Data Processing Agreement
Last updated August 1, 2026
This agreement applies where your organization uses WIMNE to process personal data and your organization decides why and how that data is processed. In that arrangement your organization is the controller and Tekents Innovation (OPC) Private Limited is the processor. It is written to satisfy Article 28 of the UK and EU GDPR and the corresponding obligations under India's Digital Personal Data Protection Act, 2023.
1. How this agreement takes effect
This agreement forms part of, and is governed by, our Terms of Service. It takes effect when your organization starts using WIMNE to process personal data and continues for as long as we do so. Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement governs.
If your procurement process needs a signed copy, or your own DPA template executed instead, email info@tekents.com and we will countersign. We do not require you to accept this version in order to have an agreement in place.
2. What we process, and for whom
Subject matter and duration. Provision of the WIMNE conference planning service, for as long as your organization has an active account, plus the deletion window in section 8.
Nature and purpose. Storing, organizing, displaying, exporting, and transmitting the data your organization enters or imports, solely to provide the service to your organization.
Categories of data subject. Your organization's own personnel who hold WIMNE accounts; conference organizer contacts your team records; and individuals whose details your team imports as leads, typically from badge scans or event guest lists. That last category matters most: those people are not WIMNE users and have no relationship with us.
Types of personal data. For account holders: name, email address, password hash, job title, employer, professional social profiles, time zone. For organizer contacts and leads: name, email address, employer, job title, and any notes, qualification, or deal value your team records against them. We do not seek and the service is not designed to hold special category data under Article 9, nor payment card numbers, which our payment provider handles directly.
3. Our obligations
We process personal data only on your organization's documented instructions, which comprise this agreement, the Terms of Service, and the actions your users take in the product. If we are required by law to process it otherwise, we will tell you before doing so unless that law forbids it.
Everyone with access is bound by a duty of confidentiality. We do not sell personal data, we do not use lead data to market to those individuals, and we do not use your organization's content to train AI models. See section 6 for how AI features work.
We assist your organization, taking into account the nature of the processing, in responding to data subject requests, and in meeting your obligations under Articles 32 to 36 on security, breach notification, and data protection impact assessments.
4. Security measures
The technical and organizational measures in place, which are the Article 32 measures for this agreement:
- All traffic served over HTTPS.
- Passwords hashed with scrypt, never stored or logged in plain text.
- Every query that reads or writes organization data is scoped to the requesting user's organization at the server layer, so a user cannot reach another organization's data by changing an identifier.
- Role-based access control within an organization (Owner, Admin, Member, Viewer), each mapped to an explicit permission set.
- API keys stored as one-way hashes.
- Outbound webhook payloads signed with HMAC.
- Uploaded files served through short-lived signed URLs rather than public links.
- Rate limiting on authentication and public forms, and a scoped activity log of who did what and when.
- Automated linting, type-checking, and an automated test suite gate every change before release, with a staging environment for rehearsing database migrations.
Stated plainly, because a procurement questionnaire will ask: Tekents Innovation (OPC) Private Limited is an early-stage company and has not completed a SOC 2 or ISO 27001 audit or an independent penetration test. We will say so rather than imply otherwise, and we will tell you if that changes.
5. Subprocessors
Your organization gives general authorization for us to engage the subprocessors below. Each is bound by data protection terms no less protective than this agreement, and we remain liable for their performance.
- Application hosting, database, and cache providers — running the service and storing your data.
- Resend — transactional email such as reminders and password resets.
- OpenAI — AI features. See section 6 for what is and is not sent.
- Paddle — merchant of record for paid plans: payment processing, billing, and sales tax.
- Cloudflare R2 — storage for files your team uploads.
- Sentry — error monitoring, configured to exclude user identifiers, cookies, and credential headers.
- PostHog — product analytics, and only for visitors who have allowed analytics cookies.
We will give at least 30 days' notice before adding or replacing a subprocessor, to the email address on your organization's account. If your organization reasonably objects on data protection grounds within that period and we cannot offer a workable alternative, your organization may terminate the affected part of the service and receive a pro-rata refund of prepaid fees. To receive these notices, email info@tekents.com.
6. AI features
The talk pitch generator, conference recommendations, and conference summaries send only what each feature needs: the topic text a user types, interest tag names, or a conference's own public description. Names, email addresses, passwords, billing details, and lead records are never sent to the AI provider. Prompts and responses are not used to train any model. AI output is a draft and should be reviewed before it is relied on.
7. International transfers
Tekents Innovation (OPC) Private Limited is established in India, and some subprocessors process data outside the UK and European Economic Area. Where personal data is transferred out of the UK or EEA, the transfer is made under the European Commission's Standard Contractual Clauses, with the UK Addendum where UK data is involved, together with any additional measures the transfer risk assessment identifies. India is not currently the subject of an EU adequacy decision, so we rely on those clauses rather than adequacy.
8. Deletion, return, and retention
Your organization can export its data at any time from the product, and each user can export their own personal data from account settings.
Lead data can be deleted by an organization administrator at any time from the conference workspace: deleting an import removes every lead in it immediately. This is the mechanism to use when someone asks your organization to erase their details, and it exists because those individuals are not our users and cannot ask us directly.
On termination, we delete your organization's personal data within 30 days, or return it first if you ask within that window. Deleted data is removed from the live database immediately and may persist in routine backup snapshots for a limited period before those snapshots age out, during which it remains subject to this agreement and is not used for any purpose.
9. Personal data breaches
We will notify your organization without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken. Where full information is not yet available we will send what we have and follow up rather than wait.
10. Audits
On reasonable written request, and no more than once a year unless a regulator requires otherwise or a breach has occurred, we will make available the information needed to demonstrate compliance with Article 28 and respond to a reasonable security questionnaire. Where that is not sufficient for your organization's obligations, we will cooperate with an audit conducted by your organization or an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, and in a manner that does not compromise other customers' data.
11. Contact
Data protection questions, subprocessor notices, breach notifications, audit requests, and signature requests all go to info@tekents.com. See also our Privacy Policy, which covers the data we process as a controller in our own right, such as the accounts of individual users who sign up without an organization.