Data Processing Addendum

Last updated and effective: August 31, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Mohrer Associates LLC, doing business as Wave ("Wave," "we," "us"), and the customer identified in that agreement ("Customer," "you") governing your use of Wave's applications, website, and related services (the "Services") — normally our Terms of Service (the "Agreement"). If the parties have executed a separate data processing agreement covering the same processing, that executed agreement controls and this DPA does not apply.

This DPA applies automatically, without any signature required, whenever Customer uses the Services in the course of business — for example as a company, a Wave for Teams workspace, or an individual professional — and Wave processes Personal Data on Customer's behalf. It reflects the parties' agreement on the processing of Personal Data under the GDPR, UK GDPR, Swiss FADP, CCPA, and similar data protection laws ("Data Protection Laws").

If you need a countersigned copy of this DPA for your records or vendor-management process, email privacy@wave.co with your company name and the email address on your Wave account, and we will return an executed copy.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person. "Customer Content" means the content Customer submits to or generates with the Services — audio recordings, transcripts, summaries, notes, messages, calendar data, and the Personal Data of Customer's meeting participants and correspondents contained in them. "Account Data" means Personal Data Wave collects and uses for its own purposes — Customer's registration, billing, support, and product usage data. "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in the GDPR. "Subprocessor" means a third party engaged by Wave to process Customer Content on Wave's behalf.

2. Roles and Scope

This DPA covers Customer Content. As between the parties, Customer is the Controller (or, where Customer acts on behalf of its own customers, a Processor) of Customer Content, and Wave is a Processor (or Subprocessor, as applicable). For Account Data, Wave is an independent Controller (and a "business" under the CCPA) and processes it as described in our Privacy Policy — for example to operate accounts, bill, provide support, secure the Services, and improve the product. Each party will comply with the Data Protection Laws that apply to it. Customer is responsible for the lawfulness of the Personal Data it submits to the Services — including obtaining any consent required to record conversations and providing any notices required to Data Subjects. The subject matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.

3. Processing on Instructions

Wave will process Customer Content only on Customer's documented instructions — which consist of the Agreement, this DPA, and Customer's use and configuration of the Services — including with regard to transfers of Personal Data to a third country or an international organization, unless required to do otherwise by applicable law, in which case Wave will inform Customer of that legal requirement before processing (unless the law prohibits doing so on important grounds of public interest). Wave will immediately inform Customer if, in Wave's opinion, an instruction infringes Data Protection Laws. Wave does not use Customer Content to train generalized AI or machine-learning models, and does not authorize its Subprocessors to do so.

4. Confidentiality

Wave ensures that all personnel authorized to process Customer Content are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and access Customer Content only as needed to provide the Services.

5. Security

Wave implements and maintains appropriate technical and organizational measures to protect Customer Content against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures are described in Annex 2. Wave may update them from time to time, provided the updates do not materially reduce the overall level of protection.

6. Subprocessors

Customer provides general written authorization for Wave to engage the Subprocessors listed in Annex 3. Wave will engage each Subprocessor under a written agreement imposing data protection obligations that are no less protective than those in this DPA and that provide sufficient guarantees to implement appropriate technical and organizational measures, and Wave remains fully liable to Customer for each Subprocessor's performance.

Wave will give at least 30 days' advance notice before adding or replacing a Subprocessor, by updating Annex 3 on this page and by email to customers who have subscribed to change notices (send a request to privacy@wave.co with the subject "Subprocessor updates"). Customer may object on reasonable data protection grounds within that notice period; Wave will not process the objecting Customer's Content with the new Subprocessor while the objection is unresolved. If the parties cannot resolve the objection within 30 days of it being raised, Customer may terminate the affected Services and receive a pro-rata refund of any prepaid, unused fees.

