Last updated: September 18, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Wrenzik ("the Processor", "we") and the customer organization ("the Controller", "you") and governs all personal data you store in the Service ("Customer Data"), as required by Article 28 GDPR. It applies automatically to every customer — no signature is needed.
We process Customer Data solely to provide the Service described in the Terms, for as long as your account exists, plus the deletion window described below.
Hosting, storage, display, transmission, backup and deletion of Customer Data as driven by the features you use — scheduling, attendance, member records, payment tracking, portals and email notifications.
We process Customer Data only on your documented instructions — given through your use of the Service and these terms — unless EU or member-state law requires otherwise, in which case we inform you before processing unless that law forbids it. We will tell you if we believe an instruction violates the GDPR.
Access to Customer Data is limited to the people who need it to operate and support the Service, all of whom are bound by confidentiality.
You authorize the subprocessors listed on our Subprocessors page. We impose data-protection obligations no less protective than this DPA on each of them and remain fully liable for their performance. We will update that page and notify account owners by email at least 30 days before adding or replacing a subprocessor, so you can object on reasonable data-protection grounds.
Taking into account the nature of the processing, we assist you with data-subject requests (access, rectification, erasure, portability, restriction, objection) and with your obligations under Articles 32–36 GDPR, including data protection impact assessments, at no charge for reasonable requests.
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information Article 33(3) requires as it becomes available, and we document all breaches and remediation steps.
On termination of the Service we delete all Customer Data within 30 days (backup copies expire within a further 14 days), unless EU or member-state law requires storage. Before deletion, you may request an export of your Customer Data.
We make available the information reasonably necessary to demonstrate compliance with Article 28 and, no more than once per year and under confidentiality, allow audits you commission at your own cost, provided they do not endanger the isolation of other customers' data.
Customer Data is hosted in the EU. Where a subprocessor processes limited data outside the European Economic Area (see the Subprocessors page), the transfer relies on an EU adequacy decision or on Standard Contractual Clauses.
If this DPA and the Terms conflict on a matter of personal data, this DPA prevails. The English version prevails over any translation.