Start$149/mo

Data Processing Addendum

Last Updated: July 26, 2026
Effective: August 25, 2026

How This Works

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Omnymous Terms of Service or any other written agreement between Omnymous, LLC ("Omnymous," "we," "Processor") and the customer ("Customer," "you," "Controller") governing use of the Omnymous platform (the "Agreement").

You do not need to sign this DPA. It applies automatically to every Customer whose use of the Platform involves the processing of Personal Data, from the date the Agreement takes effect. If your procurement process requires a countersigned copy, email legal@omnymous.com with your entity's full legal name, registered address, and signatory, and we will return an executed copy of this document. We do not negotiate this DPA outside of a signed enterprise Order Form, and we do not accept customer-form DPAs, which are expressly rejected under Section 1.1 of the Terms of Service.

Precedence. In the event of conflict, this DPA controls over the Terms of Service and the Privacy Policy as to the processing of Personal Data, and the Standard Contractual Clauses control over this DPA. A signed Order Form controls over all of them.


1. Definitions

Capitalized terms not defined here have the meanings given in the Agreement.

"Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," and "Supervisory Authority" have the meanings given in the GDPR, and equivalent terms under other Data Protection Laws are construed accordingly (including "Business," "Service Provider," "Consumer," and "Personal Information" under US State Privacy Laws).

"Customer Personal Data" means Personal Data contained within Customer Data that Omnymous Processes on Customer's behalf under the Agreement.

"Data Protection Laws" means all laws applicable to the Processing of Customer Personal Data under the Agreement, including: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (the "UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); the EU ePrivacy Directive 2002/58/EC and national implementations, including the UK Privacy and Electronic Communications Regulations; and US State Privacy Laws.

"EEA" means the European Economic Area.

"Restricted Transfer" means a transfer of Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a country not subject to an adequacy decision or equivalent finding.

"SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

"Sub-processor" means any third party engaged by Omnymous to Process Customer Personal Data on Omnymous's behalf.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

"US State Privacy Laws" means the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the comprehensive consumer privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and any other US state law of similar effect, each as amended.


2. Roles of the Parties

2.1 Customer is Controller, Omnymous is Processor

For Customer Personal Data, Customer is the Controller (and the "Business" under US State Privacy Laws) and Omnymous is the Processor (and the "Service Provider"). Where Customer is itself a processor acting for a third-party controller, Customer warrants that it has the third-party controller's authority to appoint Omnymous as a sub-processor on these terms and to give the instructions in this DPA, and Customer's obligations here apply as if it were the controller.

2.2 Where Omnymous is a Controller

Omnymous is an independent Controller for Personal Data it processes for account administration, billing, security, fraud prevention, support, product analytics, legal compliance, and its own marketing. That processing is governed by the Privacy Policy, not by this DPA. Nothing in this DPA restricts it.

2.3 AI providers are not Omnymous's sub-processors

The Platform operates on a bring-your-own-key basis. Where Omnymous transmits Customer Personal Data to an artificial intelligence provider, it does so using credentials issued to and supplied by Customer, against Customer's own account, under Customer's own agreement with that provider. Omnymous acts solely as a technical conduit executing Customer's instruction.

Accordingly, AI providers are Customer's own processors (or sub-processors), not Omnymous's, and Customer is responsible for concluding the necessary data processing terms and transfer mechanisms with them. Omnymous makes no representation about their processing and is not liable for it. Customer instructs Omnymous to make such transmissions and warrants it has the authority to do so.

2.4 Independent controllers downstream

Where Customer instructs Omnymous to transmit Customer Personal Data to an advertising or commerce platform, that platform Processes the data as an independent controller under its own terms. Omnymous is not responsible for that Processing. Customer is responsible for establishing a lawful basis for the transmission and for any required consent.


3. Processing of Customer Personal Data

3.1 Documented instructions

Omnymous will Process Customer Personal Data only on Customer's documented instructions, which consist of: this DPA; the Agreement; the configuration, settings, features, and integrations Customer selects; the operations Customer and its Users initiate through the Platform and its programmatic interfaces; and any other written instruction the parties agree.