7. Data Subject Requests

Taking into account the nature of the processing, Wave will assist Customer through appropriate technical and organizational measures — including the in-product export, correction, and deletion tools — in fulfilling Customer's obligation to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, and objection). If a Data Subject contacts Wave directly about Personal Data processed on Customer's behalf, Wave will promptly forward the request to Customer and will not respond substantively except as required by law.

8. Assistance

Taking into account the nature of processing and the information available to Wave, Wave will provide reasonable assistance to Customer with its obligations under Articles 32 to 36 of the GDPR — security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.

9. Personal Data Breach

Wave will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Content. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Wave will provide timely updates as further information becomes available and will reasonably cooperate with Customer's own notification obligations. Wave's notification of a breach is not an acknowledgement of fault or liability.

10. Deletion and Return

Customer can export and delete Customer Content at any time through the Services; deletion takes effect in Wave's systems when performed, and Wave does not retain deleted Customer Content in backup archives. At Customer's choice following termination or expiration of the Agreement, Wave will return all Customer Content in a commonly used, machine-readable format or delete it, and in either case delete existing copies within 30 days, unless applicable law requires continued storage — in which case Wave will protect the retained data under this DPA and process it only for the purpose the law requires. Upon request, Wave will confirm deletion in writing.

11. Audits and Reports

Wave will make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. The parties agree that these obligations are ordinarily satisfied by: Wave's SOC 2 Type 1 report (download), the documentation in Wave's Trust Center, and written responses to reasonable security questionnaires. The independent report addresses Wave's system description and the suitability of the design of controls relevant to the Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time.

Where those materials are not sufficient to demonstrate compliance, Customer (or an independent auditor bound by confidentiality) may audit Wave's compliance with this DPA on at least 30 days' written notice, during normal business hours, at Customer's expense, no more than once per 12-month period, and in a manner that does not access other customers' data or unreasonably disrupt Wave's operations — except that the frequency and notice limits do not apply where an audit is required by a supervisory authority or follows a Personal Data Breach or material noncompliance with this DPA.

12. International Transfers

Wave processes Customer Content in the United States. Where the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to Wave requires a lawful transfer mechanism, the parties enter into the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) ("SCCs"), which are incorporated into this DPA by reference and completed as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is a Processor.
  • Clause 7 (docking clause) is included. In Clause 9, Option 2 (general written authorization) applies with the notice period in Section 6 of this DPA. In Clause 11, the optional independent-dispute-resolution language does not apply.
  • In Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland. In Clause 18, disputes will be resolved before the courts of Ireland.
  • Annex I.A: the data exporter is Customer (contact details as provided in Customer's Wave account; activities: use of the Services described in the Agreement; role: controller, or processor where Module Three applies). The data importer is Mohrer Associates LLC d/b/a Wave, New York, New York, United States, privacy@wave.co (activities: providing the Services; role: processor). By entering into the Agreement, each party is deemed to have signed the SCCs, including their Annexes, as of the Agreement's effective date.
  • Annex I.B is completed with Annex 1 of this DPA; Annex II with Annex 2 of this DPA; Annex III with Annex 3 of this DPA (Customer Content Subprocessors).
  • Annex I.C / Clause 13: the competent supervisory authority is the supervisory authority of the EEA member state in which the data exporter is established, or — where the exporter is not established in the EEA — the supervisory authority of the member state in which the exporter's EU representative is based or in which the relevant Data Subjects are located.
  • For transfers from the United Kingdom, the SCCs apply as amended by the UK International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner's Office, which is incorporated by reference. Table 1 is completed with the parties' details above and the date of the Agreement; Table 2 with the SCCs as completed above; Table 3 with Annexes 1, 2, and 3 of this DPA; and in Table 4, either party may end the Addendum as set out in its Section 19. The Addendum's Part 2 Mandatory Clauses apply as published by the ICO.
  • For transfers from Switzerland governed by the Swiss FADP (and not the GDPR), references in the SCCs to the GDPR are read as references to the FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and Data Subjects habitually resident in Switzerland may enforce their rights and bring claims in Switzerland under Clause 18(c). Where a transfer is subject to both the GDPR and the FADP, the SCCs as completed above apply unchanged for GDPR purposes, supplemented by the foregoing for FADP purposes, and the term "personal data" is read to include data relating to legal entities to the extent the FADP protects them.

