Data processing addendum for Windmill Enterprise Edition Cloud
Effective as of September 28, 2026. Last updated September 28, 2026.
This Data Processing Addendum (this "DPA"), including its Annexes, is entered into between Windmill Labs, Inc. ("Company" or "Processor") and the customer that subscribes to Windmill Enterprise Edition Cloud ("Customer" or "Controller") (each a "Party" and collectively the "Parties"), and forms part of the Agreement between them. It sets out how Company Processes the Personal Data contained in Customer Data when it hosts and operates Windmill Enterprise Edition Cloud for Customer.
Application of this DPA
a. Application. This DPA applies to every Windmill Enterprise Edition Cloud subscription from its Effective Date and forms part of the Agreement. Customer accepts it by accepting an Order for Enterprise Edition Cloud or by using the Services. It applies equally to subscriptions that began before this DPA was first published, including subscriptions that have since ended where Company still Processes Customer Personal Data under them, with effect from the date of first publication.
b. Other plans. This DPA does not apply to the Windmill Cloud Team plan, which is governed by the Data processing addendum for Windmill Cloud Team plan, nor to self-hosted deployments, which are governed by the Windmill self-hosted license terms or the agreements signed for them.
c. Changes to this DPA. Company may update this DPA by publishing a new version on this page, stating the date of the change. Company shall not, during a subscription term, make a change that materially reduces the protection given to Customer Personal Data, except where required by Applicable Data Protection Laws or by a Supervisory Authority. Changes to the Subprocessors listed in Annex 3 follow Section 5.
1. Definitions
a. "Agreement" means the Terms of Service, or any other written agreement between Customer and Company governing the Services, together with each Order.
b. "Applicable Data Protection Laws" means all laws and regulations relating to data protection and privacy applicable to the Processing of Customer Personal Data under this DPA, including the GDPR, the UK GDPR, the U.S. State Privacy Laws, and any successor or equivalent legislation.
c. "Customer Data" means any data, information or other material processed, stored or transmitted by Customer in its use of the Services.
d. "Customer Personal Data" means the Personal Data contained in Customer Data that Company Processes on Customer's behalf under the Agreement and this DPA, as described in Annex 1.
e. "Data Subject", "Personal Data", "Personal Data Breach", "Processing" (and "Process", construed accordingly) and "Supervisory Authority" each have the meaning given to them in the GDPR.
f. "Effective Date" means the earlier of the date on which Customer first accepts an Order for Enterprise Edition Cloud and the date on which Customer first uses the Services, or, for a subscription that began before this DPA was first published, that date of first publication.
g. "GDPR" means Regulation (EU) 2016/679, and "UK GDPR" means that Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
h. "International Data Transfer" means any disclosure of Personal Data subject to Applicable Data Protection Laws to an organisation located outside the EEA, Switzerland or the UK.
i. "Order" means the quote, order form or Service Order by which Customer subscribes to Windmill Enterprise Edition Cloud, as accepted by Company.
j. "Services" means the Windmill Enterprise Edition Cloud service provided by Company to Customer under the Agreement.
k. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to EU Commission Implementing Decision 2021/914 of 4 June 2021, as amended or replaced from time to time.
l. "Subprocessor" means any third party engaged by Company to Process Customer Personal Data on Company's behalf.
m. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 (version B1.0, in force 21 March 2022).
n. "U.S. State Privacy Laws" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA"), the Colorado Privacy Act, the Connecticut Personal Data Privacy and Online Monitoring Act, the Utah Consumer Privacy Act, the Virginia Consumer Data Protection Act, and any other U.S. state privacy law of general application, in each case as amended or superseded.
