Data Processing Agreement
Data Processing Agreement
WellDatabase · ctrlDev, LLC d/b/a WellDatabase · Version 2026.10 · Last updated 12 August 2026
This Data Processing Agreement applies where WellDatabase processes personal data on a customer's behalf. It forms part of the WellDatabase Terms and Conditions and takes effect when a customer accepts an Order — no separate signature is required. It contains the terms required by Article 28 of the GDPR, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and the CCPA service provider terms. The current subprocessor list is maintained at welldatabase.com/subprocessors.
Contents
- 1. Scope, Parties and Incorporation
- 2. Definitions
- 3. Roles and Details of the Processing
- 4. Instructions
- 5. Confidentiality of Personnel
- 6. Security
- 7. Subprocessors
- 8. Assistance with Data Subject Rights
- 9. Personal Data Breach
- 10. Data Protection Impact Assessments
- 11. Return and Deletion
- 12. International Transfers
- 13. Government and Law Enforcement Requests
- 14. Audits and Demonstrating Compliance
- 15. CCPA Service Provider Terms
- 16. Liability
- 17. Term, Precedence and General
- Annex I — Description of the Processing
- Annex II — Technical and Organisational Measures
- Annex III — Subprocessors
- Signing a copy
1. Scope, Parties and Incorporation
1.1This Data Processing Agreement (this “DPA”) forms part of, and is incorporated into, the agreement between ctrlDev, LLC d/b/a WellDatabase, a Texas limited liability company with its principal place of business at 4 Waterway Square Place, Suite 477, The Woodlands, TX 77380, United States (“WellDatabase”), and the customer identified in the Order (“Customer”), consisting of the WellDatabase Terms and Conditions and that Order (together, the “Agreement”). Capitalised terms not defined here have the meanings given in the Agreement.
1.2This DPA applies only where and to the extent WellDatabase processes Personal Data on Customer's behalf in connection with the Services. It does not apply to the Content, which consists of oil and gas well, production, permit, completion and lease data compiled from public records and third-party sources and which WellDatabase processes as a controller of its own data and not on Customer's behalf.
1.3Customer accepts this DPA by accepting the Order in accordance with Section 18 of the Terms and Conditions. No separate signature is required. Where Customer's internal requirements call for a separately executed copy, the execution page at the end of this DPA may be used; executing it does not create obligations additional to those in this DPA.
1.4Where Customer is itself acting as a processor on behalf of a third-party controller, Customer warrants that it has the authority of that controller to enter into this DPA and to give the instructions it gives under it.
2. Definitions
- “Applicable Data Protection Laws” means all laws relating to the processing of Personal Data applicable to a party in connection with the Services, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”), and comparable U.S. state privacy laws.
- “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the GDPR. “Business”, “Service Provider”, “Sell”, “Share” and “Consumer” have the meanings given in the CCPA.
- “Personal Data” means Personal Data, personal information or personal data as defined under Applicable Data Protection Laws that WellDatabase processes on Customer's behalf under the Agreement, as described in Annex I.
- “Restricted Transfer” means a transfer of Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country not the subject of an adequacy decision.
- “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- “Subprocessor” means any third party engaged by WellDatabase to process Personal Data on Customer's behalf.
- “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
3. Roles and Details of the Processing
3.1For Personal Data within the scope of Section 1.2, Customer is the Controller (and, under the CCPA, the Business) and WellDatabase is the Processor (and, under the CCPA, the Service Provider).
3.2The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I. Annex I forms part of this DPA and satisfies the specification required by Article 28(3) GDPR.
3.3Each party is independently responsible for its own compliance with Applicable Data Protection Laws. Customer is responsible for the lawfulness of the Personal Data it provides and of the instructions it gives in respect of processing carried out on its behalf, including for having a valid legal basis and for providing any required notices to Data Subjects in respect of that processing.
3.4 WellDatabase as controller. WellDatabase acts as a controller, and not as a processor on Customer's behalf, in respect of the following, and is responsible for its own legal basis and its own notices for them: billing, payment and collections; preparation and execution of Orders; administration of the customer relationship, including customer relationship management and marketing to business contacts; security, fraud prevention and abuse detection; the analytics and session recording described in the Privacy and Data Protection provisions of the Terms and Conditions, used to identify usage trends and diagnose performance issues; the recording and transcription of calls with Customer personnel; and compliance with WellDatabase's own legal obligations. Sections 4 and 11 of this DPA do not apply to that processing, and Section 1.2 continues to apply to the Content.
