# Data Processing Agreement for Waterglass Waves

> The data processing agreement under Article 28 GDPR between Waves customers and Waterglass FlexCo, with the description of processing, the security measures and the subprocessor annex.

Canonical: https://www.waterglass.ai/en/products/waves/data-processing-agreement/
Language: English (Deutsch: https://www.waterglass.ai/de/produkte/waves/auftragsverarbeitung.md)
Company: Waterglass FlexCo, Börseplatz 1/3/6, 1010 Vienna, Austria · hi@waterglass.ai

Updated: September 2026

## § 1 Subject Matter, Parties and Application

(1) This data processing agreement (DPA) governs the processing of personal data that the Client, as controller, brings into Waterglass Waves and that Waterglass FlexCo, as processor, processes on the Client's behalf. It specifies the obligations under Article 28 GDPR and is modelled on the standard contractual clauses of the European Commission under Implementing Decision (EU) 2021/915.

(2) The DPA is concluded upon acceptance of the [General Terms and Conditions (General Terms)](https://www.waterglass.ai/en/terms/) and the [Product Terms for Waterglass Waves](https://www.waterglass.ai/en/products/waves/terms/) (§ 10 of the product terms). It applies for the term of the usage contract and beyond it until all personal data has been deleted or returned.

(3) In matters of data protection this DPA prevails over the General Terms and the product terms. Terms have the meaning given to them in the GDPR.

(4) The controller is the Client as identified in its organisation in the console. The processor is Waterglass FlexCo, Vienna, [hi@waterglass.ai](mailto:hi@waterglass.ai). Our postal address and further contact details are stated in the [legal notice](https://www.waterglass.ai/en/imprint/). The contact person for data protection matters is Bernhard Hauser.

## § 2 Description of the Processing (Annex 1)

(1) Subject matter: the provision of Waves, that is, the console, the application programming interface, the command-line tools and the execution environments, for the definition and operation of AI agents.

(2) Nature and purpose: storage of the content brought in by the controller and of the content arising during runs, transmission of that content to the AI model providers and connected services selected by the controller, execution of agents in isolated environments, creation of run trails and archives, and provision of exports. The purpose is the operation of the controller's agents according to its instructions.

(3) Categories of data subjects: determined by the controller through the content it brings in, typically the controller's employees, customers, prospects and suppliers, and other persons appearing in documents, messages or connected services.

(4) Categories of personal data: all data the controller brings in through instructions, knowledge bases, connected services, stored credentials and retrieved content, and all data arising during runs. Special categories of personal data within the meaning of Article 9 GDPR are processed only where the controller has a valid legal basis and applies the measures described in Annex 2, Part B (§ 6 paragraph 4 of the product terms).

(5) Duration: the term of the usage contract and the transitional and retrieval periods under § 11.

## § 3 Instructions

(1) We process personal data only on the documented instructions of the controller, unless we are required to process by Union law or Austrian law. In that case we inform the controller of that requirement before processing, unless the law prohibits such information.

(2) The controller gives instructions through its use of the platform, in particular by configuring its agents, selecting models, tools, connected services and network destinations, starting runs and deleting data, and in text form to [support@waterglass.ai](mailto:support@waterglass.ai). We may decline instructions that go beyond the platform's functions or offer them as a separately remunerated service.

(3) If we consider an instruction to infringe the GDPR or other data protection law, we inform the controller without delay and may suspend its execution until the controller confirms or changes the instruction.

## § 4 Purpose Limitation and Confidentiality

(1) We process the data exclusively for the purposes stated in § 2. Processing for our own purposes takes place only where the product terms provide for it (§ 10 paragraphs 3 and 4 of the product terms). For that processing we are the controller.

(2) We grant access to the data only to persons who need it to provide the service and who are bound by confidentiality. We limit administrative access to stored content to operation, fault diagnosis and recovery, and we log it.

## § 5 Security of Processing

(1) We implement the technical and organisational measures described in Annex 2. They take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk for the data subjects.

(2) We may develop the measures further as long as the level of protection is not reduced. We notify material changes.

(3) The controller assesses whether the measures are sufficient for the data it brings in and takes the measures that lie within its own responsibility (Annex 2, Part B).

## § 6 Subprocessors

(1) The controller gives a general authorisation for the engagement of the subprocessors named in Annex 3. We announce changes on the page referred to in Annex 3 and by email at least 14 days before they take effect. The controller may object on compelling data protection grounds. Where the objection cannot be resolved by agreement, the controller may terminate the usage contract with effect from the date the change takes effect.

(2) We bind subprocessors by contract to substantially the same data protection obligations as those binding us under this DPA and ensure that they provide sufficient guarantees of appropriate measures. Where a subprocessor fails to fulfil its obligations, we remain liable to the controller for that failure as for our own conduct.

(3) On request we provide the controller with a copy of our contract with a subprocessor. We may redact commercial information in doing so.

(4) Recipients determined by the controller itself are not subprocessors: the services it connects, its own tool servers and network destinations, and the websites its agents retrieve (§ 8 of the product terms). The AI model provider is a subprocessor, but the controller makes the selection for each agent.

## § 7 Transfers to Third Countries

(1) We transfer personal data to a country outside the European Union or the European Economic Area only where the controller causes this by selecting a model operated there, by enabling the web search tool or by connecting a service established there, or where we are legally required to do so.

(2) For subprocessors in third countries without an adequacy decision, we base the transfer on the standard contractual clauses of the European Commission and supplementary measures. Annex 3 states the country of processing for every subprocessor.

