Company Registration Details
- Legal name: WawaCloud Inc.
- Operating brand: WawaNode
- Corporation number: 1796675-0
- Business number (BN): 712062637RC0001
- Date of incorporation: May 26, 2026
- Governing legislation: Canada Business Corporations Act (CBCA), federal corporation
- Registered office: 366 Coachwhip Trail, Newmarket, ON L3X 2R2, Canada
- Website: https://wawanode.com
WawaCloud Inc. is the legal contracting party for the Services; WawaNode is its operating brand. The registered office is the corporation's legal address, not a customer-support channel.
Effective date: March 19, 2026
Company name: WawaCloud Inc. (operating as "WawaNode", "we", "us")
WawaCloud Inc. is a corporation incorporated under the Canada Business Corporations Act (CBCA), a Canadian federal corporation, with its registered office located in the Province of Ontario, Canada. WawaNode is the operating brand of WawaCloud Inc.; WawaCloud Inc. is the legal contracting party that provides the service.
Website: https://wawanode.com
To contact us, please open a support ticket via Dashboard → Tickets (https://wawanode.com/dashboard/tickets/new), or use one of the following email addresses:
- Customer support: support@wawanode.com
- Abuse reports: abuse@wawanode.com
- Legal matters: legal@wawanode.com
- Privacy matters: privacy@wawanode.com
- DMCA / copyright complaints: dmca@wawanode.com
1. Overview
This Data Processing Agreement (the "Agreement" or "DPA") applies where WawaCloud Inc. (operating as "WawaNode", "we", or "us") processes personal data on behalf of the customer in the course of providing cloud servers, VPS, dedicated servers, networking, storage, IP addresses, control panels, technical support, and other related services through the WawaNode platform.
This Agreement forms part of the Terms of Service, the Privacy Policy, the Acceptable Use Policy, and other applicable service terms.
Where you use our services to process personal data and applicable data protection law requires a data processing agreement, this Agreement governs the relevant data processing activities between you and us.
2. Roles of the Parties
In most cases:
- The customer determines the purposes and means of processing the personal data it uploads, stores, transmits, hosts, or processes through the services;
- The customer acts as the controller of such personal data;
- WawaCloud provides infrastructure, hosting, network, storage, and technical support services through the WawaNode platform solely in accordance with the customer's instructions;
- WawaCloud acts as the processor or service provider within that scope.
With respect to information we collect and process on our own behalf for account registration, billing, payments, risk control, security, customer service, abuse handling, legal compliance, and business operations, we generally act as an independent controller and process such information in accordance with our Privacy Policy.
3. Definitions
Unless otherwise defined in this Agreement, the following terms have the meanings set out below:
- "Personal data" means information relating to an identified or identifiable natural person;
- "Customer data" means data uploaded, stored, transmitted, hosted, or processed by the customer or its end users through the services;
- "Processing" means collecting, recording, organizing, storing, accessing, using, transmitting, deleting, or otherwise operating on personal data;
- "Controller" means the party that determines the purposes and means of processing personal data;
- "Processor" means the party that processes personal data on behalf of a controller;
- "Sub-processor" means a third party engaged by a processor to assist in processing personal data;
- "Applicable data protection law" means the privacy and data protection laws applicable to the relevant processing activities, including, where applicable, Canadian federal and provincial privacy laws (such as PIPEDA), the GDPR, the UK GDPR, U.S. state privacy laws, and other relevant laws.
4. Subject Matter and Duration of Processing
The subject matter of the processing under this Agreement is: WawaCloud's provision of cloud servers, VPS, dedicated servers, network connectivity, IP addresses, storage, control panels, technical support, and other related services to the customer through the WawaNode platform.
The duration of processing is: the period during which the customer uses the relevant services, together with a reasonable period following termination of the services as required for deletion, export, backup retention, dispute handling, legal compliance, security, and abuse handling.
After the services are terminated, cancelled, or expire, we may delete customer data in accordance with the Terms of Service, the Privacy Policy, the Refund Policy, and the relevant product rules.
5. Nature and Purpose of Processing
The nature and purposes for which we process customer data include:
- Providing infrastructure and hosting services;
- Storing and transmitting customer data;
- Allocating servers, IP addresses, bandwidth, and network resources;
- Maintaining service stability and security;
- Providing technical support requested by the customer;
- Troubleshooting faults;
- Operating backup, snapshot, or image features, where applicable;
- Detecting, preventing, and handling security incidents;
- Handling abuse complaints;
- Complying with laws, court orders, regulatory requirements, or law-enforcement requests;
- Enforcing the Terms of Service and related policies;
- Protecting the legitimate interests of us, customers, suppliers, end users, and third parties.
