Client Data

Data Processing Framework

A starting point for documenting client-controlled data in Wirtu automation and software engagements. Use a project-specific agreement before processing production personal data.

Last reviewed: [OWNER INPUT REQUIRED]

What this page is

This page is a public overview of how Wirtu may process data while delivering automation, AI agents, CRM systems, software, websites, and integrations. It is not a complete data-processing agreement and should not replace a negotiated client contract or legal review.

Controller and processor roles

For Wirtu's own enquiries, Wirtu generally decides why contact information is collected and acts as the business responsible for that lead process. For client project data, the client may decide the purpose and means while Wirtu acts on documented instructions. The roles and responsibilities must be confirmed per project. [OWNER INPUT REQUIRED]

Project data map

  • Identify each data category and whose information it concerns.
  • Document the purpose, lawful basis or other required justification, system, location, provider, access role, retention, deletion, and backup behavior.
  • Record every AI provider, automation platform, CRM, hosting service, API, and subprocessor used for the project.
  • Define how the client can review, correct, export, return, or delete data and how incidents are handled.

Security and confidentiality

Wirtu should apply access controls, credential protection, environment separation, secure transfer, logging, backup, and incident procedures appropriate to the project. The exact controls, service levels, audit rights, breach-notice timing, and security schedule are [OWNER INPUT REQUIRED].

Retention and deletion

Project retention, return, deletion, backups, and legal holds should be set in the applicable agreement. No general retention period is asserted here because the repository does not define one. [OWNER INPUT REQUIRED]

International providers and subprocessors

International processing and subprocessors depend on the tools selected for the project. Wirtu should maintain a current provider list and obtain any required client approval or contractual protections. The list is [OWNER INPUT REQUIRED].

Items to confirm before publishing

  • Decide whether Wirtu will offer a separate signed data-processing agreement.
  • Define controller/processor roles, security commitments, incident timing, and audit rights.
  • Create a project-specific data map and subprocessor list for every client system.
  • Set return, deletion, backup, and retention requirements per engagement.
Questions about these notices can be sent to firomsa@wirtu.tech. See also Contact Wirtu.