Trust
Data processing addendum
If you are a facility, a research partner, or any organisation whose people use Waterfall, this sets out how we handle personal data on your behalf. We will sign a countersigned copy on request. Ask us at hello@waterfallwisdom.com.
Read this alongside our trust page. We are in pilot deployments and are not yet SOC 2 certified, nor operating under a HIPAA Business Associate Agreement. This addendum covers data protection generally; it is not a BAA and does not authorise sending us protected health information.
Roles
You are the controller of the personal data your people put into Waterfall. We are the processor, acting on your documented instructions. Where a storyteller signs up on their own account, we are the controller for that relationship.
What we process
Names and contact details, audio recordings, transcripts and the material derived from them, account and usage records, and any consent decisions attached to a story.
Why
To provide the service: capturing, storing, organising and sharing stories at the direction of the person who told them, and improving our own models strictly within the consent tier that person chose.
Subprocessors
Listed publicly and kept current on our subprocessors page. We give notice before adding one that handles personal data, and you may object.
Security
Encryption in transit and at rest, access limited by role and enforced at the database, audit logging of administrative access and disclosures, and least-privilege credentials. Our current certification status is set out on the trust page.
International transfers
Data is processed on Google Cloud in the United States. For transfers out of the EEA, the UK or Switzerland we rely on Standard Contractual Clauses and the UK Addendum, with supplementary measures.
Your people’s rights
We help you answer access, correction, deletion and portability requests. A storyteller can also exercise these directly in the product: revoking consent scrubs the record, deletes derived training data, removes it from search and writes an audit entry.
Retention and deletion
We keep data for as long as the account is active or the consent stands. On deletion or the end of the agreement we delete or return it, backups included, on the schedule set out in the signed copy.
Breach notification
We notify you without undue delay after becoming aware of a personal data breach affecting your people, with what we know and what we are doing about it.
Audits
We provide the information reasonably needed to demonstrate compliance, and will share our SOC 2 report once it is issued.
This page summarises the addendum in plain language. The signed document governs.