Data Processing Agreement | Writesonic

Data Processing Agreement

Last updated May 16, 2026

Preamble

This Data Processing Agreement (" DPA") forms part of, and is incorporated by reference into, the Master Subscription Agreement, Terms of Service, Order Form, or other written agreement (the " Agreement") between Writesonic, Inc. ("Writesonic", "Processor") and the customer identified in the Agreement ("Customer", "Controller"). Each is a "Party" and together the "Parties".

This DPA governs Writesonic's processing of Personal Data on behalf of Customer in connection with the Services. The Services are defined in the Agreement and cover all products and websites operated by Writesonic, Inc., including the Writesonic AI Search Visibility Platform and any other Writesonic products and domains.

In the event of any conflict, inconsistency, or discrepancy between this DPA and the Agreement with respect to data protection, privacy, or processing of Personal Data, the terms of this DPA will prevail to the extent of such conflict.

Customer agrees to this DPA for itself and, where applicable under Applicable Data Protection Law, as agent for and on behalf of its Authorized Affiliates that use the Services under the Agreement. A signed counterpart of this DPA is available on request to support@writesonic.com.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

(a) " Affiliate" has the meaning given in the Agreement.

(b) " Applicable Data Protection Law" means all data-protection and privacy laws applicable to a Party's processing of Personal Data under the Agreement, including:

(c) " Authorized Affiliate" means an Affiliate of Customer that is permitted to use the Services under the Agreement and on whose behalf Customer enters into this DPA.

(d) " Controller", " Processor", " Data Subject", " Personal Data", " Processing", " Special Categories of Personal Data", and " Supervisory Authority" have the meanings given in the EU GDPR (or, where applicable, the UK GDPR or FADP). For the CCPA/CPRA, " Business", " Service Provider", " Sale", " Share", " Personal Information", and " Sensitive Personal Information" have the meanings given in the CCPA/CPRA. References in this DPA to "Personal Data" include "Personal Information" where the CCPA/CPRA applies, and references to "Controller" and "Processor" include "Business" and "Service Provider" respectively.

(e) " Customer Personal Data" means Personal Data contained in Customer Data that Writesonic processes on Customer's behalf in providing the Services.

(f) " Data Protection Impact Assessment" or " DPIA" has the meaning given in Article 35 EU GDPR.

(g) " Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by Writesonic or its Sub-processors. It does not include unsuccessful attempts that do not compromise the security of Customer Personal Data.

(h) " Restricted Transfer" means any of:

(i) " Standard Contractual Clauses" or " SCCs" means:

(j) " Sub-processor" means any third party engaged by Writesonic (or its Affiliate) that processes Customer Personal Data in connection with the Services.

(k) " Services" has the meaning given in the Agreement.

2. Scope and Roles

2.1 Subject Matter

This DPA applies to Writesonic's processing of Customer Personal Data carried out on Customer's behalf in providing the Services. The details of the processing are set out in Schedule 1 (Details of Processing).

2.2 Roles

For Customer Personal Data, Customer acts as Controller and Writesonic acts as Processor. For the CCPA/CPRA, Writesonic acts as Service Provider with respect to Customer Personal Data.

2.3 Each Party's Compliance

Each Party will comply with its respective obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness of its processing instructions and the means by which it acquired Personal Data.

3. Customer Instructions and Responsibilities

3.1 Documented Instructions

The Agreement (including this DPA), Customer's use of the Services, and any further written instructions mutually agreed by the Parties constitute Customer's complete instructions.

3.2 Lawfulness of Instructions

Customer represents and warrants that (a) it has the legal basis under Applicable Data Protection Law to provide Customer Personal Data to Writesonic and to instruct Writesonic to process it as described, (b) it has provided all required notices and obtained all required consents, and (c) the instructions, if followed, do not violate Applicable Data Protection Law.

