Legal

Data Processing Agreement

What we do with the data of the people who visit your portfolio, on whose instructions, with what safeguards, and what happens at the end. Compliant with Article 28 GDPR.

Last updated 13 September 2026

This English version is provided for your convenience. The French version is the legally binding text and prevails in case of any discrepancy. Read the French version

This agreement (the “Agreement”) forms an integral part of the oReel Terms of Service. It is entered into between the customer holding an account (the “Customer”) and Wedey OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia, registered under number 17153535 (the “Processor”). It applies from the creation of the account, without any additional signature. The French version prevails.

Definitions and roles

The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given to them by Regulation (EU) 2016/679 (“GDPR”).

Visitor Data
The personal data of people who interact with the Customer's portfolio, processed by the service on behalf of the Customer (see Annex 1).
Controller
The Customer, who decides to publish the contact, booking, newsletter and assistant features, and how the data received is used.
Processor
Wedey OÜ, which processes Visitor Data solely in order to provide the service.

The data of the Customer's own account (identity, billing) is not covered by this Agreement: for that data, Wedey OÜ is the controller, in accordance with the Privacy Policy.

Subject matter and duration

The Processor processes Visitor Data in order to host, display and operate the Customer's portfolio and its interactive features, for the entire duration of the Customer's use of the service, and then for the erasure period provided for in article 10. The nature and purpose of the processing, and the categories of data and of data subjects, are described in Annex 1.

Documented instructions

The Processor processes Visitor Data only on documented instructions from the Customer. These instructions consist of: this Agreement, the Terms of Service, and the settings the Customer makes in the service (features enabled, messages read, exported or deleted).

The Processor does not use Visitor Data for its own purposes, does not sell it, does not use it for advertising purposes and does not use it to train an artificial intelligence model. It informs the Customer if it considers that an instruction infringes the GDPR, or if Union or Member State law requires it to carry out processing, unless the law prohibits it from doing so.

Customer obligations

  • Have a legal basis for each processing operation it carries out through the service.
  • Inform Visitors of the processing of their data, in particular by means of a notice on its portfolio, and obtain their consent where the law requires it.
  • Not have the service collect special categories of data (health, opinions, etc.) without necessity and without a legal basis.
  • Respond to requests from Visitors exercising their rights.

Confidentiality

The Processor ensures that the persons authorised to process Visitor Data are bound by an obligation of confidentiality. Access is limited to those persons who need it to operate, secure or troubleshoot the service, and every administrative action is recorded in an audit log.

Security

The Processor implements the appropriate technical and organisational measures provided for in Article 32 GDPR, described in Annex 2. It may change them provided that the level of protection is not reduced.

Sub-processors

The Customer gives general authorisation for the use of the sub-processors listed in Annex 3. The Processor imposes on each of them, by contract, data protection obligations equivalent to those of this Agreement, and remains liable to the Customer for their performance.

The Processor informs the Customer of any addition or replacement at least 30 days before it takes effect, by updating this page and by e-mail. The Customer may object on reasonable grounds relating to data protection; failing agreement, the Customer may terminate the service free of charge, and the unused prepaid portion is refunded.

Assistance to the Customer

The Processor assists the Customer, through appropriate measures, in responding to requests from Visitors exercising their rights. The service allows the Customer to view, export and delete messages, appointment requests and subscribers themselves. If a Visitor contacts the Processor directly, the Processor forwards the request to the Customer without responding to it on the merits.

The Processor also assists the Customer, taking into account the information available to it, in complying with its obligations relating to security, breach notification, data protection impact assessment and prior consultation (Articles 32 to 36 GDPR).

Personal data breach

The Processor notifies the Customer of any personal data breach affecting Visitor Data without undue delay and no later than 48 hours after becoming aware of it, at the account's e-mail address. The notification describes, as far as possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The information may be provided in phases.

End of processing

Throughout the duration of the service, the Customer can export its data in JSON format from Settings > Danger zone. Upon deletion of the account, the Processor erases Visitor Data within 30 days, including backup copies (backups are kept for 14 days and a deleted file is removed from the copy within 30 days), unless a legal retention obligation applies.

Documentation and audit

The Processor makes available to the Customer the information necessary to demonstrate compliance with this Agreement, in particular by answering a reasonable security questionnaire in writing once a year. If this information is not sufficient, the Customer may have an audit carried out by an independent auditor bound by confidentiality, once a year, with 30 days' notice, at its own expense and without disrupting the service or compromising other customers' data.

Transfers outside the European Union

The application is hosted in France and the database in the European Union. Where a sub-processor processes data outside the European Economic Area, the transfer is governed by an adequacy decision or by the standard contractual clauses adopted by the European Commission, which the Customer authorises by this Agreement.

Liability and order of precedence

Each party's liability under this Agreement is governed by the Terms of Service, without prejudice to Articles 82 and 83 GDPR. In the event of a conflict concerning data protection, this Agreement prevails over the Terms of Service.

Governing law

This Agreement is governed by Estonian law. Disputes fall within the jurisdiction of the Harju County Court (Harju Maakohus, Tallinn, Estonia). For any question: [email protected].

Annex 1 — Description of the processing

Data subjects
Visitors to the Customer's portfolio: prospects, clients, correspondents, subscribers to its newsletter, people who book an appointment or chat with its assistant.
Categories of data
Name, e-mail address, subject and content of messages; date, slot and note of an appointment request; e-mail address and confirmation status of a subscriber; text of the questions asked to the assistant and of its answers (without IP address); visit statistics aggregated by country, page and source (without IP address).
Nature and purpose
Collection through the portfolio forms, storage, display to the Customer, sending of notifications and confirmations by e-mail, sending of the newsletter at the Customer's request, generation of the assistant's answers, calculation of statistics.
Duration
For as long as the Customer keeps the data in the service; erasure within 30 days after deletion of the account.

Annex 2 — Security measures

  • TLS encryption of all communications; encryption at rest of the database by the provider.
  • Per-customer isolation at database level (enforced Row Level Security) and column privileges on public data.
  • Application hosted on a dedicated server (Contabo GmbH, Lauterbourg, France); no administration port exposed.
  • Restricted administrative access, verified on every request, and an audit log of every action.
  • Request rate limiting and bot verification on public forms; escaping of all content submitted by a visitor.
  • No IP address stored for visit statistics or for assistant conversations.
  • Daily backup of data and files, kept for 14 days, with automatic restore verification.
  • External availability monitoring and alerting of the operations team.

Annex 3 — Sub-processors

  • Supabase — authentication, database and file storage. Place of processing: European Union (eu-central-1).
  • Stripe — payment, subscription and tax processing. Place of processing: Ireland and United States (standard contractual clauses).
  • Brevo — sending transactional e-mails. Place of processing: France — French company, data in the European Union.
  • DeepSeek — artificial intelligence features (bio writing, visitor chatbot, CV extraction); requests are not used to train models. Place of processing: outside the European Union (standard contractual clauses).
  • Contabo GmbH — hosting of the application on a dedicated server. Place of processing: Lauterbourg, France.
  • Cloudflare — content delivery network, attack protection and bot verification (Turnstile); sees the IP address of every request. Place of processing: global network, US company (standard contractual clauses).
  • Upstash — request rate limiting against abuse; keeps the IP address or account identifier for a few minutes. Place of processing: Frankfurt, Germany (EU region).
  • Sentry — collection of technical errors for diagnosis. Place of processing: European Union (EU region).
  • PostHog — product analytics, session recording and browser error tracking. Place of processing: European Union (EU region).