(3) The console states the country of processing for every model. Where the controller requires processing exclusively within the Union, it selects models operated there, leaves the web search tool switched off and does not connect services outside the Union.

## § 8 Assistance to the Controller

(1) We assist the controller with appropriate measures in fulfilling its obligation to respond to requests from data subjects. Where a data subject contacts us directly, we forward the request to the controller without delay and do not answer it ourselves.

(2) Taking into account the nature of the processing and the information available to us, we assist the controller in ensuring the security of processing, in notifying personal data breaches to the supervisory authority and to data subjects, in data protection impact assessments and in prior consultation of the supervisory authority.

(3) The controller can itself view, rectify, export and delete its data through the interfaces. Assistance beyond that is provided against remuneration on a time and materials basis at the agreed rates or our usual rates, unless it is occasioned by our own conduct.

## § 9 Personal Data Breaches

(1) We notify the controller of any personal data breach affecting its data without undue delay after becoming aware of it, as a rule within 48 hours, by email to the address of the organisation's owner.

(2) The notification contains, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact point. Information not yet available is provided subsequently.

(3) We document breaches and assist the controller in fulfilling its notification obligations under Articles 33 and 34 GDPR.

## § 10 Documentation and Audits

(1) We make available to the controller all information necessary to demonstrate compliance with this DPA, in particular the description of measures in Annex 2, the list of subprocessors and, on request, further documentation.

(2) The controller may audit compliance with this DPA once a year and where there is a specific reason, itself or through an auditor bound by confidentiality. Audits are announced with reasonable notice, take place during business hours and do not impair the operation or the data of other customers. They are conducted primarily by inspection of documentation and written information. The controller bears the cost of audits without a specific reason on a time and materials basis.

(3) There is currently no certification under ISO 27001 and no comparable audit report.

## § 11 Deletion and Return

(1) After the end of the usage contract we keep the controller's data available for return during the 30-day transitional period and the subsequent 30-day retrieval period under § 5a of the product terms. The controller can export the data through the interfaces during the transitional period and request it in a structured, commonly used and machine-readable format until the end of the retrieval period. We then delete all personal data and copies unless Union law or Austrian law requires retention. Data in encrypted backups is deleted at the end of the backup cycle.

(2) The controller may also request deletion during the contract, for individual runs directly in the console and for the account and organisation in text form to [support@waterglass.ai](mailto:support@waterglass.ai). We confirm the deletion on request.

## § 12 Liability, Non-Compliance and Final Provisions

(1) The liability of the parties is governed by § 8 of the General Terms and § 11 of the product terms. Article 82 GDPR remains unaffected.

(2) If we breach this DPA, the controller may suspend the affected processing and, if the breach is not remedied within a reasonable period, terminate the usage contract for good cause. Conversely, we may terminate the usage contract if the controller insists on an unlawful instruction.

(3) The final provisions of the General Terms apply. The German version is authoritative. Which data the platform processes in detail is described in the [Privacy Notice for Waterglass Waves](https://www.waterglass.ai/en/products/waves/privacy/).

## Annex 2: Technical and Organisational Measures

Part A, measures of the processor.

Place of processing: the platform, its databases, object storage and backups are operated in data centres in Germany. Transfers outside the Union arise only from the controller's choices described in § 7.

Access control: two-factor authentication is available for user accounts, API keys are stored as verification values only and displayed once, sessions use rotating identifiers, the roles Owner and Member separate billing and key management from use, and sign-in attempts are rate-limited.

Authorisation control: the application accesses the database through an identity with restricted rights, administrative access to the systems is limited to a very small group of persons and is required for operation, fault diagnosis and recovery, and every administrative read of stored content is logged.

Encryption: transport encryption for all public access, stored credentials encrypted with a separate key per entry, two-factor secrets encrypted, backups encrypted, and the values of stored credentials masked in logs, trail data and instructions sent to AI models.

Separation: each run executes in its own isolated environment with limited resources and network traffic restricted to the destinations approved by the controller, tenants are separated in the database, and the execution environment receives no credentials of the AI model providers because calls run through our own gateway.

Integrity: the trail of a run is append-only and its immutability is enforced in the database, and delivered software is verified by checksum before it is executed.

Availability and recovery: daily encrypted backups of the database kept for around two weeks at a second location in the same country, continuous archiving of transaction logs, rehearsed restoration, and monitoring that alerts us to faults.

Logging: access logs contain no content and rotate continuously, and the gateway to the AI models does not store inputs or outputs.

Organisation: all persons with access are bound by confidentiality, rights are granted according to the principle of least privilege, incidents follow a documented procedure, and cryptographic keys are managed by a defined process.

Deletion: finished runs, including their trail, artifacts and working directory, can be deleted with immediate effect in the console and on the command line, and accounts and organisations are deleted on request.

Part B, measures within the responsibility of the controller.

Selecting a model operated within the Union, leaving the web search tool switched off and refraining from connections to services outside the Union where transfers to third countries are to be excluded. Separating stored credentials from open internet access for an agent. Activating two-factor authentication, keeping the group of authorised persons up to date and revoking keys and memberships that are no longer needed. Establishing its own legal basis and further measures where special categories of personal data are processed. Exporting in good time content that it needs outside the platform.

## Annex 3: Subprocessors

The [list of subprocessors](https://www.waterglass.ai/en/subprocessors/) engaged for Waves, with purpose and country of processing, is published on our website. It forms part of this DPA and is changed in accordance with § 6.
