Data Processing Addendum
Effective July 10, 2026
This Data Processing Addendum governs Wiki’s processing of personal data on behalf of customers and is incorporated into our Terms of Service. Enterprise customers may request a countersigned version from our privacy team.
Definitions
- Customermeans the entity that executes or accepts this Data Processing Addendum (“DPA”) and uses the Service.
- Personal Data means any information relating to an identified or identifiable natural person that Wiki processes on behalf of Customer through the Service.
- Service means the Wiki application, hosted documentation, APIs, and related services described in the Terms of Service.
- Subprocessor means any third party engaged by Wiki to process Personal Data on behalf of Customer.
- Data Protection Laws means all applicable laws relating to privacy and data protection, including the GDPR, UK GDPR, CCPA/CPRA, and other U.S. state privacy laws, as applicable to the processing.
Scope, Duration, and Order of Precedence
This DPA applies when Wiki, a company organized under the laws of the State of Montana(“Wiki,” “Processor,” “we,” “us,” or “our”), processes Personal Data on Customer’s behalf through the Service. This DPA is effective upon execution, acceptance through account settings or checkout where enabled, or incorporation into an order form, and remains in effect for the duration of the Service agreement.
In the event of conflict between this DPA and the Terms, this DPA governs with respect to the processing of Personal Data. In the event of conflict between this DPA and an executed order form or enterprise agreement, the order form or enterprise agreement governs.
Nature and Purpose of Processing
Wiki processes Personal Data to provide wiki management, knowledge governance, AI policy controls, answer testing, documentation publishing, analytics enabled by Customer, audit logging, and related support services as configured by Customer through the Service.
Categories of Personal Data
- Account and contact information for authorized users (name, email, role).
- Organization and workspace membership and permission data.
- Content uploaded by Customer that contains personal data.
- Usage, audit, support, and operational logs related to the Service.
- Public documentation visitor data where Customer enables relevant features.
Categories of Data Subjects
- Customer employees, contractors, agents, and authorized users.
- Individuals whose personal data appears in Customer Content.
- Public documentation visitors where Customer enables analytics or assistant features.
Controller and Processor Roles
Customer is the controller (or equivalent) of Personal Data it submits to the Service. Wiki acts as processor (or service provider) except where Wiki acts as controller for its own account administration, billing, security monitoring, product improvement using aggregated or de-identified data, and compliance activities as described in the Privacy Policy.
Processing Instructions
Wiki shall process Personal Data only on documented instructions from Customer, including through Customer’s configuration and use of the Service, unless required by applicable law. If Wiki is required by law to process Personal Data contrary to Customer instructions, Wiki shall inform Customer of that requirement before processing unless prohibited by law.
Customer is responsible for ensuring that its instructions comply with Data Protection Laws and that it has established an appropriate legal basis for processing.
Confidentiality
Wiki ensures that personnel authorized to process Personal Data are bound by written confidentiality obligations and receive appropriate training on data protection. Wiki maintains access controls limiting personnel access to Personal Data on a need-to-know basis.
Security Measures
Wiki implements and maintains appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. A summary of security measures is available on our Security page and in Annex B below.
Customer is responsible for configuring appropriate permissions, access controls, and publishing settings within the Service.
Subprocessors
Customer provides general authorization for Wiki to engage Subprocessors listed at https://wiki.co/subprocessors. Wiki shall:
- Impose data protection obligations on Subprocessors substantially similar to those in this DPA.
- Provide at least thirty (30) days’ advance notice of intended additions or replacements of Subprocessors that process Customer Personal Data, by updating the Subprocessor list and, where contact information is available, by email notification.
- Allow Customer to object to a new Subprocessor on reasonable grounds relating to data protection by notifying hello@wiki.co within fifteen (15) days of notice. If the parties cannot resolve the objection, Customer may terminate the affected Service upon written notice as the sole remedy.
Wiki remains liable to Customer for the performance of Subprocessor obligations.
Data Subject Requests
Wiki shall, taking into account the nature of processing, provide reasonable assistance to Customer in responding to data subject requests under Data Protection Laws, using available account tools where practicable. Customer is responsible for responding to data subjects. Wiki shall promptly notify Customer if it receives a request directly from a data subject unless prohibited by law.
