Wisty

Data processing agreement

Last updated September 23, 2026

This data processing agreement (the "DPA") forms part of the Terms of Service between Wisty Labs AS, org. nr. 938 423 490, Elisenbergveien 34, 0263 Oslo, Norway ("Wisty") and the organisation using the Wisty service (the "Customer"). It applies whenever Wisty processes personal data on the Customer's behalf, and it is the binding statement of how that processing is done. The security page describes the same controls in more detail and is informational.

1. Scope and roles

For personal data contained in Customer Data, the Customer is the controller, or a processor acting for its own controller, and Wisty is the processor or subprocessor. Annex 1 describes the processing. The Customer is responsible for the lawfulness of its instructions and for providing notices and establishing any legal basis required for processing Customer Personal Data.

This DPA excludes processing for Wisty’s own purposes, including account administration, billing, business correspondence, and product usage analytics, as described in the privacy policy. Customer content handled for support and generation diagnostics remains covered by this DPA.

2. Definitions

"Customer Data" means data the Customer or its users submit to the service or that the service reads from the Customer's Salesforce org on their behalf, including chat, uploaded files, Salesforce metadata, generated code, and record data read while an app runs. "Customer Personal Data" means personal data contained in Customer Data.

"Data Protection Law" means the EU General Data Protection Regulation (GDPR) as incorporated into Norwegian law by the Personal Data Act, and any other data protection law that applies to the processing. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR.

"Subprocessor" means a third party Wisty engages to process Customer Data on Wisty's behalf.

3. Instructions

Wisty processes personal data in Customer Data only on the Customer’s documented instructions, including this DPA, the terms, and use of the service. These instructions include generation diagnostics described in Annex 1, limited to providing, supporting, securing, and improving the service. Wisty does not use Customer Data to train AI models.

These instructions also include producing aggregated, de-identified statistics about how the service is used, such as the kinds of apps customers build. Such statistics contain no Customer Personal Data and do not identify the Customer, and Wisty may use and publish them for its own purposes.

Wisty will inform the Customer if it considers an instruction to infringe Data Protection Law. If law requires processing other than as instructed, Wisty will inform the Customer before that processing unless the law prohibits notice.

4. Confidentiality

Wisty limits access to Customer Data to personnel who need it to provide, support, or secure the service, and ensures that those personnel are bound by confidentiality obligations. Access to production systems is granted on a need-to-know basis and protected by multi-factor authentication.

5. Security

Wisty implements the technical and organisational measures in Annex 2, which are appropriate to the risk of the processing, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing. Wisty may update those measures over time, provided the overall level of protection does not decrease.

6. Subprocessors

The Customer gives Wisty general authorisation to engage the subprocessors listed in Annex 3. Wisty imposes on each subprocessor data protection obligations that are no less protective than those in this DPA, and remains responsible to the Customer for each subprocessor's performance.

Wisty will notify workspace administrators by email at least 30 days before adding or replacing a subprocessor that will process Customer Data. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected service and delete its workspace, and Wisty will refund any prepaid fees for the period after termination.

7. International transfers

The Customer authorises the processing locations described in Annex 3, subject to this DPA. For transfers outside the EEA, Wisty will ensure an applicable adequacy decision or appropriate safeguards, including Standard Contractual Clauses and supplementary measures where required. This includes transfers through remote access. Information about the safeguards relevant to Customer Data is available on request.

8. Assistance

Taking into account the nature of processing, Wisty will assist the Customer with data subject requests. Wisty will forward requests concerning Customer Data without undue delay and respond directly only on the Customer’s instructions or as required by law.

Taking into account the information available to it, Wisty will assist the Customer with obligations under Articles 32–36 of the GDPR, including security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

9. Personal data breaches

Wisty notifies the Customer of a personal data breach affecting Customer Data without undue delay, and no later than 72 hours after becoming aware of it. The notice goes by email to the workspace's administrators and includes what is known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Wisty provides updates as the investigation continues and cooperates with the Customer's own notifications.

10. Information and audits

Wisty will provide information necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires. The security page describes the service’s controls.

Where written information is insufficient, Wisty will allow and contribute to a remote review of relevant records and documentation by the Customer or an independent auditor bound by confidentiality, once in any 12 months with 30 days’ written notice and reasonable safeguards against disclosure of other customers’ data. Wisty will also cooperate with any audit or inspection required by law or a supervisory authority.

11. Deletion and return

At the end of the service, Wisty will, at the Customer’s choice, return or delete personal data processed on its behalf and delete remaining copies unless law requires retention. The Customer may request return or deletion through legal@wisty.ai. Return covers all stored Customer Personal Data; Salesforce records remain in Salesforce.

Deleting a workspace revokes access to its published apps and starts asynchronous removal of its customer data. Project deletion removes that project’s data without disconnecting shared Salesforce connections. Removing a connection requests revocation of its OAuth grant in Salesforce; revocation is best-effort and administrators can also revoke access directly in Salesforce.

Removal from active systems proceeds without undue delay. Database backups expire within 14 days. Prompt and generated-code content in AI traces expires after 14 days; replays expire after 3 months. Model-provider copies follow the provider retention described on the security page. Wisty will address requests for earlier erasure in accordance with applicable law and its obligations to obtain deletion from subprocessors. Retained copies remain protected under this DPA.

Billing records, trial-abuse records, and product usage events retained for Wisty’s own purposes are governed by the privacy policy. This does not authorise retaining customer content for unrelated purposes.

12. Liability

Each party is liable for damage caused by its processing as set out in Article 82 of the GDPR. Wisty's total liability under this DPA is subject to the limitation of liability in the Terms of Service. Nothing in this section limits liability that Data Protection Law does not allow to be limited.