2. Roles, scope and instructions
a. Roles. With respect to Customer Personal Data, Customer acts as controller and Company acts as processor. Where Customer itself acts as a processor on behalf of a third-party controller, Company acts as a subprocessor and Customer warrants that it is authorised by that controller to appoint Company on the terms of this DPA.
b. Scope. This DPA applies only to Company's Processing of Customer Personal Data as described in Annex 1. Customer determines the purposes and means of that Processing.
c. Instructions. Company shall Process Customer Personal Data only on Customer's documented instructions, including with regard to International Data Transfers, unless required to do otherwise by a law to which Company is subject. In that case Company shall inform Customer of that legal requirement before Processing, unless the law prohibits it on important grounds of public interest. The Agreement, this DPA and Customer's use and configuration of the Services constitute Customer's complete documented instructions. Company shall inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.
d. Purpose limitation. Company shall not Process Customer Personal Data for any purpose other than performing the Services, and in particular shall not Sell or Share Customer Personal Data, retain, use or disclose it outside the direct business relationship between the Parties, or combine it with Personal Data obtained from any other source, except as permitted by Applicable Data Protection Laws.
e. Confidentiality of personnel. Company shall ensure that persons authorised to Process Customer Personal Data are bound by an obligation of confidentiality, and shall limit access to those personnel who need it to perform the Services.
f. Customer responsibilities. Customer is responsible for the lawfulness of the Customer Personal Data it provides to Company and for having obtained all consents and provided all notices required under Applicable Data Protection Laws.
3. Data received by Company
a. Deployment model. Company hosts and operates a dedicated, single-tenant instance of the Enterprise Edition for Customer on infrastructure managed by Company. Company accordingly Processes all Customer Data held on that instance, including workflow inputs and outputs, script and flow source code, variables, secrets and credentials, user identities and any files and database contents.
b. Data location. Customer's instance is deployed in the region stated in the Order, being either the United States (us-east) or the European Union (eu-central). Processing defaults to the United States; Customer may elect processing in the European Union at no additional cost. Company shall not relocate Customer's instance to another region without Customer's prior written agreement.
c. Access by Company personnel. Access to Customer's instance is restricted to authorised Company personnel who need it to operate and support the Services, is granted on a least-privilege basis, requires single sign-on with multi-factor authentication over a zero-trust network, and is logged and auditable. Access lists are reviewed at least quarterly.
d. Data export. Customer may request a snapshot of its database at any time during the term of the Agreement.
e. Telemetry. Company additionally receives the licensing telemetry described in the Enterprise Edition documentation, used solely to calculate licensed usage and verify licence compliance and retained for one (1) year. By default, the only Personal Data in that telemetry is a single superadmin email address per instance. Where Customer enables optional telemetry settings, the telemetry also contains the user email addresses, external JWT user identifiers and workspace information those settings describe.
f. Support data. Customer Personal Data may additionally reach Company where Customer discloses it in a support channel, for example in logs, screenshots or reproduction data attached to a support request. Company Processes such data only to resolve the request.
4. Optional AI features
a. The Services include optional features that submit prompts, and code and context selected by the user, to a third-party large language model provider. These features are not enabled by default and do not operate unless Customer configures its own credentials or endpoint for a provider it has selected from those supported by the Services.
b. Where Customer enables such a feature, the terms on which the provider Processes the submitted data are those agreed between Customer and that provider. That provider is not a Subprocessor of Company, and Company is not a party to and gives no warranty in respect of Customer's arrangements with it.
c. Company does not use Customer Data or Customer Personal Data to train or fine-tune any model, and does not permit any third party to do so.
5. Subprocessors
a. Authorisation. Customer generally authorises Company to engage Subprocessors to Process Customer Personal Data. The Subprocessors authorised as at the date of this DPA are listed in Annex 3.
b. New Subprocessors. Before authorising a new Subprocessor to Process Customer Personal Data, Company shall notify Customer in writing of the identity of that Subprocessor and the Processing concerned. Customer may object on reasonable written grounds within fifteen (15) days of that notice. The Parties shall discuss the objection in good faith; if it cannot be resolved and Company proceeds with the Subprocessor, Customer may terminate the affected Services on written notice given before that Subprocessor begins Processing, without penalty, and Company shall refund any prepaid fees covering the period after termination.
c. Flow-down and liability. Company shall impose on each Subprocessor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor's obligations.
d. Monitoring and logging tooling. Company's logging and monitoring stack is self-hosted on Company-managed infrastructure and is not a Subprocessor.