Omnymous will not Process Customer Personal Data for any other purpose, and specifically will not sell it, share it for cross-context behavioral advertising, retain, use, or disclose it outside the direct business relationship, or combine it with Personal Data received from other sources, except as permitted by US State Privacy Laws for a service provider.

Omnymous may Process Customer Personal Data where required by applicable law to which it is subject; in that case it will inform Customer of the requirement before Processing, unless the law prohibits such notice on important grounds of public interest.

3.2 Instructions that appear unlawful

If Omnymous determines that an instruction infringes Data Protection Laws, it will inform Customer without undue delay and may suspend performance of that instruction until it is amended or withdrawn. Omnymous has no obligation to assess the lawfulness of Customer's instructions generally, and does not do so.

3.3 Subject matter, nature, and purpose

The subject matter is the provision of the Platform. The nature and purpose of Processing is the collection, recording, organization, structuring, storage, retrieval, consultation, use, analysis, derivation, transmission, restriction, erasure, and destruction of Customer Personal Data as necessary to provide the Platform, as further described in Annex I.

3.4 Duration

Processing continues for the term of the Agreement plus the deletion period in Section 10, and thereafter only for periods and purposes permitted by Section 10.3.

3.5 Categories of Data Subjects and Personal Data

Set out in Annex I.

3.6 Prohibited data

Customer will not, and will not permit any User or connected system to, submit or cause Omnymous to Process any special category data within the meaning of GDPR Article 9, criminal conviction data within Article 10, or any sensitive or high-risk Personal Data, including health or medical information, precise geolocation, government-issued identifiers, biometric or genetic data, financial account or payment card numbers, authentication credentials of Data Subjects, or Personal Data of children under 16.

The Platform is not designed, configured, or assessed for such data. Omnymous cannot detect or filter it. Customer bears sole responsibility for any consequence of submitting it, and Section 12 of this DPA applies.


4. Customer's Obligations and Warranties

Customer warrants and undertakes, for the entire duration of Processing, that:

  1. it has provided all notices and obtained all consents, authorizations, and permissions required under Data Protection Laws for Omnymous and its Sub-processors to Process Customer Personal Data as contemplated by the Agreement — including consent for the storage of and access to information on Data Subjects' devices where required by ePrivacy rules;
  2. it has a valid legal basis for each purpose of Processing it instructs, and has recorded that basis;
  3. its instructions comply with Data Protection Laws, and its privacy notices accurately describe the Processing, the use of a Processor in the United States, and the transmission of data to advertising platforms;
  4. it has the right to transfer, and to authorize Omnymous to Process, all Customer Personal Data it submits;
  5. Customer Personal Data is accurate and is limited to what is adequate, relevant, and necessary;
  6. it will respond to Data Subject requests it receives, and will operate mechanisms to receive and act on objections, opt-outs, consent withdrawals, and applicable universal opt-out signals;
  7. it will configure the Platform, including any tracking technology, consistently with its own compliance obligations and with the consents it has obtained; and
  8. it will not instruct Processing that would cause Omnymous to violate Data Protection Laws.

Omnymous is not responsible for Customer's compliance with Data Protection Laws, does not verify Customer's notices, consents, or legal bases, and does not audit Customer's configuration.


5. Confidentiality and Personnel

Omnymous will ensure that persons authorized to Process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty, receive appropriate data protection and security training, and are granted access only to the extent necessary for their role and on the principle of least privilege. Access to production Personal Data is restricted, logged, and reviewable.


6. Security

6.1 Measures

Omnymous will implement and maintain the technical and organizational measures described in Annex II, having regard to the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risk to Data Subjects.

6.2 Updates

Omnymous may update its measures provided the overall level of security is not materially reduced. Annex II reflects the measures current at the Last Updated date.

6.3 Customer's share

Customer is responsible for the security of its own systems, credentials, devices, and networks; for configuring roles, permissions, scopes, and access keys appropriately; for promptly de-provisioning Users; and for assessing whether the measures in Annex II are appropriate for the data it chooses to submit. Omnymous is not responsible for any incident arising from Customer's side of that boundary.


7. Personal Data Breach

7.1 Notification

Omnymous will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the Account's notice address; Customer is responsible for keeping that address current and monitored.

7.2 Content

Notice will describe, to the extent known and as it becomes known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where information is not available at the time of notification, Omnymous will provide it in phases without undue further delay.

