
Between: WISHGATE LTD, a company incorporated in Bulgaria (UIC 208871609), registered office ul. Stefan Peshev 76, fl. 1, 5400 Sevlievo, Gabrovo Province, Bulgaria ("Processor")
And: Organization using the Wishgate platform ("Controller")
Effective date: July 1, 2026
Contact: legal@wishgate.io
This Data Processing Addendum ("DPA") applies when Wishgate processes personal data on behalf of organizations (Studios and Creators) registered on the platform. It supplements the Terms of Service and governs the data protection obligations between the parties.
Each organization registered on Wishgate acts as a Data Controller for personal data it collects from its own partners, team members, and the personal data it inputs about its business activities on the platform.
Wishgate acts as a Data Processor when it stores and processes personal data on behalf of organization accounts, including:
Wishgate also acts as an independent Data Controller for account registration data, platform analytics, payment data, and platform security purposes.
Wishgate processes personal data on behalf of Controllers only to:
Processing outside this scope requires additional written agreement.
Wishgate uses the following sub-processors when processing Controller data:
| Sub-processor | Country | Processing Purpose |
|---|---|---|
| Microsoft Azure / Azure SQL | EU — Sweden Central (EEA) | Application and database hosting |
| Resend (Resend, Inc.) | USA (SCCs / EU-US Data Privacy Framework) | Transactional and digest email delivery |
We will notify Controllers of material changes to sub-processors with 14 days' notice.
Where Wishgate receives a data subject request (access, erasure, portability) relating to data processed on behalf of an organization:
Wishgate implements technical and organizational measures proportionate to the risk, including:
Controllers may request, no more than once per year, a summary report of Wishgate's data protection practices. More detailed audits may be arranged with reasonable notice at the Controller's cost.
Wishgate will notify affected Controllers of any personal data breach without undue delay and within 72 hours of becoming aware, where the breach is likely to result in risk to natural persons.
Upon termination of an organization account:
This DPA is governed by the same jurisdiction as the Terms of Service. Where GDPR applies, this DPA is interpreted in accordance with GDPR requirements.