Data processing terms
Last updated 26 September 2026
These terms apply where Writine processes personal data on your behalf, which is everything inside your workspace. They form part of our agreement with you and need no separate signature.
1. Roles
You are the controller of the personal data in your workspace. Writine is the processor. Where you are yourself a processor for someone else, we are the sub-processor.
2. Subject matter and duration
We process that data to provide live chat and a shared inbox, for as long as your workspace exists, plus the short period our backups take to expire.
3. What is processed
Categories of person: your members, and the visitors who open the widget on your websites.
Categories of data: names, email addresses, profile pictures, message content, attachments, IP-derived coarse location, and technical data such as timestamps and browser information.
Do not put special category data, payment card numbers or government identifiers into conversations. The service is not designed to hold them.
4. Our obligations
- process personal data only on your documented instructions, which your use of the service constitutes
- keep the people who handle it bound by confidentiality
- apply appropriate technical and organisational measures, described in section 6
- help you respond to requests from individuals, and with your impact assessments, as far as is reasonable
- tell you without undue delay if there is a personal data breach
- delete or return the data at the end of the agreement, as section 8 describes
5. Sub-processors
You give general authorisation for us to use sub-processors. Each one is bound by terms no weaker than these, and we remain responsible for what they do.
They are, by purpose:
- cloud hosting and managed database, in our operating region
- transactional email delivery
- payment processing and invoicing
We will give reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds.
6. Security
Encryption in transit, encryption at rest for the database, passwordless sign in with single-use emailed links, least-privilege access to production, per-service database roles that cannot read another service's data, and origin restrictions on the widget so it answers only your listed domains.
7. International transfers
Where data moves outside the UK or EEA, we rely on an approved transfer mechanism such as the standard contractual clauses with the UK addendum where it applies.
8. Deletion and return
You can export or delete data at any time from the dashboard. Deleting a workspace deletes its conversations and personal data, and backups holding it expire on their normal schedule.
9. Audit
We will provide the information reasonably needed to show we meet these terms. Where that is not enough, we will cooperate with an audit on reasonable notice, no more than once a year unless a regulator requires otherwise.
10. Contact
Data protection questions go to privacy@writine.com.