7.3 Assistance

Omnymous will take reasonable steps to contain, investigate, and mitigate the breach, and will provide reasonable assistance to enable Customer to meet its own notification obligations to Supervisory Authorities and Data Subjects.

7.4 Customer's obligations

Customer is solely responsible for determining whether a breach requires notification to a Supervisory Authority or Data Subjects, and for making any such notification. Customer will not name, identify, or make any public statement about Omnymous in connection with a breach without Omnymous's prior written consent, unless legally required, in which case Customer will give Omnymous advance notice and a reasonable opportunity to comment.

7.5 Not an admission

Notification is not, and will not be construed as, an acknowledgement of fault, liability, or responsibility. Omnymous's obligations under this Section are in addition to, and do not enlarge, its liability under the Agreement.


8. Sub-processors

8.1 General authorization

Customer grants Omnymous general written authorization to engage Sub-processors, subject to this Section. Omnymous's current Sub-processors are listed at omnymous.com/subprocessors (the "Sub-processor List").

8.2 Obligations

Omnymous will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, including as to confidentiality, security, and international transfers. Omnymous remains fully liable to Customer for its Sub-processors' performance of those obligations, subject to the limitations of liability in the Agreement.

8.3 Notice of changes

Omnymous will give notice of the intended addition or replacement of a Sub-processor at least thirty (30) days in advance, by updating the Sub-processor List and notifying Customers who have subscribed to notifications at that page. Customer is responsible for subscribing and for monitoring the notifications it receives.

Where a change is required urgently to protect the security, availability, or continuity of the Platform, or is compelled by law or by an existing Sub-processor's failure, Omnymous may make it immediately and give notice as soon as practicable.

8.4 Objection

Customer may object to a new Sub-processor on reasonable, documented data protection grounds by written notice to privacy@omnymous.com within thirty (30) days of notice under Section 8.3. The parties will discuss the objection in good faith, and Omnymous may propose a change in configuration or an alternative that avoids the Processing objected to.

If Omnymous cannot reasonably accommodate the objection within thirty (30) days of receipt, Customer's sole and exclusive remedy is to terminate the affected subscription on written notice, in which case Omnymous will refund prepaid, unused fees for the terminated portion of the then-current Subscription Term, calculated on a straight-line basis. Objection does not suspend the change, entitle Customer to withhold fees, or give rise to any claim for damages.


9. Data Subject Rights

9.1 Assistance

Taking into account the nature of the Processing, Omnymous will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to Data Subject requests under Data Protection Laws. The Platform's self-service functionality — including search, access, correction, export, and deletion — is the primary means by which this assistance is provided, and Customer will use it before requesting Omnymous's manual assistance.

Where manual assistance beyond that functionality is required and is not attributable to a failure by Omnymous, Omnymous may charge its then-current professional services rates.

9.2 Requests received by Omnymous

If Omnymous receives a request from a Data Subject relating to Customer Personal Data, it will not respond substantively other than to acknowledge and to direct the Data Subject to Customer, and will forward the request to Customer without undue delay. Omnymous will not access, disclose, correct, delete, or restrict Customer Personal Data on the instruction of anyone other than Customer, unless legally compelled.

9.3 Compliance assistance

Omnymous will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities under GDPR Articles 35 and 36, insofar as they relate to Omnymous's Processing and taking into account the information available to Omnymous. Annex I, Annex II, the Privacy Policy, and the Sub-processor List are provided for that purpose and will ordinarily be sufficient.


10. Deletion and Return

10.1 During the term

Customer may access, export, and delete Customer Personal Data at any time using the Platform's functionality.

10.2 On termination

For thirty (30) days after the effective date of termination or expiry, Omnymous will make Customer Personal Data available for export through the Platform, provided the Account is in good standing and all amounts due are paid. This period constitutes Customer's opportunity to require return of the data. After that period, Omnymous will delete or de-identify Customer Personal Data, and Customer instructs it to do so.

10.3 Exceptions

Omnymous may retain Customer Personal Data: to the extent required by applicable law, in which case it will continue to protect it and Process it only for the purpose and period required; where subject to a legal hold, dispute, investigation, or regulatory request; in encrypted backups, which are purged on Omnymous's ordinary rotation and are not restored into production; and in aggregated or de-identified form that cannot reasonably identify any Data Subject, which is not Customer Personal Data and may be retained indefinitely.