4. Instructions
4.1WellDatabase will process Personal Data only on Customer's documented instructions, including as to Restricted Transfers, unless required to do otherwise by Union or Member State law, or applicable UK or Swiss law, to which WellDatabase is subject. Where such a legal requirement applies, WellDatabase will inform Customer before processing unless that law prohibits it on important grounds of public interest. Requests from public authorities are governed by Section 13.
4.2The Agreement, this DPA and Customer's use of the features and settings of the Services constitute Customer's complete and final documented instructions. Customer may give additional instructions throughout the term of the Agreement. Additional or alternative instructions must be given in writing, and WellDatabase will not unreasonably withhold agreement to an instruction reasonably required by Applicable Data Protection Laws. WellDatabase may charge a reasonable fee where an instruction requires material effort or a change to the Services.
4.3WellDatabase will inform Customer immediately if, in its opinion, an instruction infringes Applicable Data Protection Laws, and may suspend performance of that instruction until it is confirmed, amended or withdrawn.
5. Confidentiality of Personnel
WellDatabase will ensure that persons authorised to process Personal Data are subject to an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement, and that access is limited to those personnel who require it to perform the Services.
6. Security
6.1WellDatabase will implement and maintain the technical and organisational measures set out in Annex II, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.
6.2WellDatabase may update the measures in Annex II from time to time provided that the updated measures do not materially reduce the overall level of security.
6.3Customer is responsible for its own use of the Services, including configuring access controls, managing User credentials in accordance with Section 2 of the Terms and Conditions, and determining whether the security of the Services is appropriate for the Personal Data Customer chooses to submit.
6.4WellDatabase does not currently hold a SOC 2, ISO 27001 or comparable third-party certification. On Customer's reasonable written request, no more than once in any twelve (12) month period, WellDatabase will provide a written description of the measures in Annex II and complete a reasonable security questionnaire.
7. Subprocessors
7.1Customer gives WellDatabase general authorisation to engage Subprocessors. The Subprocessors engaged by WellDatabase are listed at https://app.welldatabase.com/subprocessors and reproduced in Annex III as at the date of this DPA.
7.2WellDatabase will impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor's obligations.
7.3WellDatabase will give Customer at least thirty (30) days' notice before engaging a new Subprocessor or replacing an existing one, by email to Customer's designated contact or by notice through the Services. Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected Services on written notice and receive a pro-rata refund of prepaid unused fees, which is Customer's sole remedy.
7.4Where a Subprocessor must be engaged at short notice to address a security or continuity risk, WellDatabase may do so on shortened notice and will notify Customer as soon as reasonably practicable and in any event before the Subprocessor begins processing where practicable. Customer's right to object under Section 7.3 applies to that engagement, exercisable within thirty (30) days of the notice, with the same remedy.
8. Assistance with Data Subject Rights
8.1Taking into account the nature of the processing, WellDatabase will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights.
8.2Where the Services provide functionality allowing Customer to access, correct, export or delete Personal Data itself, Customer will use that functionality in the first instance.
8.3If WellDatabase receives a request directly from a Data Subject relating to Customer's Personal Data, it will not respond substantively except to confirm receipt and direct the Data Subject to Customer, and will forward the request to Customer without undue delay.
9. Personal Data Breach
9.1WellDatabase will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on Customer's behalf.
9.2The notification will describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and the name and contact details of a point of contact.
9.3WellDatabase will not delay notification in order to complete its investigation. WellDatabase will cooperate reasonably with Customer's investigation and with Customer's own notification obligations to Supervisory Authorities and Data Subjects.
9.4WellDatabase's notification is not, and will not be construed as, an acknowledgement of fault or liability.
10. Data Protection Impact Assessments
Taking into account the nature of the processing and the information available to it, WellDatabase will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities under Articles 35 and 36 GDPR, at Customer's cost where the assistance requires material effort.
11. Return and Deletion
11.1On expiration or termination of the Agreement, Customer may retrieve Personal Data through the Services for ninety (90) days, in accordance with Section 9.8 of the Terms and Conditions. At Customer's written election within that period, WellDatabase will return or delete the Personal Data.
11.2After the ninety (90) day period, WellDatabase will delete the Personal Data, except to the extent retention is required by law, is necessary to establish, exercise or defend legal claims, or relates to processing for which WellDatabase is a controller under Section 3.4. In each case WellDatabase will retain the Personal Data only for as long as necessary for that purpose and will continue to protect it in accordance with this DPA.
