Legal
Data Processing Agreement
How Weflayr processes personal data on behalf of its customers.
Version 1.0 · Last updated 20 August 2026
This Data Processing Agreement (the “DPA”) forms part of the Weflayr Terms of Service (the “Terms”) between Weflayr SAS (“Weflayr”, “we”, “Processor”) and the customer accepting them (“you”, “Controller”). It applies where we process personal data on your behalf in providing the Service.
It applies in the version current at the time of your use, and does not require separate signature to be binding. Where you have signed a separate data processing agreement with us, that agreement applies in place of this one for as long as it remains in force. Where this DPA and the Terms conflict on a data protection matter, this DPA prevails.
Terms defined in the Terms have the same meaning here. “GDPR” means Regulation (EU) 2016/679. “Personal Data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “personal data breach” have the meanings given in the GDPR.
1. Roles of the parties
You act as controller for the personal data contained in Customer Data. We act as processor, and process it only on your documented instructions.
Where you are yourself a processor acting for another controller, you confirm that you have the authority of that controller to appoint us as a sub-processor on these terms.
We act as controller for the personal data of your administrators and users that we process to operate our own business, for example to authenticate them, to bill you, to provide support and to send service communications. That processing is described in our Privacy Policy and is not governed by this DPA.
2. Instructions
We process Customer Data only:
- to provide, secure and maintain the Service in accordance with the Terms
- in accordance with your further documented instructions, where they are consistent with the Terms
- where required by European Union or Member State law, in which case we will inform you before processing unless that law prohibits it
Your acceptance of the Terms, and your configuration of the Service, constitute your documented instructions. This includes your decision whether to leave capture of prompt and completion content enabled, and your decision to connect a billing provider.
We will inform you if, in our opinion, an instruction infringes the GDPR.
3. Subject matter and details of processing
The subject matter, duration, nature and purpose of the processing, the categories of personal data and of data subjects, and the applicable retention periods, are set out in Annex A.
4. Duration
This DPA applies for as long as we process Customer Data on your behalf, and survives termination of the Terms until deletion is complete in accordance with clause 11.
5. Confidentiality
We ensure that every person authorised to process Customer Data is bound by an obligation of confidentiality, and that access is limited to those who need it to perform their role.
6. Security
We implement the technical and organisational measures set out in Annex C, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to data subjects.
We may update those measures, provided the level of protection is not reduced. The current version is always the one published with this DPA.
7. Sub-processors
You grant us a general authorisation to engage the sub-processors listed in Annex B.
We impose on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, and we remain fully liable to you for their performance.
We will give you at least thirty days notice before engaging a new sub-processor or replacing an existing one, by email or through the Service. If you object on reasonable data protection grounds within that period, we will either propose an alternative or you may terminate the affected part of the Service without penalty.
Adding or removing a model available through a sub-processor already listed in Annex B does not constitute the engagement of a new sub-processor. The models we benchmark against are published on our sub-processors page and kept current.
8. Assistance with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights.
If we receive a request directly from one of your data subjects, we will not respond to it substantively. We will forward it to you without undue delay.
Where capture of prompt and completion content is disabled in your configuration, we hold no such content and are unable to search for, extract, rectify or delete it. You acknowledge that this is a consequence of the configuration you have selected.
9. Assistance with your other obligations
Taking into account the nature of the processing and the information available to us, we assist you in complying with your obligations under Articles 32 to 36 of the GDPR, including security of processing, personal data breach notification, data protection impact assessments and prior consultation.
10. Personal data breach
We notify you without undue delay, and in any event within forty-eight hours, after becoming aware of a personal data breach affecting Customer Data.
The notification is sent to the security contact you have nominated or, failing that, to your registered account email address. It describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, to the extent then known, and is supplemented as the investigation progresses.
We cooperate with you and with the relevant supervisory authorities, and provide reasonable assistance with your own notification obligations.
11. Deletion and return
On termination of the Terms, we delete Customer Data within thirty days. Encrypted backups roll off within a further thirty days.
If you ask us before that period expires, we will return Customer Data to you in a commonly used machine-readable format. We will confirm deletion in writing on request.
We retain Customer Data beyond these periods only where European Union or Member State law requires it, in particular the accounting records referred to in Annex A.
12. Audits and information
We make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR.
We satisfy your audit rights by providing, under a non-disclosure agreement, our then-current independent audit report, our security documentation, and responses to reasonable written questions, no more than once in any twelve month period unless a personal data breach or a supervisory authority requires otherwise.
An on-site audit may be conducted only where required by law, where the information above is demonstrably insufficient, or where agreed in a master services agreement signed by us. It is conducted at your cost, during business hours, with at least thirty days notice, by an independent auditor bound by confidentiality who is not a competitor of Weflayr, and in a manner that does not disrupt our operations or the confidentiality of other customers’ data.
13. International transfers
The Service and the analytical store are hosted in the European Union.
Benchmarking runs on Amazon Bedrock, within the European Union. For models that are not available there, we access them through our gateway provider and publish which ones. The current list of models used for benchmarking, with their hosting region, is published at weflayr.com/subprocessors.
Where personal data is transferred to a country outside the European Economic Area that is not subject to an adequacy decision, the transfer is governed by the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, module three, controller to processor to sub-processor, which are incorporated into our agreements with the sub-processors concerned. A copy of the relevant clauses is available on request at privacy@weflayr.com.