10.4 Certification

On written request made within the deletion window, Omnymous will certify in writing that deletion has been completed in accordance with this Section.


11. Audits

11.1 Documentation first

Omnymous will make available the information necessary to demonstrate compliance with Article 28 of the GDPR in the form of: this DPA and its Annexes; the Privacy Policy; the Sub-processor List; and any security documentation, questionnaire responses, penetration test summaries, or third-party attestations Omnymous then maintains. Customer will accept this documentation as satisfying its audit and inspection rights wherever it reasonably does so.

11.2 On-site audits

Where documentation is genuinely insufficient, and no more than once in any twelve (12) month period except where required by a Supervisory Authority or following a confirmed Personal Data Breach affecting Customer Personal Data, Customer may audit Omnymous's compliance with this DPA, subject to all of the following:

  1. at least thirty (30) days' prior written notice, with a proposed scope and plan;
  2. conducted during normal business hours, without unreasonably disrupting operations;
  3. limited to Omnymous's own systems and controls, and excluding any third-party facility, any data or system of another customer, source code, and any information whose disclosure would breach Omnymous's obligations to a third party or compromise its security;
  4. conducted by Customer or an independent auditor that is not a competitor of Omnymous, bound by written confidentiality obligations acceptable to Omnymous;
  5. all findings, reports, and information obtained are Omnymous's Confidential Information; and
  6. at Customer's sole cost, including reimbursement of Omnymous's reasonable costs and personnel time at its then-current professional services rates, unless the audit identifies a material breach of this DPA by Omnymous, in which case Omnymous bears its own costs.

12. International Transfers

12.1 Consent to transfer

Omnymous Processes Customer Personal Data in the United States and may access it from other jurisdictions where it or its Sub-processors operate. Customer instructs and authorizes those transfers.

12.2 EU Standard Contractual Clauses

For Restricted Transfers from the EEA, the SCCs are incorporated into this DPA by reference and apply, on the following terms:

  • Module Two (Controller to Processor) applies where Customer is a controller; Module Three (Processor to Processor) applies where Customer is a processor for a third-party controller.
  • Clause 7 (docking clause) does not apply.
  • Clause 9: Option 2 (general written authorization) applies, with a notice period of thirty (30) days as provided in Section 8.3.
  • Clause 11(a): the optional independent dispute resolution language does not apply.
  • Clause 13 and Annex I.C: the competent Supervisory Authority is that of the EU Member State in which Customer is established, or where Customer is not established in the EU, that of the Member State in which its Article 27 representative is established, or failing that, Ireland.
  • Clause 17: Option 1 applies, and the SCCs are governed by the law of Ireland.
  • Clause 18(b): disputes will be resolved before the courts of Ireland.
  • Annex I to the SCCs is Annex I to this DPA. Annex II to the SCCs is Annex II to this DPA. Annex III (where applicable) is the Sub-processor List.
  • The data exporter is Customer; the data importer is Omnymous, LLC.

12.3 United Kingdom

For Restricted Transfers from the United Kingdom, the UK Addendum is incorporated by reference and applies to the SCCs as modified by it. In Table 1, the parties' details are those in Annex I. In Tables 2 and 3, the selected clauses and Annexes are those in Section 12.2 and this DPA. In Table 4, neither party may end the UK Addendum as set out in Section 19 of it, to the extent permitted.

12.4 Switzerland

For Restricted Transfers from Switzerland, the SCCs apply with the following modifications: references to the GDPR are to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; references to EU Member States do not prevent Data Subjects in Switzerland from bringing proceedings in Switzerland; and, until the revised FADP is fully in force, the SCCs also protect the data of legal entities.

12.5 Alternative mechanisms

If a transfer mechanism relied on here is invalidated, superseded, or held insufficient, the parties will cooperate in good faith to implement a valid alternative — including any successor clauses, certification, or adequacy framework — without undue delay. Adoption of a valid alternative mechanism is not a breach of this DPA and does not give rise to a right of termination.

