Data Processing Agreement
Version 1.0 · Last updated: July 26, 2026
This agreement applies whenever you use Wolk CRM to hold information about other people — buyers, sellers, leads, or your own staff. For that data you are the controller and Wolk is your processor, and Article 28 of the GDPR requires the terms below to be in writing. It forms part of the Terms of Service and takes effect when you first store personal data in the CRM.
This agreement does not cover your own account data — your name, email, subscription and the walkthroughs you record. For that, Wolk is the controller and the Privacy Policy applies.
1. Parties and roles
The Controller is the agency, brokerage or individual professional holding the Wolk subscription. The Processor is Marco Carotenuto, an individual developer established in Italy, trading as Wolk, contactable at privacy@wolk.website.
Agents and staff you invite into your organisation are not separate controllers or processors. They act under your authority within the meaning of Article 29, and instructing them properly — including in writing, where required — is your responsibility, not ours.
2. Subject matter, duration, nature and purpose
Wolk processes personal data on your behalf solely to provide the CRM: storing and retrieving your records, matching buyer requests against properties, generating listing material, sending notifications you have enabled, and keeping the service running and secure. Processing lasts as long as your subscription, plus the deletion periods in section 10.
3. Categories of data subjects and personal data
Data subjects: your prospective and actual buyers and sellers, other leads and contacts you record, and the agents and staff in your organisation.
Personal data: names, email addresses, telephone numbers, the source of the lead, free-text notes, budget and search preferences, appointment and activity history, deal values, addresses and locations of properties, and the consent records you create — including scanned or photographed consent forms, which typically carry a handwritten signature.
Wolk is not designed for special categories of data under Article 9. Please do not put health information, or anything similarly sensitive, into the free-text notes field.
4. Processing on documented instructions
Wolk processes personal data only on your documented instructions, which consist of this agreement, the Terms of Service, and the actions you take in the app. Wolk will tell you if, in its opinion, an instruction infringes the GDPR or other applicable data protection law. Wolk does not sell your CRM data, does not use it for advertising, and does not use it to train AI models.
5. Confidentiality
Access to production data is limited to the developer operating the service, who is bound by a duty of confidentiality and accesses it only where necessary to maintain or support the service.
6. Security measures (Article 32)
The technical and organisational measures in force are set out in Annex II. In summary:
- All traffic is encrypted in transit over HTTPS; data at rest is encrypted by the hosting provider.
- Tenants are isolated in the database itself, by row-level security keyed on the organisation identifier, rather than by application code alone.
- Consent documents live in a private storage bucket, reachable only through short-lived signed links, with no client-side update or delete permission.
- Consent records are append-only: they cannot be edited or silently removed, so the evidence of a consent survives a later change of mind.
- Authentication, password handling and session management are provided by Supabase; server-side keys are never shipped to a client.
- Walkthrough audio is transcribed on the device and never uploaded.
7. Subprocessors
You give a general written authorisation for Wolk to engage subprocessors. The current list, with the role and location of each, is published at wolk.website/subprocessors. Wolk imposes data protection obligations on each subprocessor no less protective than those in this agreement, and remains fully liable to you for their performance.
Wolk gives at least 30 days’ notice before adding or replacing a subprocessor. If you object on reasonable data protection grounds, you may terminate before the change takes effect, with a refund of the unused portion of the current term.
8. Assisting with data subject rights
Wolk provides the tools for you to answer requests yourself, without waiting on us:
- Access and portability (Articles 15 and 20). Every contact has an Export data action that downloads a structured, machine-readable JSON file containing the contact record, its consent history, search requests, activities, deals and linked properties.
- Erasure (Article 17). Every contact has a Delete permanently action that removes the record, its consent history and the attached consent documents from storage. It is irreversible.
- Rectification (Article 16). Contact records are editable at any time.
- Withdrawal of consent (Article 7(3)). Recording a withdrawal is as easy as recording the consent, and both are kept.
Where a request cannot be satisfied with these tools, Wolk will assist you by appropriate technical and organisational measures, taking into account the nature of the processing.
9. Breach notification and assistance (Articles 32–36)
Wolk will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, providing the information you need for your own notification to the supervisory authority. Wolk will also give you reasonable assistance with data protection impact assessments and prior consultations, taking into account the information available to it.
10. Return and deletion
You can export your data at any time while the subscription is live. Deleting your account removes your records and the associated files from storage. Where you were the only member of your organisation, the organisation and everything keyed to it is deleted as well. Encrypted backups held by the hosting provider roll off on their own schedule and are deleted within 30 days.
11. Audit
Wolk will make available the information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Given the size of the operation, this normally takes the form of written answers and documentation; on-site inspections require reasonable notice and may be charged at cost.
12. International transfers
Wolk’s infrastructure is hosted with Supabase on Amazon Web Services in the US West (N. California) region, and several subprocessors are established in the United States. Personal data is therefore transferred outside the European Economic Area. Those transfers rely on the European Commission’s Standard Contractual Clauses concluded with each provider, and, where the provider is certified, on the EU–U.S. Data Privacy Framework. The current provider list and the safeguard relied on for each is at wolk.website/subprocessors.
13. Version and acceptance
This is version 1.0, in force from July 26, 2026. Storing personal data in the CRM constitutes acceptance. If your organisation needs a countersigned copy for its own records, write to privacy@wolk.website and we will return a signed PDF. Material changes will be notified at least 30 days in advance.
Annex I — Details of processing
| Subject matter | Provision of the Wolk CRM service. |
|---|---|
| Duration | The term of the subscription, plus the deletion periods in section 10. |
| Nature and purpose | Storage, retrieval, organisation, matching, generation of listing material, notification, backup and deletion. |
| Types of personal data | As listed in section 3, including scanned consent forms bearing a signature. |
| Categories of data subjects | Buyers, sellers, leads and other contacts recorded by the controller; the controller’s agents and staff. |
| Special categories | None intended or expected. The service is not designed for Article 9 data. |
| Frequency | Continuous, for the duration of the subscription. |
Annex II — Technical and organisational measures
| Encryption | TLS for all traffic in transit; encryption at rest by the hosting provider. |
|---|---|
| Tenant isolation | Row-level security enforced in the database on every table holding customer data, keyed on the organisation identifier. |
| Access control | Two roles per organisation (admin, agent). Privileged operations are validated server-side against the database, never against a client-supplied claim. |
| File storage | Private buckets. Consent documents and property photos are reachable only through expiring signed URLs, scoped to the organisation. |
| Integrity of consent evidence | The consent register is append-only: no update or delete permission is granted to any client, and the current consent state is derived from it. |
| Data minimisation | Walkthrough audio is transcribed on the device and discarded; only the text is transmitted. |
| Departing staff | When a member deletes their account, their contacts, listings and appointments are reassigned to the organisation’s admin rather than deleted, so the controller keeps its records. Consent entries keep their date, method and document; only the “recorded by” attribution is cleared, because reassigning it would misstate who took the signature. |
| Calendar export (optional) | If an agent switches on calendar sync in the iOS app, appointment text and property addresses are written to a “Wolk” calendar on their device, and follow whatever account that calendar syncs with (typically iCloud). It is off by default and the agent is told what leaves before enabling it. Instruct your staff accordingly if you do not want this. |
| Deletion | Account and per-contact deletion remove both database records and the associated stored files. |
| Availability | Managed hosting with automated backups by the infrastructure provider. |