3.3 Notice of Conflict

If Writesonic believes that an instruction violates Applicable Data Protection Law, Writesonic will, to the extent permitted by law, inform Customer without undue delay.

3.4 CCPA/CPRA Service-Provider Commitments

For Customer Personal Data subject to the CCPA/CPRA, Writesonic:

(a) will not Sell or Share Customer Personal Data; (b) will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for any purpose other than the Business Purposes, except as permitted by the CCPA/CPRA; (c) will not combine Customer Personal Data with personal information received from or on behalf of any other person, except as permitted by CCPA regulations; (d) certifies its understanding of and compliance with the restrictions in this DPA; and (e) grants Customer the rights specified in CCPA.

4. Confidentiality of Personnel

Writesonic will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.

5. Security

Writesonic will implement and maintain the technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.

Customer acknowledges that the Services are designed to be configured and used in a manner that supports the security of Customer Personal Data.

6. Personal Data Breach

6.1 Notification

Writesonic will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

6.2 Information Provided

The notification will describe (a) the nature of the breach, (b) the likely consequences, (c) the measures taken to address it, and (d) the contact for further information. Writesonic will provide periodic updates as the investigation progresses.

6.3 Cooperation

Writesonic will provide Customer with reasonable assistance, taking into account the nature of the processing, to help Customer comply with its notification obligations.

6.4 Not a Concession

Notification of a Personal Data Breach under this DPA is for informational purposes only and will not be construed as an admission by Writesonic.

7. Assistance to Customer

7.1 Data Subject Requests

Taking into account the nature of the processing, Writesonic will assist Customer to fulfill Customer's obligations to respond to Data Subject requests under Applicable Data Protection Law.

7.2 DPIAs and Prior Consultation

Writesonic will provide reasonable cooperation in support of Customer's DPIAs and prior consultations with Supervisory Authorities, to the extent relevant information is available to Writesonic.

7.3 Regulatory Inquiries

Writesonic will provide reasonable assistance to Customer in responding to inquiries or investigations by Supervisory Authorities.

8. Sub-processors

8.1 General Authorization

Customer provides general written authorization for Writesonic to engage Sub-processors to process Customer Personal Data.

8.2 Current Sub-processors

The list of Sub-processors used as of the effective date of this DPA is set out in Schedule 3 (Sub-processors).

8.3 New or Replacement Sub-processors

Writesonic will notify Customer of any new or replacement Sub-processor at least 30 days before the new Sub-processor begins processing Customer Personal Data.

8.4 Right to Object

Customer may object to a new Sub-processor in writing within 15 days of notification, on reasonable data-protection grounds. The Parties will work in good faith to address the objection.

8.5 Sub-processor Obligations

Writesonic will impose contractual data protection obligations on its Sub-processors that are materially consistent with this DPA.

9. International Transfers

9.1 Transfer Mechanism

Where Customer's use of the Services involves a Restricted Transfer of Customer Personal Data, the Parties agree on the appropriate SCCs and related terms.

9.2 Transfer Impact Assessment

Writesonic has performed a Transfer Impact Assessment for transfers to the United States and other jurisdictions.

9.3 Adequacy

If a new adequacy decision applies to Customer Personal Data transferred under the Services, the transfer may rely on that adequacy decision.

10. Return or Deletion of Customer Personal Data

On termination or expiration of the Agreement, Writesonic will, at Customer's choice, return or delete all Customer Personal Data, except to the extent Writesonic is required by applicable law to retain some or all of it.

11. Audits

11.1 Audit Rights

Writesonic will provide information necessary to demonstrate compliance with this DPA.

11.2 On-site Audits

Customer may, subject to certain conditions, conduct an audit of Writesonic's compliance with this DPA.

12. AI Processing of Customer Personal Data

12.1 No Training on Customer Data

Writesonic does not use Customer Personal Data to train or fine-tune any general-purpose models.

12.2 Model Providers as Sub-processors

Writesonic uses Model Providers as Sub-processors for AI Features.

