Data Processing Addendum
Last updated 6 September 2026. Counsel signed 6 September 2026. Download signed pack (PDF)
This Data Processing Addendum (DPA) is part of the Terms when you use WiseTap to collect, store, email or export contacts, form answers, assistant messages or insights about visitors. You are the controller of that data. WiseTap Ltd (company number 15646517), whose registered office is at 163 Woodland Gardens, Isleworth, United Kingdom, TW7 6LX is the processor.
It is intended to meet UK GDPR Article 28. If the UK Information Commissioner publishes a revised standard, we will update this page. Account data (your login, billing, chips) is not in scope — we are the controller of that; see the Privacy Policy.
1. Definitions
“UK GDPR”, “personal data”, “process”, “controller”, “processor”, “sub-processor” and “data subject” have the meanings in the UK GDPR and the Data Protection Act 2018. “Lead data” means personal data visitors submit on your page, plus first-party events and assistant turns that relate to those visits.
2. Details of processing (Article 28(3))
| Item | Detail |
|---|---|
| Subject matter | Hosting and delivering lead data and visitor events for your WiseTap pages |
| Duration | For as long as you have an account, or until you delete the record |
| Nature | Store, display in your inbox, email you an alert, send a follow-up you start, export if your plan allows, count events, run the optional assistant |
| Purpose | So you can see and follow up people who used your page |
| Types of personal data | Name, email, phone, company, message, custom answers, marketing consent, source, chip, time, country, device class, referrer host, visitor/session ids if they accepted insights, assistant messages |
| Categories of data subject | Visitors to your page and people whose details are typed into your form |
Special-category data is not required for the service. Do not configure forms to collect it. If we see a form that does, we may suspend that form and tell you.
3. Instructions
We only process lead data to: show it in your inbox, send you a lead-alert email, send a follow-up you start from the product, export it if your plan allows, attach it to the chip and page it came from, retain insights for the window on your plan, and operate the assistant you switched on. We do not sell lead data. We do not use it for WiseTap marketing. Your documented instructions are these terms, this DPA, and the actions you take in the product (delete, export, disable a form).
If an instruction appears to infringe the UK GDPR or PECR we will tell you immediately and we may refuse that instruction. If we are required by UK law to process data beyond those instructions we will tell you unless the law forbids it.
4. Your obligations
You confirm you have a lawful basis for each use (consent or legitimate interests in the usual case) and that your privacy notice, if you need one, tells visitors you use WiseTap. You must not instruct us to process in a way that breaks UK GDPR or PECR. If you later connect a webhook, Zapier or CRM, that destination is your processor, not ours.
5. Confidentiality and staff
People who can see lead data are limited to you, anyone you add to the account, and WiseTap staff who need it to run or secure the service. They are under a confidentiality duty.
6. Security
We apply Article 32 measures appropriate to a small UK SaaS: TLS in transit, access control, hashed page passwords, origin checks and rate limits on public forms, backups of the database, and encryption of Social monitor tokens at rest. No measure is perfect. We will tell you without undue delay if we become aware of a personal-data breach that affects your lead data, with the facts we have, so you can meet your own 72-hour ICO duty.
7. Sub-processors
You authorise us to use the processors listed below (and in the Privacy Policy). That is a general written authorisation. We will impose data-protection terms on each sub-processor that are no less protective than this DPA. If we add or replace a sub-processor we will update this list. You may object within 14 days; if we cannot reasonably accommodate the objection you may stop collecting leads or delete the account.
| Processor | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosting, CDN, serverless functions, cron, optional AI Gateway | EU / US |
| Neon, Inc. | Postgres for accounts, pages, leads, events and short links | UK / EU (project region) |
| Amazon Web Services EMEA SARL | S3 for images and files you upload. Bucket region eu-west-2 (London) | UK |
| Resend, Inc. | Transactional email (magic links, lead alerts, chip codes, owner follow-ups) | US / EU |
| Google Ireland Limited | Google sign-in. Safe Browsing checks on short-link targets when that key is set | EEA / US |
| GitHub, Inc. | GitHub sign-in | US |
| Stripe Payments Europe, Ltd | Subscriptions and card payments when Checkout is open | EEA / US |
| Upstash, Inc. | Distributed rate limits in production | UK (London) |
| Functional Software, Inc. (Sentry) | Error monitoring, when a DSN is configured | US / EU |
| Model providers behind Vercel AI Gateway (including OpenAI, Inc. and Google) | Visitor chat, knowledge split and comment sentiment — only when AI is enabled on a page | US / EU |
| Meta Platforms Ireland Limited | Social monitor: Graph API for Facebook and Instagram comments on Pages a customer connects. Also used on WiseTap’s own Pages until the customer tool ships | EEA / US |
8. International transfers
If a sub-processor is outside the UK we use the UK IDTA, or the EU SCCs plus the UK Addendum, or the UK Extension to the EU-US Data Privacy Framework where the processor is certified. We will not make a further transfer without one of those safeguards or your documented instruction.
9. Assistance
Taking into account the nature of the processing, we will help you answer data-subject requests, and with Articles 32 to 36 (security, breach, DPIA, prior consultation), by providing the tools in the product (search, delete, export) and by answering privacy@wisetap.co.uk. We will not charge for reasonable assistance; disproportionate requests we will price in good faith first.
10. Deletion and return
You can delete a contact, a page or the whole account. Export (CSV) of contacts is available on Pro; insights export on Premium. A full account copy is available from Settings → Download my data, or on request to privacy@wisetap.co.uk. Within 30 days of deletion we delete or anonymise processor copies, except where UK law requires a longer keep (for example a billing dispute). Backups roll off on their normal cycle. On termination you may ask us to return a copy before we delete.
11. Audits
You may audit our compliance with this DPA once per year, on 30 days’ notice, during UK business hours, in a way that does not expose other customers’ data. We may satisfy an audit with current third-party reports or written answers where that is reasonable. You pay your own costs.
12. Liability
Liability under this DPA follows the cap and exclusions in the Terms, except that nothing limits either party’s liability to a data subject that UK GDPR does not allow to be limited. Each party remains responsible to the ICO for its own role (controller or processor).
13. Term
This DPA starts when you first collect a contact or enable insights or the assistant, and ends when we have deleted or returned the lead data. Sections on confidentiality, deletion, liability and law survive.
14. Governing law
England and Wales, as in the Terms.
15. Contact
privacy@wisetap.co.uk · hello@wisetap.co.uk · info@wisetap.co.uk (shop)
0330 043 8860
WiseTap Ltd (company number 15646517), whose registered office is at 163 Woodland Gardens, Isleworth, United Kingdom, TW7 6LX · Companies House