12.6 Government access requests

Omnymous will, unless legally prohibited, notify Customer of any legally binding request from a public authority for disclosure of Customer Personal Data, will challenge requests it considers unlawful or overbroad, will disclose only the minimum permissible, and will maintain records of such requests. Omnymous has not, to date, created any backdoor or provided any government with direct or unrestricted access to Customer Personal Data.


13. US State Privacy Laws

Where US State Privacy Laws apply, Omnymous acts as a service provider (or processor) to Customer as business (or controller), and:

  1. Omnymous is prohibited from, and will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than performing the services specified in the Agreement, including retaining, using, or disclosing it for a commercial purpose other than those services; retain, use, or disclose it outside the direct business relationship between the parties; or combine it with Personal Data received from another source, except as permitted for a service provider.
  2. Omnymous will comply with applicable obligations, will provide the same level of privacy protection as required of Customer, and will notify Customer if it determines it can no longer meet those obligations.
  3. Customer may take reasonable and appropriate steps under Section 11 to ensure Omnymous's use is consistent with Customer's obligations, and may take reasonable and appropriate steps to stop and remediate unauthorized use.
  4. Omnymous will assist Customer in responding to verifiable consumer requests, and will impose these obligations on any subcontractor.
  5. Customer is responsible for providing notices to, and obtaining any required consent or opt-out from, consumers, and for determining whether its own disclosures constitute a sale or share.

Omnymous certifies that it understands and will comply with these restrictions.


14. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the exclusions and limitations of liability set out in the Agreement, including the cap in Section 21.2 of the Terms of Service. Liability under this DPA is aggregated with, and does not enlarge, liability under the Agreement. Any reference in the SCCs to a party's liability is to be read subject to those limitations, except to the extent applicable law prohibits limiting liability to a Data Subject under the SCCs.

Where both parties are responsible for damage caused by Processing, each will bear liability in proportion to its responsibility.


15. General

15.1 Term. This DPA takes effect with the Agreement and continues until all Customer Personal Data has been deleted or returned under Section 10.

15.2 Amendment. Omnymous may amend this DPA where necessary to comply with Data Protection Laws, to reflect a change in transfer mechanisms, or to reflect a change in the Platform, on thirty (30) days' notice, provided the amendment does not materially reduce the protections afforded to Customer Personal Data.

15.3 Severability and conflict. If any provision is invalid or unenforceable, the remainder continues in effect. Nothing in this DPA is intended to conflict with the SCCs; in the event of conflict, the SCCs prevail.

15.4 Entire agreement. This DPA supersedes any prior data processing terms between the parties relating to the subject matter, including any customer-form addendum, unless expressly incorporated in a signed Order Form.

15.5 Governing law. This DPA is governed by the law governing the Agreement, except where Data Protection Laws or the SCCs require otherwise.


Annex I — Description of Processing

A. List of Parties

Data exporter: Customer, as identified in its Account, acting as Controller (or as Processor where Section 2.1 applies). Contact: the Account's notice address. Activities relevant to the transfer: use of the Platform for e-commerce marketing, advertising operations, and analytics.

Data importer: Omnymous, LLC, 1111b South Governors Ave, STE 94887, Dover, DE 19904, United States. Contact: privacy@omnymous.com. Activities relevant to the transfer: provision of the Platform as described in the Agreement. Role: Processor.

B. Description of Transfer

Categories of Data Subjects

  • Customer's personnel, contractors, and authorized Users
  • Customer's customers, prospective customers, and website and storefront visitors
  • Individuals whose publicly available content is retrieved by research features at Customer's direction
  • Individuals whose Personal Data Customer chooses to include in workspace content

Categories of Personal Data

  • Identity and contact: names, email addresses, phone numbers where transmitted at checkout, platform customer identifiers, account tags
  • Commercial and transactional: orders and order values, line items, SKUs, quantities, discounts, shipping and tax amounts, refunds, currency, payment gateway name, financial and fulfilment status, order sequence and new-customer status, aggregate spend, first and last order dates, derived lifetime value and per-customer economics
  • Location: shipping country and province, shipping method and carrier; approximate region inferred from IP address
  • Online identifiers and device data: persistent pseudonymous visitor identifiers stored in first-party cookies, session identifiers, user agent strings, truncated one-way hashes of IP addresses, advertising click identifiers, campaign parameters, creative and landing page identifiers
  • Behavioral: page and product views, collection views, cart and checkout events, purchases, on-site search terms, page URLs and titles, referrers, session sequences, and reconstructed customer journeys with per-touch attribution credit
  • Derived identifiers: one-way SHA-256 hashes of normalized email addresses used for identity resolution
  • User account data: names, business email addresses, hashed passwords, authentication identifiers, roles and permissions, session and audit records, IP address and user agent in audit logs
  • Content: any Personal Data contained in prompts, uploads, generated outputs, assistant conversations, support communications, or retrieved third-party content

