Data Processing Agreement

Last Updated: 7 September 2026

This Data Processing Agreement (“DPA”) forms an integral part of the Terms and Conditions and/or any Order Form or Subscription Agreement (the “Main Agreement”) between:

Customer (Controller): [●]
And
100mentors Single Member PC (“Wiserwork”, “Company”, “Processor”), with registered office at Pl. Kornarou 31, Heraklion, Crete, Greece.

Where the Customer creates or activates an Organization account, commences a free trial, purchases a subscription, or otherwise accepts the Main Agreement, an authorized representative of the Customer shall be deemed to have accepted this DPA electronically on behalf of the Customer. This DPA shall remain applicable to any renewal, upgrade, downgrade, or other change to the Customer’s subscription plan without requiring renewed acceptance, unless the Customer or contracting entity changes, this DPA is materially amended, or the relevant change introduces processing activities not already covered by this DPA.

1. DEFINITIONS

For the purposes of this DPA:

“Applicable Data Protection Law” means Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and any applicable national laws implementing or supplementing it.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach”, and “Supervisory Authority” shall have the meanings given to them under the GDPR.

“Customer Data” means any personal data processed by the Company on behalf of the Customer through the Services, including Meeting Data and related content such as recordings, transcripts, summaries, action items, messages, and related outputs**, Organization-, team-, meeting-, and User-level analytics or metrics derived from such data, and personal data processed through Customer-enabled integrations.

“Customer Personal Data” means any Personal Data contained within Customer Data.

“Usage Data” means data relating to the access, use, and performance of the Services, including technical logs, metadata, telemetry, and analytics data, to the extent that such data has been aggregated and irreversibly anonymized so that it does not identify and cannot reasonably be linked to the Customer, an Organization, or any individual.

“Subprocessor” means any third party engaged by the Company to process Personal Data on behalf of the Customer.

“Services” means the Wiserwork platform and related functionalities as described in the Main Agreement.

2. SCOPE AND ROLES

2.1 This DPA applies to the Processing of Customer Personal Data by the Company in the course of providing the Services.

2.2 The Customer acts as the Data Controller and appoints the Company as a Data Processor.

2.3 Where the Customer acts as a processor on behalf of another controller, the Customer shall:

  • act as the sole point of contact for the Company;
  • ensure that all necessary authorizations have been obtained;
  • issue all instructions on behalf of such controller(s).

2.4 The Company may process certain Personal Data as an independent Data Controller, as further described in the Privacy Policy, for its own legitimate business purposes, including account management, billing, security, analytics, service improvement, and compliance with legal obligations. Such processing is governed exclusively by the Privacy Policy and falls outside the scope of this DPA. For the avoidance of doubt, Organization-, team-, meeting-, or User-level analytics and metrics generated from Customer Personal Data and made available through the Services constitute Customer Personal Data processed by the Company as Processor. The Company may use only aggregated and irreversibly anonymized Usage Data for its independent analytics and service-improvement purposes.

3. SUBJECT MATTER, NATURE AND PURPOSE OF PROCESSING

The Company shall process Customer Personal Data solely for the purpose of providing, operating, maintaining, and supporting the Services and in accordance with the documented instructions of the Customer.

This includes, without limitation:

  • enabling meeting participation, recording, transcription, and summarization functionalities;
  • generating action items, insights, and collaboration outputs;
  • generating and displaying descriptive Organization-, team-, meeting-, and User-level analytics and metrics, as configured and instructed by the Customer;
  • managing user accounts, permissions, and organizational structures;
  • managing team memberships, User roles, invitations, and access permissions;
  • establishing and operating integrations enabled by the Customer or its authorized Users, including calendar connections, webhooks, MCP connections, and the transmission of Customer Personal Data to recipients, clients, or endpoints selected by the Customer;
  • ensuring system security, integrity, and performance;
  • providing customer support and troubleshooting.

Processing shall be carried out only to the extent necessary for the performance of the Services and in accordance with the documented instructions set out in this DPA, the Main Agreement, and the Customer’s authorized use and configuration of the Services.

4. PROCESSING INSTRUCTIONS

4.1 The Company shall process Customer Personal Data only on documented instructions from the Customer, as set out in:

  • this DPA;
  • the Main Agreement;
  • the Customer’s use and configuration of the Services.

4.2 The Company shall inform the Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law.

4.3 The Customer may provide additional instructions, provided that such instructions are lawful, reasonable, and technically feasible. The Company may charge reasonable fees for implementing such instructions.

4.4 Customer Configurations and Integrations

The Customer’s configuration of the Services through its authorized Users, including the assignment of roles and permissions, the management of invitations, Meeting Bot settings, and the enabling of calendar connections, MCP connections, webhooks, or other integrations, constitutes a documented instruction for the purposes of this DPA.

The Customer is responsible for ensuring that its authorized Users are permitted to configure such functionality and that any external client, service, recipient, or endpoint selected by the Customer is authorized to receive the relevant Customer Personal Data.

Where Customer Personal Data is transmitted to a third-party service independently selected and controlled by the Customer, such third party shall not be considered a Subprocessor of the Company solely because it is connected to the Services. This does not affect the Company’s obligations concerning the secure and lawful transmission of Customer Personal Data under this DPA.

