Last updated and effective: August 31, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Mohrer Associates LLC, doing business as Wave ("Wave," "we," "us"), and the customer identified in that agreement ("Customer," "you") governing your use of Wave's applications, website, and related services (the "Services") — normally our Terms of Service (the "Agreement"). If the parties have executed a separate data processing agreement covering the same processing, that executed agreement controls and this DPA does not apply.
This DPA applies automatically, without any signature required, whenever Customer uses the Services in the course of business — for example as a company, a Wave for Teams workspace, or an individual professional — and Wave processes Personal Data on Customer's behalf. It reflects the parties' agreement on the processing of Personal Data under the GDPR, UK GDPR, Swiss FADP, CCPA, and similar data protection laws ("Data Protection Laws").
If you need a countersigned copy of this DPA for your records or vendor-management process, email privacy@wave.co with your company name and the email address on your Wave account, and we will return an executed copy.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person. "Customer Content" means the content Customer submits to or generates with the Services — audio recordings, transcripts, summaries, notes, messages, calendar data, and the Personal Data of Customer's meeting participants and correspondents contained in them. "Account Data" means Personal Data Wave collects and uses for its own purposes — Customer's registration, billing, support, and product usage data. "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in the GDPR. "Subprocessor" means a third party engaged by Wave to process Customer Content on Wave's behalf.
2. Roles and Scope
This DPA covers Customer Content. As between the parties, Customer is the Controller (or, where Customer acts on behalf of its own customers, a Processor) of Customer Content, and Wave is a Processor (or Subprocessor, as applicable). For Account Data, Wave is an independent Controller (and a "business" under the CCPA) and processes it as described in our Privacy Policy — for example to operate accounts, bill, provide support, secure the Services, and improve the product. Each party will comply with the Data Protection Laws that apply to it. Customer is responsible for the lawfulness of the Personal Data it submits to the Services — including obtaining any consent required to record conversations and providing any notices required to Data Subjects. The subject matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.
3. Processing on Instructions
Wave will process Customer Content only on Customer's documented instructions — which consist of the Agreement, this DPA, and Customer's use and configuration of the Services — including with regard to transfers of Personal Data to a third country or an international organization, unless required to do otherwise by applicable law, in which case Wave will inform Customer of that legal requirement before processing (unless the law prohibits doing so on important grounds of public interest). Wave will immediately inform Customer if, in Wave's opinion, an instruction infringes Data Protection Laws. Wave does not use Customer Content to train generalized AI or machine-learning models, and does not authorize its Subprocessors to do so.
4. Confidentiality
Wave ensures that all personnel authorized to process Customer Content are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and access Customer Content only as needed to provide the Services.
5. Security
Wave implements and maintains appropriate technical and organizational measures to protect Customer Content against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures are described in Annex 2. Wave may update them from time to time, provided the updates do not materially reduce the overall level of protection.
6. Subprocessors
Customer provides general written authorization for Wave to engage the Subprocessors listed in Annex 3. Wave will engage each Subprocessor under a written agreement imposing data protection obligations that are no less protective than those in this DPA and that provide sufficient guarantees to implement appropriate technical and organizational measures, and Wave remains fully liable to Customer for each Subprocessor's performance.
Wave will give at least 30 days' advance notice before adding or replacing a Subprocessor, by updating Annex 3 on this page and by email to customers who have subscribed to change notices (send a request to privacy@wave.co with the subject "Subprocessor updates"). Customer may object on reasonable data protection grounds within that notice period; Wave will not process the objecting Customer's Content with the new Subprocessor while the objection is unresolved. If the parties cannot resolve the objection within 30 days of it being raised, Customer may terminate the affected Services and receive a pro-rata refund of any prepaid, unused fees.
7. Data Subject Requests
Taking into account the nature of the processing, Wave will assist Customer through appropriate technical and organizational measures — including the in-product export, correction, and deletion tools — in fulfilling Customer's obligation to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, and objection). If a Data Subject contacts Wave directly about Personal Data processed on Customer's behalf, Wave will promptly forward the request to Customer and will not respond substantively except as required by law.
8. Assistance
Taking into account the nature of processing and the information available to Wave, Wave will provide reasonable assistance to Customer with its obligations under Articles 32 to 36 of the GDPR — security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
9. Personal Data Breach
Wave will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Content. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Wave will provide timely updates as further information becomes available and will reasonably cooperate with Customer's own notification obligations. Wave's notification of a breach is not an acknowledgement of fault or liability.
10. Deletion and Return
Customer can export and delete Customer Content at any time through the Services; deletion takes effect in Wave's systems when performed, and Wave does not retain deleted Customer Content in backup archives. At Customer's choice following termination or expiration of the Agreement, Wave will return all Customer Content in a commonly used, machine-readable format or delete it, and in either case delete existing copies within 30 days, unless applicable law requires continued storage — in which case Wave will protect the retained data under this DPA and process it only for the purpose the law requires. Upon request, Wave will confirm deletion in writing.