If the SCCs conflict with this DPA or the Agreement, the SCCs control to the extent of the conflict. Nothing in the Agreement or this DPA limits the rights of Data Subjects, or either party's liability to Data Subjects, under the SCCs.

13. CCPA Service Provider Terms

Where the California Consumer Privacy Act, as amended ("CCPA"), applies to Customer Content, Wave acts as Customer's "service provider" and processes Customer Content for the limited and specific business purposes described in Annex 1 — providing, securing, and supporting the recording, transcription, summarization, search, synchronization, and communications features of the Services. Wave will: (a) not sell or share Customer Content; (b) not retain, use, or disclose it for any purpose other than those business purposes, or as otherwise permitted by the CCPA; (c) not retain, use, or disclose it outside the direct business relationship between the parties; (d) not combine it with personal information Wave receives from other sources, except as permitted by the CCPA; (e) provide the same level of privacy protection as the CCPA requires of Customer; (f) ensure that any subcontractor processing Customer Content is bound by a written contract meeting CCPA service-provider requirements; and (g) assist Customer in responding to consumer requests, including through the tools described in Section 7. Wave will notify Customer if it determines it can no longer meet its obligations under the CCPA, and Customer may take reasonable and appropriate steps — including under Section 11 — to verify compliant use and to stop and remediate any unauthorized use of Customer Content. Wave certifies that it understands and will comply with these restrictions.

14. Sensitive Data

The Services are not designed for regulated health information. Wave is not a HIPAA business associate and does not sign Business Associate Agreements; Customer must not use the Services to process protected health information subject to HIPAA. Because Customer controls what is discussed in recorded conversations, sensitive Personal Data may appear incidentally in recordings and transcripts; Annex 1 describes the categories reasonably foreseeable in conversational content and the restrictions applied to them.

15. Liability, Precedence, Term, and Changes

Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement, except for liability that cannot be limited under applicable law and the Data Subject rights described in Section 12. This DPA takes precedence over the Agreement to the extent of any conflict concerning the processing of Personal Data, and the SCCs take precedence over this DPA as described in Section 12. This DPA takes effect when the Agreement takes effect (or, for existing customers, on the date above) and remains in force as long as Wave processes Customer Content. We may update this DPA from time to time as Data Protection Laws evolve; updates will not reduce the level of protection for Customer Content, will not modify the SCCs except as required or permitted by the issuing authority, and material changes will be announced on this page with a new effective date and by email to subscribed customers before they take effect.

Annex 1 — Details of Processing

  • Subject matter and duration: the provision of the Services under the Agreement, for the duration of the Agreement plus the deletion period in Section 10.
  • Nature and purpose: recording, storage, transcription, summarization, search, synchronization, and related AI-powered features for meetings, calls, and voice notes; where enabled, calendar synchronization, meeting bots, and phone calling and text messaging; and the security, support, and billing processing needed to provide those features.
  • Categories of Data Subjects: Customer's authorized users; participants in meetings, calls, and conversations that Customer records; persons Customer communicates with using Wave phone numbers; and persons referenced in Customer Content.
  • Types of Personal Data: names, email addresses, and account identifiers; audio recordings and voice data; transcripts, summaries, notes, and action items; speaker names and labels; calendar and meeting metadata (titles, times, attendees, conferencing links); phone numbers, call and message content, and communications metadata; billing and subscription records; and usage data.
  • Sensitive data: the Services do not require sensitive data, but conversational content controlled by Customer may incidentally include special categories of Personal Data — for example information revealing health, political opinions, religious beliefs, trade union membership, or sexual orientation. Wave applies the restrictions in Annex 2 to all Customer Content regardless of category: strict purpose limitation, need-to-know access with logging, encryption, deletion controls, and the flow-down of these obligations to Subprocessors. Voice audio is processed to provide transcription and speaker labeling, not to uniquely identify individuals for Wave's own purposes.
  • Frequency: continuous, for as long as Customer uses the Services.

