Data Processing Agreement (DPA)
Sets out Wooli's obligations as a service provider (processor) for Personal Information processed on a Customer's behalf.
Wooli Data Processing Agreement Last Updated: June 5, 2026
This Data Processing Agreement ("DPA") is entered into by and between Wooli, Inc., a Delaware corporation located in Lee County, Florida ("Wooli," "Processor"), and the Customer identified in the Order Form ("Customer," "Controller"). This DPA is incorporated into the Wooli Terms of Service ("ToS") and forms part of the agreement governing the Wooli Subscription Service (the "Service"). The Service supports the upload, storage, and management of diverse data (including documents, personal information, and information on others) and features (such as task assignment, file sharing, and team coordination). Subscriptions to the Service are sold and billed by Wooli and may include content or features provided by affiliated organizations, such as Wooli Safety, Inc.
This DPA ensures compliance with applicable data protection laws. Terms not defined in this DPA have the meanings set forth in the ToS.
Table of Contents
- 1 Scope and Roles
- 2 Definitions
- 3 Processing Details
- 4 Processor Obligations
- 5 Subprocessors
- 6 Data Security
- 7 Breach Notification
- 8 Data Subject and Consumer Rights
- 9 Data Transfers
- 10 Compliance Verification
- 11 Data Return or Deletion
- 12 Liability and Indemnity
- 13 Termination and Survival
- 14 Governing Law and Dispute Resolution
- 15 Miscellaneous
- 16 Reference Links
1 Scope and Roles
This DPA governs the Processing of Personal Information by Wooli as a service provider (processor) on behalf of the Customer, who acts as the data controller, in connection with the Service. This DPA applies to all Personal Information processed under the ToS and the Order Form. Wooli processes Personal Information only on the Customer's documented instructions, unless required by law. The Customer is responsible for ensuring the lawfulness of its collection of Personal Information and for providing any necessary notices and consents. This DPA supplements the ToS, and in case of conflict, this DPA controls for data protection matters. This DPA applies only to Personal Information that Wooli Processes as a processor on the Customer's behalf in connection with the Customer's Subscription to the Subscription Service. It does not apply to data Wooli collects as a controller through the Wooli Website (www.wooli.com) or Explore (explore.wooli.com), which is addressed in the Privacy Policy.
2 Definitions
2.1 Personal Information
Information relating to an identified or identifiable individual that is processed under this DPA.
2.2 Sensitive Personal Information
Categories of Personal Information that require additional protection under applicable law, such as health or biometric data or government-issued identifiers.
2.3 Processing
Any operation performed on Personal Information, such as collection, storage, use, disclosure, or deletion.
2.4 Data Subject
An individual whose Personal Information is processed.
2.5 Consumer
A natural person whose Personal Information is processed, as understood under applicable U.S. state privacy laws.
2.6 Subprocessor
A third-party provider engaged by Wooli to process Personal Information on the Customer's behalf.
2.7 Security Event
Unauthorized access to, acquisition of, or use of Personal Information that requires notification under applicable law.
2.8 Customer Data
All data uploaded or processed by the Customer or its Users through the Service, including Personal Information.
2.9 User Content
A subset of Customer Data directly uploaded or processed by the Customer or its Users.
2.10 System Data
Anonymized, aggregated data that is not attributable to any individual. System Data does not include audit, security, or activity logs that identify, or are reasonably attributable to, a specific user; such logs are treated as Personal Information and handled in accordance with the Privacy Policy.
3 Processing Details
Subject Matter: Processing of Personal Information to provide the Service, including its features and data management, as specified in the Order Form.
Duration: The term of the Subscription and 30 days after termination to allow export.
Nature and Purpose: To host, store, process, and display Customer Data and User Content, enable the Service's features (e.g., task sharing), and fulfill Wooli's obligations under the ToS.
Types of Personal Information:
- Identification and contact data (e.g., name, address, phone, email).
- Financial information (e.g., credit card details, billing data).
- IT and technical data (e.g., IP addresses, cookies, device identifiers).
- Authentication and security data (e.g., usernames, hashed passwords, MFA details).
- Usage and interaction data (e.g., application logs, clickstream data, feature usage).
- Communication data (e.g., chat messages, support transcripts).
- Third-party and integrated service data (e.g., from Google or Stripe).
- Metadata and analytics data.
- Personal Information uploaded by the Customer (e.g., documents, custom fields).
- Sensitive Personal Information (e.g., health or biometric data), only if enabled with appropriate safeguards.
Categories of Data Subjects: Users (e.g., employees, contractors), third parties whose data the Customer uploads (e.g., clients), and individuals interacting with the Customer in an employment or business context.
4 Processor Obligations
Wooli agrees to:
- Process Personal Information only on the Customer's documented instructions, as provided in the ToS, Order Form, or this DPA, unless required by law.
- Implement appropriate technical and organizational measures (e.g., encryption, access controls) to protect Personal Information.
- Ensure that personnel authorized to process Personal Information are bound by confidentiality obligations.
- Notify the Customer if Wooli determines it can no longer meet its obligations under this DPA or applicable law, so the Customer can take steps to address the issue.