11.3Neither party is required to purge Personal Data from routine backup or archival systems made in the ordinary course of business. Such data remains subject to this DPA for as long as it is retained and will be deleted in accordance with WellDatabase's standard backup rotation.
11.4WellDatabase will certify deletion in writing on Customer's request.
12. International Transfers
12.1WellDatabase processes Personal Data in the United States. Customer acknowledges that submitting Personal Data to the Services involves a transfer to the United States.
12.2 European Economic Area. Where a Restricted Transfer from the EEA occurs, the SCCs apply and are incorporated into this DPA by reference, on the following basis: Module Two (controller to processor) applies; Clause 7 (docking) applies; under Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 7.3; under Clause 11, the optional independent dispute resolution language does not apply; under Clause 17, the governing law is the law of Ireland; under Clause 18(b), the forum is the courts of Ireland; Annex I, Annex II and Annex III of this DPA populate Annexes I, II and III of the SCCs respectively.
12.3 United Kingdom. Where a Restricted Transfer from the UK occurs, the UK Addendum applies to the SCCs on the basis set out in Section 12.2, whether or not a transfer from the EEA also occurs. Table 1 is populated by Annex I.A, and the start date is the Effective Date stated in the Order; Table 2 is populated by the module and clause selections in Section 12.2; Table 3 is populated by Annexes I, II and III; in Table 4, neither party may end the Addendum as set out in Section 19 of the Addendum.
12.4 Switzerland. Where a Restricted Transfer from Switzerland occurs, the SCCs apply with the following adaptations: references to the GDPR are to the Swiss Federal Act on Data Protection; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” does not prevent Data Subjects in Switzerland from bringing proceedings in Switzerland.
12.5If the SCCs, the UK Addendum or any other transfer mechanism relied on is invalidated or superseded, the parties will work in good faith to implement a replacement mechanism promptly.
12.6 Transfer assessment. For the purposes of Clause 14 of the SCCs, the parties have considered the circumstances of the transfer. WellDatabase is a private company established in Texas that provides oil and gas data services. It is not a provider of electronic communications services within the meaning of 50 U.S.C. § 1881a and has not to date received any request for Personal Data under that provision, under Executive Order 12333, or by National Security Letter. Personal Data is encrypted in transit and at rest and WellDatabase controls the encryption keys. WellDatabase maintains the commitments in Section 13 in respect of any request from a public authority. WellDatabase will notify Customer if it becomes aware of any change that renders this assessment inaccurate.
13. Government and Law Enforcement Requests
13.1If WellDatabase receives a legally binding request from a public authority for disclosure of Personal Data processed on Customer's behalf, it will, unless legally prohibited: notify Customer without undue delay; inform the requesting authority that it is a processor and that the request should be directed to Customer; and challenge the request where it has reasonable grounds to consider it unlawful.
13.2WellDatabase will disclose only the minimum amount of Personal Data necessary to respond, based on a reasonable interpretation of the request.
13.3Where WellDatabase is legally prohibited from notifying Customer, it will use reasonable efforts to obtain a waiver of the prohibition and will document its efforts so that it can demonstrate them to Customer as soon as it is permitted to do so.
13.4WellDatabase will, to the extent legally permitted, make available to Customer on request general information about the government requests for Personal Data it has received.
14. Audits and Demonstrating Compliance
14.1WellDatabase will make available to Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, which will ordinarily be satisfied by the description of measures in Annex II and by WellDatabase's response to a security questionnaire under Section 6.4.
14.2Where the information provided under Section 14.1 is not sufficient to demonstrate compliance, Customer may conduct an audit no more than once in any twelve (12) month period, on at least thirty (30) days' written notice, during normal business hours, subject to confidentiality, and in a manner that does not unreasonably disrupt WellDatabase's operations. Customer will bear its own costs and WellDatabase's reasonable costs of supporting the audit.
14.3An additional audit may be conducted following a Personal Data Breach affecting Customer's Personal Data, or where required by a Supervisory Authority.
14.4Audits may not include access to WellDatabase's systems or premises in a manner that would compromise the confidentiality or security of other customers' data, and may not be conducted by a Competitor of WellDatabase.
