Data Processing Agreement (DPA)
This DPA is part of the subscription contract. Whalemate acts as processor of employee data that the customer (controller) uploads or syncs to operate the Human Risk Management program.
Last updated: 2026-08-28. Standard model. Requires legal review and signature in each customer contract.
Subject
Process name, work email, area, role, simulation results and training progress for the sole purpose of providing the contracted service: simulate, train, measure, report.
Instructions
Whalemate processes data only under the customer's documented instructions and this DPA. It does not use individual metrics for its own disciplinary purposes. It does not sell the data.
Security
Measures aligned to ISO/IEC 27001:2022, described in the Trust Center: encryption, access control, logging, regional residency when the contract provides for it.
Subprocessors
Infrastructure on AWS. Other subprocessors are notified at least 30 days in advance. The customer may object on reasonable data-protection grounds.
Data-subject rights and audit
Whalemate assists the customer in responding to rights requests. Retention and deletion: per Trust Center. The customer may audit with reasonable notice, or accept third-party reports (ISO certificate, pentest summary under NDA).
Contact
privacidad@whalemate.com · security@whalemate.com
What this DPA does not cover
It does not cover public-site leads (demo, contact, partnership, application): there Whalemate is controller and the privacy policy applies. It does not cover the conversation with the Fede assistant: that channel has its own terms. It does not authorize Whalemate to use individual employee metrics for disciplinary purposes. The customer, as controller, defines its own internal policy; Whalemate does not enforce it.
Incident and end of processing
A data incident is notified within the contract and applicable-law timelines, with the detail the Trust Center summarizes for the customer. When the service ends, deletion or return follows the contract: there is no “endless archive” of churned customer rosters except a legal duty. The vendor’s ISO/IEC 27001:2022 certificate does not replace the customer’s review of this DPA.
Governing law and transfers
The subscription contract’s law and forum govern this DPA, except data-protection rules that cannot be contracted away. If the customer is in a country with restricted international transfers, residency is agreed in the contract (AWS in the agreed region). Standard contractual clauses are signed when the customer asks under its framework (GDPR, LGPD or other): this HTML is not that annex. Whalemate does not claim SOC 2. ISO/IEC 27001:2022 covers the vendor’s operation; it does not certify the customer’s ISMS. The processor does not choose the controller’s legal basis: the customer documents why it processes its roster. Notices to privacidad@whalemate.com and security@whalemate.com do not replace the contractual incident channel when the contract defines one.