- Assist the Customer in responding to individual rights requests (e.g., access, deletion) within the time required by applicable law.
- Make available information reasonably necessary to demonstrate its compliance with this DPA.
5 Subprocessors
The Customer authorizes Wooli to engage Subprocessors to process Personal Information under written agreements at least as protective as this DPA. A current list of Subprocessors is available in the Subprocessor List. Wooli will notify the Customer of new or replacement Subprocessors by email or through in-Service notifications. If the Customer has reasonable data-protection concerns about a Subprocessor, it may raise them with the Privacy Contact, and Wooli will work with the Customer to address them. Wooli remains responsible for its Subprocessors' compliance with the data protection obligations in this DPA.
6 Data Security
Wooli implements industry-standard security measures, including:
- Technical Measures: Encryption, hashed passwords, access controls, and secure transmission protocols.
- Organizational Measures: Regular security reviews, employee training, and internal security policies.
- HIPAA Compliance: For HIPAA-enabled Subscriptions, Wooli executes a Business Associate Agreement (BAA).
- Confidentiality: Personnel are bound by confidentiality obligations.
The Customer must use strong passwords and enable multi-factor authentication where available. Further details are described in the Privacy Policy.
7 Breach Notification
In the event of a Security Event, Wooli will:
- Notify the Customer without undue delay after becoming aware, and within the time required by applicable law, at the contact associated with the Customer's Account, with the available details of the event and any remedial actions.
- Investigate promptly and cooperate with the Customer to notify affected individuals, if required by law or at the Customer's direction.
- Make available information reasonably necessary to demonstrate compliance.
The Customer must report any suspected Security Event to Wooli via the Privacy Contact without undue delay.
8 Data Subject and Consumer Rights
Wooli will assist the Customer in fulfilling individual rights requests under applicable data protection law, including:
- Access, correction, deletion, and, where applicable, portability and restriction of Processing.
- Requests to know about, delete, or opt out of the sale or sharing of Personal Information (Wooli does not sell Personal Information).
Requests may be submitted through the Account Management Page or via the Privacy Contact, with responses provided within the time required by applicable law. The Customer must provide lawful instructions and any necessary consents.
9 Data Transfers
Wooli primarily stores and processes Personal Information in the United States. Certain limited data is processed by a Subprocessor in the European Union, as identified in the Subprocessor List. Where Personal Information is transferred across borders, Wooli implements the safeguards required by applicable data protection law. Storage locations are described in the Order Form and the Subprocessor List.
10 Compliance Verification
Upon the Customer's reasonable written request, and no more than once per year, Wooli will make available information reasonably necessary to demonstrate its compliance with this DPA, such as responses to a security questionnaire or a summary of its security practices. Any such review is subject to reasonable confidentiality obligations and must not unreasonably disrupt Wooli's operations. Wooli will also cooperate with any audit or inspection required by applicable law or a competent authority.
11 Data Return or Deletion
Upon termination of the Subscription, Wooli will retain Personal Information for 30 days to allow export through the Account Management Page, then delete it, except as required by law (e.g., archived backups). Data shared in collaborative features may persist in other Users' accounts. The Customer may request the return or destruction of Personal Information, including copies, unless retention is legally required.
12 Liability and Indemnity
Wooli is liable for breaches of this DPA, subject to the limitations in Section 13 of the ToS. The Customer will indemnify Wooli for claims arising from the Customer's unlawful instructions or data, as provided in the ToS. Wooli's total liability is capped as set out in Section 13 of the ToS (the greater of the fees paid in the prior 12 months or $100).
13 Termination and Survival
This DPA remains in effect for the term of the Subscription and survives termination with respect to obligations relating to data protection, confidentiality, and deletion.
14 Governing Law and Dispute Resolution
This DPA is governed by the laws of the State of Florida, and disputes are resolved as provided in Section 15 of the ToS (including the arbitration provisions), with venue in Lee County, Florida.
15 Miscellaneous
This DPA, together with the ToS, the Privacy Policy, and the Order Form, constitutes the entire agreement between the parties regarding data processing. If any provision is held invalid, the remaining provisions remain in effect. Wooli may not assign this DPA except as permitted in the ToS. Notices to Wooli must be sent to the Privacy Contact or to Wooli, Inc., PO Box 39, Estero, FL 33929.
16 Reference Links
The websites, pages, policies, and contact addresses referenced in this DPA are listed below. Where this DPA refers to a Wooli website, page, policy, or contact by name (for example, the Wooli Website, the Wooli Terms of Service, the Privacy Policy, the Subprocessor List, or the Account Management Page), that reference means the corresponding resource identified in this section. Wooli may update the links below from time to time without altering the substance of this DPA.
| Resource | Link |
|---|---|
| Wooli Website | www.wooli.com |
| Explore (Free Resources) | explore.wooli.com |
| Subscription Service (App) | apps.wooli.com |
| Wooli Terms of Service (ToS) | www.wooli.com/legal/terms |
| Privacy Policy | www.wooli.com/legal/privacy |
| Subprocessor List | www.wooli.com/legal/subprocessors |
| Account Management Page | apps.wooli.com |
| Privacy Contact | privacy@wooli.com |