6. International data transfers
a. Customer authorises Company to carry out International Data Transfers to a country benefiting from an adequacy decision, on the basis of other adequate safeguards under Applicable Data Protection Laws, or pursuant to the SCCs and the UK Addendum as completed in this Section 6.
b. EU Standard Contractual Clauses. By entering into this DPA the Parties conclude Module Two (controller to processor) of the SCCs and, to the extent Customer acts as a processor on behalf of a third-party controller, Module Three (processor to processor), which are incorporated and completed as follows: the data exporter is Customer and the data importer is Company; the optional docking clause in Clause 7 applies; Option 2 of Clause 9(a) applies with a notice period of fifteen (15) days; the optional redress wording in Clause 11(a) is struck; under Clause 17, Option 2 applies and the Member State specified in it is Ireland, whose law also governs where the data exporter is not established in an EU Member State; the courts under Clause 18(b) are the courts of the EU Member State whose law governs the SCCs under Clause 17; and Annexes I, II and III to the SCCs are Annex 1, Annex 2 and Annex 3 to this DPA respectively.
c. UK Addendum. The Parties conclude the UK Addendum, which applies to International Data Transfers subject to the UK GDPR. Table 1 is completed with the Parties' details as set out in this DPA and the Order; in Table 2 the first option is selected and the Approved EU SCCs are those referred to in Section 6.b; in Table 3 the Appendix Information is Annex 1, Annex 2 and Annex 3 to this DPA; and in Table 4 both the Importer and the Exporter may terminate the UK Addendum.
d. Swiss transfers. For transfers subject to the Swiss Federal Act on Data Protection, references in the SCCs to the GDPR are to be understood as references to that Act, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term "Member State" shall not be read so as to prevent Data Subjects in Switzerland from bringing proceedings in Switzerland.
e. Government access requests. Company has received no request from any government intelligence, security or law enforcement agency for access to Customer Personal Data. Should Company receive such a request, it shall seek to redirect the agency to Customer, shall not disclose Customer Personal Data voluntarily, shall give Customer notice and an opportunity to seek a protective order unless legally prohibited from doing so, and shall challenge any request that appears unlawful. Company shall report on such requests to Customer on request, to the extent permitted by law.
f. Change in law. If a mechanism relied on under this Section 6 is invalidated, amended or replaced, or a Supervisory Authority requires transfers to be suspended, the Parties shall work together in good faith to put an alternative lawful mechanism in place without undue delay. Company may execute updated or additional standard clauses required for that purpose, and shall do so at Customer's reasonable request, including as a separate document where Applicable Data Protection Laws require it.
7. Data subject rights
a. Taking into account the nature of the Processing, Company shall assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws.
b. Company shall promptly notify Customer of any request it receives directly from a Data Subject relating to Customer Personal Data, and shall not respond to that request itself other than to confirm that the request has been passed to Customer, unless Customer instructs it in writing to do so.
c. Where Company is required by Applicable Data Protection Laws to retain Personal Data that Customer has directed it to delete, Company shall inform Customer of the exception relied on and shall Process the retained data for no purpose other than that permitted by the exception.
8. Security
a. Company shall implement and maintain the technical and organisational measures set out in Annex 2, which are designed to ensure a level of security appropriate to the risk. Customer acknowledges that those measures are appropriate to the Processing described in Annex 1, and shall notify Company before any intended Processing for which they may not be appropriate.
b. Company shall not materially decrease the overall security of the Services during the term of the Agreement.
9. Personal data breach
a. Company shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification shall be given by email to Customer's notice contact stated in the Order or, where none is stated, to the billing contact on Customer's account.
b. The notification shall describe, to the extent known and as it becomes known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information.
c. Company shall provide reasonable assistance to Customer in investigating, mitigating and remedying the breach and in meeting Customer's own notification obligations, shall promptly correct the circumstances that gave rise to it, and shall provide Customer with reasonable assurance that it has done so.
d. A notification under this Section 9 is not an acknowledgement by Company of fault or liability.
