Requesting a Data Processing Addendum (DPA)
Last updated: September 10, 2026
Available on: Mac, Windows, iOS, Android
If your organization is subject to the EU or UK GDPR, you may need a Data Processing Addendum with Wispr before rolling out Wispr Flow. Our standard DPA covers every paying customer — including individual and team subscriptions — and you can execute it yourself through the Trust Center.
Note: No plan upgrade, annual contract, or separate MSA is required. The DPA applies to your account as it stands today.
How to get the DPA
Go to our Trust Center at trust.wispr.ai.
Sign in with your company email address. Personal domains (for example gmail.com or outlook.com) cannot sign in.
Accept the non-disclosure agreement (NDA) when prompted — legal and compliance documents are NDA-gated.
Download the DPA from the document list, alongside compliance materials such as the SOC 2 report.
Note: Use your work email even if your Wispr Flow account uses a personal address. The two do not need to match.
What the DPA includes
The EU Standard Contractual Clauses (SCCs) for transfers of personal data out of the EEA.
A UK Addendum for transfers subject to the UK GDPR.
Annex III, listing our current subprocessors. We give at least 10 days' prior written notice before adding a new subprocessor.
FAQs
Can support email us a copy of the DPA instead?
No. The DPA, SOC 2 report, and security questionnaire responses are distributed only through the Trust Center, behind the NDA.
Do you provide a Transfer Impact Assessment (TIA)?
No. Under the SCC framework, you carry out the TIA as the data controller. To support it, we provide the DPA (including the SCCs and Annex III), our SOC 2 report, and detailed security information through the Trust Center.
Where is our data processed?
All customer data is processed in the United States; we do not operate regional processing in the EEA or Asia-Pacific. Transfers out of the EEA are covered by the SCCs in the DPA.
Do we also need a signed MSA?
No. A signed MSA is typically part of an enterprise agreement, but the DPA stands on its own.
Still need help?
Contact support if:
Your company domain is rejected at Trust Center sign-in — include the domain you tried.
You need a compliance document that is not listed in the Trust Center.