This Data Processing Addendum ("DPA") forms part of the Terms of Service between Customer ("Controller") and odnoga, operator of odnoga ("Processor"), and applies when Processor processes Personal Data on behalf of Controller as part of the Service.
1. Definitions
Terms have the meaning given in the GDPR (Regulation (EU) 2016/679).
2. Subject matter and details of processing
- Subject: provision of the odnoga platform.
- Duration: term of the Terms of Service.
- Nature and purpose: routing, logging, billing, observability of AI requests.
- Categories of data subjects: Customer's end users, Customer's personnel.
- Categories of personal data: identifiers (end_user_id), prompt content if submitted by Controller, account contact data, and a salted SHA-256 hash of the signup phone number used solely for fraud prevention.
3. Processor obligations
- Process Personal Data only on documented instructions from Controller, including those given through the Service configuration.
- Processor shall not (a) sell Customer Personal Data, (b) use Customer Personal Data, prompts or completions to train, fine-tune or evaluate any model — ours or any third party's, or (c) share it with third parties other than the Sub-processors listed at /legal/subprocessors.
- Where AI vendors offer a zero-retention / no-training mode (e.g. OpenAI, Anthropic, Google), Processor enables it by default.
- Ensure persons authorised to process Personal Data are bound by confidentiality.
- Implement technical and organisational measures under Art. 32 GDPR (see Annex II).
- Assist Controller with data subject requests, DPIAs and breach notifications.
- Make available information necessary to demonstrate compliance and allow audits, subject to confidentiality.
- Notify Controller of a Personal Data breach without undue delay and in any case within 48 hours of becoming aware.
4. Sub-processors
Controller provides general authorisation for Processor to engage sub-processors listed at /legal/subprocessors. Processor will notify Controller of intended changes at least 30 days in advance; Controller may object on reasonable grounds.
5. International transfers
Where Personal Data is transferred outside the EEA, the parties rely on the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (Controller-to-Processor), incorporated by reference.
6. Return or deletion
On termination Processor will, at Controller's choice, return or delete Personal Data within 30 days, except where retention is required by law.
7. Liability
The liability cap in the Terms of Service applies to this DPA, except that the parties' liability under the Standard Contractual Clauses is not limited by this DPA.
Annex I — Processing details
See Section 2 above.
Annex II — Security measures
Confidentiality
- TLS 1.2+ in transit, AES-256 at rest.
- Row-level security in the database, least-privilege roles.
- Hardware-backed 2FA for staff accessing production.
- Vendor API keys held in a dedicated vault, never in source code.
Integrity and availability
- Daily encrypted backups, point-in-time recovery.
- Multi-AZ infrastructure with documented disaster recovery.
- Continuous monitoring, alerting on anomalies.
Organisational
- Background checks, mandatory security training.
- Documented change-management and incident-response procedures.
- Annual penetration testing.
Signing
For a countersigned copy, email legal@odnoga.com with your company details. Acceptance of the Terms of Service constitutes acceptance of this DPA.