Data Processing Agreement | Writesonic
Data Processing Agreement
Last updated May 16, 2026
Preamble
This Data Processing Agreement (" DPA") forms part of, and is incorporated by reference into, the Master Subscription Agreement, Terms of Service, Order Form, or other written agreement (the " Agreement") between Writesonic, Inc. ("Writesonic", "Processor") and the customer identified in the Agreement ("Customer", "Controller"). Each is a "Party" and together the "Parties".
This DPA governs Writesonic's processing of Personal Data on behalf of Customer in connection with the Services. The Services are defined in the Agreement and cover all products and websites operated by Writesonic, Inc., including the Writesonic AI Search Visibility Platform and any other Writesonic products and domains.
In the event of any conflict, inconsistency, or discrepancy between this DPA and the Agreement with respect to data protection, privacy, or processing of Personal Data, the terms of this DPA will prevail to the extent of such conflict.
Customer agrees to this DPA for itself and, where applicable under Applicable Data Protection Law, as agent for and on behalf of its Authorized Affiliates that use the Services under the Agreement. A signed counterpart of this DPA is available on request to support@writesonic.com.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
(a) " Affiliate" has the meaning given in the Agreement.
(b) " Applicable Data Protection Law" means all data-protection and privacy laws applicable to a Party's processing of Personal Data under the Agreement, including:
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR") and EU Member-State laws supplementing it;
- the UK General Data Protection Regulation as defined in the UK Data Protection Act 2018 ("UK GDPR") and the Data Protection Act 2018;
- the Swiss Federal Act on Data Protection ("FADP");
- the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"); and
- other comprehensive U.S. state privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, New Hampshire, Delaware, New Jersey, Minnesota, Maryland, and any other in force during the Term.
(c) " Authorized Affiliate" means an Affiliate of Customer that is permitted to use the Services under the Agreement and on whose behalf Customer enters into this DPA.
(d) " Controller", " Processor", " Data Subject", " Personal Data", " Processing", " Special Categories of Personal Data", and " Supervisory Authority" have the meanings given in the EU GDPR (or, where applicable, the UK GDPR or FADP). For the CCPA/CPRA, " Business", " Service Provider", " Sale", " Share", " Personal Information", and " Sensitive Personal Information" have the meanings given in the CCPA/CPRA. References in this DPA to "Personal Data" include "Personal Information" where the CCPA/CPRA applies, and references to "Controller" and "Processor" include "Business" and "Service Provider" respectively.
(e) " Customer Personal Data" means Personal Data contained in Customer Data that Writesonic processes on Customer's behalf in providing the Services.
(f) " Data Protection Impact Assessment" or " DPIA" has the meaning given in Article 35 EU GDPR.
(g) " Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by Writesonic or its Sub-processors. It does not include unsuccessful attempts that do not compromise the security of Customer Personal Data.
(h) " Restricted Transfer" means any of:
- a transfer of Personal Data from the EEA to a country not subject to an adequacy decision of the European Commission;
- a transfer of Personal Data from the United Kingdom to a country not subject to UK adequacy regulations;
- a transfer of Personal Data from Switzerland to a country not on the FDPIC's list of countries with an adequate level of data protection.
(i) " Standard Contractual Clauses" or " SCCs" means:
- for transfers from the EEA, the Standard Contractual Clauses approved by the European Commission;
- for transfers from the United Kingdom, the International Data Transfer Addendum to the EU SCCs;
- for transfers from Switzerland, the EU SCCs as adapted in accordance with the FDPIC's guidance.
(j) " Sub-processor" means any third party engaged by Writesonic (or its Affiliate) that processes Customer Personal Data in connection with the Services.
(k) " Services" has the meaning given in the Agreement.
2. Scope and Roles
2.1 Subject Matter
This DPA applies to Writesonic's processing of Customer Personal Data carried out on Customer's behalf in providing the Services. The details of the processing are set out in Schedule 1 (Details of Processing).
2.2 Roles
For Customer Personal Data, Customer acts as Controller and Writesonic acts as Processor. For the CCPA/CPRA, Writesonic acts as Service Provider with respect to Customer Personal Data.
2.3 Each Party's Compliance
Each Party will comply with its respective obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness of its processing instructions and the means by which it acquired Personal Data.
