Data Processing Addendum
Version 1.0. Effective date: August 24, 2026.
This Data Processing Addendum (“DPA”) is between SeedProd, LLC (“WPVibe”, “we”, “us”) and the customer that uses the WPVibe service (“Customer”, “you”).
WPVibe is operated by:
SeedProd, LLC
400 Executive Center Drive
West Palm Beach, FL 33401
United States
[email protected]
This DPA forms part of the WPVibe Terms of Service (the “Terms”). If you use WPVibe, this DPA applies. If you need a countersigned copy, email [email protected] with your company legal name and the name and title of the person signing.
If there is a conflict between this DPA and the Terms on the processing of Customer Personal Data, this DPA controls. The EU Standard Contractual Clauses and the UK Addendum (where they apply) control over this DPA on international transfers.
1. Scope
1.1 This DPA applies where WPVibe processes Customer Personal Data as a processor (or sub-processor) on your behalf to provide the Service, and that data is subject to European Data Protection Laws.
1.2 This DPA does not apply to Account Data. WPVibe is the controller of Account Data (your email, plan, billing identifiers, sign-in records, and support correspondence about your WPVibe account). Account Data is described in the Privacy Policy.
1.3 WPVibe does not run the large language model. Your AI client (Claude, ChatGPT, Cursor, or another MCP-compatible client) receives tool outputs under your agreement with that vendor. That vendor is not WPVibe’s sub-processor for model generation.
2. Definitions
Account Data means personal data relating to Customer’s WPVibe account, including email address, plan, Stripe customer and subscription identifiers, sign-in and session records, and support correspondence about the account.
Applicable Data Protection Laws means the laws that apply to the processing of Customer Personal Data under the Terms, including European Data Protection Laws and, where they apply, United States state privacy laws.
Customer Personal Data means personal data that WPVibe processes on Customer’s behalf in providing the Service. It includes personal data in or about connected WordPress sites that passes through the WPVibe relay when you (or your AI client on your behalf) request a tool action. It does not include Account Data.
European Data Protection Laws means the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection, in each case as applicable.
EU GDPR means Regulation (EU) 2016/679.
EU SCCs means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Restricted Transfer means a transfer of Customer Personal Data to a country that is not covered by an adequacy decision under the EU GDPR or, for UK GDPR, adequacy regulations under section 17A of the Data Protection Act 2018.
Service means the WPVibe hosted relay, MCP server, related websites, and the WPVibe WordPress plugin, as described in the Terms.
UK Addendum means the International Data Transfer Addendum issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018 (version B1.0, as updated).
UK GDPR means the EU GDPR as it forms part of UK law.
The terms controller, processor, sub-processor, data subject, personal data, personal data breach, processing, and supervisory authority have the meanings in European Data Protection Laws. “Sub-processor” here means a processor engaged by WPVibe to process Customer Personal Data.
3. Roles
3.1 For Customer Personal Data, you are the controller (or a processor acting for your own customer), and WPVibe is the processor (or sub-processor).
3.2 If you are an agency or other processor (for example, you connect a client’s WordPress site), then:
- your client is typically the controller of that site’s personal data;
- you are the processor;
- WPVibe is your sub-processor.
You warrant that your instructions to WPVibe, including appointing WPVibe as a sub-processor, are authorised by the relevant controller.
3.3 WPVibe processes Customer Personal Data only to provide the Service you requested. We do not use Customer Personal Data to train WPVibe-owned AI models. We do not sell Customer Personal Data.
4. Instructions
4.1 You instruct WPVibe to process Customer Personal Data as needed to provide the Service. Documented instructions are: the Terms, this DPA, the configuration of your account and connected sites, and the tool requests you (or your AI client on your behalf) submit.
4.2 WPVibe will not process Customer Personal Data except on those instructions, unless required by applicable law. If law requires us to process it, we will tell you before processing unless the law prohibits that notice.