Personal Data Breach Notification
Wiki shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data breach affecting Customer Personal Data. Notification shall include, to the extent reasonably available:
- A description of the nature of the breach.
- Categories and approximate number of data subjects and records affected.
- Likely consequences of the breach.
- Measures taken or proposed to address the breach and mitigate harm.
- Contact information for Wiki’s data protection contact.
Wiki shall cooperate with Customer’s investigation and provide additional information as it becomes available. Wiki’s notification obligations do not constitute acknowledgment of fault or liability.
Deletion and Return of Data
Upon termination of the Service or upon Customer’s written request, Wiki shall delete or return Customer Personal Data according to the Terms and account deletion procedures, unless retention is required by applicable law. Backup copies may persist for a limited period in accordance with Wiki’s backup retention schedule before being overwritten in the ordinary course.
Audits and Compliance Information
Upon Customer’s written request no more than once per twelve (12) month period, Wiki shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may include:
- Wiki’s most recent third-party security audit report (e.g., SOC 2 Type II), if available.
- Completed security questionnaires for enterprise customers upon request.
- Responses to reasonable written inquiries regarding Wiki’s processing practices.
On-site audits may be conducted no more than once per twelve (12) month period upon thirty (30) days’ prior written notice, during normal business hours, subject to confidentiality obligations, and at Customer’s expense. Customer shall minimize disruption to Wiki operations. Wiki may satisfy audit requests through third-party reports in lieu of on-site inspection where such reports address the scope of the request.
International Transfers
Where Wiki transfers Personal Data from the EEA, UK, or Switzerland to countries without an adequacy decision, Wiki shall implement appropriate safeguards, including the Standard Contractual Clauses approved by European Commission Decision 2021/914:
- Module Two (Controller to Processor) where Customer is controller and Wiki is processor.
- Module Three (Processor to Processor) for onward transfers to Subprocessors where applicable.
For UK transfers, the UK International Data Transfer Addendum applies as incorporated into the applicable SCCs. Wiki has conducted transfer impact assessments for relevant Subprocessors and implements supplementary measures where appropriate. A copy of applicable transfer mechanisms may be requested from hello@wiki.co.
Assistance with Compliance
Wiki shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities where required by Data Protection Laws, taking into account the nature of processing and information available to Wiki. Additional assistance beyond reasonable scope may be subject to separate fees.
Liability
Liability arising under or in connection with this DPA is subject to the limitations and exclusions set forth in the Terms, except where prohibited by applicable Data Protection Laws. Nothing in this DPA limits either party’s liability for breaches of Data Protection Laws to the extent such limitation is prohibited by law.
Governing Law
This DPA is governed by the laws of the State of Montana, without regard to conflict-of-law principles, except where Data Protection Laws require otherwise with respect to the processing of Personal Data.
Execution and Incorporation
This DPA is incorporated into the Terms by reference and applies automatically to Customer’s use of the Service where Customer processes Personal Data through the Service. Enterprise customers may request a countersigned version by contacting hello@wiki.co. For questions regarding this DPA, contact hello@wiki.co.
Annex A: Processing Details
- Subject matter: Provision of wiki management and knowledge governance services for AI applications.
- Duration: Term of the Service agreement plus any post-termination retention period described herein.
- Nature of processing: Storage, retrieval, search, indexing, publishing, policy evaluation, answer testing, analytics, support, and deletion.
- Purpose: To provide the Service as configured by Customer.
Annex B: Technical and Organizational Measures
Wiki maintains measures including, without limitation:
- Encryption of data in transit using TLS/HTTPS.
- Encryption at rest provided by cloud infrastructure providers.
- Role-based access controls and multi-tenant isolation.
- Authentication through industry-standard identity providers.
- Audit logging for sensitive administrative actions.
- Application security headers and input validation.
- Secure payment processing through Stripe, Inc.
- Incident response procedures and security monitoring.
- Personnel background checks and confidentiality agreements for staff with data access.
- Regular review and update of security measures.