10. Data protection impact assessments
Taking into account the nature of the Processing and the information available to it, Company shall provide reasonable assistance to Customer with data protection impact assessments and with prior consultations with Supervisory Authorities, to the extent required by Articles 35 and 36 of the GDPR.
11. Audit and demonstration of compliance
a. Company shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA. Company's current SOC 2 Type II report and summary penetration test results shall be provided on request and are the primary means of demonstrating compliance.
b. Where that information is not sufficient, Customer or an independent auditor mandated by Customer and reasonably acceptable to Company may audit Company's compliance with this DPA. Any such audit shall be conducted no more than once in any twelve (12) month period, on at least thirty (30) days' prior written notice, during business hours, at Customer's expense, subject to confidentiality obligations, and in a manner that minimises disruption to Company's business. Customer may additionally audit where required to do so by a Supervisory Authority or following a Personal Data Breach affecting Customer Personal Data, without regard to the annual limit.
c. An audit shall not extend to Company's other customers' data, to Company's internal pricing or commercial information, or to any information Company is prohibited from disclosing by law or by an obligation to a third party.
12. Data protection contact
Company's designated contact for data protection matters is the Security Officer, reachable at [email protected]. Company has appointed a designated person responsible for data protection rather than a statutory data protection officer under Article 37 of the GDPR, as its core activities do not involve large-scale regular and systematic monitoring of Data Subjects or large-scale Processing of special categories of Personal Data.
13. Return or deletion of customer personal data
a. On expiry or termination of the Agreement, Company shall, at Customer's election, return Customer Data to Customer or delete it. Customer may request a final export before the effective date of termination under Section 3.d.
b. Company shall delete Customer Data and any remaining copies within thirty (30) days of the effective date of termination or of Customer's written request, whichever is earlier, except to the extent retention is required by law or is necessary to establish, exercise or defend legal claims. Where data is retained on that basis, Company shall isolate it, protect it, and Process it for no other purpose. Backups containing Customer Data are overwritten within the seven (7) day backup retention period.
c. During the term of the Agreement, Customer may configure the retention period applied to historical execution data held on its instance.
14. U.S. State Privacy Laws
a. Where Company Processes Personal Data governed by the U.S. State Privacy Laws on Customer's behalf, Customer is the "business" or "controller" and Company is a "service provider", "contractor" or "processor" as those terms are defined in the applicable law.
b. Company shall comply with the obligations applicable to it in that capacity, shall provide the level of privacy protection required by those laws, and shall not Sell or Share Personal Data, retain, use or disclose it for any purpose other than performing the Services, retain, use or disclose it outside the direct business relationship between the Parties, or combine it with Personal Data from any other source except as those laws permit. Company shall not attempt to re-identify any deidentified data made available to it.
c. Company shall notify Customer within five (5) business days of determining that it can no longer meet its obligations under the U.S. State Privacy Laws, and Customer may on receiving that notice direct Company to take reasonable steps to stop and remediate any unauthorised use of Personal Data.
d. The Parties acknowledge that no Personal Data is exchanged between them as monetary or other valuable consideration.
e. Where the Agreement includes a CCPA addendum, this Section 14 supplements that addendum. To the extent of any conflict between them, this DPA prevails in accordance with Section 15.b.
15. General
a. Term. This DPA takes effect on the Effective Date and remains in force for as long as Company Processes Customer Personal Data under the Agreement, terminating automatically thereafter.
b. Conflict. In the event of a conflict between the Agreement and this DPA, this DPA prevails to the extent of the conflict. Where Customer and Company have executed a separate written data processing agreement covering the Services, that agreement prevails over this DPA for as long as it is in force, and this DPA applies only to matters that agreement does not address. In the event of a conflict between the SCCs and the remaining terms of this DPA, the SCCs prevail to the extent of the conflict. Nothing in this DPA modifies the SCCs or affects any third party's rights under them.
