This page provides a pre-filled Article 30 records-of-processing template that you can hand to your DPO or auditor. It describes what odnoga processes on your behalf, why, for how long, and which sub-processors are involved. Fill in the blanks marked [Customer] with your own details before signing.
1. Controller and Processor
- Controller: [Customer legal entity], [address], [DPO email].
- Processor: odnoga, operated by [odnoga entity], Poland. Contact: privacy@odnoga.com.
- Processing under: Data Processing Addendum at /legal/dpa and Standard Contractual Clauses Module Two.
2. Purpose and lawful basis
| Activity | Purpose | Lawful basis |
|---|---|---|
| Account management | Provide access, billing, support | Art. 6(1)(b) contract |
| AI request routing | Forward prompts to chosen vendors and return completions | Art. 6(1)(b) contract |
| Logging & metering | Cost ledger, observability, audit trail | Art. 6(1)(b) + (f) legitimate interest |
| Fraud prevention | One-account-per-person enforcement | Art. 6(1)(f) legitimate interest |
| Marketing (with consent) | Product updates and campaigns | Art. 6(1)(a) consent |
3. Categories of data subjects and personal data
- Customer personnel: name, email, workspace role, 2FA factors (hashed/secrets), login metadata.
- Customer end users: external identifier supplied by Customer, optional email/name/phone if end-user billing is enabled.
- Prompt content and completions: only when raw capture is enabled or when data retention mode is not "none".
- Billing data: company name, VAT ID, billing address, invoice history.
4. Retention periods
- Account data: while active, then 30 days.
- Request metadata: configurable, default 90 days (workspace settings).
- Raw prompts/completions: configurable, default 24 hours when capture is on.
- Aggregated billing/invoices: 5 years (tax law).
- Security logs: 12 months.
5. Sub-processors and international transfers
See the current list at /legal/subprocessors. Transfers outside the EEA rely on EU Standard Contractual Clauses (2021/914), Module Two. The actual endpoint and region used for each AI request are recorded in request metadata.
6. Security measures
- TLS in transit, AES-256 at rest (via Supabase/AWS).
- Row-level security (RLS) scoped to workspace, tenant and end user.
- Supabase Vault for vendor API keys; virtual keys with per-workscope scopes.
- Optional TOTP 2FA, enforced for workspace admins.
- Audit logs for requests, key changes, prompt versions, admin actions and DSR activity.
7. Data subject rights support
- Access, rectification and erasure for end users: workspace Security & data page (DSR export/erase) or email privacy@odnoga.com.
- Full tenant egress: organisation admin can export all workspace data from Tenant admin.
- Response time: 30 days, free of charge.
8. Signature block
Completed by: ____________________________ Date: _______________
On behalf of: [Customer legal entity]
Processor acknowledgement: odnoga