3. Customer Instructions and Responsibilities
3.1 Documented Instructions
The Agreement (including this DPA), Customer's use of the Services, and any further written instructions mutually agreed by the Parties constitute Customer's complete instructions.
3.2 Lawfulness of Instructions
Customer represents and warrants that (a) it has the legal basis under Applicable Data Protection Law to provide Customer Personal Data to Writesonic and to instruct Writesonic to process it as described, (b) it has provided all required notices and obtained all required consents, and (c) the instructions, if followed, do not violate Applicable Data Protection Law.
3.3 Notice of Conflict
If Writesonic believes that an instruction violates Applicable Data Protection Law, Writesonic will, to the extent permitted by law, inform Customer without undue delay.
3.4 CCPA/CPRA Service-Provider Commitments
For Customer Personal Data subject to the CCPA/CPRA, Writesonic:
(a) will not Sell or Share Customer Personal Data; (b) will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for any purpose other than the Business Purposes, except as permitted by the CCPA/CPRA; (c) will not combine Customer Personal Data with personal information received from or on behalf of any other person, except as permitted by CCPA regulations; (d) certifies its understanding of and compliance with the restrictions in this DPA; and (e) grants Customer the rights specified in CCPA.
4. Confidentiality of Personnel
Writesonic will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
5. Security
Writesonic will implement and maintain the technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
Customer acknowledges that the Services are designed to be configured and used in a manner that supports the security of Customer Personal Data.
6. Personal Data Breach
6.1 Notification
Writesonic will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
6.2 Information Provided
The notification will describe (a) the nature of the breach, (b) the likely consequences, (c) the measures taken to address it, and (d) the contact for further information. Writesonic will provide periodic updates as the investigation progresses.
6.3 Cooperation
Writesonic will provide Customer with reasonable assistance, taking into account the nature of the processing, to help Customer comply with its notification obligations.
6.4 Not a Concession
Notification of a Personal Data Breach under this DPA is for informational purposes only and will not be construed as an admission by Writesonic.
7. Assistance to Customer
7.1 Data Subject Requests
Taking into account the nature of the processing, Writesonic will assist Customer to fulfill Customer's obligations to respond to Data Subject requests under Applicable Data Protection Law.
7.2 DPIAs and Prior Consultation
Writesonic will provide reasonable cooperation in support of Customer's DPIAs and prior consultations with Supervisory Authorities, to the extent relevant information is available to Writesonic.
7.3 Regulatory Inquiries
Writesonic will provide reasonable assistance to Customer in responding to inquiries or investigations by Supervisory Authorities.
8. Sub-processors
8.1 General Authorization
Customer provides general written authorization for Writesonic to engage Sub-processors to process Customer Personal Data.
8.2 Current Sub-processors
The list of Sub-processors used as of the effective date of this DPA is set out in Schedule 3 (Sub-processors).
8.3 New or Replacement Sub-processors
Writesonic will notify Customer of any new or replacement Sub-processor at least 30 days before the new Sub-processor begins processing Customer Personal Data.
8.4 Right to Object
Customer may object to a new Sub-processor in writing within 15 days of notification, on reasonable data-protection grounds. The Parties will work in good faith to address the objection.
8.5 Sub-processor Obligations
Writesonic will impose contractual data protection obligations on its Sub-processors that are materially consistent with this DPA.
9. International Transfers
9.1 Transfer Mechanism
Where Customer's use of the Services involves a Restricted Transfer of Customer Personal Data, the Parties agree on the appropriate SCCs and related terms.
9.2 Transfer Impact Assessment
Writesonic has performed a Transfer Impact Assessment for transfers to the United States and other jurisdictions.
9.3 Adequacy
If a new adequacy decision applies to Customer Personal Data transferred under the Services, the transfer may rely on that adequacy decision.
10. Return or Deletion of Customer Personal Data
On termination or expiration of the Agreement, Writesonic will, at Customer's choice, return or delete all Customer Personal Data, except to the extent Writesonic is required by applicable law to retain some or all of it.
11. Audits
11.1 Audit Rights
Writesonic will provide information necessary to demonstrate compliance with this DPA.
11.2 On-site Audits
Customer may, subject to certain conditions, conduct an audit of Writesonic's compliance with this DPA.
12. AI Processing of Customer Personal Data
12.1 No Training on Customer Data
Writesonic does not use Customer Personal Data to train or fine-tune any general-purpose models.