c. Liability. Each Party's liability arising out of or in connection with this DPA is subject to the exclusions and the aggregate cap on liability set out in the Agreement. Where the Agreement is the Terms of Service, Company's aggregate liability arising out of or in connection with this DPA shall not exceed the fees paid or payable by Customer under the Agreement in the twelve (12) months preceding the event giving rise to the claim. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Laws, including a Data Subject's rights under the SCCs.
d. Governing law. Save as provided in Sections 6.b and 6.c, this DPA is governed by the law governing the Agreement.
e. Changes in law. The Parties shall cooperate in good faith to agree such amendments to this DPA as are necessary to address changes to Applicable Data Protection Laws.
Annex 1: description of the processing and of the transfer
A. List of parties
Data exporter:
- Name, address and contact person: as stated for Customer in the Order.
- Activities relevant to the data transferred: Customer receives the Services described in the Agreement, and Company Processes Customer Personal Data in that context.
- Role: controller, or processor on behalf of a third-party controller.
- Signature and date: by accepting an Order for Enterprise Edition Cloud or using the Services, the data exporter is deemed to have signed the Standard Contractual Clauses incorporated herein, as of the Effective Date.
Data importer:
- Name: Windmill Labs, Inc.
- Address: 1111B S Governors Ave STE 6013, Dover, DE 19904, USA.
- Contact: Security Officer, [email protected].
- Activities relevant to the data transferred: Company provides the Services described in the Agreement and Processes Customer Personal Data in that context.
- Role: processor on behalf of Customer, or subprocessor on behalf of a third-party controller.
- Signature and date: by publishing this DPA and accepting the Order, the data importer is deemed to have signed the Standard Contractual Clauses incorporated herein, as of the Effective Date.
B. Description of the processing
| Categories of Data Subjects | Customer's employees, contractors and other authorised users of the Services; individuals whose Personal Data Customer chooses to Process in workflows on its instance; individuals whose Personal Data Customer includes in a support request. |
| Categories of Personal Data | Account and identity data (names, email addresses, IP addresses, browser and device information, authentication and audit records); any Personal Data contained in workflow inputs, outputs, execution history, scripts, flows, apps, variables, secrets, files and database contents that Customer chooses to Process on its instance; the Personal Data contained in telemetry, as described in Section 3.e. |
| Special categories of Personal Data | Determined by Customer. Where Customer Processes special categories of Personal Data or data subject to sectoral regimes such as HIPAA, it shall notify Company so that additional terms, including a business associate agreement where applicable, can be put in place. |
| Frequency of the transfer | Continuous. |
| Nature of the Processing | Hosting, storage, execution, transmission, backup, monitoring and support of Customer's dedicated instance. |
| Purpose of the Processing | Provision, operation, maintenance and support of the Services under the Agreement. |
| Retention | For the duration of the Agreement, subject to the retention period Customer configures for historical execution data, and deleted in accordance with Section 13. |
| Transfers to Subprocessors | As set out in Annex 3, for the subject matter, nature and duration described above and for the duration of the Agreement. |
C. Competent supervisory authority
The competent Supervisory Authority is the authority determined in accordance with Clause 13 of the SCCs, being the Supervisory Authority of the EU Member State in which the data exporter is established or, where the data exporter is not established in the EEA, the Supervisory Authority of the Member State in which the data exporter's representative is established or in which the Data Subjects whose Personal Data is transferred are located. For Processing relating to Data Subjects in the UK, the competent authority is the UK Information Commissioner.
Annex 2: technical and organisational measures
This Annex describes the measures Company applies to Customer's dedicated instance and to the Customer Personal Data it Processes.
Pseudonymisation and encryption. All Customer Personal Data is encrypted in transit using industry-standard TLS 1.2 or above, and at rest using AES-256. Encryption keys for Company-managed infrastructure are held in AWS KMS and rotated annually. Windmill encrypts workspace secrets with per-workspace AES-256 keys. Customer may additionally encrypt data before it is sent to the Services, with no loss of functionality.
