1. Introduction and Acceptance
This Data Processing Addendum (“DPA”) forms part of the OliveOps Terms of Service. It becomes effective when a Customer accepts those Terms and OliveOps processes Personal Information on the Customer’s behalf. Viewing this page alone does not create a separate agreement.
In this DPA, OliveOps (“OliveOps”) acts as the Processor or service provider; the Customer acts as the Controller or responsible organization for the Personal Data it submits to the Service.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on Personal Data, including collection, storage, use, transmission, and deletion
- Controller: The Customer or organization that determines the purposes and means of processing
- Processor: OliveOps, which processes data on behalf of the Controller
- Subprocessor: A third-party service provider authorized to process data on behalf of OliveOps
- Data Subject: The individual to whom Personal Data relates
- Security Incident: Unauthorized access to, disclosure of, or loss of Personal Data
3. Roles and Responsibilities
Customer's Role as Controller:
- Determines what Personal Data to collect and how it will be processed
- Ensures lawful basis for processing exists (consent, contract, legal obligation, legitimate interest, etc.)
- Obtains necessary consents from Data Subjects (especially employees, customers, or contractors)
- Complies with privacy and data protection laws applicable in their jurisdiction
- Responds to Data Subject requests for access, correction, or deletion
OliveOps' Role as Processor:
- Processes Personal Data only in accordance with Customer's instructions
- Implements appropriate security safeguards
- Maintains records of processing activities
- Assists Customer in responding to Data Subject requests
- Notifies Customer of security incidents without undue delay, as required by applicable law
- Deletes or returns Personal Data in accordance with the applicable agreement, legal obligations, technical limitations, and normal backup retention processes
4. Processing Scope and Instructions
OliveOps processes Personal Data on behalf of Customer only to provide the OliveOps Service as described in the Terms of Service. Permitted processing includes:
- Storage of Customer Data in our databases
- Transmission of data between Customer's devices and our servers
- Analysis and reporting on Customer Data
- Technical support and platform maintenance
- Security monitoring and fraud prevention
- Aggregation and de-identification for service improvement
OliveOps will not process Personal Data for purposes other than those specified above without prior written approval from Customer.
5. Security Measures
OliveOps implements the following technical and organizational security measures:
- Encryption of data in transit (TLS/HTTPS)
- Access controls for stored data, where supported by the applicable infrastructure provider
- Role-based access control (RBAC)
- User authentication and session management
- Regular security updates and vulnerability management
- Audit logging and monitoring
- Employee confidentiality obligations
- Incident response procedures
Additional security details are available in our Security page.
6. Subprocessors
OliveOps uses third-party subprocessors to process Personal Data on our behalf. Customer consents to the use of subprocessors as listed on our Subprocessors page.
Current Subprocessors:
- Vercel: Hosting and deployment
- AWS (Amazon Web Services): Database and cloud infrastructure
- Resend: Email communications
Changes to Subprocessors: OliveOps may add or replace subprocessors as necessary to provide the Service. Where practical, we will provide notice of material changes. Customers who object to a new subprocessor may contact us at support@oliveops.ca to discuss the concern. Resolution will depend on the applicable agreement and circumstances.
7. Data Subject Rights
OliveOps will assist Customer in fulfilling Data Subject requests for:
- Right of access: To obtain copies of Personal Data held
- Right to rectification: To correct inaccurate or incomplete data
- Right to erasure: To delete Personal Data (where legally permitted)
- Right to restrict processing: To limit how data is used
- Right to data portability: To receive data in a structured, portable format
- Right to object: To object to certain processing activities
Customer remains responsible for responding to Data Subject requests and ensuring lawful compliance. OliveOps will provide reasonable assistance in response to requests, subject to operational feasibility.
8. Security Incidents
If OliveOps becomes aware of a security breach or unauthorized access to Personal Data, we will:
- Investigate the incident
- Document the scope and impact
- Notify Customer without undue delay (as required by law)
- Take steps to remediate the issue and prevent recurrence
- Preserve evidence for legal proceedings if necessary
OliveOps will notify the primary account administrator at the email address on file. Customer is responsible for notifying affected Data Subjects as required by applicable law.
9. International Data Transfers
Customer acknowledges that OliveOps processes Personal Data in the United States (specifically in the us-east-2 AWS region). By using OliveOps, Customer consents to the transfer of Personal Data to the United States.
OliveOps complies with applicable mechanisms for international data transfers, including:
- Standard Contractual Clauses (SCCs) or other transfer mechanisms under GDPR, where applicable
- Adequacy determinations where applicable
- Compliance with PIPEDA and Canadian privacy law
10. Return and Deletion
Upon termination of the subscription or a written request by Customer, OliveOps will delete or return Customer Data in accordance with the applicable agreement, legal obligations, technical limitations, and normal backup retention processes. Specifically, OliveOps will:
- Cease active processing of Personal Data
- Provide Customer a reasonable opportunity to export Personal Data where export is supported
- Remove Personal Data from production systems in accordance with normal deletion cycles
- Allow backup copies to persist until overwritten under normal retention cycles
Certain financial, billing, security, and legal records may be retained longer where required or reasonably necessary. OliveOps will confirm deletion upon written request where feasible.
11. Canadian Privacy Law (PIPEDA)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and similar Canadian privacy laws:
- Customer remains the organization responsible for the collection and use of Personal Information
- OliveOps acts as a service provider on behalf of Customer
- OliveOps will not disclose Personal Information to third parties except as necessary to provide the Service
- OliveOps will implement security safeguards appropriate to the sensitivity of the information
- OliveOps will comply with Data Subject requests facilitated by Customer
- OliveOps will notify Customer of Privacy Commissioner complaints or inquiries related to Customer's Personal Information
12. GDPR Provisions
To the extent GDPR applies to the processing of Personal Data, the following additional provisions apply:
- Customer is the "Controller" and OliveOps is the "Processor"
- This DPA constitutes an adequate written contract under GDPR Article 28
- OliveOps will process Personal Data only on documented instructions from Customer
- OliveOps will ensure that persons authorized to process Personal Data are subject to confidentiality obligations
- OliveOps will implement Technical and Organizational Measures (TOMs) as described in this DPA
- OliveOps will not engage subprocessors without prior specific or general written authorization from Customer
- OliveOps will assist Customer in fulfilling GDPR rights (access, rectification, erasure, etc.)
- OliveOps will assist Customer in complying with GDPR obligations (data protection impact assessments, privacy notices, etc.)
- OliveOps will delete or return Personal Data in accordance with the applicable agreement, legal obligations, and normal backup retention processes
- OliveOps will make available to Customer all information necessary to demonstrate compliance with GDPR Article 28
13. Audits and Information Rights
Customer has the right to:
- Request information about OliveOps' security practices and compliance measures
- Audit OliveOps' compliance with this DPA (with reasonable notice and during business hours)
- Request reports or documentation related to security incidents or data handling
- Receive copies of OliveOps' privacy policies and subprocessor agreements
OliveOps will provide reasonable cooperation with audits and information requests, subject to:
- Reasonable notice (minimum 14 days)
- Reasonable scheduling to avoid operational disruption
- Confidentiality obligations for sensitive information
- Reimbursement of excessive audit costs if audits occur more than annually
14. Contact Information
For questions about this DPA, security practices, or data processing inquiries, contact:
Privacy and Legal Contact:
support@oliveops.ca