12.2 Model Providers as Sub-processors
Writesonic uses Model Providers as Sub-processors for AI Features.
12.3 Aggregated and De-identified Data
Writesonic may use de-identified data for operational purposes.
12.4 Customer's Responsibility for Inputs
Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law.
13. Term
This DPA is effective on Customer's first acceptance of the Agreement and continues until termination or expiration of the Agreement.
14. Authorized Affiliates
Customer enters into this DPA on behalf of its Authorized Affiliates.
15. Liability
Each Party's liability arising out of this DPA is subject to the limitations of liability set out in the Agreement.
16. General
16.1 Order of Precedence
In the event of conflict on a data-protection matter, a specified order of precedence applies.
16.2 Governing Law
This DPA is governed by the law of the Agreement.
16.3 Severability
If any provision of this DPA is held invalid, the rest remain in effect.
16.4 Counterparts and Signature
A signed counterpart is available on request from support@writesonic.com.
Schedule 1. Details of Processing
| Item | Details |
|---|---|
| Subject matter | Provision of the Writesonic AI Search Visibility Platform and other Writesonic Services to Customer |
| Duration | The Term of the Agreement, plus the period from termination or expiration until deletion of all Customer Personal Data per §10 |
| Nature and purpose | Hosting, storing, transmitting, processing, and analyzing Customer Personal Data to provide the Services, including AI Features. |
| Categories of Data Subjects | (a) Customer's Authorized Users; (b) individuals identified or referenced in Inputs. |
| Categories of Personal Data | (a) Authorized User account data; (b) free-text content in Inputs and Outputs. |
| Special categories of Personal Data | None expected. |
| Frequency of processing | Continuous |
| Recipients | Writesonic personnel; Sub-processors listed in Schedule 3. |
| Retention | While Customer's account is active, then per §10 of this DPA |
Schedule 2. Technical and Organizational Measures
Writesonic implements and maintains the technical and organizational measures described below. The current state is published at writesonic.trust.site.
| Domain | Measures |
|---|---|
| Hosting | Microsoft Azure; Amazon Web Services for select workloads. |
| Encryption in transit | TLS 1.2 or higher for all customer-facing endpoints. |
| Encryption at rest | AES-256 for data at rest in primary data stores. |
| Access control | Role-based access; least privilege; SSO and MFA for employee access. |
| Authentication | SSO and SAML support for enterprise customers. |
| Network security | Segmented production network; DDoS protection. |
| Logging and monitoring | Centralized application and security logs; tamper-evident audit logs. |
| Vulnerability management | Regular vulnerability scanning; documented remediation timeframes. |
| Secure SDLC | Code review; automated security testing in CI. |
| Endpoint security | Managed devices; disk encryption; endpoint detection and response. |
| Personnel security | Security training on hire and annually; confidentiality obligations. |
| Vendor risk | Sub-processor risk reviews; contractual flow-down of data-protection obligations. |
| Business continuity | Documented incident-response plan; backup procedures. |
| Resilience | Documented RTO and RPO targets for enterprise plans. |
| Data minimization | Least-data-collected approach. |
| Pseudonymization and de-identification | Applied to internal analytics. |
| Compliance certifications | SOC 2 Type 2. |
Schedule 3. Sub-processors
The following Sub-processors may process Customer Personal Data:
Cloud hosting and infrastructure
| Vendor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Primary cloud hosting | United States |
| Amazon Web Services | Hosting for select workloads | United States |
AI Model Providers
| Vendor | Purpose | Region |
|---|---|---|
| OpenAI | Foundation-model inference | United States |
Specialized AI services
| Vendor | Purpose | Region |
|---|---|---|
| Stability AI | Image generation | United States |
Schedule 4. EU Standard Contractual Clauses (Module 2 and Module 3)
Where the EU SCCs apply under §9 of this DPA, the Parties agree as follows.
| SCC reference | Election |
|---|---|
| Module | Module Two (Controller-to-Processor). |
Schedule 5. UK International Data Transfer Addendum
Where the UK Addendum applies under §9, the Parties agree as follows.
| Reference | Election |
|---|---|
| Table 1 (Parties) | Customer (Exporter) and Writesonic (Importer). |
Schedule 6. CCPA/CPRA Service Provider Addendum
For Customer Personal Data subject to the CCPA/CPRA, Writesonic acts as Service Provider under §1798.140(ag).