercially reasonable efforts to modify the services to avoid processing by the proposed Subprocessor, or work with Client to find a mutually acceptable solution.

6.2.3 If no resolution is possible within 30 days of Client's objection, Client may terminate the affected services with written notice.

6.3 Subprocessor requirements

6.3.1 Vendor shall impose on Subprocessors data protection obligations no less protective than those in this DPA.

6.3.2 Vendor remains responsible for its Subprocessors' compliance with the obligations of this DPA.

7. Data Subject rights

7.1 Vendor shall implement appropriate technical and organizational measures to assist Client in responding to Data Subject requests.

7.2 If Vendor receives a Data Subject request related to Personal Data processed on behalf of Client, Vendor shall promptly notify Client, shall not respond directly to the Data Subject unless authorized by Client, and shall assist Client in fulfilling the request as reasonably required.

7.3 Vendor shall assist Client in meeting obligations to respond to Data Subject requests under Applicable Privacy Law, taking into account the nature of the processing and the information available to Vendor. Assistance is provided at no charge for requests of ordinary scope and frequency. Where a request is repeated, or requires effort disproportionate to the nature of the processing, Vendor may recover its reasonable costs, notified to Client in advance.

8. Personal Data Breach

8.1 Notification

8.1.1 Vendor shall notify Client without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Client's Personal Data.

8.1.2 Notification shall include, to the extent possible: the nature of the breach; categories and approximate number of Data Subjects affected; categories and approximate volume of Personal Data records affected; likely consequences; measures taken or proposed; and contact details for further information.

8.2 Cooperation and mitigation

8.2.1 Vendor shall cooperate with Client and take reasonable steps to mitigate any adverse effects of a Personal Data Breach.

8.2.2 Vendor shall provide reasonable assistance to Client in meeting any notification obligations to regulatory authorities or Data Subjects.

9. Data protection impact assessment

9.1 Vendor shall provide reasonable assistance to Client with any data protection impact assessments and prior consultations with supervisory authorities required under Applicable Privacy Law, taking into account the nature of the processing and information available to Vendor. Vendor may recover its reasonable costs for assistance that is repeated or disproportionate, notified to Client in advance.

10. Data return and deletion

10.1 Upon termination of the Principal Agreement, or upon Client's request, Vendor shall return all Personal Data to Client in a commonly used electronic format, or delete all Personal Data including copies, as Client elects.

10.2 Deletion shall be completed:

  • within 60 days of the effective date of termination; or
  • within 30 days of a verified deletion request made by Client during the term,

whichever applies. Backup copies age out within a further 7 days. Deletion is performed in accordance with NIST SP 800-88 Rev. 1, and Vendor shall issue a certificate of destruction on completion.

10.3 Vendor's obligations under clauses 10.1 and 10.2 are unconditional and are not contingent on payment of any outstanding sums or on any other condition.

10.4 Vendor may retain Personal Data if required by applicable law, in which case Vendor shall ensure the confidentiality of such Personal Data, shall process the retained data only as required by law, and shall notify Client of such legal requirement unless prohibited by law.

11. Audit rights

11.1 Vendor shall make available to Client information necessary to demonstrate compliance with this DPA.

11.2 Vendor's obligations under clause 11.1 are satisfied in the first instance by making available its current independent third-party audit reports and certifications, including its SOC 2 Type 2 report, together with responses to reasonable written questions.

11.3 Where those materials do not address a specific compliance concern that Client has identified in writing, Vendor shall allow for and contribute to an audit or inspection conducted by Client or an auditor mandated by Client, subject to the following: Client shall provide at least 30 days' advance notice; audits shall occur no more than once per year, unless there is reasonable belief of non-compliance; Client shall minimize disruption to Vendor's operations; audits shall be conducted during normal business hours; all auditors shall be bound by confidentiality obligations and shall not be a competitor of Vendor; and Client shall bear its own costs and Vendor's reasonable costs of supporting the audit.

12. International transfers

12.1 Vendor shall not transfer Personal Data outside the jurisdiction where Client is located unless: the transfer is to a country with an adequacy decision; appropriate safeguards are in place (such as Standard Contractual Clauses); or a derogation under Applicable Privacy Law applies.

12.2 If the transfer relies on Standard Contractual Clauses, the appropriate modules will be selected based on the parties' roles, and are incorporated by reference: Module 2 (Controller to Processor) or Module 3 (Processor to Processor), as applicable. The governing law shall be the law of Client's country. The competent supervisory authority shall be in Client's country.

12.3 UK transfers. Where a transfer of Personal Data under this DPA is subject to the UK GDPR, the parties incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018 (the "UK Addendum"). The UK Addendum applies to the Standard Contractual Clauses incorporated under clause 12.2 and is completed as follows:

  • Table 1 (Parties) is completed with the parties' details, roles and key contacts as set out in the Principal Agreement and this DPA;
  • Table 2 (Selected SCCs, Modules and Selected Clauses) selects the version of the Standard Contractual Clauses and the Module identified under clause 12.2;
  • Table 3 (Appendix Information) is completed by Appendices 1 and 2 to this DPA and by the Subprocessor list referred to in clause 6.1.2;
  • Table 4 (Ending this Addendum when the Approved Addendum changes) is completed as "neither Party", so that neither party may end the UK Addendum by reason only of a revision issued by the Information Commissioner.