6. Types of Personal Data
The customer may process the following types of personal data through the services, depending on the customer's own business:
- Names;
- Email addresses;
- Phone numbers;
- IP addresses;
- Account identifiers;
- Usernames;
- Address information;
- Device information;
- Log information;
- Transaction or order information;
- Communication content;
- Website visit data;
- User profiles within the customer's business systems;
- Other personal data the customer chooses to upload or process.
We do not actively decide which personal data the customer processes through its servers. The customer is responsible for confirming the types of data it processes and its legal basis for doing so.
7. Categories of Data Subjects
The customer may process the personal data of the following categories of data subjects through the services:
- The customer's users;
- The customer's website visitors;
- The customer's employees;
- The customer's contractors;
- The customer's suppliers;
- The customer's business contacts;
- The customer's end users;
- Other natural persons connected with the customer's business.
8. Customer Obligations
The customer is solely responsible for:
- Confirming that it has a legal basis for processing personal data;
- Providing data subjects with the necessary privacy notices;
- Obtaining any necessary consent or authorization;
- Ensuring that its use of the services to process personal data complies with applicable law;
- Ensuring that the data it uploads, stores, transmits, and processes is lawful;
- Reasonably configuring servers, applications, databases, access controls, and security measures;
- Promptly patching vulnerabilities and handling security incidents;
- Responding to data subject rights requests;
- Reasonably managing backups and data deletion;
- Avoiding the processing of unlawful, excessive, or unnecessary personal data through the services;
- Not processing data through the services that is prohibited by law or that it is not authorized to process.
The customer may not require us to carry out data processing activities that violate applicable law.
9. WawaCloud's Processing Obligations
Within the scope of this Agreement, we will:
- Process customer data only in accordance with the customer's documented instructions;
- Process customer data for the purposes of providing the services, technical support, security protection, and compliance;
- Implement reasonable technical and organizational measures to protect customer data;
- Restrict access to customer data by employees, contractors, and service providers;
- Require persons authorized to access customer data to be bound by confidentiality obligations;
- Assist the customer, to a reasonable extent, in meeting its obligations under applicable data protection law;
- Assist with data subject requests where required by applicable law;
- Delete or return customer data after termination of the services in accordance with the relevant terms;
- Manage sub-processors in accordance with this Agreement;
- Notify the customer of a personal data security incident in accordance with this Agreement.
10. Customer Instructions
The customer issues processing instructions to us by:
- Using the services;
- Configuring servers or the control panel;
- Uploading, storing, or deleting data;
- Submitting support tickets;
- Using the API;
- Purchasing, cancelling, or changing services;
- Making other requests in accordance with the Terms of Service and related policies.
If we believe that a customer instruction may violate applicable data protection law, we may notify the customer and may suspend execution of the relevant instruction until both parties confirm a lawful method of processing.
11. Confidentiality
We will take reasonable measures to ensure that persons authorized to access customer data access it only to the extent necessary to perform their job duties and are subject to appropriate confidentiality obligations.
We will not access the content of a customer's servers except as necessary to provide the services, technical support, security protection, abuse handling, legal compliance, or other purposes permitted by this Agreement.
12. Security Measures
We will implement reasonable technical and organizational measures to protect customer data, including but not limited to:
- Access controls;
- Permission management;
- Network security measures;
- Encrypted transmission, where applicable;
- System monitoring;
- Logging;
- Security alerting;
- Anti-abuse and risk-control mechanisms;
- Restrictions on employee access;
- Incident response procedures;
- Data center and infrastructure security measures;
- Vendor management measures.
The customer understands that internet services and server hosting cannot guarantee absolute security. The customer is responsible for implementing adequate security measures for its own operating systems, applications, databases, accounts, keys, code, and business data.
13. Customer Security Responsibilities
The customer is solely responsible for the security configuration of its use of the services, including but not limited to:
- Server operating system security;
- Application security;
- Database security;
- Account and password security;
- SSH key and API key security;
- Firewall and access control;
- Encryption configuration;
- Data backup;
- Vulnerability patching;
- Malware removal;
- End-user permission management;
- Log auditing;
- Reasonable data minimization and retention policies.
The customer bears sole responsibility for security incidents, data loss, or compliance issues resulting from the customer's misconfiguration, unpatched vulnerabilities, compromised accounts, application defects, operational errors, or failure to back up data.
14. Sub-processors
The customer agrees that we may engage sub-processors to assist in providing the services.
Sub-processors may include:
- Data centers;
- Upstream network providers;
- IP resource providers;
- Cloud infrastructure providers;
- Storage and backup providers;
- Payment processors;
- Anti-fraud and risk-control providers;
- Identity verification providers;
- Ticketing and customer service system providers;
- Email service providers;
- Security monitoring and logging providers;
- Legal, accounting, audit, and compliance providers;
- Other providers necessary to deliver the services.
We will require sub-processors to process personal data only to the extent necessary to provide the relevant services and to undertake appropriate confidentiality and security obligations.
