Data Processing Agreement
Last updated: 10 September 2026
This Data Processing Agreement (the "DPA") is entered into by the customer identified on the applicable We-Link ordering document ("Customer") and We-Link, operated by We-Connect ("We-Link"). It governs the processing of personal data that Customer provides to We-Link, or that We-Link processes on Customer's behalf, in connection with the We-Link services (the "Services").
This DPA is incorporated into the We-Link services agreement or terms of use entered into by Customer (the "Agreement"). In the event of a conflict regarding the processing of personal data, the order of precedence is: (a) the Standard Contractual Clauses; (b) this DPA; (c) the Agreement.
1. Definitions
"Data Protection Laws" means all laws and regulations applicable to the processing of personal data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
"Customer Personal Data" means personal data that We-Link processes on Customer's behalf in providing the Services.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
"Process" and "Processing" mean any operation performed on personal data, whether or not by automated means.
"Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision 2021/914 for the transfer of personal data to third countries, and, for UK transfers, the UK International Data Transfer Addendum.
"Subprocessor" means a third party engaged by We-Link to process Customer Personal Data.
Terms not defined here have the meaning given in the Agreement or in Data Protection Laws.
2. Roles of the parties
Customer is the controller of Customer Personal Data, and We-Link is the processor. For personal data relating to Customer's own account (such as registration, billing and usage data), We-Link acts as a controller and processes it in accordance with its Privacy Policy at we-link.ai/privacy.
The parties are independent controllers and processor respectively, and are not joint controllers.
3. Scope and instructions
We-Link will process Customer Personal Data only:
- to provide, support and secure the Services; and
- in accordance with Customer's documented instructions.
Customer's use of the Services, including the API calls it makes, whether through an AI agent over MCP or through Customer's own program over REST, constitutes its documented instructions to We-Link. We-Link will not process Customer Personal Data for any other purpose, and will not sell it or use it to build or improve its own products.
We-Link will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Nature of processing
We-Link provides the Services as a transit processor. Customer Personal Data is processed to carry out the API call Customer makes and returned to Customer, and is not retained by We-Link as a standing database. The categories of data subjects, categories of personal data, nature and purpose of the processing, and retention periods are set out in Schedule A.
5. Confidentiality
We-Link will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
6. Security
We-Link will maintain appropriate technical and organizational measures to protect Customer Personal Data, as described in Schedule C, which applies as Annex II to the SCCs. These include encryption of data in transit, encryption at rest for the data We-Link retains, access controls, and monitoring.
7. Subprocessors
Customer authorizes We-Link to engage the Subprocessors listed in Schedule A. We-Link will:
- impose data protection obligations on each Subprocessor that are no less protective than those in this DPA;
- remain liable to Customer for each Subprocessor's performance; and
- give Customer notice of any intended addition or replacement of a Subprocessor, and a reasonable opportunity to object on data protection grounds.
8. Data subject requests
We-Link will assist Customer, taking into account the nature of the processing, in responding to requests from data subjects to exercise their rights. If We-Link receives such a request directly, it will not respond substantively, and will promptly route the request to Customer.
9. Personal data breach
We-Link will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the likely consequences, and the measures taken or proposed. We-Link will provide reasonable assistance to Customer in meeting its own breach obligations.
10. Assistance
Taking into account the nature of the processing and the information available to We-Link, We-Link will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities.
11. Return and deletion
On termination of the Services, and except where retention is required by law, We-Link will delete or return Customer Personal Data at Customer's choice. We-Link will permanently delete Customer Personal Data within 90 days of termination. For clarity, We-Link may retain data that has been aggregated so that it no longer identifies any individual.
12. International transfers
We-Link processes Customer Personal Data on servers in the United States. Where the Services involve a transfer of personal data from the EEA, UK or Switzerland to a country without an adequacy decision, the SCCs (Module Two, controller to processor) are incorporated into this DPA by reference, together with the UK Addendum where UK personal data is transferred. Schedule A applies as Annex I and Schedule C as Annex II to the SCCs.
13. Audit
We-Link will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire. Where that information is not sufficient, Customer or an independent auditor may audit We-Link's compliance no more than once per year, on reasonable notice, during business hours, and subject to confidentiality. Customer bears the costs of any such audit.
