Skip to main content
Platform Review
PricingSign in
Wrike assessment

Wrike procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Wrike
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow Wrike makes its own international transfers of personal data, including on the basis of the recipient’s membership in the DPF, Standard Contractual Clauses or other appropriate contract language, depending on the situation. To exercise any legal right to see copies of the data transfer mechanism documents that Wrike uses to transfer data to third parties, please contact us. Our Service Offerings allow our Customers and Users to make international data transfers to third parties, such as to other Users, or to providers of integrations, for which they are solely responsible. If we were to transfer personal data to a country that does not provide an adequate level of protection, we would perform a Transfer Impact Assessment (TIA) to ensure that the data remains protected by safeguards equivalent to those in the jurisdiction of origin. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow For human resources personal data that Wrike receives under the DPF (defined under DPF essentially as information about an employee collected in the context of the employment relationship): cooperation with the EEA data protection authorities (DPAs), the U K Information Commissioner’s Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC). Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium Personal data processed through providers of conference, recording, transcription, storage, analytics, and AI-assisted services, including in connection with recorded videoconferences and email communications, may be transferred to and processed in the United States and other countries where Wrike or its providers and their sub processors operate, subject to applicable transfer mechanisms and safeguards. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow We are headquartered in the United States, and recipients of the data disclosures described in this Privacy Policy are located in the United States and elsewhere in the world, including where privacy laws may not provide as much protection as those of your country of residence. However, eligible Customers can arrange to have their Workspaces stored in our data center located in the European Union . Customers also may transfer Customer Data to Wrike on the basis of legal mechanismsapproved by the European Commission and other relevant authorities for cross-border data transfers. These include Standard Contractual Clauses, which may be used in conjunction with additional safeguards that Wrike offers, such as Wrike Lock (which allows Customers to access to their Wrike data while managing their own encryption keys) and other encryption and security features provided under our multiple information security certifications: ISO/IEC 27001:2013, SOC2 Type II, ISO/IEC 27018:2019, and Cloud Security Alliance STAR Level 2. Wrike has certified that it adheres to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework program (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Wrike, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow EEA, Swiss, and UK individuals have the right to access their personal data that has been transferred into the United States and to correct or update that information. Individuals also have the right to erase information that has been processed in violatio n of the DPF Principles. To exercise any of these rights, which are subject to exceptions under the DPF Principles, individuals should refer to the contact information at the end of this policy. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslowDPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Wrike has certified to the U.S. Department of Commerce that it adheres to Swiss-U.S. Data Privacy Framework program Principles (Swiss-U.S. Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is a conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/. The following statements apply to all EEA, UK, and Swiss personal data that is received by Wrike in the United States pursuant to the DPF:Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow When Wrike receives personal data under the DPF and then transfers it to a third - party service provider acting as an agent on Wrike’s behalf, Wrike has certain responsibility under the DPF if both (i) the agent processes the information in a manner inconsi stent with the DPF, and (ii) Wrike is responsible for the event giving rise to the damage. Covered European residents should direct any questions, concerns, or complaints regarding Wrike’s compliance with the DPF to Wrike as described at the bottom of this Privacy Policy. Wrike will attempt to answer your questions and satisfy your concerns in a timely and complete manner as soon as possible. If, after discussing the matter with Wrike, your issue or complaint is not resolved, Wrike has agreed to participate in the DPF independent dispute resolution mechanisms listed below, free of charge to you. Please contact Wrike first. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Residents of the European Economic Area, the UK, and Switzerland also have certain rights under the Data Privacy Framework, as described in the “International Data Transfers” section below.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmediumlaw without authorization from the U.S. government. Both Parties also agree to comply with all other laws, rules, and regulations applicable to that Party under the Agreement. 8.20. Audit . To the extent permitted by applicable law, Customer agrees to allow Wrike to audit Customer’s compliance with the Agreement. 8.21. Notices . All legal notices required under the Agreement shall be in writing and delivered in person or by certified or registered express mail to the address last designated on the Customer Account or such other address as either Party may specify by notice to the other Party as provided herein. Notice shall be deemed given (i) upon personal delivery; (ii) if delivered by air courier or email, upon confirmation of receipt; or (iii) five (5) days after deposit in the mail. A copy of all legal notices from Customer to Wrike must also be sent to the email address [email protected] . Wrike may provide Customer with general notices through in-product messaging or dashboards, which shall likewise be deemed effective immediately. 8.22. Entire Agreement; Order of Precedence . The Agreement sets forth the entire agreement and understanding of the Parties relating to the Service and Customer Data and supersedes all prior and contemporaneous oral and written agreements. For any conflict between the terms of the Agreement and any supplementary BAA terms related to PHI, the Agreement shall control. Nothing contained in any other document submitted by Customer shall in any way add to or otherwise modify the Agreement or any Wrike license program terms under which an Order is submitted. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Except where indicated, this Privacy Policy does not apply to Customer Data or personal data Wrike processes in connection its performance of the Service Offerings. We do not control the content of Customer Data, and, because of security features in the Platform, in most cases we are unable to read such content. Under the EU General Data Protection Regulation (“ GDPR ”) and similar laws, Wrike is considered the Customer’s processor of any personal data in the Customer Data. Wrike processes personal data in connection with its performance of the Service Offerings pursuant to the instructions of the relevant Customer or as required by applicable law, as described in the Wrike Terms of Service at https://www.wrike.com/security/terms/ or the alternative terms of service or agreement (if applicable) between Wrike and that Customer for the Service Offerings, together with its related Data Processing Addendum (“ DPA ”). For any Workspace on the Platform, the relevant Customer is the one that Wrike authorizes to control the Customer account. Specifically, that Customer is the controller for all information submitted by any User to that Workspace, including Full Users and Limited Users . This is true even when those Users happen to be employees of another company or Customer, as each Customer is a controller of only its own Workspaces. Regular Users of a Workspace can find contact information for the relevant Customer’s administrator(s) by logging in to the Workspace and selecting “Profile”, then “Profile Settings”, and then “Account Information”. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium The subsections below apply only to “personal information” about California residents (as that term is defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CPRA”), and its regulations (collectively, the “CCPA”)) and they supplement the information in the rest of our Privacy Policy above. Data about individuals who are not residents of California is handled differently and is not subject to the same rights described below. These subsections also do not apply to Customer Data or personal data that we receive and process on behalf of our customers in connection with performing our Service Offerings as explained above, which is handled as described in Section 1 of our Privacy Policy, even when the Customer Data or such related personal data is about a resident of California. Retention: Your personal information is retained until after its retention no longer is necessary to fulfill the business purposes described in this policy, or as otherwise required under law. Because we may collect and use the same category of personal information for different purposes and in different contexts, there is no fixed retention period that always will apply to a particular category of personal information. Duration of retention may vary depending upon factors such as legal compliance requirements, recordkeeping or, for resolving inquiries or complaints, and the existence of an ongoing relationship with you. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow Customer account information: We retain personal data related to your active account for the duration of your contract with us. Following contract termination, we retain core account records (such as invoices, signed contracts, and payment history) for 10 years to comply with statutory tax and commercial record - keeping obligations. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium Once the retention period has expired or the purpose for processing has been exhausted, we will either permanently delete the data, destroy it, or anonymize it such that it can no longer be associated with a specific individual. Personal data may remain in encrypted backup copies for a limited period beyond the primary retention period as part of our disaster recovery and business continuity protocols. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium Wrike retains personal data only for the period necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy. To determine the appropriate retention period, we apply a criteria-based retention schedule that considers the nature of the data, our legal obligations, and potential limitation periods for legal claims. Our retention criteria are as follows:Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow Prospect and marketing data: personal data collected for marketing purposes (e.g., lead generation forms, webinar registrations) is retained for as long as you remain an " a ctive p rospect ive customer ." We consider you active as long as you continue to interact with our communications. If no interaction is recorded for a period o f 36 months, y our personal data will be deleted or anonymized, unless you have opted out, in which case we retain only a record of your opt - out preference to ensure we respect your ch oice. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow Cookies and automated data: The retention periods for data collected via cookies vary by category (e.g., “Essential” vs. “Analytics”). Categories of cookies are detailed in our Cookie Preferences tool. By way of example, most analytics cookies are set to expire within 12 to 24 months. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium AI - p rocessed b usiness c ommunications: r ecordings, transcripts, and AI - generated summaries of business meetings are retained for a standard period of up to 12 months for quality assurance and training purposes, unless a specific legal hold is applied or a longer period is contractually agreed upon with the relevant Customer. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow Security and audit logs: information collected for security monitoring, fraud prevention, and system integrity (such as IP addresses and access logs) is typically retained for a maximum of two years, after which it is overwritten or deleted, unless required for an ongoing investigation. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium Deactivate their accounts by contacting us at https://help.wrike.com/hc/en- us/articles/25097464163607-Contact-Wrike-Customer-Support , subject to any contractual provisions between Wrike and the Customer responsible for the account. Except when the Customer has requested closure of all its User accounts, information in a deactivated User account may be available to the Customer for some time. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmediumNotwithstanding, Wrike may retain backup copies of Customer Data for security, backup, or business continuity purposes for a limited period of time in accordance with Wrike’s then-current practices. The Agreement states Wrike’s exclusive obligations with respect to care of Customer Data. 5.2. Customer Account . Customer is solely responsible for ( i ) the configuration of its Customer Account; ( ii ) the operation, performance and security of Customer’s equipment, networks and other computing resources used to connect to the Service; ( iii ) ensuring all Users exit or log off from the Service at the end of each session in accordance with Customer’s session policy; ( iv ) maintaining the confidentiality of a Customer Account, User IDs, conference codes, passwords and/or personal identification numbers used in conjunction with the Service, including not sharing login information among Users; and ( v ) all uses of the Service that occur using Customer’s password or Account. Customer will notify Wrike immediately of any unauthorized use of its Customer Account or any other breach of security relating to Customer’s use of the Service. Customer will be liable for losses, damages, liability, expenses, and attorneys’ fees incurred by Wrike or a third party due to someone other than a User using a Customer Account. Ownership of a Customer Account is directly linked to the individual or entity that completes the registration process for such Customer Account. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Other entities involved in the significant corporate transactions described above, such as an acquirer of Wrike; orCaptured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Regulatory authorities, courts, or government agencies where we believe disclosure is necessary as a matter of applicable law or regulation.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Other third party entities that help us with any of the above, such as our sub-processors , our CRM system provider, data storage and backup providers, marketing service providers, event services, chatbot technology providers, event sponsors, webinar providers, customer relationship management providers, accounting providers, technical service providers, our payment processor, and the marketing and analytics companies and other providers described in Section 6 below or as listed on our Cookie Preferences tool linked in the footer of our website as well as providers of conference, recording, transcription, storage, analytics, and AI-Large Language Model (LLM) infrastructure that help us process videoconferences, transcripts, and email communications for the purposes described in this Privacy Policy. We may engage a third-party provider to host or operate any aspect of our business, potentially including any mechanism through which we send or receive communications, such as our email systems and websites. Certain third-party providers engaged in this manner may collect information from you directly when you interact with us;Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Categories of third parties to which it was disclosed for a business purpose Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium In connection with an actual or potential business sale, merger, consolidation, change in control, transfer of substantial assets or reorganization. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium 8.9. Voice and Data Charges; Customer Connectivity . Customer is responsible for all fees and charges imposed by Customer’s telephone carriers, wireless providers, and other voice and/or data transmission providers arising out of access to and use of the Service. If Customer’s broadband connection and/or telephone service fails, or Customer experiences a power or other failure or interruption, the Service may also cease to function for reasons outside of Wrike’s control. 8.10. Generative AI Provider Policies. Wrike uses Microsoft Azure OpenAI Service to provide certain generative AI features and functionality of Wrike AI. Customer shall not use Wrike AI in a manner that violates any Azure OpenAI Service policy, including, but not limited to, Microsoft’s Code of Conduct for the Azure OpenAI Service . Customer acknowledges and accepts the manner in which Microsoft Azure OpenAI Service processes data and the relevant protections and security measures which are set out Microsoft’s Data, Privacy, and Security Policy for the Azure OpenAI Service . For the avoidance of doubt, Customer is aware and accepts that, in connection with Customer’s use of Wrike AI, the Azure OpenAI Service will temporarily store all prompts and generated content to monitor for and prevent abusive or harmful uses or outputs of the Azure OpenAI Service. Authorized Microsoft employees may review such data that has triggered its automated systems to investigate and verify potential abuse. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Our affiliates;Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Other entities involved in the legal-related matters described above;Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium For making appropriate disclosures in response to lawful requests by public authorities, such as to meet national security or law enforcement requirements; and Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Affiliates, accounting providers, payment processors, service providers (including providers of analytics and AI-enabled tools), marketing and analytics companies, and entities involved in legal-related matters with Wrike.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium To comply with law and legal process and protect rights, safety and property; and Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Reseller and referral partners;Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow To offer and provide our Service Offerings to you through our approved resellers; Captured 2026-06-08Open source →Finding permalink →
Tier differencesAll applicable tierslowUsers may be provisioned licenses by Customer as Full Users or Limited Users, the rights and privileges of which are defined at https://www.wrike.com/types-of-licenses/ , and may include Customer’s or Customer’s Affiliates’ employees, representatives, and agents. Customer shall purchase Subscription(s) to the Service for each User assigned a Full User license and may purchase additional Limited User licenses for accessing the Service. 1.19. “ Wrike Order Form ” means an ordering document prepared by Wrike and executed by the Parties that specifies the Service Subscription(s) purchased by Customer under the Agreement. Each Wrike Order Form shall reference the Terms of Service as governing terms and incorporate the Terms of Service by reference. 1.20. “ Wrike AI ” means any features or functionality made available by Wrike as part of, or in the course of providing, the Service or as an Add-On that utilize generative artificial intelligence trained by machine learning using Wrike and/or third-party data models to create new content based on Customer Data that Customer provides or makes available to the Service or Add-On as input to Wrike AI. Wrike AI shall not encompass any artificial intelligence and/or machine learning features or functionality capable of analyzing existing data, including Customer Data, to make predictions, classifications and/or provide Customer focus and understanding based on patterns found in such existing data. Captured 2026-06-08Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.