Annex 2 — Technical and Organizational Measures

  • Encryption: Customer Content is encrypted in transit (TLS 1.2+) and at rest (AES-256) in Wave's primary storage systems, with encryption keys managed by Wave's cloud providers' key-management services.
  • Infrastructure: primary hosting on Google Cloud, under Google's physical, network, and operational security controls; limited processing by the Subprocessors in Annex 3 under their own audited controls.
  • Access control: access to production systems and Customer Content is restricted to authorized personnel on a need-to-know, least-privilege basis, protected by strong authentication including multi-factor authentication, with audit logging on sensitive actions. Wave personnel do not access customer recordings except in narrow, audit-logged cases: support with the customer's consent, investigating abuse or a security incident, or where required by law.
  • Independent examination: Wave completed a SOC 2 Type 1 examination covering the Security trust services criteria, and its compliance posture is continuously monitored through its compliance platform, with current status published in Wave's Trust Center.
  • Vulnerability management: security monitoring and alerting, dependency and infrastructure patching, and a coordinated disclosure channel at security@wave.co.
  • Incident response: a defined process for detecting, escalating, containing, and remediating security incidents, including the customer notification commitments in Section 9.
  • Data separation and deletion: logical separation of customer data; deletion tooling that removes Customer Content from Wave's systems when deleted — Wave does not retain deleted content in backup archives.
  • Secure development: code review for production changes and separation of production and development environments.
  • Personnel: confidentiality obligations for all personnel and security training appropriate to their roles.
  • Business continuity: infrastructure redundancy and durability provided by Wave's cloud providers.
  • Assistance: the export, correction, and deletion tooling described in Sections 7 and 10, available to support Data Subject requests.

Annex 3 — Subprocessors and Vendors

Wave uses the following Customer Content Subprocessors to provide the Services. These vendors may process Customer Content (recordings, transcripts, summaries, messages, calendar data) and are the Subprocessors authorized under Section 6 and listed in SCC Annex III:

VendorPurposeLocation
Google LLC (Google Cloud / Firebase)Cloud infrastructure, storage, databases, and authenticationUnited States
AssemblyAI, Inc.Speech-to-text transcription of audio recordingsUnited States
OpenAI, LLCAI-generated summaries and language featuresUnited States
Turbopuffer, Inc.Search indexing of session titles, summaries, and transcript textUnited States
Recall.aiMeeting bot infrastructure and calendar synchronizationUnited States
Trigger.dev, Inc.Background processing for the transcription and summarization pipelineUnited States
Vercel Inc.Web application and API hostingUnited States
Twilio Inc.Phone call recording infrastructureUnited States
Telnyx LLCPhone number provisioning, calling, and SMS deliveryUnited States

For transparency, Wave also uses the following vendors to process Account Data (account, usage, billing, and support data), for which Wave acts as an independent Controller as described in Section 2 and the Privacy Policy:

VendorPurposeLocation
Stripe, Inc.Payment processing for web subscriptionsUnited States
PostHog, Inc.Product usage analyticsUnited States
Functional Software, Inc. (Sentry)Application error monitoringUnited States
Intercom, Inc.Customer support messagingUnited States
Peaberry Software, Inc. (Customer.io)Product and lifecycle emailUnited States
Resend, Inc.Transactional email deliveryUnited States
Adapty Tech Inc.In-app subscription managementUnited States

Contact

Questions about this DPA, requests for a countersigned copy, and subprocessor notice subscriptions: privacy@wave.co.

Wave app screenshot showing meeting transcription
Wave AI note taker background pattern
Start today

Wave. Catch every word