← woople.ai

Version 1.0 (draft) · Effective date 31 July 2026 · Entity Woople, a product of Mooning Agency Pty Ltd (ABN 20 656 190 608) trading as woople · Contact hello@woople.ai

Data processing agreement

This is a working draft. Sections marked with a placeholder still need input from woople before this page is final. It is not legal advice.

This Data Processing Agreement (DPA) is incorporated by reference into the woople Terms of Service. By using the woople platform, the customer agrees to the terms of this DPA. In the event of any conflict between this DPA and the Terms of Service on matters of data protection, this DPA prevails.

1. Definitions

In this DPA the following words have the meanings set out below. Capitalised terms not defined here have the meaning given to them in the woople Terms of Service.

Applicable data protection law means each applicable privacy and data protection law in force in the relevant jurisdiction, including: the Privacy Act 1988 (Cth) and Australian Privacy Principles; the Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) of Hong Kong and its data protection principles; and any other applicable national, state, or territory privacy law.

Customer data means any personal data or personal information submitted to, uploaded to, or processed through the platform by or on behalf of the customer, including the content of any nominated website processed for the Brain and any publicly available third-party content collected on the customer's instruction through the platform's competitive or channel analysis features.

Data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, customer data.

Personal data and personal information have the meanings given to them under applicable data protection law in each relevant jurisdiction.

Sub-processor means a third-party service provider engaged by woople to process customer data in connection with delivering the platform.

Sub-processor list means the list of current sub-processors maintained by woople, available on request by contacting hello@woople.ai, as updated from time to time in accordance with section 6.

2. Roles and scope

2.1 The customer is the controller (or data user under the PDPO) of customer data. woople is the processor (or data processor under the PDPO) of customer data, processing it solely on the customer's documented instructions.

2.2 This DPA applies only to customer data. Account data collected by woople about the customer's own account holders and users is processed by woople as a controller and is governed by the woople Privacy Policy, not this DPA.

2.3 The customer's instructions to woople are set out in the Terms of Service and the applicable plan. Where the customer uses the platform's competitor analysis, channel watchlist, ads research (including the Meta Ad Library), or AI-visibility features, the customer's instruction includes woople collecting publicly available third-party content and, for AI-visibility checks, using the customer's brand name in prompts to third-party AI systems, in each case to inform the customer's generated content. The customer may issue additional written instructions to woople at hello@woople.ai. woople will notify the customer if it believes any instruction would cause woople to breach applicable data protection law.

3. Processing details

Subject matterBrand voice model building (the Brain), competitive and channel signal collection, and AI-powered content generation
DurationFor the term of the customer's subscription and the deletion period set out in section 8
Nature of processingCollection, storage, analysis, automated processing for brand voice modelling, competitive and channel signal analysis, content generation, and deletion
Purpose of processingProvision of the woople platform to the customer under the Terms of Service
Types of personal dataWebsite content (which may include names, contact details, and other personal data present on the customer's nominated website); publicly available third-party content collected for competitive, channel, or AI-visibility analysis on the customer's instruction; any other personal data the customer submits to the platform
Categories of data subjectsThe customer's website visitors, employees, contractors, and any other individuals whose personal data appears in content submitted to or referenced by the platform

4. woople's obligations as processor

woople will:

5. Security

woople will implement and maintain technical and organisational measures appropriate to the risk presented by the processing, to protect customer data against unauthorised or unlawful processing and against accidental loss, destruction, or damage.

Those measures include: encryption of data in transit (TLS) and at rest; role-based access controls with workspace and brand-scoped authorization; row-level tenancy isolation in the database; credential and secret management through environment configuration rather than in code; least-privilege access for staff; hosted infrastructure with managed backups (Supabase and Railway); and breach notification in accordance with section 7 of this DPA. woople will review and update these measures periodically.

The security measures in place at any time are available to the customer on written request to hello@woople.ai.

6. Sub-processors

6.1 Sub-processor list. woople maintains a current list of sub-processors, available on request. That list identifies each sub-processor's name, role, and location. The customer may request a copy of the sub-processor list at any time by contacting hello@woople.ai.

