Wraps Logo

Data Processing Agreement

Last Updated: August 28, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between FlatironKids LLC ("Wraps", "we", "us") and the customer agreeing to those terms ("Customer", "you"). It governs our processing of Personal Data on your behalf.

These are our standard terms and they apply automatically — you do not need to sign anything to rely on them. If your procurement process requires a countersigned copy, or your own paper, email privacy@wraps.dev.

1. Definitions

"Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Applicable Data Protection Law" means the GDPR, the UK GDPR, the Swiss FADP, and the California Consumer Privacy Act as amended by the CPRA, in each case to the extent it applies to the Processing.

"Customer Personal Data" means Personal Data that Wraps Processes on your behalf in providing the Services.

2. Roles of the parties

You are the Controller of Customer Personal Data. Wraps is the Processor, and Processes Customer Personal Data only on your documented instructions. Your use of the Services, including configuration you perform in the dashboard, CLI, or API, constitutes those instructions.

Wraps is an independent Controller for a limited set of data it determines the purposes of: account and billing records, anonymous CLI telemetry, and website analytics. That Processing is described in the Privacy Policy and is outside the scope of this DPA.

2.1 The sending path is not within scope

Wraps deploys infrastructure into your AWS account. The emails you send, their content, their recipients, and the raw delivery events they generate are Processed by Amazon Web Services within your own AWS account, under your own agreement with AWS. For that Processing, AWS is your Processor and Wraps is not in the chain at all. This DPA covers only Customer Personal Data that reaches the Wraps platform layer.

3. Scope of processing

ItemDetail
Subject matterProvision of the Wraps email and messaging platform, as described in the Terms of Service
DurationThe term of your subscription, plus the deletion period in section 9
Nature and purposeStoring and organising contacts and audiences; rendering and storing templates; executing workflows and broadcasts; recording a send ledger; producing delivery and engagement analytics
Categories of Data SubjectYour end users and email recipients; your own personnel who hold Wraps accounts
Categories of Personal DataEmail addresses; contact attributes you choose to store; consent and suppression state; message-level send history; engagement metadata (open and click events, including the user agent AWS attaches to them); account names and email addresses
Special category dataNot contemplated. Do not submit special category data, or protected health information, to the Services

4. Wraps obligations

Wraps will:

  • Process Customer Personal Data only on your documented instructions, including regarding international transfers, unless required to do otherwise by law — in which case we will inform you first, unless that law prohibits it
  • Ensure that personnel authorised to Process Customer Personal Data are bound by an obligation of confidentiality
  • Implement the technical and organisational measures described in section 5
  • Respect the conditions in section 6 for engaging another Processor
  • Assist you, insofar as reasonably possible, in responding to Data Subject requests under Chapter III of the GDPR
  • Assist you with data protection impact assessments and prior consultations, taking into account the nature of Processing and the information available to us
  • Delete or return Customer Personal Data as described in section 9
  • Make available the information necessary to demonstrate compliance with this DPA, as described in section 8

Wraps does not sell or share Personal Data as those terms are defined under the CCPA/CPRA, does not retain, use, or disclose Customer Personal Data for any purpose other than performing the Services, and does not combine Customer Personal Data with data from other customers or other sources.

5. Security measures

Wraps maintains technical and organisational measures appropriate to the risk, including:

  • Encryption in transit. HTTPS/TLS on all external connections
  • No stored cloud credentials. Access to your AWS account is via a cross-account IAM role you create, restricted by an sts:ExternalId condition and exercised only through short-lived STS credentials. We never store your AWS access keys
  • Least privilege. The role's data-plane permissions are scoped by ARN to resources Wraps deployed
  • Tenant isolation. Platform data is scoped by organization at the query layer, enforced in code and verified by automated tests
  • Access control. Production access is limited to personnel who require it. The Services support SSO and SCIM provisioning
  • Auditability. The Wraps codebase, including every IAM policy it generates, is published under AGPLv3 and can be reviewed by you

A fuller description is at /security, which also states plainly which certifications Wraps does and does not currently hold.

6. Subprocessors

You give general authorisation for Wraps to engage Subprocessors. The current list is published at /subprocessors and forms part of this DPA.

Before engaging a new Subprocessor that Processes Customer Personal Data, Wraps will update that page and give at least 30 days' notice by email to customers who have subscribed to subprocessor notices. You may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.

Wraps imposes data protection obligations on each Subprocessor no less protective than those in this DPA, and remains fully liable to you for a Subprocessor's performance.

7. International transfers

Wraps and all of its Subprocessors Process Customer Personal Data in the United States. Where Customer Personal Data originating in the EEA, the United Kingdom, or Switzerland is transferred to Wraps, the transfer is made pursuant to the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), which are incorporated into this DPA by reference and completed as follows:

  • Clause 7 (docking): applies
  • Clause 9 (subprocessors): Option 2, general written authorisation, with the 30-day notice period in section 6
  • Clause 11 (redress): the optional independent dispute resolution paragraph does not apply
  • Clause 17 (governing law): the law of Ireland
  • Clause 18 (forum): the courts of Ireland
  • Annexes I, II and III: populated by sections 3, 5 and 6 of this DPA respectively

For UK transfers, the International Data Transfer Addendum issued by the ICO applies to the Standard Contractual Clauses above. For Swiss transfers, references to the GDPR are read as references to the FADP and the competent authority is the FDPIC.

8. Audits

Wraps will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a reasonable security questionnaire no more than once in any twelve month period.

Wraps does not currently hold a SOC 2 or ISO 27001 report. In place of an audit report, the entire Wraps codebase — including the IAM policies it generates and the telemetry it collects — is published under AGPLv3 and may be inspected by you or your auditors at any time without notice to us.

Where Applicable Data Protection Law grants you an on-site audit right that the above does not satisfy, we will cooperate in good faith to agree a scope, on reasonable notice, at your cost, and no more than once a year absent a Personal Data Breach.

9. Deletion and return

You may export or delete Customer Personal Data at any time through the Services. On termination, Wraps will delete Customer Personal Data from the platform database within 30 days, except where retention is required by law.

Infrastructure and data in your own AWS account — including SES configuration, DynamoDB event history, and any archived messages — are unaffected by termination and remain entirely yours. Wraps has no ability to delete them once the cross-account role is removed.

Backups are retained on our providers' standard cycles and expire on their own; Customer Personal Data in a backup remains subject to this DPA until it does.

10. Personal data breach

Wraps will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate volume of data and Data Subjects concerned, the likely consequences, and the measures taken or proposed — to the extent known at the time, with further detail provided as it becomes available.

Notification is not an acknowledgement of fault or liability.

11. Data subject requests

The Services let you access, correct, export, and delete contact records directly. Where you cannot fulfil a Data Subject request yourself, email privacy@wraps.dev and we will assist within a reasonable period.

If a Data Subject contacts Wraps directly regarding data we Process on your behalf, we will refer them to you and will not respond substantively unless you instruct us to or the law requires it.

12. Order of precedence

In the event of a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service, in each case only as to the subject matter of Processing Personal Data.

13. Changes

We may update this DPA to reflect changes in law, the Services, or our Subprocessors. Material changes that reduce your protections will be notified by email at least 30 days in advance. The current version always lives at this URL.

Contact

FlatironKids LLC, Colorado, United States.
Data protection enquiries: privacy@wraps.dev
Security enquiries: security@wraps.dev
Legal: legal@wraps.dev