14. Liability
Our liability under this DPA is subject to the aggregate limitation of liability set out in the Terms. This DPA does not create a separate, additional or increased cap.
15. Governing law
This DPA is governed by French law. The competent courts of Paris have exclusive jurisdiction, without prejudice to the jurisdiction provisions of any applicable Standard Contractual Clauses.
Annex A - Details of the processing
Subject matter. The provision of the Weflayr platform, being the measurement, attribution and optimization of the cost and margin of the AI calls made by your application.
Duration. The term of your subscription, plus the deletion periods set out below.
Nature and purpose. Collection, recording, storage, structuring, analysis, transmission to model providers for benchmarking, and erasure, for the purpose of providing the Service.
Categories of data subjects. Your administrators and users of the Service. Your own end customers and their users, where their data appears in Customer Data.
Categories of personal data
| Category | Description |
|---|---|
| Call metadata | The customer or user identifier you choose to pass, the feature name or tag, the model and provider used, token counts, computed cost, and a timestamp. Where you pass an opaque identifier, as we recommend, this category contains no direct identifier. |
| Prompt and completion content | The input messages, tool definitions and output messages of the instrumented AI calls. Captured unless you disable capture. May contain personal data, depending on what your application sends. |
| Benchmark samples and results | Samples of the above transmitted to candidate model providers, the outputs returned, and the scores produced by the automated judge. |
| Revenue records | Amounts attributed to your end customers, uploaded by you or read from your connected billing provider. Where read from a billing provider, may include the names and email addresses of your end customers. |
| Account and configuration data | Names, email addresses and roles of your administrators and users, organisation and project configuration, API key identifiers. |
| Operational data | Application logs, metrics and error reports, and security and access logs. |
Special categories of data. The Service is not intended to process special category data within the meaning of Article 9, criminal conviction data within the meaning of Article 10, payment card data, government identifiers or children’s data. You must not send such data.
Retention
All Customer Data is stored in the European Union.
| Category | Retention |
|---|---|
| Telemetry, cost and revenue data | For the term of your subscription, then deleted within 30 days of its end |
| Prompt and completion content | For the term of your subscription, then deleted within 30 days of its end |
| Benchmark samples, provider outputs and judge results | Same as prompt and completion content |
| Managed cache entries, where included in your plan | Until the cache entry expires |
| Account, configuration and user information | For the term, then deleted within 30 days of its end |
| Security and access logs | 12 months |
| Billing records and accounting documents | 10 years, as required by article L123-22 of the French Commercial Code |
Encrypted backups are retained for 30 days and replicated within the European Union.
Annex B - Sub-processors
| Sub-processor | Location of processing | Purpose |
|---|---|---|
| Amazon Web Services EMEA SARL | eu-central-1, Germany | Hosting, compute, storage, key management, logging, and model inference through Amazon Bedrock |
| ClickHouse, Inc. | European Union | Analytical database |
| Auth0, part of Okta, Inc. | European Union | Authentication of users of the Service |
| Functional Software, Inc. (Sentry) | European Union | Application error monitoring |
| Stripe Payments Europe, Ltd. | European Union and United States | Billing of the Weflayr subscription |
| Vercel, Inc. | United States | Gateway used to reach models that are not available through Amazon Bedrock |
Annex C - Technical and organisational measures
Organisation of information security. An information security management system aligned with ISO/IEC 27001. Security policies approved annually by management and accepted by all personnel. Confidentiality obligations in every employment and contractor agreement. Security awareness training on hire and annually. Continuous automated control monitoring.
Access control. Federated identity with mandatory multi-factor authentication. Role-based, least-privilege permissions. Administrative access to production requires an individual VPN certificate. Access reviewed periodically and revoked within one business day of a departure.
Logical isolation. Each customer project has its own dedicated analytical database, so that no query can span two customers’ data. Every API request is authenticated and scoped to the caller’s organisation and project.
Encryption. Data encrypted in transit using TLS 1.2 as a minimum. Data encrypted at rest, including the application database, the analytical store and object storage. Keys managed in a managed key service with rotation. Secrets held in a managed secret store and never committed to source code.
Network security. Compute and data resources deployed in private subnets. A single internet-facing load balancer. Firewall rules defined by explicit business justification. Outbound access restricted to a single allowlisted address.
Secure development. Mandatory peer review before merge, enforced by branch protection. Automated dependency scanning, static analysis and secret scanning on every change. Segregated development environment with its own database. Infrastructure declared as code.
Monitoring and incident response. Threat detection across compute, database, storage and network. Centralised logging with restricted access. Alerting to a monitored channel. A documented incident response plan, with notification to affected customers within forty-eight hours.
Resilience. Automated backups of the application database and the analytical store, replicated within the European Union. Restoration tested at least annually.
Vendor management. Assessment of every provider before engagement, review of independent assurance reports, and a written data processing agreement with each.
Physical security. Weflayr operates no data centre. Physical and environmental security of hosting facilities is the responsibility of the infrastructure providers, verified through their independent assurance reports. Personnel access company resources from devices subject to full disk encryption, automatic screen lock and endpoint protection, monitored continuously.
Contact
Questions about this DPA: privacy@weflayr.com
Weflayr SAS, 12 place Henri Bergson, 75008 Paris, France. RCS Paris 103 332 649.