GDPR Article 28 Compliance
Data Processing Agreement (DPA)
Last updated: August 2026 • WELINK TECH SASU
This Data Processing Agreement ("DPA") governs the processing of personal data between WELINK TECH SASU ("Processor") and the Customer ("Controller") pursuant to Article 28 of the GDPR.
1. Roles and Scope of Processing
The Customer acts as the Data Controller for all community member profiles, chat telemetry, and transaction logs. WELINK TECH SASU acts strictly as a Data Processor executing documented instructions via SaaS automation.
2. Technical & Organizational Security Measures
- End-to-end data encryption in transit via TLS 1.3.
- AES-256-GCM encryption at rest for vector stores and relational databases.
- Strict tenant data partitioning and automated data isolation.
- Automated 30-day cryptographic shredding upon account closure.
3. Authorized Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Edge Hosting & Serverless Compute | USA / EU |
| Supabase Inc. | PostgreSQL & Vector Storage | EU (Frankfurt) / USA |
| Stripe Payments Europe | Direct Billing Infrastructure | Ireland / EU |
| Google Cloud (Vertex AI) | LLM Inference & Vector Slicing | EU / USA |
| Resend Inc. | Transactional Email Dispatch | USA |