# WiBiz Vendor and Subprocessor Management Summary

**Version:** v1.0  
**Published:** 6 August 2026  
**Owner:** WiBiz Operations  
**Classification:** Public  
**Status:** Current public summary

## 1. Purpose

WiBiz relies on managed cloud and service providers. This summary explains the risk-based provider process and the evidence boundary for public and client statements.

## 2. Provider review

Before approval and after material change, WiBiz requires the review to consider:

- service purpose, criticality, data categories, and legal role;
- storage, processing, backup, support, and transfer locations;
- access, authentication, logging, retention, deletion, and recovery;
- independent assurance and the exact scope of that assurance;
- contractual security, confidentiality, data protection, incident, audit, and exit terms;
- concentration, continuity, fourth-party, and replacement risk;
- open evidence, exceptions, owner, deadline, and next review.

## 3. Subprocessor transparency

The organisation-level provider page identifies the current public baseline and known limitations. The applicable build-specific schedule identifies the exact provider, role, service, data, purpose, location, safeguard, notice process, and approval status for a client's service.

WiBiz does not assume that every vendor is a subprocessor. A payment or other provider may act as an independent controller. The role is assessed from the processing purpose and contract.

## 4. Evidence boundary

A provider's certificate, report, or public statement applies to the provider's defined scope. It does not prove WiBiz configuration, access, data flow, retention, or contract status. WiBiz records those facts separately and leaves unknowns visible until verified.

## 5. Changes and exit

Material provider changes trigger reassessment, client notice where required, annex updates, data-transfer review, access removal, data return or deletion, and replacement evidence. Client objection and termination rights follow the signed agreement.

## 6. Contact

Assurance enquiries: security@wibiz.ai  
Data-protection enquiries: dpo@wibiz.ai

---

WiBiz Vendor and Subprocessor Management Summary v1.0, 6 August 2026.