14. Term
This DPA takes effect when Customer accepts the Agreement and continues until We-Link has ceased all processing of Customer Personal Data and it has been returned or deleted under Section 11.
15. Governing law
This DPA is governed by the law and jurisdiction stated in the Agreement, except where Data Protection Laws or the SCCs require otherwise.
Schedule A: Details of processing and subprocessors
Categories of data subjects
The LinkedIn users that Customer reaches through its connected account, including people whose profiles Customer searches or views, and people to whom Customer sends connection requests or messages. Also, Customer's own authorized users who administer the account.
Categories of personal data
Depending on Customer's use: LinkedIn profile details (such as name, headline, current job title and company, location, profile URL and image), connection and engagement status, and the content of messages sent and received through Customer's connected account. For Customer's own users: account and connection data, including We-Link API credentials and, for the connected LinkedIn account, an encrypted session token and encrypted connection credentials.
Sensitive data
None intended. Customer agrees not to submit special categories of personal data through the Services.
Nature and purpose of processing
Transit processing to carry out the API calls Customer makes and to return the results to Customer, together with the operational processing needed to provide, secure and support the Services.
Data matrix (storage and retention)
| Category | Examples | Storage and retention |
|---|---|---|
| LinkedIn profile and search data | Names, headlines, titles, profile URLs, connection status | Transient. Processed to carry out the call and returned to Customer; not stored as a standing database. |
| Message content | Messages sent and received through the connected account | Transient. Processed to carry out the call and returned to Customer; not stored as a standing database. |
| Request metadata and technical logs | Request status, usage, timestamps | Kept up to 3 months for monitoring, debugging, usage reconciliation and security. |
| Account and connection data | We-Link API credentials, encrypted session token and encrypted connection credentials | Kept for the life of the account, then deleted within 90 days of closure. |
| Network and proxy metadata | Destination host, connection timing, request IP addresses | Processed transiently in memory during an active connection; not retained after transmission. |
Subprocessors
Subprocessors that process Customer Personal Data in providing the Services:
| Subprocessor | Purpose | Jurisdiction | Data location | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure | United States | United States | Standard Contractual Clauses |
| Cloudflare, Inc. | Content delivery and network security | United States | United States | Standard Contractual Clauses |
| Vultr, Inc. | Cloud server provider | United States | United States | Standard Contractual Clauses |
| Oxylabs, UAB | Network proxy services | Lithuania | European Union | Within the EEA, no transfer mechanism required |
| Bright Data Ltd | Network proxy services | Israel | Israel / EU | European Commission adequacy decision |
| Webshare Software Company | Network proxy services | United States | United States | Standard Contractual Clauses |
We-Link's cloud infrastructure is configured to process in the United States.
Schedule B: CCPA addendum
This Addendum applies to Customer Personal Data of California residents and supplements this DPA.
For the purposes of the CCPA, We-Link acts as a "service provider" and processes Customer Personal Data only to provide the Services under this DPA. We-Link does not sell or share Customer Personal Data, and does not retain, use or disclose it for any purpose other than performing the Services or as permitted by the CCPA. We-Link certifies that it understands and will comply with these restrictions.
Schedule C: Technical and organizational measures (Annex II to the SCCs)
We-Link maintains an information security program with measures that include:
- Encryption of Customer Personal Data in transit, and encryption at rest for the data We-Link retains, including account details, connection credentials and logs.
- Storage of the LinkedIn connection as an encrypted session token and, where a connection method requires it, an encrypted account password; these credentials are encrypted at rest and used solely to operate the connected account.
- Dedicated, geo-matched IP addresses for each connected account, provided through a specialized proxy provider acting as a Subprocessor. Proxy providers route network connections only; message content is encrypted in transit and is not decrypted, accessed or stored by them.
- Access controls that limit access to Customer Personal Data to personnel who need it, with access reviewed periodically.
- Logging and monitoring of access to production systems.
- Secure software development practices, including code review and periodic security testing.
- Vulnerability management and incident response procedures.
- Confidentiality obligations and security training for personnel.
Contact
Questions about this DPA, or requests for a countersigned copy, can be sent to [email protected].