WiloSync · Operated by Willow Team LLC
Data Processing & Subprocessors
Last updated: June 27, 2026
1. Overview and roles
These Data Processing terms describe how Willow Team LLC ("WiloSync," "we," "us") processes the data you submit or connect when you use the WiloSync application and automations (the "Services"), and they supplement our App Terms of Service and Privacy Policy. They apply to "Customer Data" — the personal data and other content that you provide, connect, or generate through your workflows.
For Customer Data, you act as the controller (or business) and we act as your processor (or service provider): we process Customer Data only on your documented instructions and only to provide, secure, support, and improve the Services, except where the law requires otherwise. You are responsible for having a lawful basis to collect and process Customer Data and for providing any required notices and obtaining any required consents from the individuals it concerns.
2. Scope of processing
The subject matter of processing is the operation of the Services you configure. The duration is the term of your use of the Services plus any retention period described in our Privacy Policy. The nature and purpose are to host, transmit, transform, and act on Customer Data as needed to run your automations and integrations. The types of data and categories of individuals depend on what you choose to process — typically business contacts, leads, and the records you route through your workflows. You agree not to submit special-category, health, full financial-account, or government-ID data except as expressly permitted under our App Terms of Service.
3. Subprocessors
We use a limited set of trusted third-party providers ("subprocessors") to host and operate the Services. We require subprocessors to protect data consistent with these terms, and we remain responsible for their performance of the tasks we delegate. Our current subprocessors include:
- Vercel — hosting and delivery of the WiloSync website and application (United States).
- Supabase — managed PostgreSQL database hosting and authentication storage (United States).
- Hostinger — infrastructure hosting for our workflow-execution engine (n8n) (United States / EU).
- Anthropic — AI processing for features and workflows that use AI (United States).
- Resend — delivery of transactional and notification emails (United States).
- Google (Analytics) — aggregate website analytics, used only where you accept analytics cookies (United States).
- Payment processor — when paid plans are offered, a PCI-compliant processor will handle payments; we do not store full card numbers.
4. Changes to subprocessors
We may add or replace subprocessors as the Services evolve. We will update the list above with a new date when we make material changes. If you have signed a separate agreement that entitles you to advance notice of new subprocessors, that agreement governs.
5. Services you connect
Separately from our subprocessors, you may connect your own third-party accounts and tools to the Services (for example, email, calendars, spreadsheets, CRMs, messaging, or accounting tools). Those providers are not our subprocessors — they act on your direction. Your use of them is governed by their own terms and privacy policies, and you are responsible for the data you send to and receive from them. We are not responsible for their availability, security, or actions.
6. Security measures
We maintain reasonable administrative, technical, and organizational measures designed to protect Customer Data, including access controls and authentication, encryption of data in transit, encryption at rest (AES-256) for connected-account credentials, segregation of customer credentials, and least-privilege access for our personnel. No method of transmission or storage is completely secure, and you are responsible for configuring secure access to the accounts and integrations you connect and for safeguarding your own credentials.
7. Assisting with individual rights and obligations
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from individuals to exercise their rights (such as access, correction, or deletion) and to meet your security, breach-notification, and impact-assessment obligations, to the extent you cannot reasonably do so yourself through the Services. If we receive a request directly from one of your individuals, we will, where appropriate, direct them to you.
8. Security incident notification
If we become aware of a confirmed breach of security leading to the unauthorized access, disclosure, alteration, or loss of Customer Data, we will notify you without undue delay using the contact information associated with your account, and will provide the information reasonably available to help you meet your own notification obligations.
9. Return and deletion of data
On termination of the Services, and where practical, we will make Customer Data available for export for a reasonable period, after which we may delete it in accordance with our Privacy Policy and our standard retention and deletion practices, unless retention is required by law.
10. International transfers
We and our subprocessors primarily process Customer Data in the United States. Where we transfer personal data from the EEA, the UK, or Switzerland, we rely on appropriate safeguards (such as Standard Contractual Clauses) where required by applicable law.
11. Contact
For data-processing questions, or to request a signed data processing addendum where one is available, contact us at info@wilosync.com.