This Data Processing Addendum ("DPA") forms part of the Winslow Terms of Service (the "Agreement") between Winslow AI, Inc. ("Winslow") and the customer that accepts the Agreement ("Customer"). It governs Winslow's processing of personal information on Customer's behalf.
If there is any conflict between the Agreement and this DPA regarding data protection, this DPA controls.
1. Roles of the parties
- Customer is the controller / business. Customer determines the purposes and means of processing Personal Information about its clients and prospects and is responsible for its own privacy notices, consents, and legal obligations.
- Winslow is the service provider / processor. Winslow processes Personal Information only on Customer's documented instructions and on Customer's behalf, to provide the Services.
- For Personal Information about Customer's own personnel and account users, Winslow may act as a controller/business as described in the Privacy Policy.
The Agreement, this DPA, and Customer's use of the Services constitute Customer's complete and documented instructions to Winslow.
2. Definitions
- "Personal Information" means information relating to an identified or identifiable individual that Winslow processes on Customer's behalf, including Meeting Content and Client Data.
- "Client Data" means Personal Information about Customer's clients and prospects.
- "NPI" means nonpublic personal information as defined under the Gramm-Leach-Bliley Act ("GLBA") and its implementing regulations.
- "De-identified Data" means data derived from Personal Information that has been de-identified and/or aggregated so it cannot reasonably be used to identify any individual, entity, or Customer.
- "Security Incident" means a confirmed breach of security leading to unauthorized access to, or acquisition of, Personal Information in Winslow's systems.
- "Subprocessor" means a third party engaged by Winslow to process Personal Information.
- "Data Protection Laws" means applicable privacy and data-protection laws, including the GLBA and its implementing regulations, U.S. state privacy laws (including the CCPA/CPRA), and Canada's PIPEDA.
3. Scope and purpose of processing
- Subject matter: Provision of the Winslow AI sales-coaching Services.
- Nature and purpose: Recording and ingesting meetings; transcription; AI analysis to produce coaching Outputs; storage, display, support, security, and maintenance of the Services.
- Duration: For the term of the Agreement, plus the retention and deletion periods in Section 10.
- Categories of individuals: Customer's Authorized Users; Customer's clients and prospects; other meeting participants.
- Categories of Personal Information: Identifiers (names, email addresses); meeting audio, video, and transcripts; financial information disclosed during meetings (NPI); meeting metadata; account, usage, and billing information.
4. Winslow's obligations
Winslow will:
4.1 Process only on instructions. Process Personal Information only to provide the Services and as otherwise instructed by Customer, or as required by law (in which case Winslow will notify Customer unless legally prohibited).
4.2 Honor GLBA use limits. Consistent with GLBA's reuse and redisclosure limits, Winslow will use NPI it receives solely to carry out the Services for Customer, and will not use or disclose it for any other purpose.
4.3 Not sell or share. Winslow will not sell or share (as those terms are defined under the CCPA/CPRA) Personal Information, will not retain, use, or disclose it for any purpose other than providing the Services, and will not combine it with information from other sources except as permitted by law to provide the Services. Winslow certifies that it understands and will comply with these restrictions.
4.4 Not train on identifiable data. Winslow will not use identifiable Client Data to train its own AI models, and will contractually require its AI Subprocessor not to use Customer's content to train that provider's models.
4.5 No advertising use. Winslow will not use Personal Information processed under this DPA for advertising or marketing to Customer's clients or prospects.
4.6 Confidentiality of personnel. Limit access to Personal Information to personnel who need it to perform the Services, who are bound by confidentiality obligations and receive appropriate training. Access to Meeting Content is restricted to a limited group of authorized personnel for support, quality assurance, and debugging, and is logged.
4.7 Assist Customer. Provide reasonable assistance to Customer in meeting its own obligations under Data Protection Laws, including responding to individuals' requests, conducting assessments, and consulting regulators, taking into account the nature of the processing and information available to Winslow.
5. Customer's obligations
Customer will:
- Provide all notices and obtain all consents required by law — including recording, wiretap, and all-party consents from meeting participants and any consents required to permit AI processing and the creation of De-identified Data;
- Ensure it has the right and authority, under its own client agreements and privacy notices and under GLBA, to provide Personal Information to Winslow and to authorize the processing described here;
- Not provide Winslow with categories of data the Services are not designed to process (such as government-ID numbers, health records, or biometric identifiers); and
- Configure retention settings consistent with its own recordkeeping obligations.
6. De-identified and aggregated data
Winslow may create De-identified Data from Personal Information and use it for any lawful purpose, including to operate, improve, secure, analyze, and benchmark the Services (current and future). Winslow will:
- implement reasonable measures to ensure the data cannot be re-associated with any individual, entity, or Customer;
- not attempt to re-identify the data, and contractually prohibit any recipient from doing so; and
- not disclose De-identified Data in any manner that identifies Customer, its clients, or any individual.
De-identified Data is not Personal Information and is not subject to the deletion obligations in Section 10.
7. Security
7.1 Security program. Winslow maintains a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including the measures in Annex B.
7.2 Ongoing evaluation. Winslow will review and update its security program periodically and in response to material changes in risk.
