Frequently asked questions
-
Do we need to sign a Data Processing Addendum (DPA) with Woodpecker?
No signature is required. Our DPA is incorporated by reference into the Agreement (Terms of Service and Privacy Policy) and is entered into automatically when you accept the Agreement — that is, when you sign up for and start using the Service. The DPA already includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum by reference, so it is a complete instrument as of acceptance. If your internal procedures require a countersigned copy or a version with the full SCC text physically attached, we can provide one on request, but it is not a precondition for coverage.
-
Does the DPA / Terms of Service also apply to your sub-processors?
Yes. Under the DPA you grant us a general authorization to engage sub-processors to perform our obligations under the Agreement. We require every sub-processor to maintain security and confidentiality practices consistent with the Agreement and the GDPR, and to protect personal data. Only the minimum necessary data is disclosed to any sub-processor, and where required we enter into a data processing agreement with them. The current list of sub-processors is published on our Processors' List and is kept up to date; it is also available on request.
-
Do you or your sub-processors use customer or prospect data to train or improve AI/ML models?
We process your data only to provide and maintain the Service and on your instructions, and we do not sell, lease, trade, or exchange customer or prospect personal data. We do not use Customer Content or prospect personal data to train general-purpose or third-party AI models. AI-based features are delivered via a contracted sub-processor (OpenAI, listed on our Processors' List) under business/API terms that do not use submitted data to train their models. Data sent to power an AI feature is processed to deliver that feature, not to train foundation models. A written attestation to this effect is available from our privacy contact on request.
-
Where is our data stored, and is it transferred outside the EEA?
Personal data of EU citizens for which Woodpecker acts as controller is stored on EU-located servers. Some data may be transferred outside the EEA to sub-processors, in which case only the minimum necessary data is transferred and appropriate safeguards apply — Standard Contractual Clauses, an adequacy decision, or another mechanism required by applicable data protection law. Our sub-processors are located mainly in the EU, Canada, and the United States, and each provider and its processing purpose is identified on the Processors' List.
-
Can we audit Woodpecker or obtain evidence of GDPR compliance / get my compliance form filled up?
Yes, on a controlled basis. On written request we make available the information necessary to demonstrate compliance with Article 28 GDPR or assist with compliance forms (to the reasonable extent and in line with the current legal standards and regulations). To know more contact [email protected].