Legal

Data processing agreement

The Article 28 terms that apply when we process personal data on your behalf. Written to be read by a DPO in one sitting.

Version 1.0Effective 1 June 2026Art. 28 GDPR

This agreement is entered into between the customer (“Controller”) and Wildfire ApS, Smedevej 1, 5800 Nyborg, Denmark. CVR 18101580. (“Processor”), and forms part of the terms of service or of a signed order form. Where a negotiated DPA has been signed, that document governs.

1. Roles and scope

The Controller determines the purposes and means of processing personal data in its workspace. The Processor processes that data solely to provide the service. Nothing in this agreement makes the Processor a controller of customer content.

Tools the Controller connects itself remain the Controller’s own systems and are not sub-processors of the Processor.

2. Instructions

The Processor processes personal data only on documented instructions from the Controller. Configuring a workspace, setting a tier policy, authorising a connector and dispatching a task are all instructions.

The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and may suspend that processing until the instruction is amended.

The Processor does not use customer content to train, fine-tune or evaluate any model, its own or a third party’s. This obligation is passed through to every sub-processor listed in Annex III.

3. Confidentiality and personnel

  • Access is limited to personnel who need it to deliver or support the service.
  • All personnel are bound by written confidentiality obligations surviving employment.
  • Personal memory spaces are technically inaccessible to Processor personnel. There is no support override.
  • Access to production is logged and reviewed.

4. Security measures

The Processor implements the technical and organisational measures set out in Annex II, appropriate to the risk under Article 32. Measures may be updated, but not reduced below the level described.

5. Sub-processors

The Controller grants general authorisation to engage the sub-processors listed in Annex III.

  • The Processor gives at least 30 days’ notice before adding or replacing a sub-processor.
  • The Controller may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, the Controller may terminate the affected part of the service without penalty and with a pro-rata refund.
  • Sub-processors are bound by data protection obligations no less protective than these.
  • The Processor remains fully liable for its sub-processors’ performance.

6. International transfers

Tier 3 regulated processing takes place within European jurisdiction and is enforced at the gateway, not by policy. Where any transfer outside the EEA occurs, it relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses, with a transfer impact assessment available on request.

The Processor notifies the Controller if it receives a legally binding request from a public authority for customer content, unless prohibited from doing so, and challenges requests that appear unlawful.

7. Data subject requests

The Processor assists the Controller in responding to requests under Articles 15–22, including retrieval, correction, export and deletion. Where a data subject contacts the Processor directly, the Processor refers them to the Controller and informs the Controller promptly.

8. Personal data breach

  • Notification to the Controller without undue delay and in any case within 24 hours of becoming aware.
  • Notification includes the nature of the breach, categories and approximate number of records, likely consequences, and measures taken or proposed.
  • The Processor does not notify a supervisory authority or data subject on the Controller’s behalf unless instructed to.
  • Where full information is not immediately available, it is provided in phases without further delay.

9. Data protection impact assessments

The Processor provides the information reasonably required for the Controller to carry out a DPIA and, where applicable, prior consultation with a supervisory authority. This includes tier-routing configuration, sub-processor detail and the security measures in Annex II.

10. Audits and information

On reasonable notice and no more than once in any 12-month period, unless required by a supervisory authority or following a breach, the Controller may audit compliance with this agreement. Audits may be satisfied by current certifications and audit reports where these adequately address the scope. The evidence ledger is available to the Controller at all times and is the primary audit surface.

11. Deletion and return

  • At any time during the term, the Controller may export customer content and ledger entries in standard formats.
  • On termination, customer content is deleted within 30 days unless the Controller requests return first, or law requires retention.
  • Ledger entries are retained for the period configured in the order form — between 3 and 7 years — because they constitute the audit record. The Controller sets this period.
  • Backups age out on their own cycle, no longer than 35 days.

12. Liability and governing law

The limitations of liability in the terms of service apply to this agreement, save that nothing limits either party’s liability under Article 82 GDPR or for administrative fines properly attributable to it.

Danish law governs. The courts of Copenhagen have exclusive jurisdiction. In case of conflict between this agreement and the terms of service, this agreement prevails on matters of personal data.

Annex I — Description of processing

Subject matterProvision of the Wildfire AI coworker platform to the Controller.
DurationThe term of the agreement, plus the ledger retention period configured by the Controller.
Nature and purposeStorage, retrieval, indexing, transmission to model providers within the assigned tier, generation of drafts and summaries, and append-only logging of every action.
Categories of data subjectsThe Controller’s employees and contractors; the Controller’s customers, prospects and suppliers where they appear in connected systems; any individual named in content the Controller processes.
Categories of personal dataIdentification and contact data; employment and role data; commercial and correspondence content; file content from connected systems; usage and audit metadata.
Special categoriesOnly where the Controller deliberately routes such data, which the platform confines to Tier 3. Not permitted in Tier 1 or 2 by policy enforcement.
FrequencyContinuous, for the duration of the agreement.

Annex II — Technical and organisational measures

Encryption

AES-256 at rest, TLS 1.3 in transit. Keys managed per tenant and rotated on a documented schedule.

Access control

SAML SSO, least-privilege roles, separation between workspace administration and policy administration. Production access is time-bound, justified and logged.

Network isolation

Per-tenant private network. No shared application runtime between tenants for regulated workloads.

Routing enforcement

Every request is classified by sensitivity and routed at the gateway. A request classified Tier 3 cannot reach a non-European endpoint; the control is technical, not procedural.

Logging and integrity

Append-only, hash-chained ledger of every agent action, including model, jurisdiction, actor and data scope. Daily root hashes are published so tampering is detectable by the Controller independently of us.

Resilience

Daily encrypted backups with a maximum 35-day rolling window, documented restore procedure, tested restores.

Hosting

European data centres with audited physical security. Certifications are listed on the compliance page.

Organisational

Written security policy, onboarding and annual security training, background checks where lawful, documented incident response, vendor assessment before engagement.

Annex III — Authorised sub-processors

Current as of the effective date. Changes are notified in advance under clause 5.

Sub-processorPurposeLocation
Webdock ApSInfrastructure hosting and dedicated computeDenmark
AnthropicTier 1 model inferenceEU regions
OpenAITier 1 model inferenceEU regions
Mistral AITier 2 model inferenceFrance
Google CloudTier 1 model inference, EU regions onlyEU regions
TailscalePer-tenant network isolation, metadata onlyEU / US — SCCs in place
Tier 3 has no model sub-processor

Regulated workloads run on inference we operate on our own hardware in Europe. No third-party model provider is involved, which is the point of the tier.

Need this signed
before procurement?