Sensitive data

None. Section 3.6 prohibits its submission. No Processing of special category or criminal conviction data is contemplated, and no additional restrictions or safeguards for such data are agreed.

Frequency of transfer

Continuous, for the duration of the Agreement.

Nature and purpose of Processing

Hosting; storage; ingestion and synchronization from connected platforms; event collection; identity resolution and journey reconstruction; attribution modelling; economics and margin computation; content generation via Customer-supplied AI credentials; research retrieval and summarization; campaign composition and transmission to advertising platforms; conversion event relay; reporting, analytics, and conversational query; support; security, abuse prevention, and audit; backup and deletion.

Retention

For the duration of the Agreement, plus the deletion period and exceptions in Section 10.

Sub-processors

Subject matter, nature, and duration as set out in the Sub-processor List at omnymous.com/subprocessors.

C. Competent Supervisory Authority

As determined under Section 12.2.


Annex II — Technical and Organizational Measures

Measures current at the Last Updated date, maintained under Section 6.

Pseudonymization and encryption. TLS 1.2 or higher for all data in transit. Encryption at rest for databases, object storage, and backups. Third-party API keys encrypted with AES-256-GCM; OAuth tokens encrypted at rest. Passwords hashed with bcrypt. Programmatic access keys stored only as SHA-256 hashes. IP addresses collected by the tracking pixel stored only as truncated one-way hashes. Email addresses used for identity resolution stored as one-way SHA-256 hashes.

Confidentiality. Role-based access control with least privilege; multi-tenant isolation enforced at the data layer with every record scoped to an organization; restricted and logged internal access to production data; unique named accounts; strong authentication requirements for personnel; written confidentiality obligations and security training.

Integrity. Input validation and schema enforcement at API boundaries; idempotency controls on event ingestion; code review and change management; dependency management and security patching; separation of production, staging, and development environments with no production Personal Data in non-production environments.

Availability and resilience. Managed cloud infrastructure with redundancy; automated encrypted backups with defined rotation; monitoring and alerting; queue-based processing with retry semantics for asynchronous work.

Restoration. Documented backup and restore procedures; periodic verification of restore capability.

Testing and evaluation. Automated test suites in continuous integration; security review of changes; dependency vulnerability scanning; error and performance monitoring; periodic review of measures.

Access control to premises and systems. Physical security is provided by the cloud infrastructure provider under its own certifications, including ISO 27001 and SOC 2. Omnymous maintains no data centre of its own. Administrative access to infrastructure is restricted to authorized personnel and is logged.

Transmission and transport control. Encrypted transport for all external transmissions; no transport of Personal Data on removable media; secrets held in a managed secrets store, never in source code.

Input control and auditability. Audit logging of security-relevant actions and configuration changes, recording actor, action, resource, before-and-after values, IP address, user agent, and timestamp.

Instruction control. Processing performed only on Customer's documented instructions as defined in Section 3.1; contractual and technical controls preventing use of Customer Personal Data for Omnymous's own purposes; contractual prohibition on Sub-processors using data for their own purposes.

Separation control. Logical separation of Customer data by organization; separation of duties for administrative functions.

Incident management. Documented incident response process covering detection, triage, containment, eradication, recovery, notification, and post-incident review; defined notification path to Customers under Section 7; security contact at security@omnymous.com.

Governance. Assigned responsibility for data protection; maintenance of records of Processing; sub-processor due diligence and contractual flow-down; periodic review of this Annex.

Measures applying to Sub-processors. Written contracts imposing obligations no less protective than this DPA; assessment of security posture before engagement; transfer mechanisms flowed down where applicable.


Document Version: 1.0 Classification: Public

Questions about this document? Contact our legal team