Source
Privacy policy — Wrike
Checked for Wrike on 15 Sep 2026
- Page
- https://www.wrike.com/privacy
- Checked
- 15 Sep 2026, 16:37 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:77ce9b850ce7d5ab0d34f3860cea511e11f6f56b1dea68a1278aa7e008bfd7f5
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Last updated Report an error
“Last updated June 1, 2026.”
-
Customer data role Report an error
“Under the EU General Data Protection Regulation (“GDPR”) and similar laws, Wrike is considered the Customer’s processor of any personal data in the Customer Data.”
-
DPA reference Report an error
“as described in the Wrike Terms of Service at https://www.wrike.com/security/terms/ or the alternative terms of service or agreement (if applicable) between Wrike and that Customer for the Service Offerings, together with its related Data Processing Addendum (“DPA”)”
-
AI meeting processing Report an error
“when individuals participate in a videoconference using a Wrike conference tool or another conference tool made available by Wrike, we may collect and process audio recordings, video recordings, transcripts, and related meeting metadata (such as date, time, participants, and meeting title), but only where the relevant participant has provided active consent to the recording”
-
AI vendor training prohibition Report an error
“Wrike does not permit third-party providers engaged to provide transcription, storage, analytics, or AI- assisted services to use such data to train their own general-purpose AI models, except where expressly authorized by Wrike and permitted by applicable law and contract.”
-
EU datacenter option Report an error
“However, eligible Customers can arrange to have their Workspaces stored in our data center located in the European Union.”
-
Transfer mechanisms Report an error
“These include Standard Contractual Clauses, which may be used in conjunction with additional safeguards that Wrike offers, such as Wrike Lock (which allows Customers to access to their Wrike data while managing their own encryption keys) and other encryption and security features provided under our multiple information security certifications: ISO/IEC 27001:2013, SOC2 Type II, ISO/IEC 27018:2019, and Cloud Security Alliance STAR Level 2.”
-
Dpf certification Report an error
“Wrike has certified that it adheres to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework program (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
-
Ftc jurisdiction Report an error
“Wrike is subject to the jurisdiction and enforcement authority of the United States Federal Trade Commission.”
-
Dpf dispute resolution Report an error
“Wrike has further committed to refer unresolved privacy complaints under the DPF Principles to an independent dispute resolution mechanism, Data Privacy Framework Services, operated by BBB National Programs.”
-
Hq country Report an error
“We are headquartered in the United States”
-
Tia practice Report an error
“If we were to transfer personal data to a country that does not provide an adequate level of protection, we would perform a Transfer Impact Assessment (TIA) to ensure that the data remains protected by safeguards equivalent to those in the jurisdiction of origin.”
-
Children policy Report an error
“The Service Offerings are not directed at minors under 18. We do not knowingly collect personal information from minors under 18.”
-
Retention account records Report an error
“Following contract termination, we retain core account records (such as invoices, signed contracts, and payment history) for 10 years to comply with statutory tax and commercial record-keeping obligations.”
-
Retention prospect marketing Report an error
“If no interaction is recorded for a period of 36 months, your personal data will be deleted or anonymized, unless you have opted out”
-
Retention AI recordings Report an error
“recordings, transcripts, and AI-generated summaries of business meetings are retained for a standard period of up to 12 months for quality assurance and training purposes, unless a specific legal hold is applied or a longer period is contractually agreed upon with the relevant Customer.”
-
Retention security logs Report an error
“information collected for security monitoring, fraud prevention, and system integrity (such as IP addresses and access logs) is typically retained for a maximum of two years, after which it is overwritten or deleted, unless required for an ongoing investigation.”
-
Retention analytics cookies Report an error
“By way of example, most analytics cookies are set to expire within 12 to 24 months.”
-
Cookie categories Report an error
“The cookies and other technologies described here fall into the following categories: Essential”
-
GDPR user rights Report an error
“Residents of the European Economic Area, the UK, and many other jurisdictions have certain legal rights to do the following with personal data we control:”
-
Marketing opt out Report an error
“Anybody can unsubscribe from marketing emails by clicking the unsubscribed link they contain.”
-
Account deactivation Report an error
“Deactivate their accounts by contacting us at https://help.wrike.com/hc/en- us/articles/25097464163607-Contact-Wrike-Customer-Support, subject to any contractual provisions between Wrike and the Customer responsible for the account.”
-
Browser extension optout Report an error
“Deactivate data collection by our browser extension by uninstalling it.”
-
Gpc honored Report an error
“Wrike.com treats qualifying browsers for which the user has activated the GPC signal as having opted out of what CCPA calls a “sale” or “sharing” of any California personal information that is collected on that site from that browser using cookies and similar technology.”
-
CCPA sale disclosure Report an error
“During the 12 months leading up to the effective date of this Privacy Policy, we “sold” and “shared” (as those terms are defined under the CCPA), what the CCPA calls “identifiers” (like IP addresses and email addresses), “internet or other electronic network activity information” (like information regarding an individual’s browsing interactions on wrike.com), and “commercial information” (like the fact that a browser visited a page directed to people who are considering purchasing from us) about Californians to third parties that assist us, such as marketing partners and analytics providers.”
-
Minors sale Report an error
“To our knowledge, we do not “sell” or “share” (as those terms are defined under the CCPA) the personal information of individuals under 16 years of age.”
-
Sensitive info limits Report an error
“Wrike does not use or disclose Sensitive Personal Information for purposes other than those permitted by the CCPA/CPRA (e.g., to perform services or for security purposes).”
-
User rights customer data routing Report an error
“To exercise any rights relating to Customer Data, Users should contact the relevant administrator for the Workspace associated with Customer Data, not Wrike.”
-
Categories Report an error
“such as our sub-processors, our CRM system provider, data storage and backup providers, marketing service providers, event services, chatbot technology providers, event sponsors, webinar providers, customer relationship management providers, accounting providers, technical service providers, our payment processor”
-
Third party integrations security Report an error
“Third-party software and services integrated into our Service Offerings, such as Google Drive, Box, Dropbox, and other integrations, as well as third-party sites hyperlinked from ours, are handled by such third parties subject to their own privacy and security procedures, which we do not control.”
-
Platform plan security options Report an error
“The specific Platform security options available to Customers depend on their Platform Plan.”
-
Automated decisions Report an error
“Wrike does not use call or video recordings, transcripts, email content, or related communications described in this section to make solely automated decisions that produce legal effects or similarly significant effects on individuals without providing a mechanism for human review and the ability for the individual to contest the outcome.”
-
Dpia Report an error
“we would (i) conduct a Data Protection Impact Assessments (DPIAs) where our processing (especially involving AI) is likely to result in a high risk to the rights and freedoms of natural persons”
-
Registered entity Report an error
“Wrike, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles”
Scores citing this record
- The Bootstrapper European sovereignty
- The Bootstrapper Support & documentation
- The Data Protection Officer European sovereignty
- The Data Protection Officer Support & documentation
- The Enterprise Architect Integrations
- The Enterprise Architect European sovereignty
- The Enterprise Architect Support & documentation
- The Integrator Integrations
- The Integrator European sovereignty
- The Integrator Support & documentation
- The Skeptic European sovereignty
- The Skeptic Support & documentation
- The UX Purist European sovereignty
- The UX Purist Support & documentation