Legal
Data Processing Addendum
Winch Labs FZ-LLC
Registered address: HD18B, First Floor, in5 Tech, Dubai Internet City, King Salman Bin Abdulaziz Al Saud Street, Al Sufouh 2, Dubai, United Arab Emirates.
Licensed by Dubai Development Authority.
Last updated: 3 October 2026 · v1.1. This DPA forms part of the agreement between the customer organisation ("Customer") and Winch Labs FZ-LLC ("Winchlabs") for the hosted Deltz service, and applies automatically wherever Winchlabs processes personal data within Customer Content on Customer's behalf. A countersigned copy is available on request via hello@winchlabs.io.
1. Roles, scope, duration
Customer is the controller (or a processor acting for its own controllers) and Winchlabs is the processor of personal data contained in Customer Content: repository content processed transiently for reviews and scans, and the derived governance records stored for Customer's organisation (findings with code excerpts, context documents, receipts, episodes, coverage records, audit entries naming Customer's users). Subject matter and duration follow the underlying agreement. Data subjects are typically Customer's personnel and any individuals identifiable in repository content; personal-data categories are those Customer chooses to place in its repositories and accounts — Deltz neither needs nor requests special categories.
2. Instructions
Winchlabs processes Customer Content only on Customer's documented instructions: the agreement, this DPA, and Customer's configuration of the service (connecting repositories, enabling features, setting policies and retention). Winchlabs will inform Customer if, in its opinion, an instruction infringes applicable data-protection law, and may process where required by law after notifying Customer unless the law forbids notice. Winchlabs does not train machine-learning models on Customer Content.
3. Confidentiality and security
Persons authorised to process Customer Content are bound by confidentiality. Winchlabs implements appropriate technical and organisational measures, including: encryption in transit (TLS) and at rest; hard multi-tenant isolation with organisation scoping enforced on every table and query; role-based access control; append-only, hash-chained and signed governance receipts; audit logging of administrative actions; transient-only handling of repository clones; and an architecture that never holds Customer cloud credentials or state files. The current description lives at /security and prevails as it evolves, provided protection is never materially reduced.
4. Subprocessors
Customer generally authorises the subprocessors listed in the Privacy Policy (Amazon Web Services — Frankfurt; Anthropic — only when Fix/Forge run on Winchlabs' keys; OpenRouter — episodic-recall embeddings; Cloudflare — website surfaces). Winchlabs will update that list at least 30 days before adding a subprocessor that processes Customer Content; Customer may object on reasonable data-protection grounds within that window, and if no resolution is found may terminate the affected service with a pro-rata refund of prepaid fees. Winchlabs binds each subprocessor to obligations no less protective than this DPA and remains liable for their performance. Customers who bring their own Anthropic key remove Anthropic from their processing chain entirely.
5. Assistance
Taking into account the nature of processing, Winchlabs will assist Customer with data-subject requests (access, deletion, and export are largely self-service: audit CSV export, evidence bundles, and the read-only API), with security and breach obligations, and with data-protection impact assessments and prior consultations, at Customer's reasonable request.
6. Personal-data breach
Winchlabs will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting Customer Content, with the information reasonably available to support Customer's own 72-hour obligations, supplemented as investigation proceeds.
7. Deletion and return
During the term, Customer controls its records (retention windows, disconnection, deletion). On termination, export tooling remains available for 30 days; Winchlabs then deletes Customer Content from live systems within 30 days, with short-lived backups aging out on their own schedule, except where law requires retention.
8. Audit
Winchlabs will make available the information reasonably necessary to demonstrate compliance with this DPA: the public security documentation, completed security questionnaires, and — Winchlabs holds no third-party certifications yet, and says so plainly — where Customer has a reasonable, evidenced concern, an audit on 30 days' notice, at Customer's cost, during business hours, no more than annually, under confidentiality, and without access to other customers' data.
9. International transfers
Customer Content is hosted in Frankfurt (eu-central-1). Where processing under this DPA involves a transfer from the EEA to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two or Three as applicable), with Customer as data exporter and Winchlabs as importer, the optional docking clause enabled, Clause 9 Option 2 with the 30-day period of §4, and the governing law and forum of §15 of the Terms for Clause 17/18 to the extent permitted; the UK International Data Transfer Addendum applies to UK transfers; and equivalent contractual safeguards apply to transfers restricted by the UAE PDPL. Winchlabs' onward transfers to subprocessors rest on those subprocessors' SCCs and data-protection terms.
10. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service or the parties' signed agreement. If this DPA conflicts with the Terms, this DPA prevails for personal-data processing; a signed enterprise DPA prevails over this one.