Status: draft for counsel review Effective date: [TO FILL BEFORE PUBLICATION] Version: 0.1-launch-draft
This Data Processing Addendum ("DPA") applies when a business uses OVIO and OVIO processes personal data on behalf of that business as processor. It supplements the OVIO Business Terms.
Do not publish or use this DPA until counsel has approved it, completed all bracketed items, and confirmed the controller/processor role split for each product flow.
1. Parties
Business controller: the business that accepts this DPA.
Processor: [OVIO LEGAL ENTITY NAME], with registered address at [REGISTERED ADDRESS].
2. When This DPA Applies
This DPA applies only where OVIO processes personal data on the business's documented instructions as processor.
OVIO remains an independent controller for platform operations such as account management, marketplace integrity, security, billing, business identity, legal compliance, payment metadata, fraud prevention, analytics consent, support, and policy enforcement.
Businesses may be independent controllers for service delivery, customer relationships, business marketing, tax, accounting, legal obligations, and professional obligations.
[COUNSEL: Confirm whether any joint-controller arrangement is needed before publication.]
3. Processing Details
Subject matter: OVIO's provision of marketplace, booking, communication, business-operation, customer-management, notification, and payment-support tools to the business.
Duration: for the term of the business's use of OVIO and any post-termination period needed for deletion, return, backup expiry, legal retention, support, security, or dispute handling.
Nature and purpose:
- Hosting and displaying business customer records.
- Managing bookings, orders, queues, events, messages, reminders, receipts, and support records.
- Supporting customer communications.
- Supporting business staff access.
- Supporting data export, correction, deletion, and retention workflows.
- Supporting security, fraud prevention, and operational reliability.
Categories of data subjects:
- Customers and prospective customers.
- Business staff and representatives.
- Invited contacts or message recipients.
- Support requesters.
Categories of personal data:
- Name, email, phone, account identifiers, and contact details.
- Booking, order, queue, event, service, product, staff, location, and message data.
- Preferences, marketing choices, consent records, and unsubscribe records.
- Payment metadata, receipt references, refund/dispute metadata, and subscription status where relevant.
- Support, report, moderation, and audit records.
- Device, log, and security data where needed to operate the service.
Sensitive data:
OVIO does not intend businesses to use OVIO to process special-category data unless OVIO has approved the category and counsel has confirmed the required terms and safeguards.
4. Business Instructions
OVIO will process personal data under this DPA only on documented business instructions, including the Business Terms, this DPA, product configuration, and lawful written instructions from the business.
OVIO may refuse or pause an instruction if OVIO reasonably believes it violates law, OVIO's terms, payment provider rules, security requirements, or the rights of another person.
5. Business Obligations
The business is responsible for:
- Having a lawful basis for processing personal data.
- Providing required notices to customers and staff.
- Handling consent and opt-out requirements for business-controlled marketing.
- Ensuring staff have appropriate access.
- Responding to data rights requests where the business is controller.
- Ensuring its instructions to OVIO are lawful.
- Not uploading unnecessary sensitive data.
6. OVIO Processor Obligations
Where OVIO acts as processor, OVIO will:
- Process personal data only on documented instructions.
- Ensure people authorized to process personal data are bound by confidentiality obligations.
- Use technical and organizational measures designed to protect personal data.
- Assist the business with data rights requests, security, breach response, and data protection impact assessments where required and reasonably possible.
- Use subprocessors under written terms that provide appropriate data-protection obligations.
- Provide information reasonably necessary to demonstrate compliance with this DPA.
- Delete or return personal data at the end of service, subject to legal retention, backup expiry, security, dispute, and legitimate controller obligations.
7. Security Measures
OVIO's baseline measures may include:
- Authentication and role-based access controls.
- Separation of customer, business, and administrative access.
- Encryption in transit.
- Managed database and hosting controls.
- Service-role restrictions for privileged operations.
- Logging and monitoring for operational and security events.
- Webhook signature verification where applicable.
- Vendor access controls.
- Environment separation for development and production.
- Incident response procedures.
No service can guarantee absolute security.
8. Subprocessors
The business authorizes OVIO to use subprocessors listed in the Subprocessors & Security document, subject to this DPA.
OVIO will make available the current subprocessor list and will provide notice of material new subprocessors where required. If the business objects on reasonable data-protection grounds, OVIO and the business will work in good faith to address the concern. If the concern cannot be resolved, the business may stop using the affected feature or terminate the affected service as allowed by the Business Terms.
9. International Transfers
Where personal data is transferred internationally and transfer safeguards are required, OVIO will use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework certifications where applicable, or another lawful transfer mechanism.
[COUNSEL: Add final transfer module, SCC language, and supplementary measures where required.]
10. Personal Data Breach
OVIO will notify the business without undue delay after becoming aware of a personal data breach affecting personal data processed by OVIO as processor for the business.
The notice will include information reasonably available to OVIO to help the business meet its obligations. OVIO may provide information in phases as it investigates.
The business is responsible for determining whether it must notify authorities or affected individuals, unless law requires OVIO to notify directly.
11. Data Rights Requests
OVIO will provide reasonable assistance to the business for access, correction, deletion, portability, objection, restriction, and other data rights requests where OVIO acts as processor and the business cannot reasonably fulfill the request without OVIO.
If OVIO receives a request relating to business-controlled data, OVIO may direct the requester to the business or notify the business where appropriate.
12. Audit and Compliance Information
OVIO will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, limited to data processed under this DPA, protect OVIO systems and other users' data, and avoid unnecessary disruption.
[COUNSEL: Add audit notice period, cost allocation, confidentiality, and independent auditor requirements.]
13. Deletion and Return
At termination, OVIO will delete or return personal data processed as processor as described in the product, Business Terms, or written instructions, subject to legal retention, backup expiry, security, fraud, tax, accounting, dispute, support, and OVIO controller obligations.
14. Order of Precedence
If this DPA conflicts with the Business Terms, this DPA controls only for processor obligations relating to personal data processed on the business's instructions. The Business Terms control for commercial and platform matters.
15. Contact
- Privacy/DPA contact: [PRIVACY EMAIL]
- Legal notices: [LEGAL EMAIL]