For transfers subject to the UK GDPR, references in the Standard Contractual Clauses to the GDPR, to Member State law and to the competent supervisory authority are read as references to the UK GDPR, to the law of the United Kingdom and to the Information Commissioner respectively. Where there is a conflict, the UK Addendum prevails in respect of transfers subject to the UK GDPR.

12.4 The parties shall implement any additional measures necessary to ensure compliance with data transfer requirements under Applicable Privacy Law.

13. Government access requests

13.1 If Vendor receives a legally binding request from a public authority to disclose Personal Data, Vendor shall: promptly notify Client, unless prohibited by law; redirect the request to Client where possible; challenge the request if there are reasonable grounds to consider it unlawful; and disclose only the minimum Personal Data required.

13.2 If Vendor is prohibited from notifying Client, Vendor shall use reasonable efforts to obtain a waiver of the prohibition.

13.3 Vendor shall document its assessment of each request and make this documentation available to Client upon request, to the extent permitted by law.

14. California Consumer Privacy Act provisions

14.1 For purposes of the CCPA as amended by the CPRA, Vendor is a "Service Provider" or "Contractor" as applicable.

14.2 Vendor shall not: sell or share Personal Data; retain, use, or disclose Personal Data for any purpose other than providing the services; or combine Personal Data with personal information received from other sources.

14.3 Vendor shall assist Client in fulfilling CCPA obligations regarding consumer rights.

15. General provisions

15.1 Liability and indemnification

15.1.1 Each party's liability under this DPA shall be subject to the liability limitations in the Principal Agreement.

15.2 Term and termination

15.2.1 This DPA shall commence on the Effective Date and continue for as long as Vendor processes Personal Data on behalf of Client.

15.2.2 The obligations regarding confidentiality, return or deletion of Personal Data, and audit shall survive termination.

15.3 Amendments

15.3.1 Subject to clause 15.3.3, any amendment to this DPA must be in writing and signed by both parties.

15.3.2 If changes to Applicable Privacy Law require modifications to this DPA, the parties shall cooperate in good faith to amend this DPA accordingly.

15.3.3 Where an amendment is required in order to comply with, or to maintain a valid transfer mechanism under, Applicable Privacy Law, and the amendment does not reduce Client's rights or Vendor's obligations under this DPA, Vendor may make that amendment by giving Client at least 30 days' written notice. If Client reasonably objects within that period, the parties shall negotiate in good faith, and failing agreement Client may terminate the affected services on written notice.

15.4 Severability

15.4.1 If any provision of this DPA is invalid or unenforceable, the remaining provisions shall remain in effect.

15.4.2 The parties shall replace any invalid or unenforceable provision with a valid and enforceable provision that achieves the same intent.

15.5 Notices

15.5.1 All notices under this DPA shall be in writing and delivered to the contact information provided in the Principal Agreement.

Appendix 1: Details of processing

Categories of Data Subjects

  • Employees, contractors, and representatives of Client
  • End users of Client's services, as applicable
  • Other individuals whose Personal Data is processed through the services

Types of Personal Data

  • Contact information (names, email addresses, phone numbers)
  • Account credentials and authentication data
  • Content and data provided by Client through the services
  • Usage data and metadata related to use of the services

Nature and purpose of processing

  • Providing the services described in the Principal Agreement
  • Supporting, maintaining, and improving the services
  • Complying with legal obligations
  • Other purposes specified in the Principal Agreement

Duration of processing

For the term of the Principal Agreement, plus any additional period required for return or deletion of Personal Data under clause 10.

Appendix 2: Security measures

Vendor implements and maintains appropriate technical and organizational measures including:

Access controls. Role-based access controls; multi-factor authentication for system access; unique user identification; regular access review procedures.

Encryption. Encryption of data in transit using TLS; encryption of data at rest.

System security. Regular security updates and patching; vulnerability scanning and penetration testing; malware protection; intrusion detection and prevention.

Physical security. Vendor operates no data centres and no premises at which Personal Data is stored or processed. All Personal Data is hosted in Amazon Web Services facilities, and the physical and environmental controls for those facilities, including access control, environmental protection and secure media disposal, are operated by Amazon Web Services and evidenced by its independent attestations. Vendor personnel work remotely, and Vendor policy prohibits the storage of Client content on local devices or removable media.

Organizational measures. Security awareness training for personnel at hire and at least annually; documented security policies and procedures; incident response procedures exercised at least annually; regular security assessments; third-party risk assessment before engagement and at least annually thereafter.

Business continuity. Regular data backups; disaster recovery procedures; business continuity planning.

Independent assurance. SOC 2 Type 2 examination, held continuously since 2020, covering the Security criteria. Independent penetration testing at least annually.

Appendix 3: Subprocessors

The list of Subprocessors is not reproduced here. It is published and maintained at https://wxrks.com/subprocessors and is incorporated into this DPA by clause 6.1.2.

Keeping it as a linked, versioned document means a new Subprocessor can be added without amending this DPA. Client protection comes from clause 6.2: at least 30 days' prior notice before a new Subprocessor is authorised, a right to object within 15 days, and a right to terminate the affected services if no resolution is reached.

The published list records, for each Subprocessor: name, purpose of processing, processing location, and type of data processed.

Get started
for free

Try wxrks for as long as you would like with our free Starter plan. Purchase a paid wxrks plan to unlock the correct degree of scalability and features.

Get started — it's free