Roles and scope
You (the customer) are the data controller of the business data you enter into Winstia — customer records, invoices, transactions, staff details. We are the data processor and process this data only to provide the service, on your documented instructions, and never for our own purposes.
We process this data for the duration of your subscription and delete it within 90 days of account closure, as described in our Privacy Policy.
Sub-processors
We use a small set of sub-processors to run the service: Supabase (database hosting, PostgreSQL), Vercel (web hosting and delivery), Stripe (payment processing), Resend (transactional email delivery), and Anthropic (AI insights — business data is sent for processing only when you use the Foresight AI features, and is never used to train AI models). Each sub-processor is bound by its own data processing agreement with us.
We will inform customers of material changes to this list. If you object to a new sub-processor, you may terminate the affected service and receive a pro-rated refund of prepaid fees.
Details of processing
Categories of data subjects: your customers, staff members, and suppliers whose details you record in Winstia. Types of personal data: names, contact details, transaction and payment records, and employment-related records you choose to store. Purpose: providing the Winstia service. Duration: the term of your subscription plus the deletion windows below.
Confidentiality
All personnel authorized to process personal data are bound by confidentiality obligations and process data only as needed to provide and support the service.
Security measures
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to authorized personnel with multi-factor authentication. Each business's data is isolated with database row-level security.
We maintain audit logging, dependency vulnerability scanning, and an incident-response process.
Breach notification
We will notify affected customers without undue delay, and no later than 72 hours after becoming aware of a personal data breach affecting their data, with the information reasonably required for the customer's own notification obligations.
International transfers
Where personal data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) and equivalent safeguards.
Data subject rights and assistance
We assist controllers in responding to data subject requests (access, rectification, erasure, portability) through the application's export and deletion tools, and directly at privacy@winstia.com where tooling is not sufficient.
On termination, you can export your data from the application at any time; we delete personal data within 90 days as set out in the Privacy Policy.
Audit and information rights
On request, we will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security practices and sub-processor terms. Where required by law, we support audits conducted by you or your appointed auditor, by prior arrangement and no more than once per year unless a supervisory authority requires otherwise.
Executing this DPA
This DPA applies automatically to all customers as part of the Terms of Service. If your organization requires a countersigned copy, email privacy@winstia.com and we will provide one for signature.
Questions about this policy?
We're happy to explain anything in plain language.