15. Changes to Sub-processors
We may add, replace, or stop using sub-processors as required for business, technical, vendor, data center, network, or compliance reasons.
We may notify customers of material changes to sub-processors through website announcements, Privacy Policy updates, support tickets, email, or other reasonable means.
If a customer reasonably objects to a change of sub-processor, it should contact us within a reasonable period after receiving notice or after the change is published. If the parties cannot reach a resolution, the customer may stop using the affected services and cancel the services in accordance with the applicable terms.
16. International Data Transfers
WawaCloud operates an international hosting business through the WawaNode platform. Customer data and related personal data may be transferred to, stored in, or processed in multiple countries or regions.
Where applicable data protection law requires a cross-border transfer mechanism, the parties will adopt appropriate measures in accordance with applicable law, such as standard contractual clauses, supplementary safeguards, or other lawful transfer mechanisms.
The customer understands that the data center region, server region, end-user access locations, technical support requests, and upstream service arrangements selected by the customer may result in cross-border data transfers.
17. Data Subject Requests
If we receive a data subject request relating to customer data, we will generally advise the requester to contact the customer directly.
To the extent permitted by law, we may reasonably assist the customer in handling data subject requests, including access, rectification, erasure, restriction of processing, objection to processing, or data portability requests.
Where a request requires technical assistance, manual operations, data export, recovery, or complex handling, we may address it separately based on the scope of services, the workload involved, and applicable fees.
18. Deletion and Return of Customer Data
After the services are terminated, cancelled, expired, or deleted, we may delete customer data in accordance with the Terms of Service, the Privacy Policy, the Refund Policy, and the relevant product rules.
During the service term, the customer can generally export, delete, or migrate customer data itself through its servers, the control panel, backup tools, or other features.
Unless otherwise required by applicable law or otherwise agreed in writing by the parties, we have no obligation to retain, return, or restore customer data for an extended period after termination of the services.
We may retain certain records or backup data to the extent required for legal, compliance, accounting, security, abuse handling, dispute handling, backup cycle, or technical limitation reasons.
19. Personal Data Security Incidents
If we confirm a personal data security incident relating to customer data and applicable law requires us to notify the customer, we will notify the customer within a reasonable time.
The notice may include:
- The nature of the incident;
- The affected services;
- The types of data known or likely to be affected;
- The measures we have taken or plan to take;
- Recommended measures the customer may take;
- Available contact information.
The customer understands that an initial notice may be based on the information available at the time and may be updated as the investigation progresses.
20. Exclusions from Security Incidents
The following generally do not constitute a personal data security incident caused by us:
- Disclosure of the customer's account password;
- Disclosure of the customer's SSH keys;
- Disclosure of the customer's API keys;
- Vulnerabilities in the customer's applications;
- Misconfiguration of the customer's database;
- Misconfiguration of the customer's firewall;
- Compromise of the customer's server;
- Operational errors by the customer's end users;
- The customer's failure to patch vulnerabilities in a timely manner;
- The customer's failure to encrypt sensitive data;
- The customer's own public disclosure or erroneous sharing of data;
- Disclosure caused by the customer's use of third-party software or plugins;
- Problems arising from the customer's failure to follow security best practices.
The customer is responsible for assessing whether it needs to notify its data subjects, regulators, or other relevant parties.
21. Audits and Compliance Information
To the extent required by applicable data protection law, we may provide the customer with reasonably necessary information to demonstrate our compliance with our processor obligations under this Agreement.
When a customer makes an audit request, it must provide reasonable advance notice and state the scope, purpose, and legal basis of the audit.
An audit must not:
- Compromise the security of our services;
- Compromise the privacy or security of other customers;
- Require access to third-party confidential information;
- Require access to other customers' data;
- Impose an unreasonable burden on our business;
- Violate legal, contractual, or security requirements.
We may satisfy audit requests through security descriptions, policy documents, questionnaire responses, compliance materials, or other reasonable means. On-site audits or complex audits may require a separate written agreement and fee arrangement.
22. Records of Processing
To the extent required by applicable law, we will retain the necessary records of data processing, including records relating to services, accounts, billing, technical support, security incidents, abuse handling, and legal compliance.
The customer is responsible for maintaining the records of data processing it requires as a controller.
23. Special Categories of Data
Unless otherwise agreed in writing by the parties, the customer should not process highly sensitive or specially protected data through our services, including but not limited to:
- Large-scale health data;
- Biometric data;
- Precise geolocation data;
- Sensitive data about children;
- Political opinions;
- Religious beliefs;
- Racial or ethnic information;
- Trade union information;
- Criminal records;
- Other sensitive information specially protected by law.
If the customer chooses to process such data, the customer is responsible for ensuring that it has an adequate legal basis, risk assessment, security measures, and compliance mechanisms.