6.2 AI infrastructure providers. woople engages third-party AI infrastructure providers, including Anthropic, Google, OpenAI, and Perplexity, to power content generation, embeddings-based retrieval, image generation, and AI-visibility checks on the platform. woople takes reasonable steps to ensure that those providers do not use customer data to train their general-purpose models, and woople will only engage AI infrastructure providers whose contractual terms support this commitment. Perplexity's API terms apply zero data retention on the API, and API data is not used for model training.

6.3 Changes to sub-processors. woople will give the customer at least 30 days' prior written notice of any intended addition to or replacement of a sub-processor by updating the sub-processor list and notifying the customer by email. The customer may object on reasonable data protection grounds by notifying woople in writing at hello@woople.ai within that 30-day period. If the parties cannot resolve the objection, the customer may terminate the subscription without penalty before the change takes effect. If the customer does not object within the 30-day period, the customer is taken to have accepted the change.

6.4 Flow-down obligations. woople will impose data processing obligations on each sub-processor that are materially equivalent to those in this DPA. woople remains responsible to the customer for the performance of each sub-processor's obligations to the extent that woople is responsible for the relevant processing.

7. Data breach notification

woople will notify the customer without undue delay upon becoming aware of a data breach affecting customer data. The notification will include, to the extent known at the time:

Where information cannot all be provided at the time of initial notification, woople will provide it in phases as it becomes available. Notification to the customer does not constitute an acknowledgement of fault or liability.

The customer is responsible for complying with its own data breach notification obligations under applicable data protection law. woople will provide reasonable assistance to the customer in meeting those obligations.

8. Deletion and return of customer data

8.1 Export window. Following expiry or termination of the customer's subscription, woople will make customer data available for export for 30 days.

8.2 Deletion. After the export window closes, woople will delete customer data (including copies held by sub-processors) within 60 days, unless a longer retention period is required by applicable law.

8.3 Deletion confirmation. On the customer's written request, woople will provide written confirmation that deletion of customer data is complete.

8.4 Brand Brain. The customer's Brand Brain will be deleted within 90 days of the end of the subscription, as set out in the Terms of Service.

The export and deletion timelines above are not yet automated in the product. They are fulfilled manually today at current customer volume; the team owns executing them when a subscription ends.

9. Data subject rights

The customer is responsible for handling requests from individuals exercising their rights under applicable data protection law. Where a data subject makes a request directly to woople, woople will forward that request to the customer promptly. woople will assist the customer in responding to such requests to the extent technically feasible and within woople's control, on the customer's written instruction.

10. Data protection assessments

Where a processing activity is likely to result in a high risk to individuals under applicable data protection law, woople will assist the customer with any required data protection impact assessment to the extent the relevant information is within woople's control and not otherwise confidential.

11. Audits and compliance

The customer may request, no more than once per calendar year, information from woople reasonably necessary to demonstrate compliance with this DPA. woople will respond to such requests by providing written information about its security practices, policies, and controls within a reasonable time. Any request for an on-site audit or inspection must be made in writing, given with reasonable advance notice, and conducted at a time and in a manner agreed between the parties. The customer bears its own costs in connection with any audit. woople may decline to provide information that would compromise the security of its systems or the confidentiality of other customers' data.

12. Cross-border data transfers

12.1 Australian customers. woople complies with the cross-border disclosure requirements of Australian Privacy Principle 8, including taking reasonable steps to ensure overseas sub-processors handle customer data consistently with the Australian Privacy Principles.

12.2 Hong Kong customers. Section 33 of the PDPO, which would formally restrict cross-border data transfers, is not currently in force. In the meantime, woople takes steps consistent with the PCPD's 2022 guidance on recommended model contractual clauses to ensure that personal data transferred to overseas service providers is protected to a standard consistent with the PDPO. woople will update this clause when Section 33 comes into force.

AI inference processing for all named AI infrastructure providers occurs in the United States.

13. Governing law

This DPA is governed by the laws of Victoria, Australia, consistent with the governing law of the Terms of Service.


Draft for review. This document is a working draft for review and completion by Mooning Agency Pty Ltd and by qualified legal counsel. It is not legal advice. Laws change; confirm the current legal position before publishing. Placeholders shown in highlighted text must be resolved before use.