8. Security incidents
8.1 Notification to Customer. Winslow will notify Customer of a Security Incident affecting Customer's Personal Information without undue delay and in any event within seventy-two (72) hours of becoming aware of it.
8.2 Contents and cooperation. The notice will describe, to the extent known, the nature of the incident, the categories and approximate volume of data involved, likely consequences, and the measures taken or proposed. Winslow will provide reasonable cooperation and information to assist Customer in meeting its own notification obligations (including under SEC Regulation S-P, the FTC Safeguards Rule, and state breach-notification laws).
8.3 Customer's obligations. Customer remains responsible for determining whether the incident requires notification to individuals or regulators and for making those notifications.
9. Subprocessors
9.1 Authorization. Customer authorizes Winslow to engage Subprocessors to provide the Services. Winslow's current Subprocessors are described in Annex C.
9.2 Flow-down. Winslow will enter into a written agreement with each Subprocessor imposing data-protection obligations no less protective than those in this DPA, including the use limits in Section 4, and remains liable for its Subprocessors' performance.
9.3 Changes. Winslow will provide notice (by email and/or by updating its subprocessor list) before adding or replacing a Subprocessor. If Customer reasonably objects on data-protection grounds, the parties will work in good faith to find a resolution; if none is available, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.
10. Retention, return, and deletion
10.1 Retention. Winslow retains Personal Information as described in the Privacy Policy and as configured by Customer. Customer may delete Meeting Content at any time and may enable auto-deletion after analysis.
10.2 Return and deletion. For 30 days after termination of the Agreement, Winslow will make Customer Data available for export. Thereafter, Winslow will securely delete or irreversibly de-identify Customer's Personal Information — including from backups, in accordance with backup cycles — within 90 days of account closure, except where retention is required by law.
11. Individual rights requests
If Winslow receives a request from an individual to exercise rights with respect to Personal Information processed on Customer's behalf, Winslow will not respond directly (except to acknowledge and redirect) and will promptly forward the request to Customer, and will provide reasonable assistance to enable Customer to respond. Requests from Customer's clients or prospects are directed to Customer as the responsible party.
12. Audits and information
On reasonable written request (no more than once per year, unless required by a regulator or following a Security Incident), Winslow will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security program and any third-party audit reports or certifications it holds. Any audit will be at Customer's expense, during business hours, subject to confidentiality, and conducted so as not to disrupt Winslow's operations.
13. Regulatory support
Winslow will, on reasonable request, support Customer's regulatory examinations by providing export of and access to Customer Data, and will consider third-party recordkeeping undertakings (for example, under SEC Rule 17a-4) on a case-by-case basis. Customer remains solely responsible for its own recordkeeping, retention, supervision, and archiving obligations.
14. International transfers
Winslow processes and stores Personal Information in the United States. Where Customer or its clients are located in Canada, Customer acknowledges that Personal Information will be transferred to and processed in the United States, and Winslow will apply appropriate safeguards. The Services are not currently offered to residents of Quebec.
15. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.
16. Term
This DPA takes effect when Customer accepts the Agreement and remains in force for as long as Winslow processes Personal Information on Customer's behalf.
Annex A — Processing details
As described in Section 3 (subject matter, nature and purpose, duration, categories of individuals, and categories of Personal Information).
Annex B — Technical and organizational security measures
- Encryption: Personal Information is encrypted in transit (TLS) and at rest.
- Access control: Role-based access on a least-privilege basis; multi-factor authentication for administrative access; access reviews and prompt revocation on role change or departure.
- Restricted content access: Access to Meeting Content is limited to a small group of authorized personnel for support, QA, and debugging, and is logged.
- Credential protection: Integration credentials and secrets are encrypted and stored in a secrets-management system, never in source code.
- Logging and monitoring: Security and access logging, with monitoring for anomalous activity.
- Tenant isolation: Logical separation of each Customer's data; controls to prevent cross-tenant access.
- Secure development: Code review, dependency scanning, and testing prior to release.
- Backups and recovery: Regular encrypted backups with restoration testing.
- Incident response: A written incident-response plan, including the 72-hour customer-notification process in Section 8.
- Vendor oversight: Security review of Subprocessors and contractual flow-down of protections.
- Secure disposal: Secure deletion or irreversible de-identification at the end of the retention period.
Annex C — Subprocessors
| Subprocessor category | Purpose |
|---|---|
| Meeting-recording infrastructure | Joins supported meeting platforms (Zoom, Microsoft Teams, Google Meet) and captures audio, video, transcripts, participant information, and metadata on Customer's behalf. Configured for U.S. storage and minimized retention. |
| AI model provider | Processes transcripts to generate coaching analyses. Contractually prohibited from using content to train its models. |
| Cloud hosting and database | Hosts the application and stores Customer Data (U.S. region). |
| Authentication provider | User identity, login, and multi-factor authentication. |
| Payment processor | Subscription billing and payment processing. Winslow does not store full payment-card numbers. |
A current list of named Subprocessors is available on request from privacy@gowinslow.ai.
Contact
Winslow AI, Inc. [Company mailing address] Privacy and data protection: privacy@gowinslow.ai