12.3 Aggregated and De-identified Data

Writesonic may use de-identified data for operational purposes.

12.4 Customer's Responsibility for Inputs

Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law.

13. Term

This DPA is effective on Customer's first acceptance of the Agreement and continues until termination or expiration of the Agreement.

14. Authorized Affiliates

Customer enters into this DPA on behalf of its Authorized Affiliates.

15. Liability

Each Party's liability arising out of this DPA is subject to the limitations of liability set out in the Agreement.

16. General

16.1 Order of Precedence

In the event of conflict on a data-protection matter, a specified order of precedence applies.

16.2 Governing Law

This DPA is governed by the law of the Agreement.

16.3 Severability

If any provision of this DPA is held invalid, the rest remain in effect.

16.4 Counterparts and Signature

A signed counterpart is available on request from support@writesonic.com.


Schedule 1. Details of Processing

Item Details
Subject matter Provision of the Writesonic AI Search Visibility Platform and other Writesonic Services to Customer
Duration The Term of the Agreement, plus the period from termination or expiration until deletion of all Customer Personal Data per §10
Nature and purpose Hosting, storing, transmitting, processing, and analyzing Customer Personal Data to provide the Services, including AI Features.
Categories of Data Subjects (a) Customer's Authorized Users; (b) individuals identified or referenced in Inputs.
Categories of Personal Data (a) Authorized User account data; (b) free-text content in Inputs and Outputs.
Special categories of Personal Data None expected.
Frequency of processing Continuous
Recipients Writesonic personnel; Sub-processors listed in Schedule 3.
Retention While Customer's account is active, then per §10 of this DPA

Schedule 2. Technical and Organizational Measures

Writesonic implements and maintains the technical and organizational measures described below. The current state is published at writesonic.trust.site.

Domain Measures
Hosting Microsoft Azure; Amazon Web Services for select workloads.
Encryption in transit TLS 1.2 or higher for all customer-facing endpoints.
Encryption at rest AES-256 for data at rest in primary data stores.
Access control Role-based access; least privilege; SSO and MFA for employee access.
Authentication SSO and SAML support for enterprise customers.
Network security Segmented production network; DDoS protection.
Logging and monitoring Centralized application and security logs; tamper-evident audit logs.
Vulnerability management Regular vulnerability scanning; documented remediation timeframes.
Secure SDLC Code review; automated security testing in CI.
Endpoint security Managed devices; disk encryption; endpoint detection and response.
Personnel security Security training on hire and annually; confidentiality obligations.
Vendor risk Sub-processor risk reviews; contractual flow-down of data-protection obligations.
Business continuity Documented incident-response plan; backup procedures.
Resilience Documented RTO and RPO targets for enterprise plans.
Data minimization Least-data-collected approach.
Pseudonymization and de-identification Applied to internal analytics.
Compliance certifications SOC 2 Type 2.

Schedule 3. Sub-processors

The following Sub-processors may process Customer Personal Data:

Cloud hosting and infrastructure

Vendor Purpose Region
Microsoft Azure Primary cloud hosting United States
Amazon Web Services Hosting for select workloads United States

AI Model Providers

Vendor Purpose Region
OpenAI Foundation-model inference United States

Specialized AI services

Vendor Purpose Region
Stability AI Image generation United States

Schedule 4. EU Standard Contractual Clauses (Module 2 and Module 3)

Where the EU SCCs apply under §9 of this DPA, the Parties agree as follows.

SCC reference Election
Module Module Two (Controller-to-Processor).

Schedule 5. UK International Data Transfer Addendum

Where the UK Addendum applies under §9, the Parties agree as follows.

Reference Election
Table 1 (Parties) Customer (Exporter) and Writesonic (Importer).

Schedule 6. CCPA/CPRA Service Provider Addendum

For Customer Personal Data subject to the CCPA/CPRA, Writesonic acts as Service Provider under §1798.140(ag).