Wavelength
Start free

Data Processing Agreement

Effective October 6, 2026.

This Data Processing Agreement ("DPA") is part of the agreement between MVR Capital Holdings LLC, doing business as Wavelength ("Wavelength", "Processor"), and the customer that accepts it ("Customer", "Controller"). It applies when Wavelength processes Personal Data for Customer.

1. Definitions

1.1 "Personal Data" means any information about an identified or identifiable person that Wavelength processes for Customer.

1.2 "Data Protection Laws" means all data protection laws that apply to the processing. These include the EU General Data Protection Regulation (GDPR), the UK GDPR, and US state privacy laws.

1.3 "Subprocessor" means a third party that Wavelength uses to process Personal Data.

1.4 "Security Incident" means a breach of security that causes the accidental or unlawful loss, change, disclosure of, or access to Personal Data.

2. Roles and scope

2.1 Customer is the controller. Wavelength is the processor.

2.2 Wavelength processes Personal Data only to provide the service, and only on Customer's documented instructions. The agreement and Customer's use of the service are these instructions.

2.3 Annex 1 describes the processing.

2.4 If an instruction breaks Data Protection Laws, Wavelength tells Customer.

3. Confidentiality

3.1 Each person who processes Personal Data for Wavelength must keep it confidential.

4. Security

4.1 Wavelength uses the technical and organizational measures in Annex 2.

4.2 Wavelength can update these measures. An update must not decrease the overall level of protection.

5. Subprocessors

5.1 Customer gives general approval for Wavelength to use Subprocessors.

5.2 The current list is at wavelengthflow.com/subprocessors.html.

5.3 Wavelength posts a new Subprocessor on that page at least 30 days before use. Customer can object in writing for reasonable data protection reasons. If the parties cannot agree, Customer can end the affected service and get a refund of prepaid fees for the remaining term.

5.4 Wavelength makes each Subprocessor agree to data protection terms that give at least the same protection as this DPA. Wavelength is responsible for its Subprocessors.

6. Requests from data subjects

6.1 If a person asks Wavelength to use their data protection rights, Wavelength sends the request to Customer.

6.2 Wavelength helps Customer answer these requests, as far as the service allows.

7. Security Incidents

7.1 Wavelength tells Customer without undue delay, and within 72 hours, after it confirms a Security Incident.

7.2 The notice gives the facts that Wavelength knows: what happened, the data involved, and the steps taken.

7.3 Wavelength takes reasonable steps to contain the incident and to decrease its effects.

8. Deletion and return

8.1 Customer can delete flows, and its whole account, at any time in the service.

8.2 When the agreement ends, Customer can ask for its data. Wavelength deletes Customer's Personal Data within 30 days after the end, unless law requires Wavelength to keep it.

9. Audits

9.1 Wavelength gives Customer the information needed to show compliance with this DPA. This includes answers to security questionnaires and the security reports of its Subprocessors, where those reports can be shared.

9.2 Customer can ask for one audit each year, with 30 days notice. The audit must use an independent auditor under confidentiality, at Customer's cost.

10. International transfers

10.1 Wavelength stores Personal Data in the United States.

10.2 For transfers from the EEA, the UK, or Switzerland, the parties agree to the Standard Contractual Clauses (Module Two, controller to processor) and the UK Addendum. These are part of this DPA by reference. Annexes 1 and 2 give the information the clauses need.

11. Liability and order of terms

11.1 The liability limits in the main agreement apply to this DPA.

11.2 If this DPA and the main agreement conflict about Personal Data, this DPA applies.

12. Governing law

12.1 The laws of the State of Texas govern this DPA, except where Data Protection Laws require other law.

Annex 1: Details of processing

Annex 2: Security measures

Annex 3: Subprocessors

Contact: [email protected]