5. USE OF DATA AND AI PROCESSING RESTRICTIONS

5.1 The Company shall process Customer Personal Data solely for the purpose of providing the Services and shall not use such data for its own independent purposes, except as expressly permitted under the Privacy Policy or required by applicable law. This restriction does not apply to Personal Data processed by the Company as an independent Data Controller in accordance with Section 2.4, provided that such Personal Data is not Customer Personal Data processed on behalf of the Customer.

5.2 Without prejudice to the above, the Company may process Usage Data in aggregated or de-identified form for the purposes of improving, maintaining, and developing the Services.

5.3 The Company does not use Customer Personal Data, including meeting recordings, transcripts, or other User Content, to train or fine-tune artificial intelligence or machine learning models, unless explicitly agreed otherwise by the Customer through a clear opt-in mechanism.

5.4 Any third-party service providers engaged for AI or transcription services are contractually restricted from:

  • using Customer Personal Data to train or improve their models;
  • retaining data beyond what is necessary to provide the Services;
  • using data for advertising or unrelated purposes.

For the avoidance of doubt, the Company shall not use Customer Personal Data for training or improving generalized artificial intelligence or machine learning models, unless explicitly agreed with the Customer or permitted under the Privacy Policy.

6. CONFIDENTIALITY

The Company shall ensure that all personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive adequate data protection training.

7. SECURITY OF PROCESSING

The Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the nature, scope, context, and purposes of processing. Such measures may include, as appropriate, technical and organizational safeguards aligned with industry practices, taking into account the nature of the Services and the risks involved. The Company shall regularly review and update its security measures to address evolving threats and technological developments. The Company implements appropriate internal policies and procedures to ensure ongoing compliance with applicable data protection laws.

8. PERSONAL DATA BREACH

The Company shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and shall provide sufficient information to enable the Customer to comply with its legal obligations.

9. SUBPROCESSORS

The Company may engage Subprocessors as necessary for the provision of the Services. A current list of Subprocessors is made available, and the Company may update such list from time to time.

10. INTERNATIONAL DATA TRANSFERS

The Company may transfer Personal Data outside the European Economic Area where necessary for the provision of the Services. Where such transfers occur, the Company implements appropriate safeguards in accordance with Applicable Data Protection Law, including, where applicable, Standard Contractual Clauses. Transfers are assessed in light of the nature of the processing and applicable legal requirements. Transfers are assessed on a case-by-case basis to ensure an appropriate level of protection.

11. ASSISTANCE TO THE CUSTOMER

The Company shall assist the Customer to the extent reasonably possible and taking into account the nature of the processing and the information available, in complying with its obligations under Applicable Data Protection Law, including with respect to:

  • responding to data subject rights requests;
  • conducting data protection impact assessments;
  • cooperating with supervisory authorities.

Such assistance shall be limited to what is reasonably necessary and may be subject to reasonable fees.

12. COMPLIANCE

The Company shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, in a manner consistent with its security and confidentiality obligations. The Company shall not be required to provide access to its systems or facilities for audit purposes unless required by applicable law.

13. CUSTOMER RESPONSIBILITIES

The Customer is responsible for ensuring that the processing of Personal Data complies with Applicable Data Protection Law, including :

  • determining the appropriate legal basis;
  • providing required notices to data subjects;
  • obtaining any necessary consents;
  • configuring the Services appropriately.

The Customer is solely responsible for ensuring compliance with applicable laws relating to the recording, monitoring, and processing of communications, including obtaining any required consent from meeting participants. The Company does not independently verify whether such obligations have been fulfilled. The Customer represents and warrants that it has all necessary rights and legal bases to provide Personal Data to the Company for processing. This includes, without limitation:

  • obtaining all required notices and consents from Users, employees, and meeting participants;
  • ensuring lawful sharing of email addresses for invitations and onboarding;
  • ensuring compliance with laws applicable to recording and processing communications.

The Customer acknowledges that it determines the retention, access, deletion, and management of Customer Personal Data within the Services, including Meeting Data, in accordance with its own policies and applicable law. The Customer shall be solely responsible for the legality of such processing.

The Customer acknowledges that the Company does not control how meeting participants or users use or share Customer Data outside the Services. The Customer is responsible for ensuring that its access to and use of Organization-, team-, meeting-, and User-level analytics and metrics complies with Applicable Data Protection Law and, where relevant, employment and workplace-monitoring requirements. This includes providing appropriate notices, identifying a lawful basis, restricting access to authorized Users, and ensuring appropriate human review before using such information in connection with employment, disciplinary, performance-management, or other decisions that may significantly affect an individual.

The Customer is also responsible for the lawful selection, authorization, configuration, and use of external recipients, clients, and endpoints connected through Customer-enabled integrations, including MCP connections and webhooks.

14. LIABILITY

Each Party shall be liable only for the damage caused by processing for which it is responsible. Limitations of liability, disclaimers and exclusions set out in the Main Agreement shall apply equally to this DPA. The Company shall not be liable for any processing carried out in accordance with Customer instructions or configuration of the Services. All limitations of liability, disclaimers, and exclusions set out in the Terms shall apply equally to this DPA.

