Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between Openserve Holdings, LLC (“Company”) and the business customer (“Customer”) that incorporates it. It applies to Personal Data Company processes on Customer’s behalf in providing covered Services. Product-specific terms may control where a feature has a different data posture.
1. Roles and instructions
Customer is the controller/business or processor, as applicable, and Company is the processor/service provider for Personal Data processed on Customer’s behalf. Company will process Personal Data only on documented instructions from Customer, including the Agreement and permitted use of the Services, unless law requires otherwise. Company will notify Customer if an instruction appears unlawful where required by applicable privacy law.
2. Customer obligations
Customer represents that it has provided required notices, obtained required consents/authorizations, has a lawful basis for processing and disclosure, and will not instruct Company to process Personal Data unlawfully. Customer is responsible for configuration, users, integrations and data submitted to the Services.
3. Confidentiality and security
Company will require persons authorized to process Personal Data to be bound by confidentiality and will maintain appropriate technical and organizational measures proportionate to risk. Annex 2 describes the current security program, including access control, encryption, vulnerability management, logging, monitoring and personnel controls.
4. Subprocessors and model providers
Customer gives general authorization for subprocessors listed at openserve.com/legal/subprocessors. Company will impose data-protection obligations appropriate to the processing and remain responsible for subprocessor performance to the extent required by law/Agreement. Company will provide 10 days’ notice of material new subprocessors, with a reasonable objection mechanism. Model providers may be listed separately because they change more frequently; Customer’s remedy for an objected-to model may be to stop using that model/feature if technically separable.
5. Data-subject requests and assistance
Taking into account the nature of processing, Company will reasonably assist Customer with access, correction, deletion, portability, objection/restriction requests, DPIAs, regulator consultation and compliance obligations to the extent required by law and reasonably available in the Services.
6. Personal Data Breach
Company will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and provide information reasonably available to support Customer’s obligations. Notification does not constitute an admission of fault.
7. Return and deletion
Upon termination/expiration, Company will delete or return Personal Data within 90 days at Customer’s choice where technically feasible, except for data retained by law, security/fraud requirements, legal holds or routine backups that are protected and deleted according to normal cycles.
8. Audits and information
Company will make available information reasonably necessary to demonstrate compliance, including current independent audit/certification reports where available. Additional audits may be limited to once annually, on reasonable notice, during business hours, subject to confidentiality and security restrictions, unless a breach/regulator requires otherwise. Customer bears reasonable costs of special audits not caused by Company breach.
9. International transfers
For restricted cross-border transfers, incorporate the EU Standard Contractual Clauses (Module 2 or Module 3 as applicable), UK International Data Transfer Addendum and Swiss modifications as needed. For such transfers, Company acts as data importer and Customer as data exporter. Processing and hosting occur in the United States (primary hosting and database region: AWS us-east-1, via Vercel and Neon). Unless otherwise designated in the Agreement, the competent supervisory authority and governing law for the EU Standard Contractual Clauses are those of Ireland, and for the UK Addendum those of England and Wales. The technical and organizational measures applicable to transferred Personal Data are set out in Annex 2.
Annex 1 - Details of Processing
Subject matter/purpose: provision, security, support and maintenance of covered Services under Customer instructions.
Duration: term of Agreement plus agreed retention/deletion period.
Data subjects: Customer users, employees, contractors, prospects, customers, end users and other individuals whose data Customer submits.
Personal Data: account/contact data, prompts, messages, documents/files, identifiers, usage data, integration data and other Customer-submitted personal data.
Sensitive data: Customer should not submit special-category/ sensitive data unless expressly supported.
Processing operations: collection, storage, organization, transmission to authorized model/subprocessors, retrieval, consultation, generation, analysis, deletion and other operations needed to provide Services.
Annex 2 - Security Measures
Encryption in transit and at rest: all traffic is served over TLS with HTTP Strict Transport Security (two-year max-age, preload) and an enforced Content-Security-Policy. OAuth tokens and integration credentials are additionally encrypted at the application layer with AES-256-GCM (per-record IVs, authenticated tags, versioned key format supporting rotation). Data at rest is encrypted by our hosting and database providers (Vercel, Neon) using platform-level encryption.
Identity/access management and least privilege: authentication is delegated to a dedicated identity provider (Clerk); Company stores no passwords. Administrative access uses a two-tier role model (superadmin/admin) with per-permission grants, staff allowlists for sensitive features, and identity-based staff verification. Multi-factor authentication for staff accounts is managed at the identity-provider level.
Logging, monitoring and incident response: centralized error monitoring (Sentry) configured to exclude personal data (no request bodies, cookies, authorization headers or session replay); per-request usage and abuse logging; an append-only audit log of administrative and moderation actions; and automated hourly spend/abuse alarms paging an operations channel. Incidents are triaged by the engineering team; a formalized incident-response runbook is in progress on the security roadmap.
Secure development, vulnerability management and penetration testing: CI-enforced static analysis (Semgrep), production dependency vulnerability audits, supply-chain scanning of new packages, secret scanning (TruffleHog), AI-assisted security review of code changes, and weekly OWASP ZAP dynamic scans against production. Third-party CI actions are pinned to immutable commit hashes and known-CVE version floors are enforced in the package manifest.
Backups, resilience and disaster recovery: the primary database is hosted on a managed platform (Neon) with point-in-time-recovery capability; formalized restore drills and documented RPO/RTO targets are in progress on the security roadmap.
Vendor/subprocessor security review: new software dependencies are scanned for supply-chain risk before adoption; subprocessors are engaged under contractual data-protection terms and listed at openserve.com/legal/subprocessors.
Personnel confidentiality/training and offboarding: personnel with access to Personal Data are bound by confidentiality obligations; access is role-based and removed on role change or departure; a formal security-awareness training program is in progress on the security roadmap.
Data deletion, media disposal and tenant segregation: account deletion cascades across all user-keyed records (verified by automated tests across 200+ foreign-key relationships) and extends to external processors (payment, connection and file-storage providers); soft-deleted content is purged after 30 days; customer data is logically segregated per user and workspace at the application and query layer; physical media handling and disposal are managed by our cloud infrastructure providers.