15. CCPA Service Provider Terms
The following applies where WellDatabase processes Personal Data that constitutes personal information under the CCPA. WellDatabase:
- (a) is a Service Provider and processes personal information solely on Customer's behalf for the limited and specified business purposes described in Annex I;
- (b) will not Sell or Share personal information;
- (c) will not retain, use or disclose personal information for any purpose other than the business purposes specified in Annex I, including outside the direct business relationship between the parties, except as permitted by the CCPA;
- (d) will not combine personal information received from Customer with personal information received from or on behalf of another person, or collected from its own interaction with a Consumer, except as permitted by the CCPA;
- (e) will comply with the obligations applicable to it under the CCPA and will provide the same level of privacy protection as the CCPA requires of Customer;
- (f) grants Customer the right to take reasonable and appropriate steps to help ensure that WellDatabase uses the personal information transferred to it in a manner consistent with Customer's obligations under the CCPA, which the parties agree are satisfied by the information and audit rights in Section 14 and by the certification in paragraph (h) below;
- (g) will assist Customer in responding to Consumer requests to know, delete, correct and opt out, on the same basis as Section 8 of this DPA applies to Data Subject requests;
- (h) certifies that it understands and will comply with the restrictions in paragraphs (a) to (d);
- (i) will notify Customer promptly if it determines it can no longer meet its obligations under the CCPA; and
- (j) grants Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information.
16. Liability
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations in Section 15 of the Terms and Conditions, including the enhanced cap in Section 15.3 applicable to breaches of Sections 10 and 11 of the Terms and Conditions. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Laws, including a Data Subject's rights under Article 82 GDPR or under the SCCs.
17. Term, Precedence and General
17.1This DPA takes effect on the Effective Date and continues for as long as WellDatabase processes Personal Data on Customer's behalf, and thereafter until that Personal Data is returned or deleted in accordance with Section 11.
17.2In the event of a conflict, this DPA governs as to the processing of Personal Data; the SCCs govern over this DPA in respect of a Restricted Transfer to the extent of any conflict; and the Terms and Conditions govern as to all other matters, consistent with Section 17 (Priority of Documents) of the Terms and Conditions.
17.3This DPA is governed by the laws of the State of Texas, except that Sections 12.2 to 12.4 and the SCCs are governed as stated in those provisions. Disputes are resolved in accordance with Section 17 (Dispute Resolution) of the Terms and Conditions, except where the SCCs provide otherwise.
17.4WellDatabase may update this DPA on notice where required to reflect a change in Applicable Data Protection Laws, a new or replacement transfer mechanism, or a change to the Services, provided the update does not materially reduce Customer's protections. Any other amendment requires the written agreement of both parties.
17.5If any provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable and the remainder continues in effect.
17.6Notices under this DPA are given in accordance with the Notices provision of the Terms and Conditions. Data protection notices to WellDatabase may additionally be sent to privacy@welldatabase.com.
Annex I — Description of the Processing
A. List of Parties
| Data Exporter / Controller / Business | Data Importer / Processor / Service Provider | |
|---|---|---|
| Name | The customer identified in the Order | ctrlDev, LLC d/b/a WellDatabase |
| Address | As stated in the Order | 4 Waterway Square Place, Suite 477, The Woodlands, TX 77380, United States |
| Contact | The primary administrative contact on the Account | privacy@welldatabase.com |
| Activities | Receipt of oil and gas data services from WellDatabase | Provision of the Services described in the Agreement |
| Role | Controller / Business | Processor / Service Provider |
B. Description of the Processing
| Item | Detail |
|---|---|
| Categories of Data Subjects | Customer's personnel who are registered as Users of the Services, and Customer's personnel who are billing, administrative or support contacts. |
| Categories of Personal Data | Name; business email address; business telephone number; job title and employer; account username and hashed credentials; authentication and session data; IP address and device or browser information; product usage and activity records associated with a named User, including in-application event data and session recordings of User interaction with the Services; where a call is recorded, voice recording, image and transcript content; support correspondence; billing contact details. Payment card details are collected and processed directly by Stripe and are not stored by WellDatabase. |
| Special category data | None. The Services are not designed for, and Customer must not submit, special categories of Personal Data under Article 9 GDPR or data relating to criminal convictions. |
| Nature and purpose of processing | Account creation and administration; User authentication and access control; provision, maintenance, security and support of the Services; billing and collections; service communications; diagnostics, error monitoring and product improvement; compliance with legal obligations. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Location of processing | Personal Data is hosted in Microsoft Azure regions located in the United States. WellDatabase does not operate its own data centres and does not host Personal Data outside the United States. Subprocessor processing locations are stated in Annex III. |
| Duration of processing | The Term, plus the ninety (90) day retrieval period under Section 11.1, plus the period for which data persists in routine backups under Section 11.3, plus any period of retention permitted by Section 11.2. Session recordings are retained for no longer than thirty (30) days. |
| Subprocessor processing | As set out in Annex III, for the duration of the Agreement. |
C. Competent Supervisory Authority
Where the SCCs apply, the competent Supervisory Authority is that of the EEA member state in which the data exporter is established; where the data exporter is not established in the EEA but has appointed a representative under Article 27 GDPR, the Supervisory Authority of the member state in which that representative is established; and where the data exporter is not established in the EEA and has not appointed a representative, the Supervisory Authority of the member state in which the Data Subjects whose Personal Data is transferred are located. For a Restricted Transfer from the United Kingdom the competent authority is the Information Commissioner, and for a Restricted Transfer from Switzerland it is the Federal Data Protection and Information Commissioner.
