Legal
Data Processing Addendum
Last updated August 14, 2026
The short version
Your graph is an encrypted database on your own Mac, so for almost all of it we are neither controller nor processor: it never reaches us. You decide who goes into it and why, so you are the controller. Three narrow flows do reach us, and for those we act as your processor on the terms below. We decide how to run our own billing, routing, security, and analytics, so for that set we are the controller. This document forms part of our Terms of Service.
1. Definitions
Contact Data means personal data about people other than you that you store or generate in Wend: persons, organizations, links, details, notes, promises, facts extracted from a connected account or an imported file, and the sources attached to them.
Account Data means your own identity and billing records, subscription state, the directory record that routes your link, support correspondence, security and audit logs, and usage counters.
Your Deployment means the database and proxy the Wend application deploys, at your instruction, into a cloud account that you create and own.
Data Protection Law means whichever of the EU GDPR, UK GDPR, Swiss FADP, and US state privacy laws applies to a given processing.
“Controller,” “processor,” “data subject,” “personal data,” and “processing” carry their meanings under Data Protection Law.
2. Roles
Contact Data: you are the controller, we are the processor of the part that reaches us. You determine the purposes and the means. Your instructions are the actions you take in the application and the actions you direct any AI agent you connect to take on your behalf. We process Contact Data only on those instructions, plus whatever a law we are subject to requires, in which case we will tell you first unless that law forbids it.
Account Data: we are the controller. Our Privacy Policy governs it.
If we ever process Contact Data for a purpose we set ourselves, we become a controller for that processing and we say so in the Privacy Policy. We do not do this today.
3. Scope: what we actually process
The scope matters more here than in a conventional addendum, because the ordinary assumption behind one of these documents, that the vendor holds a copy of everything, is not true of Wend. The graph is an encrypted database on your machine. Raw source material (message text, mail bodies, the contents of local databases and of files you give the application) is read there and never transmitted to us.
Contact Data reaches us in exactly three flows:
- Routing. When an agent that is not on your Mac asks a question and your Mac is unavailable, we route the request to Your Deployment and carry the answer back. Those pass through our systems in memory. We do not store them.
- Publication. When you or your agent create a page for someone else (a booking link, a shared brief, an intro page, a profile card), the application sends us the payload needed to render it and we store and serve it until you remove it. Those payloads carry only content authored for the recipient, are capped in size, and reject anything outside a fixed schema.
- Search vectors. Short strings such as a name, a role, or a company are sent to an embedding provider so that search works. Raw source material is never sent.
Everything else in your graph is outside this addendum because it is outside our systems. Where you switch the cloud option on, the copy lives in Your Deployment, addressed in Section 7.
4. What you are responsible for
As controller of Contact Data you are responsible for having a lawful basis for it, for the fairness and transparency of collecting it, and for responding to the people it concerns. That includes any obligation to inform a person that you hold data about them where you did not get it from them directly, and any assessment of legitimate interests you rely on.
You must not put special-category data into Wend (health, biometric or genetic data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation), or data about children, unless you have a lawful basis that specifically permits it and you accept that we have not designed the Service around those categories.
You are responsible for the machine the graph sits on, for the accounts you connect, and for what your connected agents do with your instructions. An instruction issued by an agent you authorised is your instruction.
5. What we do
We will:
- process Contact Data only on your instructions, only in the three flows in Section 3, and only to provide, secure, and support the Service;
- never sell or share Contact Data, and never use it to train, fine-tune, or evaluate any machine learning model, ours or anyone else’s. Every provider we route data through is contractually bound to exclude it from training;
- keep everything we do hold encrypted in transit and at rest, and restrict access to personnel who need it for a specific task;
- bind everyone with access to confidentiality obligations that survive their engagement;
- build the application so that every fact records a source and every AI inference records an audit entry, so you can show where something came from;
- give you search, correction, export, and permanent deletion in the application at no charge, so you can honour a data subject request without asking us, including after a subscription ends;
- notify you without undue delay, and in any event within 48 hours of becoming aware, of any breach affecting Contact Data we hold, with what we know and what we are doing;
- help you with data subject requests, data protection impact assessments, and prior consultations, taking into account the nature of the processing and what is available to us;
- delete what we hold on your instruction, and delete or return it when the Service ends, except where a law requires us to keep a copy. Backups roll off on their own cycle, within 30 days.