15. TERM AND TERMINATION

15.1 This DPA shall remain in effect for as long as the Company Processes Customer Personal Data on behalf of the Customer.

15.2 Upon termination or expiry of the Services, the Customer may instruct the Company to return or permanently delete Customer Personal Data. Where the Customer closes or cancels the Organization without providing such an instruction, the relevant Customer Personal Data may be retained in a restricted archived state for up to twelve (12) months, as further described in the Privacy Policy. The Customer may request return or permanent deletion at any time during that period.

15.3 Unless earlier return or deletion is requested, the Company shall delete or irreversibly anonymize the relevant Customer Personal Data upon expiry of the twelve (12)-month period, except where Union or Member State law requires the continued retention of specific Personal Data.

15.4 Residual copies may remain temporarily in secure backup systems in accordance with the Company’s documented backup retention procedures and shall not be used for the ordinary provision of the Services or for the Company’s independent purposes.

16. GOVERNING LAW

This DPA shall be governed by the law specified in the Main Agreement, or otherwise by the laws of Greece.

APPENDIX 1 — DETAILS OF PROCESSING

Data Subjects: Employees, contractors, users of the Customer, and external or guest meeting participants whose data is processed through the Services.

Categories of Personal Data: Identity data, contact data, User Content, Meeting Data, usage data, technical data, Organization and team membership data, roles and permissions, invitation data, Integration and Connection Data, and Organization-, team-, meeting-, or User-level analytics and metrics.

Special Categories: Not intentionally processed.

Purpose: Provision of AI-enabled meeting and collaboration services, including meeting recording and transcription, action-item management, descriptive analytics, role and team management, and Customer-enabled integrations.

Duration: Duration of the Main Agreement and applicable retention periods.

Processing is carried out in accordance with Customer instructions and Organization settings where applicable.

APPENDIX 2 — SUBPROCESSORS

A current list of Subprocessors is available at: Subprocessors List

APPENDIX 3 — SECURITY MEASURES

The Company implements appropriate technical and organizational measures including secure cloud infrastructure, access controls, monitoring, data segregation, and backup systems according to the Privacy Policy

APPENDIX 4 — STANDARD CONTRACTUAL CLAUSES (EU 2021/914)

For the purposes of international transfers of Personal Data subject to Applicable Data Protection Law, the Parties agree that the Standard Contractual Clauses adopted by the European Commission Implementing Decision (EU) 2021/914 (the “SCCs”) shall apply, as follows:

1. APPLICATION OF MODULE

Module Two (Controller to Processor) applies, where the Customer acts as Data Controller and the Company acts as Data Processor.

2. CLAUSE SELECTIONS

Clause 7 (Docking Clause): Applies.

Clause 9 (Use of Subprocessors): Option 2 applies (general written authorization).
The time period for prior notice of Subprocessor changes shall be thirty (30) days.

Clause 11 (Redress): Optional language does not apply.

Clause 17 (Governing Law): The law of Greece shall apply.

Clause 18 (Forum and Jurisdiction): Courts of the jurisdiction determined under Clause 17.

3. ANNEX I — LIST OF PARTIES

Data Exporter (Controller):
The Customer, as identified in the Main Agreement.

Activities: Use of the Services and transfer of Personal Data to the Company for processing.

Role: Controller

Data Importer (Processor):
100mentors Single Member PC (“Wiserwork”)
Pl. Kornarou 31, Heraklion, Crete, Greece
Email: support@wiserwork.ai

Activities: Provision of the Services, including processing of Customer Personal Data.

Role: Processor

4. ANNEX I.B — DESCRIPTION OF TRANSFER

Categories of Data Subjects:

  • Employees, contractors, and users of the Customer
  • External or guest meeting participants

Categories of Personal Data:

  • Identity and contact data
  • User Content and Meeting Data (including recordings, transcripts, summaries, action items)
  • Usage data and technical data
  • Calendar and meeting metadata

Special Categories of Data:
Not intentionally processed. Any such data is processed only where included by users and strictly as necessary to provide the Services.

Nature of Processing:
Collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, and deletion of Personal Data.

Purpose of Processing:
Provision of AI-enabled meeting and collaboration services, as described in the Main Agreement and Privacy Policy.

Duration:
For the duration of the Main Agreement and in accordance with the retention provisions set out in the Privacy Policy.

5. ANNEX I.C — COMPETENT SUPERVISORY AUTHORITY

For the purposes of the SCCs, the competent supervisory authority shall be the Hellenic Data Protection Authority (www.dpa.gr).

6. ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES

The technical and organizational measures implemented by the Company are described in Appendix 3 (Security Measures) of this DPA.

7. ANNEX III — SUBPROCESSORS

A current list of Subprocessors is available at:
Subprocessors List

The Company may update this list in accordance with Section 9 of this DPA.

8. PRIORITY

In the event of conflict between the SCCs and this DPA, the SCCs shall prevail solely with respect to international data transfers.