Annex II — Technical and Organisational Measures
| Area | Measure |
|---|---|
| Encryption in transit | Personal Data is encrypted in transit using TLS 1.2 or higher. |
| Encryption at rest | Personal Data is encrypted at rest using AES-256 or equivalent. |
| Access control | Role-based access control; access to production systems limited to personnel who require it; access reviewed periodically; access revoked promptly on role change or departure. |
| Authentication | Multi-factor authentication required for administrative and production system access. |
| Credential storage | User passwords stored using a salted one-way hashing function. |
| Logging and monitoring | Security-relevant events logged; logs retained and monitored for anomalous activity. |
| Backup and resilience | Regular automated backups; backups encrypted; restoration tested periodically. |
| Vulnerability management | Dependency and infrastructure vulnerabilities monitored; security patches applied on a risk-prioritised basis. |
| Secure development | Code review before deployment; separation of development, staging and production environments. |
| Physical security | Production infrastructure hosted with a cloud provider maintaining recognised physical security certifications for its facilities. WellDatabase does not operate its own data centres. |
| Personnel | Confidentiality obligations in employment and contractor agreements; security awareness training. |
| Incident response | Documented incident response procedure covering identification, containment, assessment, notification and remediation, tested periodically. |
| Data minimisation | Personal Data collected is limited to what is required to provide, secure and support the Services; production data is not copied into development or test environments except where masked or synthetic. |
| Portability | Customer may export its User-Generated Content and Acquired Data through the Services in a documented machine-readable format, during the Term and for ninety (90) days after it ends. |
| Governance and review | Ownership of information security is assigned within WellDatabase; the measures in this Annex are reviewed at least annually and after any material change to the Services or any Personal Data Breach. |
| Subprocessor management | Written contracts imposing equivalent obligations; review before engagement. |
| Deletion | Documented process for deleting Personal Data at the end of the retention period, including from backups on the standard rotation. |
Annex III — Subprocessors
The subprocessors engaged by WellDatabase are listed at https://app.welldatabase.com/subprocessors, as updated from time to time in accordance with Section 7.3. That published list governs. The list as at the date of this DPA is reproduced below for convenience; in the event of any discrepancy, the published list applies.
| Subprocessor | Location | Purpose | Personal Data |
|---|---|---|---|
| Microsoft Corporation (Microsoft Azure) | United States | Cloud hosting, storage, database, monitoring and platform services on which the Services run | All categories listed in Annex I.B |
| Microsoft Corporation (Microsoft 365) | United States | Business email, document storage and collaboration used for customer correspondence | Name, business email, telephone, job title, correspondence |
| HubSpot, Inc. | United States | Customer relationship management, support ticketing and in-application chat | Name, business email, telephone, job title, support correspondence and account history |
| Stripe, Inc. | United States | Subscription billing, payment processing and invoicing | Billing contact name, email and address; payment instrument data, which Stripe processes as a controller for its own purposes |
| PandaDoc, Inc. | United States | Preparation, delivery and electronic execution of Orders and related documents | Signatory name, business email, IP address and signature audit trail |
| Twilio Inc. (Twilio SendGrid) | United States | Delivery of transactional and service email | Name, business email, message content and delivery metadata |
| PostHog, Inc. | United States | Product analytics and session recording, to identify usage trends and diagnose performance issues | Pseudonymous User identifier not linked to Customer account records; IP address; device and browser data; in-application events; session recordings |
| Google LLC (Google Analytics) | United States | Website and application traffic analytics | IP address; device and browser data; page and event data; pseudonymous online identifiers not linked to Customer account records |
| Fathom Video Inc. | United States | Recording, transcription and summary of video calls with Customer personnel | Name, business email, voice, image and transcript content of recorded calls |
Signing a copy
This DPA is incorporated into the Agreement and takes effect on acceptance of the Order. No separate signature is required. Where your internal processes require a separately executed copy, a signable Word version is available from privacy@welldatabase.com.