Confidentiality, integrity, availability and resilience. Company enforces least privilege across all systems on the basis of employee role, with access lists reviewed quarterly, access to all systems through single sign-on with multi-factor authentication, and access revoked on termination of employment. Company does not use Customer Data for any purpose other than delivery of the Services. Administrative access to production infrastructure is made over a zero-trust network. Recovery objectives for the Services are a recovery time objective of four (4) hours and a recovery point objective of one (1) hour, supported by backups taken daily and retained for seven (7) days, with continuous point-in-time recovery available within that window. Backups are encrypted and stored redundantly across multiple availability zones, and are automatically overwritten at the end of the retention period.
Testing and assessment of measures. Company undergoes an annual SOC 2 Type II audit and commissions an external full-scope penetration test at least annually. Company conducts an annual risk assessment which drives the prioritisation of security initiatives. Company holds neither ISO 27001 certification nor PCI-DSS attestation and makes no claim to either.
Identification and authorisation. All authentication is routed through corporate-controlled single sign-on with multi-factor authentication enabled, under a least-privilege model based on employee role.
Physical security. Physical security of the locations at which Customer Personal Data is Processed is the responsibility of Company's hosting Subprocessors. Company validates semi-annually that each Subprocessor maintains sufficient physical controls, including access control, visitor logs, video surveillance, alarm systems, backup power and environmental monitoring.
Event logging and monitoring. Company logs security-relevant events to a centralised logging and metrics stack, self-hosted on Company-managed infrastructure. Alerts are routed to an on-call rotation monitored 24/7.
System configuration. All deployments are managed through automated, repeatable processes driven by infrastructure-as-code tooling, using immutable container images scanned on every build.
Vulnerability management. Company scans dependencies and published images continuously and remediates according to severity, with target timelines of three (3) days for critical, seven (7) days for high, thirty (30) days for medium, and as needed for low severity findings.
Governance. Company maintains an information security management programme informed by the NIST Cybersecurity Framework, together with documented policies covering access management, data management and retention, incident response, business continuity and disaster recovery, key management, vendor management, audit log management and vulnerability management. All personnel are required to comply with those policies, and violations are subject to disciplinary procedures.
Data minimisation and quality. Company Processes only the data relevant and necessary to provide the Services, keeps records up to date and applies documented deletion practices.
Limited retention. Retention periods are as set out in Annex 1.B and Section 13.
Accountability. Access to Customer Personal Data is logged, and logs are retained and reviewable to confirm that access was proportionate and appropriate. Company does not permit non-employees access to Customer Personal Data or to production systems.
Portability and erasure. Customer may export its data at any time under Section 3.d, including for migration to a self-hosted deployment, may configure the retention period applied to historical execution data, and may halt processing currently in progress.
Annex 3: subprocessors
| Subprocessor | Service | Processing location |
|---|---|---|
| Ubicloud B.V., Turfschip 267, 1186 XK Amstelveen, The Netherlands | Infrastructure and hosting for Customer's instance, where Ubicloud is the provider stated in the Order | Region stated in the Order (United States or European Union) |
| Amazon Web Services, Inc., 410 Terry Ave N, Seattle, WA 98109, USA | Infrastructure and hosting for Customer's instance, where AWS is the provider stated in the Order | Region stated in the Order (United States or European Union) |
| Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA | Edge network, DNS and web application firewall; storage of licensing telemetry records | United States and EEA |
Only the hosting provider stated in the Order hosts Customer's instance. Company shall notify Customer in writing at least fifteen (15) days before moving Customer's instance to the other listed hosting provider, and Customer may object to that move as if it were a new Subprocessor under Section 5.b. Logging and monitoring are self-hosted by Company and do not involve a Subprocessor.
Where Customer Personal Data is disclosed by Customer in a support channel, it may additionally be Processed by the tooling Company uses to operate support, being the chat platform agreed with Customer (Slack, Discord or Microsoft Teams), Google Workspace for email, and Linear and GitHub for issue tracking.