← Back to Waypath

Compliance

Our commitments to data protection regulations and industry standards.

Waypath is built to help businesses understand their customer engagement data. We recognize that this responsibility comes with strict obligations around data protection, privacy, and regulatory compliance. This page outlines our current compliance posture and ongoing commitments.

1. GDPR Readiness

COMPLIANT

Waypath is designed to comply with the General Data Protection Regulation (EU) 2016/679. Our GDPR commitments include:

1.1 Lawful Basis for Processing

1.2 Data Subject Rights

We support all data subject rights under GDPR:

Requests are processed within 30 days. Contact compliance@waypath.app to exercise any right.

1.3 Data Protection by Design

2. CCPA Compliance

COMPLIANT

For California residents, Waypath complies with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

3. Data Processing Agreements

We provide Data Processing Agreements (DPAs) to customers who require them for GDPR compliance or other regulatory purposes. Our standard DPA includes:

To request a DPA, contact compliance@waypath.app.

4. Data Residency

Waypath offers data residency options to meet your regulatory requirements:

Region Location Status
United States US East (Virginia) AVAILABLE
European Union EU West (Frankfurt) AVAILABLE

Data residency selection is configured at the workspace level. Once set, all workspace data (graph store, CRM records, integration credentials) is stored and processed exclusively within the selected region. Contact us to discuss additional regions.

5. Subprocessors

Waypath uses the following subprocessors to deliver the Service. We notify customers of subprocessor changes at least 30 days in advance.

Subprocessor Purpose Location
Composio OAuth connection management and third-party integration authentication United States
Vercel Application hosting, CDN, and edge deployment Global (edge network)
Supabase (planned) User authentication and account metadata storage US / EU (configurable)

We evaluate all subprocessors for security practices, data protection policies, and compliance certifications before engagement. Each subprocessor is bound by a data processing agreement.

6. Certifications and Standards

SOC 2 Type II

IN PROGRESS

We are actively pursuing SOC 2 Type II certification covering the Security, Availability, and Confidentiality Trust Services Criteria. Our controls are designed and operating to meet these standards. Contact us for a current progress update or to review our security controls documentation.

Security Controls Summary

For more details, see our Security page.

7. Right to Audit

Enterprise customers with a signed DPA have the right to audit Waypath's data processing practices. We support audits through:

To request an audit or security review, contact compliance@waypath.app.

8. Data Retention and Deletion

9. Regulatory Updates

We actively monitor regulatory developments affecting data protection and privacy, including:

This page is updated as our compliance posture evolves. Last updated: March 27, 2026.

10. Contact

For compliance inquiries, DPA requests, or audit coordination:

Compliance team: compliance@waypath.app
Security team: security@waypath.app
General support: support@waypath.app
Website: waypath.app