Data Processing Agreement (DPA)

Join us at Wingu Technology and unlock new opportunities for business growth and innovation!

Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Wingu Technology LLC | Last Revised / Effective Date: July 2026

1. Overview and Scope

This Data Processing Agreement (this "DPA") governs the processing of Personal Data by Wingu Technology LLC, a Florida limited liability company ("Wingu Technology", "Processor", "we", "us", or "our"), on behalf of the customer legal entity ("Customer", "Controller", or "you") in connection with the cloud hosting, virtual infrastructure, endpoint management, and data backup services (collectively, the "Services") provided under our Master Terms of Use and Master Services Agreement.

This DPA applies whenever Personal Data owned, controlled, or submitted by Customer is hosted, processed, or transmitted across Wingu Technology's infrastructure. This DPA incorporates applicable federal and state data privacy statutes—including the Florida Digital Bill of Rights (FDBR), California Consumer Privacy Act (CCPA/CPRA), and international privacy standards such as the EU General Data Protection Regulation (EU GDPR) and UK GDPR.

2. Definitions and Operational Roles

For the purposes of this DPA, the following terms shall have the meanings defined below:

  • "Controller" means the natural or legal person that determines the purposes and means of processing Personal Data (Customer).
  • "Processor" means the entity that processes Personal Data on behalf of the Controller (Wingu Technology LLC).
  • "Personal Data" means any information relating to an identified or identifiable natural person processed by Wingu Technology as part of Customer Hosted Content.
  • "Security Incident" means any confirmed unauthorized, accidental, or unlawful access, acquisition, disclosure, destruction, alteration, or loss of Personal Data stored or processed on Processor's operational infrastructure.
  • "Sub-processor" means any third-party data processor engaged by Wingu Technology to assist in fulfilling its contractual processing obligations under the Master Services Agreement.

3. Processing Instructions and Purpose Limitation

Wingu Technology shall process Personal Data strictly in accordance with Customer's documented, lawful instructions as set forth in this DPA, the Master Services Agreement, and associated service orders, unless required to do so by applicable federal, state, or international law.

4. Technical and Organizational Security Measures (TOMs)

Processor shall implement and maintain comprehensive physical, administrative, and technical safeguards designed to protect Personal Data against unauthorized access, destruction, loss, or alteration. These measures include, without limitation:

A. Encryption Controls

  • Data in Transit: Mandatory cryptographic transport layer security (TLS 1.3/SSL) for all administrative web portals, API endpoints, and remote network access tunnels.
  • Data at Rest: AES-256 bit encryption deployed across primary SAN/NAS storage arrays, virtual machine disk volumes, and automated off-site backup archives (including Arbor Vault configurations).

B. Access & Isolation Infrastructure

  • Strict tenant boundary isolation preventing cross-tenant memory or storage pool leakage across hypervisors.
  • Multi-factor authentication (MFA) and least-privilege role-based access controls (RBAC) enforced across all internal operational nodes.
  • Biometric identity verification, perimeter surveillance, and logging at primary physical data center facilities.

5. Sub-processors and Vendor Oversight

Customer provides general authorization for Wingu Technology to engage vetted third-party Sub-processors (such as hardware colocation facilities, payment gateways, and transactional network carriers) to support the delivery of Services.

Wingu Technology shall ensure that every Sub-processor is bound by written contractual commitments at least as protective as those set forth in this DPA. Processor remains fully liable to Controller for the performance of its Sub-processors' processing obligations.

6. Personal Data Incident Notification Protocol

In the event Processor confirms a Security Incident affecting Customer's Personal Data, Wingu Technology shall notify Customer without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the incident.

The notification shall describe, to the extent known:

  • The nature of the Security Incident and categories of data involved.
  • The estimated scope of affected records and potential impact.
  • The immediate mitigation measures executed by Processor.
  • The technical contact details of Processor's incident response personnel.

7. Data Subject Rights and Regulatory Assistance

Taking into account the nature of the processing, Processor shall assist Controller by implementing appropriate technical and organizational measures, insofar as possible, to fulfill Controller's obligations to respond to verifiable requests from data subjects exercising their statutory rights under privacy laws (e.g., rights to access, rectify, delete, or opt-out).

If Processor receives a request directly from a data subject regarding Customer's hosted data, Processor shall direct the data subject to submit their request directly to Controller.

8. International Data Transfers

Where Personal Data originating from the European Economic Area (EEA), United Kingdom (UK), or Switzerland is transferred to Processor infrastructure located in the United States, such transfers shall be governed by valid legal mechanisms, including the EU Standard Contractual Clauses (SCCs) (incorporating Module 2: Controller-to-Processor and Module 3: Processor-to-Processor terms) and the UK International Data Transfer Addendum.

9. Data Return, Deletion, and Archival

Upon termination or expiration of the Master Services Agreement, Customer may request the export of hosted Personal Data. Within sixty (60) days following account termination, Processor shall purge and overwrite all virtual machine disk images, snapshots, and backup archives containing Personal Data from operational storage systems, unless retention is required by applicable law or court order.

10. Inquiries and Data Protection Operations

For inquiries regarding this DPA, sub-processor listings, or data protection compliance, please contact our administrative desk at:

Wingu Technology LLC — Legal & Data Protection Operations
Wesley Chapel, Florida, USA
Email: support [at] wingutechnology [dot] com
Website: www.wingutechnology.com

Subscribe Our Newsletter

We attribute our advances in cloud security and compliance to the exceptional people who work here. Stay updated with the latest insights, tips, and exclusive offers from Wingu Technology by signing up for our newsletter!

You have been successfully Subscribed! Ops! Something went wrong, please try again.
Copyright © 2015 — 2026 Wingu Technology, LLC. All rights reserved.

The information provided on this website is for general informational purposes only and does not constitute professional IT, security, or legal advice. Implementation of infrastructure solutions should be handled by qualified engineering professionals. Please review our Privacy Policy and Terms of Service to understand our commitment to data sovereignty.
Immuniweb Web Security Score

Cookie Policy

By clicking “Agree”, you have read and agree to the Terms of Use and agree to the collection and use of your information by cookies and similar technologies, as set forth in our Privacy Policy.

Agree
Wingu Technology - Managed IT Services