One limit is worth stating plainly rather than leaving to inference: we cannot delete from your machine or from Your Deployment, because we do not have that access. Those are one button each in the application, and they work whether or not we are involved.
6. Subprocessors
You give us general authorisation to use subprocessors. The current list, with what each one does and where it sits, is published at trywend.io/legal/subprocessors. We will give at least 30 days’ notice before adding or replacing one. If you object on reasonable data protection grounds within that window, tell us and we will work with you; if we cannot resolve it, you may terminate the affected part of the Service and we will refund any prepaid, unused fees for it. That is your exclusive remedy.
Every subprocessor is bound by terms no less protective than these, and we remain liable to you for their performance.
7. Your own cloud deployment
Where you switch the cloud option on, the application deploys a database and a small open-source proxy into a cloud account you create and own, and syncs a copy of your confirmed facts to it. That account is yours. You contract with the provider directly, under their terms, and they are not our subprocessor for it. The provider, as the company running the database, can technically read it; the copy is not held in a form that puts it beyond their reach, and we do not describe it as one.
We route agent traffic to Your Deployment when your Mac is unavailable, and we can update the proxy template if you grant us a scoped credential for that purpose, which you can revoke at any time. Beyond that we do not read from or write to it. You can switch it off, export it, or delete it unilaterally, and we never delete it because a subscription lapsed.
8. Research providers you connect yourself
Where you connect your own research provider account, you contract directly with that provider, under their terms, using your credential and your quota. They are not our subprocessor for that work. The application passes your instruction to them from your Mac and stores what comes back, with its source. You are responsible for your use of that provider complying with their terms and with Data Protection Law, including for the people whose information you research.
9. International transfers
Our own systems are hosted in the United States and we have no establishment in the EU, the UK, or Switzerland. Where you transfer personal data from those regions to us, the transfer is made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), incorporated here by reference, with the UK International Data Transfer Addendum and the Swiss adaptations as applicable. Where those clauses require a choice: the governing law is Irish law, the forum is the courts of Ireland, the optional docking clause applies, and the audit and subprocessor terms are as set out in this document.
Two facts about the architecture bear on transfers. Your graph sits on your own machine, wherever that machine is, so the bulk of the data is not transferred anywhere. And when the application deploys Your Deployment it asks you which region to create it in, so the residency of the cloud copy is your choice rather than ours.
The limit of what we hold ourselves out as. Wend does not target the EU, the UK, or Switzerland. We market in English to a US audience, price in US dollars, host our own systems only in the United States, and have not appointed an Article 27 representative. If you are in one of those regions you are welcome to use Wend, and this document is our good-faith attempt to give you the protections you would expect, but we are not holding ourselves out as a fully EU-ready vendor today. If that matters for your use, tell us before you rely on it.
10. Audits
On written request, no more than once a year, we will provide the information reasonably necessary to demonstrate compliance with this addendum, and will contribute to an audit conducted by you or an independent auditor you appoint who is not our competitor and who signs a confidentiality agreement. Audits happen during business hours, on at least 30 days’ notice, without unreasonable disruption, and at your cost. Where a recognised third-party certification or report answers the question, providing it satisfies this section.
Some of this is checkable without asking us. The engine that reads your sources is open source under AGPLv3, every signed build carries the source commit hash, and the list of hosts the application is allowed to contact is published.
11. Liability
Each side’s liability under this addendum is subject to the limitations and exclusions in the Terms of Service, and those limits apply to all claims in the aggregate across the Terms and this addendum combined. Nothing here limits a data subject’s rights under the Standard Contractual Clauses or any liability that cannot lawfully be limited.
12. Conflicts and term
This addendum applies for as long as we process Contact Data for you. Where it conflicts with the Terms of Service, this addendum governs the processing of Contact Data. Where it conflicts with the Standard Contractual Clauses, the Clauses govern.
Questions: [email protected].