Data Processing Agreement
Effective October 6, 2026.
This Data Processing Agreement ("DPA") is part of the agreement between MVR Capital Holdings LLC, doing business as Wavelength ("Wavelength", "Processor"), and the customer that accepts it ("Customer", "Controller"). It applies when Wavelength processes Personal Data for Customer.
1. Definitions
1.1 "Personal Data" means any information about an identified or identifiable person that Wavelength processes for Customer.
1.2 "Data Protection Laws" means all data protection laws that apply to the processing. These include the EU General Data Protection Regulation (GDPR), the UK GDPR, and US state privacy laws.
1.3 "Subprocessor" means a third party that Wavelength uses to process Personal Data.
1.4 "Security Incident" means a breach of security that causes the accidental or unlawful loss, change, disclosure of, or access to Personal Data.
2. Roles and scope
2.1 Customer is the controller. Wavelength is the processor.
2.2 Wavelength processes Personal Data only to provide the service, and only on Customer's documented instructions. The agreement and Customer's use of the service are these instructions.
2.3 Annex 1 describes the processing.
2.4 If an instruction breaks Data Protection Laws, Wavelength tells Customer.
3. Confidentiality
3.1 Each person who processes Personal Data for Wavelength must keep it confidential.
4. Security
4.1 Wavelength uses the technical and organizational measures in Annex 2.
4.2 Wavelength can update these measures. An update must not decrease the overall level of protection.
5. Subprocessors
5.1 Customer gives general approval for Wavelength to use Subprocessors.
5.2 The current list is at wavelengthflow.com/subprocessors.html.
5.3 Wavelength posts a new Subprocessor on that page at least 30 days before use. Customer can object in writing for reasonable data protection reasons. If the parties cannot agree, Customer can end the affected service and get a refund of prepaid fees for the remaining term.
5.4 Wavelength makes each Subprocessor agree to data protection terms that give at least the same protection as this DPA. Wavelength is responsible for its Subprocessors.
6. Requests from data subjects
6.1 If a person asks Wavelength to use their data protection rights, Wavelength sends the request to Customer.
6.2 Wavelength helps Customer answer these requests, as far as the service allows.
7. Security Incidents
7.1 Wavelength tells Customer without undue delay, and within 72 hours, after it confirms a Security Incident.
7.2 The notice gives the facts that Wavelength knows: what happened, the data involved, and the steps taken.
7.3 Wavelength takes reasonable steps to contain the incident and to decrease its effects.
8. Deletion and return
8.1 Customer can delete flows, and its whole account, at any time in the service.
8.2 When the agreement ends, Customer can ask for its data. Wavelength deletes Customer's Personal Data within 30 days after the end, unless law requires Wavelength to keep it.
9. Audits
9.1 Wavelength gives Customer the information needed to show compliance with this DPA. This includes answers to security questionnaires and the security reports of its Subprocessors, where those reports can be shared.
9.2 Customer can ask for one audit each year, with 30 days notice. The audit must use an independent auditor under confidentiality, at Customer's cost.
10. International transfers
10.1 Wavelength stores Personal Data in the United States.
10.2 For transfers from the EEA, the UK, or Switzerland, the parties agree to the Standard Contractual Clauses (Module Two, controller to processor) and the UK Addendum. These are part of this DPA by reference. Annexes 1 and 2 give the information the clauses need.
11. Liability and order of terms
11.1 The liability limits in the main agreement apply to this DPA.
11.2 If this DPA and the main agreement conflict about Personal Data, this DPA applies.
12. Governing law
12.1 The laws of the State of Texas govern this DPA, except where Data Protection Laws require other law.
Annex 1: Details of processing
- Subject: Turning speech and text into process diagrams, and storing them.
- Duration: The term of the agreement, plus the deletion period in section 8.
- Data subjects: Customer's users, and people that Customer's users name in calls or transcripts.
- Data categories: Name, email, account details, audio clips (processed, not stored), images from screen recordings or photos (processed, not stored), transcripts, diagrams, usage counts.
- Processing operations: Speech-to-text, AI image reading, AI diagram generation, AI summaries, storage, sharing, export, email delivery.
- Special categories: None are planned. Customer must not put special category data in the service.
- Retention: Audio and images are not stored. Transcripts and diagrams are kept until Customer deletes them or until the deletion period in section 8 ends.
Annex 2: Security measures
- Encryption in transit (TLS) and at rest (AES-256 at the database provider).
- Database access only through server functions. Each function checks a verified sign-in. Direct client access to tables is blocked.
- Accounts are isolated. Users see only their own flows and flows shared with them.
- Per-account rate limits on AI endpoints.
- Daily database backups at the database provider.
- Payment card data is handled only by Stripe.
- Infrastructure vendors with SOC 2 Type II reports (see Annex 3).
- Secrets are kept in server-side configuration, not in client code.
Annex 3: Subprocessors
Contact: [email protected]