4.3 You are responsible for the lawfulness of Customer Personal Data, for your own privacy notices to data subjects, and for not asking WPVibe to process special-category or other sensitive data unless that is necessary for your task and lawful.
4.4 If WPVibe believes an instruction infringes European Data Protection Laws, we will tell you.
5. Confidentiality
WPVibe will ensure that people authorised to process Customer Personal Data are under a contractual or statutory duty of confidentiality.
6. Security
6.1 WPVibe will implement appropriate technical and organisational measures under Article 32 GDPR / UK GDPR, including the measures in Annex 3. We may update those measures if the overall security of the Service is not reduced.
6.2 You are responsible for the WordPress sites you connect, the permissions of the WordPress user you authorise, the AI client you use, and the prompts and tool requests you send.
7. Sub-processors
7.1 You give WPVibe general written authorisation to use the sub-processors in Annex 2, and to appoint new or replacement sub-processors on the terms in this section.
7.2 WPVibe will impose data-protection obligations on each sub-processor that are no less protective of Customer Personal Data than this DPA. WPVibe remains liable to you for the sub-processor’s performance of those obligations.
7.3 The current list is in Annex 2 and at https://wpvibe.ai/security/. WPVibe will post intended additions or replacements on that page at least 14 days before the new sub-processor starts processing Customer Personal Data, and will notify the email on your WPVibe account.
7.4 You may object on reasonable data-protection grounds by emailing [email protected] within 14 days of that notice. The parties will try to resolve the objection in good faith. If WPVibe needs the sub-processor and cannot reasonably satisfy the objection, you may terminate the affected Service before the sub-processor starts. If you do not object in time, you are taken to have accepted the change.
7.5 Stripe, SendLayer / Lindris, and Google Analytics process Account Data or marketing-site analytics. They are not sub-processors of Customer Personal Data under this DPA.
8. Data subject rights
Taking into account the nature of the processing, WPVibe will help you, by appropriate technical and organisational measures and insofar as possible, to respond to requests from data subjects to exercise their rights. If we receive a request that we can reasonably tie to you, we will notify you and will not respond except on your instructions or as required by law.
9. Assistance
Taking into account the nature of the processing and the information available to WPVibe, we will provide reasonable assistance with:
- security of processing;
- personal data breach notification to a supervisory authority and to data subjects;
- data protection impact assessments;
- prior consultation with a supervisory authority.
10. Personal data breach
If WPVibe confirms a personal data breach affecting Customer Personal Data under our control, we will notify you without undue delay, and where feasible within 72 hours of confirmation. Notice goes to the email on your WPVibe account unless law requires another channel. We will describe what we know and what we are doing, and will cooperate reasonably on investigation and mitigation.
11. Return and deletion
11.1 You can disconnect a site at any time. That stops further processing of that site’s Customer Personal Data through the Service, subject to residual logs described below. You can also revoke the WordPress Application Password in WordPress under Users, Profile, Application Passwords.
11.2 After the Service ends, or on your written request, WPVibe will delete Customer Personal Data in our possession, except:
- usage, authentication, error, and security logs, generally kept for up to 24 months;
- executed or declined approval records kept for security, audit, and support;
- billing and other records we must keep by law;
- copies in backups, which are put beyond use and deleted on the next backup cycle.
11.3 WordPress content, media, drafts, theme files, and backups on your (or your client’s) WordPress site are not in WPVibe’s possession. You delete those on the site or with the host.
11.4 You may ask us to return a copy of Customer Personal Data we still hold (connected-site records and available logs). We will do that in a reasonable machine-readable form.
12. Information and audits
12.1 WPVibe will make available information reasonably needed to demonstrate compliance with this DPA, including this DPA, the Security page, and the Privacy Policy.
12.2 WPVibe is not SOC 2 or ISO 27001 certified. The Service runs on infrastructure from providers that publish independent attestations (including Cloudflare). Those provider reports are about those providers, not a WPVibe company-level certification.
