webium.ai
Data Protection

Data Processing Addendum

Data-processing terms for customers whose Webium projects process personal data.

Effective: September 3, 2026

How this DPA becomes part of the agreement. This Data Processing Addendum ("DPA") applies when Webium processes Personal Data in Customer Content on behalf of a customer under the Webium Terms of Service or another agreement that incorporates this DPA. It becomes effective when the customer accepts the applicable Webium agreement or uses the Service to process Personal Data, to the extent permitted by applicable law.

1. Parties and roles

This DPA is between Webium LLC, 7511 Greenwood Ave North, Unit 5090, Seattle, WA 98103, USA ("Webium") and the customer identified in the Webium account, order or applicable agreement ("Customer"). For Customer Personal Data, Customer is a controller or processor and Webium is a processor or subprocessor, as applicable. For Webium's own account, billing, security and business-administration data, Webium acts as an independent controller/business as described in the Privacy Policy.

2. Definitions

Applicable Data Protection Law means privacy and data-protection laws that apply to the processing under this DPA, including where applicable the GDPR, UK GDPR, Swiss data-protection law, and U.S. state privacy laws.

Customer Personal Data means Personal Data contained in Customer Content that Webium processes on Customer's behalf to provide the Service.

Personal Data, Controller, Processor, Processing and Data Subject have the meanings given by applicable data-protection law.

3. Customer instructions

Webium will process Customer Personal Data only on documented instructions from Customer, including instructions inherent in Customer's use and configuration of the Service, unless applicable law requires otherwise. If legally permitted, Webium will inform Customer before processing required by law.

Customer is responsible for the lawfulness of its instructions, the data it collects, its notices and legal bases, and the rights and permissions needed to provide Customer Personal Data to Webium.

4. Confidentiality

Webium will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

5. Security

Webium will maintain reasonable technical and organizational measures appropriate to the risk, taking into account the nature of the Service and the information processed. Measures are summarized in Annex II below and on the Security page.

6. Subprocessors

Customer gives Webium general written authorization to engage subprocessors needed to provide the Service. Current subprocessors are listed at webium.ai/subprocessors.html. Webium will impose data-protection obligations on subprocessors that are appropriate to the services they perform and will remain responsible for its obligations under this DPA to the extent required by applicable law.

Where the GDPR requires notice of a new subprocessor, Webium will provide notice through the subprocessor page, account notice, email or another reasonable mechanism. Customer may object on reasonable data-protection grounds. If the parties cannot reasonably resolve an objection, Customer may discontinue the affected feature or Service.

7. Data-subject requests

Taking into account the nature of processing, Webium will provide reasonable assistance, through available product functionality or support, to help Customer respond to legally valid requests by Data Subjects. If Webium receives a request concerning Customer Personal Data, Webium may redirect the requester to Customer unless law requires Webium to respond directly.

8. Security incidents

Webium will notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, where notification is required by applicable law. Notification does not constitute an admission of fault or liability.

Webium will provide information reasonably available to it that Customer needs to satisfy applicable breach-notification obligations and will take reasonable steps to contain and remediate the incident.

9. DPIAs and regulator assistance

Taking into account the nature of processing and information available to Webium, Webium will provide reasonable assistance with legally required data-protection impact assessments and prior consultations relating to the Service. Extraordinary assistance beyond standard documentation or product functionality may be subject to reasonable fees if permitted by law and agreed in advance.

10. Deletion and return

During the subscription, Customer may use available Service features to access, export or delete Customer Personal Data. Following termination or Customer's deletion instruction, Webium will delete or return Customer Personal Data as required by applicable law, except information that must be retained by law or that remains temporarily in protected backups, logs or security systems until normal deletion/rotation.

11. Audits and information

Webium will make available information reasonably necessary to demonstrate compliance with processor obligations under applicable law. Where legally required and after review of available documentation, Customer may conduct or commission a reasonable audit no more than once annually, unless a security incident or regulator requires more frequent review. Audits must protect other customers' confidentiality, avoid unreasonable disruption and be subject to reasonable security procedures.

12. International transfers

If Customer Personal Data protected by the GDPR is transferred to Webium in a country that does not benefit from an applicable adequacy decision and no other lawful mechanism applies, the parties incorporate the European Commission's 2021 Standard Contractual Clauses for transfers to third countries ("EU SCCs") as follows:

If the UK GDPR applies and a restricted transfer requires contractual safeguards, the then-current UK International Data Transfer Addendum to the EU SCCs is incorporated to the extent legally effective, with the information in this DPA used to complete its tables. For Swiss transfers, the EU SCCs will be interpreted with the adaptations required by Swiss law.

If a different valid transfer mechanism applies, that mechanism may be used instead.

13. U.S. state privacy terms

To the extent Webium processes Customer Personal Data subject to a U.S. state privacy law as a service provider, processor or contractor, Webium will process that data only for the limited and specified purposes of providing the Service and as otherwise permitted by the applicable law; will not sell Customer Personal Data or share it for cross-context behavioral advertising; and will not combine Customer Personal Data with personal data received from other customers except as permitted by applicable law.

14. Restricted data

Unless a separate written agreement says otherwise, Customer will not instruct Webium to process data that requires Webium to enter a HIPAA business associate agreement, maintain PCI DSS cardholder-data storage, process biometric templates, host government-classified material, or intentionally process children's personal data under a specialized child-privacy regime.

15. Liability and order of precedence

The liability provisions of the applicable Webium agreement apply to this DPA to the maximum extent permitted by law. If this DPA conflicts with the applicable agreement on processing of Customer Personal Data, this DPA controls. If the EU SCCs apply and conflict with this DPA or the agreement, the EU SCCs control for the relevant transfer.

Annex I — Parties and transfer description

A. Data exporter

Name: Customer identified in the Webium account/order.
Address and contact: As supplied by Customer in the account/order.
Role: Controller or processor, depending on Customer's use.

B. Data importer

Name: Webium LLC
Address: 7511 Greenwood Ave North, Unit 5090, Seattle, WA 98103, USA
Contact: support@webium.ai
Role: Processor or subprocessor.

C. Categories of Data Subjects

Customer personnel and account users; users, customers, prospects, suppliers, employees, contractors or other individuals whose Personal Data Customer chooses to process through a Webium application.

D. Categories of Personal Data

Identifiers, contact information, account data, application form fields, customer database records, project files, communications, technical metadata and other Personal Data submitted by Customer or Customer's users. The exact categories are determined by Customer's application.

E. Sensitive data

The Service is not intended for special-category, highly sensitive or regulated data unless Customer has a lawful basis and Webium has expressly approved the use where required by the Terms. If approved, Customer must apply appropriate safeguards.

F. Processing operations and purpose

Collection, transmission, storage, organization, retrieval, hosting, display, modification, backup, security processing, support access and deletion as necessary to provide and secure the Service according to Customer's instructions.

G. Duration

For the term of the Service plus the period needed for deletion, backup rotation, legal retention and dispute/security records as described in this DPA and Privacy Policy.

H. Supervisory authority

The competent authority determined under the EU SCCs based on the exporter and applicable GDPR rules.

Annex II — Technical and organizational measures

Annex III — Subprocessors

The current list at webium.ai/subprocessors.html is incorporated into this Annex.

Contact for this DPA

support@webium.ai