24. Regulated Industries
If the customer operates in finance, healthcare, education, government, defense, telecommunications, payments, insurance, or another regulated industry, the customer is responsible for confirming whether our services meet its industry's regulatory requirements.
Unless otherwise agreed in writing by the parties, our standard services are not specifically designed to meet HIPAA, PCI DSS, FedRAMP, GLBA, or other specific industry compliance requirements.
The customer may not use our services for specially regulated data processing scenarios without first confirming the applicable compliance requirements.
25. Data Minimization
The customer must comply with the principle of data minimization and process through the services only the personal data necessary for its business purposes.
The customer must avoid uploading, storing, or processing personal data that is unnecessary, excessive, unlawful, or beyond the scope of its purposes.
The customer must set reasonable data retention periods and delete or anonymize the relevant data when it is no longer needed.
26. Backups
Unless the customer has purchased a service that expressly includes backup or managed backup, we are not responsible for backing up customer data.
Even where a product offers snapshot, image, or backup features, this does not mean that a backup will necessarily be successful, complete, real-time, or recoverable.
The customer is responsible for maintaining independent, complete, and recoverable backups of its data.
27. Government and Legal Requests
If we receive a court order, subpoena, law-enforcement request, regulatory requirement, or other legal request relating to customer data, we may handle it in accordance with applicable law.
Where permitted by law, we may notify the customer of the relevant request. However, where prohibited by law, or in emergencies, or where confidentiality requirements or security risks exist, we may be unable to notify the customer.
We may disclose relevant information to the extent necessary to comply with legal requirements, protect legitimate interests, or handle security and abuse matters.
28. Customer End Users
The customer is responsible for the processing of its end users' personal data.
The customer must ensure that its end users are aware of and consent to the relevant data processing activities, or that the customer has another legal basis for processing.
If the customer resells, allocates, leases, or otherwise provides the services to third parties, the customer remains responsible for ensuring that end users comply with applicable data protection law, this Agreement, the Terms of Service, and related policies.
29. Limitation of Liability
Any limitation of liability under this Agreement is subject to the limitation of liability provisions in the Terms of Service.
To the maximum extent permitted by law, we are not liable for any indirect, special, incidental, consequential, or punitive damages, including but not limited to loss of profits, loss of revenue, loss of data, business interruption, loss of goodwill, or third-party claims.
30. Term of the Agreement
This Agreement takes effect when the customer uses the relevant services and processes personal data, and remains in effect for as long as we process personal data on behalf of the customer.
After termination of the services, the provisions of this Agreement that by their nature should survive will continue in effect, including those relating to confidentiality, data deletion, limitation of liability, legal requests, dispute handling, and compliance records.
31. Conflicting Terms
If this Agreement conflicts with the Terms of Service, the Privacy Policy, or other service terms, the more specific data processing provisions of this Agreement prevail with respect to matters concerning the processing of personal data.
For matters such as service purchases, payment, refunds, SLA, abuse, content liability, suspension, and termination, the corresponding service terms and policies continue to govern (including the Payment and Billing Policy, the Refund Policy, the SLA, the Abuse Complaints Policy, and the Technical Support Policy).
32. Governing Law and Dispute Resolution
This Agreement is governed by and construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to its conflict-of-laws rules.
Any dispute, controversy, or claim arising out of or in connection with this Agreement shall be submitted to the exclusive jurisdiction of the courts located in Ontario, Canada, and the parties irrevocably submit to the jurisdiction of those courts to the extent permitted by law.
33. Changes to This Policy
We may update this Agreement from time to time to reflect changes in legal, technical, business, vendor, data center, product, or compliance requirements.
The updated Agreement will be published on our website with a new effective date. Your continued use of the services after the Agreement is updated constitutes acceptance of the updated Agreement.
Where applicable law requires separate execution or additional confirmation, we may require the customer to confirm this Agreement through electronic signature, a support ticket, email, or other means.
34. Contact Information
If you have any questions about this Data Processing Agreement, the processing of personal data, privacy requests, or compliance matters, please contact us as follows:
WawaCloud Inc. (operating as "WawaNode")
Registered office: Province of Ontario, Canada
Website: https://wawanode.com
Please contact us first by opening a support ticket via Dashboard → Tickets (https://wawanode.com/dashboard/tickets/new), or use one of the following email addresses:
- Customer support: support@wawanode.com
- Abuse reports: abuse@wawanode.com
- Legal matters: legal@wawanode.com
- Privacy matters: privacy@wawanode.com
- DMCA / copyright complaints: dmca@wawanode.com
WawaCloud does not publish a telephone number; all contact should be made through the ticket system or the role email addresses above.
35. Note on Language Versions
This English version is provided for the convenience of our customers. Where any inconsistency or conflict exists between this English version and the Simplified Chinese version, the English version prevails, unless applicable law mandates otherwise.