Data Processing Addendum
Last updated: June 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and Wentzel Investments LLC ("Wentzel") for the use of Q by Wentzel ("the Service") (the "Agreement"). It governs the processing of personal data that Wentzel carries out on behalf of the Customer in providing the Service. Where there is a conflict between this DPA and the Agreement with respect to data protection, this DPA prevails.
1. Definitions
"Data Protection Laws" means all applicable laws relating to the processing and protection of personal data, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended ("CCPA/CPRA"). The terms "controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by Wentzel to process personal data on the Customer's behalf.
2. Roles & Scope
For personal data processed under the Agreement, the Customer is the controller (or a processor acting on behalf of a third-party controller) and Wentzel is the processor. Wentzel will process personal data only as necessary to provide the Service and in accordance with this DPA and the Customer's documented instructions, including those set out in the Agreement and the Customer's use of the Service.
3. Details of Processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I. The duration of processing is the term of the Agreement, plus any period during which Wentzel retains personal data in accordance with this DPA.
4. Processor Obligations
Wentzel will:
- process personal data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Wentzel will, where legally permitted, inform the Customer);
- ensure that persons authorized to process personal data are bound by an obligation of confidentiality;
- implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR (see Section 9); and
- not sell personal data and not process it for any purpose other than providing the Service.
5. Sub-processing
The Customer provides a general authorization for Wentzel to engage the sub-processors listed in Annex II. Wentzel imposes data protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for each sub-processor's performance. Wentzel will provide notice of any intended addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the matter.
6. Assistance to the Customer
Taking into account the nature of the processing, Wentzel will assist the Customer by appropriate technical and organizational measures, and insofar as is reasonably possible, in fulfilling the Customer's obligations to respond to requests from data subjects exercising their rights, and in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation), taking into account the information available to Wentzel.
7. Personal Data Breach
Wentzel will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will provide the Customer with information reasonably available to it to assist the Customer in meeting any obligation to notify supervisory authorities or data subjects.
8. Deletion or Return of Data
Upon termination or expiry of the Agreement, Wentzel will, at the Customer's choice, delete or return all personal data processed on the Customer's behalf and delete existing copies, unless applicable law requires continued storage. Consistent with the Terms, the Customer may export scan data for thirty (30) days following termination, after which Wentzel may delete it.
9. Security Measures
Wentzel implements measures appropriate to the risk, including: encryption of personal data in transit and at rest; access controls and least-privilege practices; logical separation of Customer data; monitoring and logging of its production environment; secure software development and change management; and regular review of the effectiveness of these measures. A summary of the technical and organizational measures is set out in Annex I.
10. Audits & Information
Wentzel will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations in this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits will be subject to reasonable advance notice, confidentiality obligations, and conditions designed to avoid disruption to Wentzel's operations and other customers; Wentzel may satisfy audit requests by providing existing reports or documentation where they reasonably address the Customer's request.
11. International Transfers
Where Wentzel transfers personal data originating in the European Economic Area, United Kingdom, or Switzerland to a country that has not received an adequacy decision, such transfers are governed by the European Commission's Standard Contractual Clauses (Modules Two (controller-to-processor) and Three (processor-to-processor), as applicable), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail over conflicting terms in respect of such transfers.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
13. Order of Precedence
This DPA supplements the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control with respect to the transfers they govern.
Annex I — Details of Processing
- Subject matter:Wentzel's provision of the Q by Wentzel post-quantum cryptography assessment Service to the Customer.
- Duration: the term of the Agreement plus any retention period permitted under Section 8.
- Nature and purpose: hosting, processing, and storage of Customer data to deliver cryptographic inventory scanning, CBOM generation, HNDL scoring, assessment reporting, account management, and support.
- Types of personal data: account identifiers (name, business email, organization), authentication data (hashed credentials), billing contact details, and usage/log data. Scan and assessment data is Customer content and may incidentally contain personal data the Customer chooses to submit.
- Categories of data subjects:the Customer's authorized users, administrators, and personnel.
- Technical and organizational measures: as described in Section 9 (encryption in transit and at rest, access controls, logical data separation, monitoring and logging, secure development and change management).
Annex II — Approved Sub-processors
- Cloudflare, Inc. (United States) — application hosting, edge delivery, and database/object storage.
- Amazon Web Services, Inc. (United States) — transactional email (Amazon SES) and object storage.
- Stripe, Inc. (United States) — payment processing for paid plans.
Contact
For questions about this DPA or to exercise rights related to data processing, contact us at support@wentzel.ai.