13. Term and precedence

This DPA takes effect when the Customer accepts the terms and applies for as long as Wisty processes personal data on its behalf, including retained copies after termination. It prevails over conflicting terms concerning personal-data processing. Updates must not reduce the overall protection of Customer Personal Data. Wisty will give administrators at least 30 days’ notice of material changes, subject to changes required by law.

14. Law and contact

This DPA is governed by the same law and subject to the same venue as the Terms of Service. Questions about this DPA, signed copies, and subprocessor notices: legal@wisty.ai. Security matters and breach reports: security@wisty.ai.

Annex 1: Processing details

ItemDetail
Subject matterGenerating, running, and publishing internal apps that read from and write to the Customer's Salesforce org.
DurationFor the duration of the service and until return or deletion is complete under section 11.
Nature and purposeStoring app definitions, chat history, and generated code; reading Salesforce metadata to generate apps; proxying Salesforce reads and executing approved writes as the signed-in user while an app runs; sending instructions, relevant attachments, metadata, and project code to AI providers; recording generation diagnostics to investigate errors, evaluate generation quality, and improve generation; producing aggregated, de-identified usage statistics.
Categories of data subjectsThe Customer's personnel who build or use apps. Individuals whose personal data is held in the Customer's Salesforce org, such as customers, prospects, contacts, and employees.
Categories of personal dataSalesforce user and org identifiers used to provide customer apps. Any personal data the Customer places in chat, in uploaded files, or in Salesforce metadata such as field labels and descriptions. Salesforce record data read live while an app runs, which Wisty does not store.
Special categoriesThe service is not intended for special-category data in chat or uploads; the Customer must not submit it there. The Customer determines the data accessed by runtime apps and is responsible for establishing any additional legal basis and safeguards required for special-category data in those records.

Annex 2: Technical and organisational measures

Further technical detail is available on the security page.

MeasureControl
Access to SalesforceEvery read and write runs as the signed-in Salesforce user through OAuth. Wisty holds no integration user. Field-level security, object permissions, and sharing rules apply as in Salesforce.
Isolation of generated codeGenerated browser code is restricted to the same-origin Salesforce proxy. Preview virtual machines restrict outbound connections to Wisty's backend. Writes use an authenticated, permission-checked bridge. Salesforce credentials are held by the backend.
Credential protectionSalesforce tokens are envelope-encrypted with per-credential keys wrapped by AWS KMS on FIPS-validated hardware. Each decrypt is a logged KMS call. Runtime key access can be revoked at once.
EncryptionAll data encrypted at rest by the database provider; TLS on every connection.
Data minimisationSalesforce record data is read live at runtime and is never stored, cached, or logged. Cached metadata is limited to object, field, relationship, and layout definitions.
Tenancy and authenticationThe workspace is the tenancy boundary and every backend function checks it. Standalone builders sign in through Clerk with multi-factor authentication available. Canvas builders and Salesforce viewers are identified by Salesforce.
Staff accessProduction access on a need-to-know basis, through provider consoles with multi-factor authentication. Every use of a Salesforce token is logged in AWS CloudTrail. Development and production are separate deployments.
Logging and telemetryProxy calls logged without response bodies; write logs without field values. Analytics hosted in the EU. Builder accounts are identified by name and email address; people who open apps in Salesforce are not. Replays mask inputs, exclude host write-approval content, and do not capture the cross-origin preview.
DeletionWorkspace deletion revokes published access and starts removal of projects, apps, connections, and history. Removal of connections requests Salesforce grant revocation. Backups expire within 14 days.
Incident responseIncident containment can include revoking Salesforce grants and disabling KMS access. Breach notification is without undue delay and within 72 hours of awareness, with updates as information becomes available.

Annex 3: Subprocessors

The subprocessors Wisty uses to process Customer Data, with what each processes and where. Section 6 sets out how changes to this list are notified.

SubprocessorRoleCustomer Data processedLocation
CloudflarePublished-app delivery and network securityPublished assets, runtime traffic, and request metadata.Global network
ConvexDatabase and backend hostingStored application data and published builds. Salesforce tokens are encrypted in storage and decrypted in backend memory for Salesforce calls; runtime record traffic passes through the backend.United States
Amazon Web ServicesKey management (AWS KMS) and key-use loggingEncryption keys and key-use records, including user and org identifiers in encryption context.United States
VercelFrontend hosting, preview sandboxes, AI GatewayProject code and assets in preview machines. Application requests and model traffic in transit.United States; global delivery network
AnthropicAI model providerInstructions, relevant attachments, org metadata, and project code, including personal data supplied in that content. No stored Salesforce credentials.Provider-dependent, including the United States
OpenAIAI model providerInstructions, relevant attachments, org metadata, and project code, including personal data supplied in that content. No stored Salesforce credentials.Provider-dependent, including the United States
TypeSafe AI, Inc.AI model providerInstructions, relevant attachments, org metadata, and project code, including personal data supplied in that content. No stored Salesforce credentials.Provider-dependent, including the United States
GoogleAI model providerInstructions, relevant attachments, org metadata, and project code, including personal data supplied in that content. No stored Salesforce credentials.Provider-dependent, including the United States
PostHogProduct analytics, error reports, and diagnosticsProduct events, session replays of the builder app, support conversations, and backend logs used to provide and support the service. Builder accounts are identified by name, email address, and workspace name.European Union
BraintrustAI generation tracesInstructions, the model's steps, Salesforce metadata read during generation, and generated code, with pseudonymous user and project identifiers.European Union

Clerk handles Wisty account administration and Polar handles payments as merchant of record. Those activities are described in the privacy policy rather than this subprocessor register.