12.3 If the information in 12.1 is not enough to meet Article 28(3)(h), you may request a written questionnaire, no more than once in any 12-month period, unless a supervisory authority or a confirmed personal data breach requires more. On-site audit is available only if required by European Data Protection Laws and cannot reasonably be met another way. Audits are during business hours, on reasonable notice, under confidentiality, and without disrupting the Service. You pay your own costs. If an on-site audit finds no material breach of this DPA, you also pay WPVibe’s reasonable costs.
13. International transfers
13.1 You acknowledge that WPVibe and its sub-processors may process Customer Personal Data in the United States and other countries where they operate. WPVibe does not offer a UK-only or EU-only processing region.
13.2 Where a transfer of Customer Personal Data from you to WPVibe is a Restricted Transfer, the following apply:
(a) EU and EEA. The EU SCCs are incorporated and completed as follows:
- Module Two applies where you are a controller. Module Three applies where you are a processor.
- Clause 7 (docking) applies.
- Clause 9, Option 2 (general written authorisation) applies. The notice period is as in section 7.3 of this DPA.
- Clause 11 optional language does not apply.
- Clause 17, Option 1: the law of Ireland.
- Clause 18(b): the courts of Ireland.
- Annex I is Annex 1 of this DPA. Annex II is Annex 3 of this DPA. Annex III is Annex 2 of this DPA.
(b) United Kingdom. The EU SCCs, completed as above, apply as amended by the UK Addendum, which is incorporated. Tables 1 to 3 of the UK Addendum are completed with Annexes 1 to 3 of this DPA. Table 4: either party may end the UK Addendum as set out in its clause 19. For UK transfers, Clause 17 and 18 of the EU SCCs are read so that the governing law and courts are those of England and Wales.
(c) Switzerland. The EU SCCs apply as above, read to include Switzerland and the Swiss Federal Data Protection and Information Commissioner where required.
13.3 If an adequacy decision or other lawful transfer mechanism applies, WPVibe may rely on that instead of or in addition to the clauses above.
13.4 You agree that these completed clauses are your documented instruction to make those transfers in order to provide the Service.
14. California and similar US laws
Where WPVibe processes Customer Personal Data that is “personal information” under the CCPA/CPRA or a similar US state law, WPVibe acts as a service provider / processor. WPVibe will not sell or share that information, retain or use it for any purpose other than providing the Service or as permitted by those laws, or combine it with other personal information except as those laws allow for a service provider.
15. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms, except that nothing in this DPA limits liability that cannot be limited under Applicable Data Protection Laws.
16. Term
This DPA lasts for as long as WPVibe processes Customer Personal Data. Sections that by their nature should survive (including confidentiality, deletion, liability, and transfer clauses) survive.
17. Changes
WPVibe may update this DPA if the change is required by law or a supervisory authority, or if it does not reduce your protections in any material way. The effective date at the top will change. Material reductions of your rights will be notified to the email on your WPVibe account.
18. General
18.1 Notices under this DPA: [email protected], and to you at the email on your WPVibe account.
18.2 Except for the EU SCCs and UK Addendum (which have their own governing law and courts), this DPA is governed by the same law and courts as the Terms (Florida, United States).
18.3 This DPA may be executed electronically. Use of the Service is acceptance. A countersigned copy is available on request.
Annex 1. Description of processing
A. Parties
| Role | Details |
|---|---|
| Data exporter | Customer (controller, or processor for its own customer). Contact: the email on the WPVibe account. |
| Data importer | SeedProd, LLC, 400 Executive Center Drive, West Palm Beach, FL 33401, United States. Contact: [email protected]. Processor (or sub-processor). |
B. Processing
| Item | Description |
|---|---|
| Subject matter | Hosted relay between Customer’s AI client and WordPress sites Customer authorises. |
| Duration | For the term of the Service, then as in section 11. |
| Nature | Receive tool requests; authenticate the WPVibe account; apply plan limits and safety gates; send HTTPS requests to the authorised WordPress site; return tool results to the AI client; store connection records, encrypted credentials, approvals, and usage logs. |
| Purpose | Provide, secure, support, and bill for the Service. |
| Documented instructions | Terms, this DPA, account and site configuration, and tool requests. |
C. Categories of data subjects
Depending on what you ask the Service to do: Customer’s staff; authors, users, commenters, customers, and other people whose data is stored on a connected WordPress site.