11. Audits and Reports
Wave will make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. The parties agree that these obligations are ordinarily satisfied by: Wave's SOC 2 Type 1 report (download), the documentation in Wave's Trust Center, and written responses to reasonable security questionnaires. The independent report addresses Wave's system description and the suitability of the design of controls relevant to the Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time.
Where those materials are not sufficient to demonstrate compliance, Customer (or an independent auditor bound by confidentiality) may audit Wave's compliance with this DPA on at least 30 days' written notice, during normal business hours, at Customer's expense, no more than once per 12-month period, and in a manner that does not access other customers' data or unreasonably disrupt Wave's operations — except that the frequency and notice limits do not apply where an audit is required by a supervisory authority or follows a Personal Data Breach or material noncompliance with this DPA.
12. International Transfers
Wave processes Customer Content in the United States. Where the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to Wave requires a lawful transfer mechanism, the parties enter into the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) ("SCCs"), which are incorporated into this DPA by reference and completed as follows:
If the SCCs conflict with this DPA or the Agreement, the SCCs control to the extent of the conflict. Nothing in the Agreement or this DPA limits the rights of Data Subjects, or either party's liability to Data Subjects, under the SCCs.
13. CCPA Service Provider Terms
Where the California Consumer Privacy Act, as amended ("CCPA"), applies to Customer Content, Wave acts as Customer's "service provider" and processes Customer Content for the limited and specific business purposes described in Annex 1 — providing, securing, and supporting the recording, transcription, summarization, search, synchronization, and communications features of the Services. Wave will: (a) not sell or share Customer Content; (b) not retain, use, or disclose it for any purpose other than those business purposes, or as otherwise permitted by the CCPA; (c) not retain, use, or disclose it outside the direct business relationship between the parties; (d) not combine it with personal information Wave receives from other sources, except as permitted by the CCPA; (e) provide the same level of privacy protection as the CCPA requires of Customer; (f) ensure that any subcontractor processing Customer Content is bound by a written contract meeting CCPA service-provider requirements; and (g) assist Customer in responding to consumer requests, including through the tools described in Section 7. Wave will notify Customer if it determines it can no longer meet its obligations under the CCPA, and Customer may take reasonable and appropriate steps — including under Section 11 — to verify compliant use and to stop and remediate any unauthorized use of Customer Content. Wave certifies that it understands and will comply with these restrictions.
14. Sensitive Data
The Services are not designed for regulated health information. Wave is not a HIPAA business associate and does not sign Business Associate Agreements; Customer must not use the Services to process protected health information subject to HIPAA. Because Customer controls what is discussed in recorded conversations, sensitive Personal Data may appear incidentally in recordings and transcripts; Annex 1 describes the categories reasonably foreseeable in conversational content and the restrictions applied to them.
15. Liability, Precedence, Term, and Changes
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement, except for liability that cannot be limited under applicable law and the Data Subject rights described in Section 12. This DPA takes precedence over the Agreement to the extent of any conflict concerning the processing of Personal Data, and the SCCs take precedence over this DPA as described in Section 12. This DPA takes effect when the Agreement takes effect (or, for existing customers, on the date above) and remains in force as long as Wave processes Customer Content. We may update this DPA from time to time as Data Protection Laws evolve; updates will not reduce the level of protection for Customer Content, will not modify the SCCs except as required or permitted by the issuing authority, and material changes will be announced on this page with a new effective date and by email to subscribed customers before they take effect.
Annex 1 — Details of Processing
Annex 2 — Technical and Organizational Measures
Annex 3 — Subprocessors and Vendors
Wave uses the following Customer Content Subprocessors to provide the Services. These vendors may process Customer Content (recordings, transcripts, summaries, messages, calendar data) and are the Subprocessors authorized under Section 6 and listed in SCC Annex III:
| Vendor | Purpose | Location |
|---|---|---|
| Google LLC (Google Cloud / Firebase) | Cloud infrastructure, storage, databases, and authentication | United States |
| AssemblyAI, Inc. | Speech-to-text transcription of audio recordings | United States |
| OpenAI, LLC | AI-generated summaries and language features | United States |
| Turbopuffer, Inc. | Search indexing of session titles, summaries, and transcript text | United States |
| Recall.ai | Meeting bot infrastructure and calendar synchronization | United States |
| Trigger.dev, Inc. | Background processing for the transcription and summarization pipeline | United States |
| Vercel Inc. | Web application and API hosting | United States |
| Twilio Inc. | Phone call recording infrastructure | United States |
| Telnyx LLC | Phone number provisioning, calling, and SMS delivery | United States |
For transparency, Wave also uses the following vendors to process Account Data (account, usage, billing, and support data), for which Wave acts as an independent Controller as described in Section 2 and the Privacy Policy:
| Vendor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing for web subscriptions | United States |
| PostHog, Inc. | Product usage analytics | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States |
| Intercom, Inc. | Customer support messaging | United States |
| Peaberry Software, Inc. (Customer.io) | Product and lifecycle email | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Adapty Tech Inc. | In-app subscription management | United States |
Contact
Questions about this DPA, requests for a countersigned copy, and subprocessor notice subscriptions: privacy@wave.co.

Product
Social Media
Use Cases
Compare
All rights reserved
Made with love in New York City