D. Types of personal data
Depending on the tools you use and the WordPress permissions you grant, this may include:
- connected-site records: site URL, site name, WordPress username, connection status, timestamps;
- WordPress Application Passwords generated for WPVibe (encrypted at rest);
- WordPress content and metadata requested through tools (posts, pages, comments, media records, users, roles, settings, and similar);
- operational records: tool name, action detail, status, error type, duration, approval parameters and outcomes, session identifiers.
WPVibe does not require special-category data. You should not send it through the Service unless it is necessary and lawful.
E. Competent supervisory authority (EU SCCs)
Where the exporter is established in the UK, the competent supervisory authority is the UK Information Commissioner’s Office (ICO). Where the exporter is established in an EU Member State, the competent authority is the supervisory authority of that Member State. Where the exporter is a processor acting on behalf of a controller established in the EU/EEA, the competent authority is the lead supervisory authority of that controller. For all other EU/EEA transfers, the competent authority is the Irish Data Protection Commission (DPC).
Annex 2. Sub-processors of Customer Personal Data
Current list (also at https://wpvibe.ai/security/):
| Provider | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosted relay (Workers), databases and key-value storage (D1, KV), object storage where used, edge network, security, Analytics Engine, Browser Rendering when a tool needs it | United States and Cloudflare’s global edge |
| DigitalOcean, LLC | Egress forwarder for WordPress hosts that challenge or block Cloudflare-origin traffic | United States |
Feature-triggered
| Provider | Role | When used |
|---|---|---|
| Unsplash, Inc. (and similar media providers) | Image search queries, photo metadata, download tracking | Only if you use WPVibe image search |
Your AI provider is not a WPVibe sub-processor for model generation.
Annex 3. Technical and organisational measures
These match the public Security page. They may change as the product changes, provided overall security is not reduced.
Transport and storage
- HTTPS between the AI client, WPVibe, and the connected WordPress site.
- WordPress Application Passwords encrypted at rest with AES-GCM.
- WPVibe does not store the site’s normal WordPress login password.
- Credentials decrypted only as needed to call the site for a requested tool.
Access control
- Magic-link sign-in and session cookies. No WPVibe account password.
- Plugin runs as the WordPress user you authorised, and cannot exceed that user’s capabilities.
- Staff access to production systems is limited to people who need it to operate or support the Service.
Product safety (reduces unauthorised or destructive processing)
- Draft-first theme workflows, with preview and explicit publish.
- Approval gates and dry-run previews for destructive or high-risk operations.
- Approval log of gated operations.
- Trash rather than hard-delete for content where WordPress supports trash.
- WP-CLI commands emulated in PHP against an allowlist. No open shell. No arbitrary eval.
Logging and retention
- Usage and reliability logs: tool name, site URL, action detail, status, error type, duration, plan, client, session id. Not a full archive of edited pages.
- Pending approval links expire in about 10 minutes.
- Connected-site records and encrypted Application Passwords kept until disconnect, revocation, or account deletion, subject to section 11.
Breach
- Notification as in section 10.
Infrastructure
- Service hosted primarily on Cloudflare. Independent attestations published by those providers are theirs, not a WPVibe SOC 2 or ISO 27001 certification.
Signature (optional countersigned copy)
If you want a signed copy, complete this block and email it to [email protected]. Use of the Service is already acceptance of this DPA.
Customer
Legal name: ________________________________
Jurisdiction of incorporation: ________________________________
Address: ________________________________
Name: ________________________________
Title: ________________________________
Date: ________________________________
Signature: ________________________________
SeedProd, LLC (WPVibe)
Name: John Turner
Title: Founder
Date: ________________________________
Signature: ________________________________