Data Processing Addendum

Addendum governing data processing, roles, security, and compliance

Effective Date:
August 5, 2026
Last Updated:
August 5, 2026
Estimated Read Time:
14 min read
Version:
1.0

1. Introduction and Acceptance

This Data Processing Addendum (“DPA”) forms part of the OliveOps Terms of Service. It becomes effective when a Customer accepts those Terms and OliveOps processes Personal Information on the Customer’s behalf. Viewing this page alone does not create a separate agreement.

In this DPA, OliveOps (“OliveOps”) acts as the Processor or service provider; the Customer acts as the Controller or responsible organization for the Personal Data it submits to the Service.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on Personal Data, including collection, storage, use, transmission, and deletion
  • Controller: The Customer or organization that determines the purposes and means of processing
  • Processor: OliveOps, which processes data on behalf of the Controller
  • Subprocessor: A third-party service provider authorized to process data on behalf of OliveOps
  • Data Subject: The individual to whom Personal Data relates
  • Security Incident: Unauthorized access to, disclosure of, or loss of Personal Data

3. Roles and Responsibilities

Customer's Role as Controller:

  • Determines what Personal Data to collect and how it will be processed
  • Ensures lawful basis for processing exists (consent, contract, legal obligation, legitimate interest, etc.)
  • Obtains necessary consents from Data Subjects (especially employees, customers, or contractors)
  • Complies with privacy and data protection laws applicable in their jurisdiction
  • Responds to Data Subject requests for access, correction, or deletion

OliveOps' Role as Processor:

  • Processes Personal Data only in accordance with Customer's instructions
  • Implements appropriate security safeguards
  • Maintains records of processing activities
  • Assists Customer in responding to Data Subject requests
  • Notifies Customer of security incidents without undue delay, as required by applicable law
  • Deletes or returns Personal Data in accordance with the applicable agreement, legal obligations, technical limitations, and normal backup retention processes

4. Processing Scope and Instructions

OliveOps processes Personal Data on behalf of Customer only to provide the OliveOps Service as described in the Terms of Service. Permitted processing includes:

  • Storage of Customer Data in our databases
  • Transmission of data between Customer's devices and our servers
  • Analysis and reporting on Customer Data
  • Technical support and platform maintenance
  • Security monitoring and fraud prevention
  • Aggregation and de-identification for service improvement

OliveOps will not process Personal Data for purposes other than those specified above without prior written approval from Customer.

5. Security Measures

OliveOps implements the following technical and organizational security measures:

  • Encryption of data in transit (TLS/HTTPS)
  • Access controls for stored data, where supported by the applicable infrastructure provider
  • Role-based access control (RBAC)
  • User authentication and session management
  • Regular security updates and vulnerability management
  • Audit logging and monitoring
  • Employee confidentiality obligations
  • Incident response procedures

Additional security details are available in our Security page.

6. Subprocessors

OliveOps uses third-party subprocessors to process Personal Data on our behalf. Customer consents to the use of subprocessors as listed on our Subprocessors page.

Current Subprocessors:

  • Vercel: Hosting and deployment
  • AWS (Amazon Web Services): Database and cloud infrastructure
  • Resend: Email communications

Changes to Subprocessors: OliveOps may add or replace subprocessors as necessary to provide the Service. Where practical, we will provide notice of material changes. Customers who object to a new subprocessor may contact us at support@oliveops.ca to discuss the concern. Resolution will depend on the applicable agreement and circumstances.

7. Data Subject Rights

OliveOps will assist Customer in fulfilling Data Subject requests for:

  • Right of access: To obtain copies of Personal Data held
  • Right to rectification: To correct inaccurate or incomplete data
  • Right to erasure: To delete Personal Data (where legally permitted)
  • Right to restrict processing: To limit how data is used
  • Right to data portability: To receive data in a structured, portable format
  • Right to object: To object to certain processing activities

Customer remains responsible for responding to Data Subject requests and ensuring lawful compliance. OliveOps will provide reasonable assistance in response to requests, subject to operational feasibility.

8. Security Incidents

If OliveOps becomes aware of a security breach or unauthorized access to Personal Data, we will:

  • Investigate the incident
  • Document the scope and impact
  • Notify Customer without undue delay (as required by law)
  • Take steps to remediate the issue and prevent recurrence
  • Preserve evidence for legal proceedings if necessary

OliveOps will notify the primary account administrator at the email address on file. Customer is responsible for notifying affected Data Subjects as required by applicable law.

9. International Data Transfers

Customer acknowledges that OliveOps processes Personal Data in the United States (specifically in the us-east-2 AWS region). By using OliveOps, Customer consents to the transfer of Personal Data to the United States.

OliveOps complies with applicable mechanisms for international data transfers, including:

  • Standard Contractual Clauses (SCCs) or other transfer mechanisms under GDPR, where applicable
  • Adequacy determinations where applicable
  • Compliance with PIPEDA and Canadian privacy law

10. Return and Deletion

Upon termination of the subscription or a written request by Customer, OliveOps will delete or return Customer Data in accordance with the applicable agreement, legal obligations, technical limitations, and normal backup retention processes. Specifically, OliveOps will:

  • Cease active processing of Personal Data
  • Provide Customer a reasonable opportunity to export Personal Data where export is supported
  • Remove Personal Data from production systems in accordance with normal deletion cycles
  • Allow backup copies to persist until overwritten under normal retention cycles

Certain financial, billing, security, and legal records may be retained longer where required or reasonably necessary. OliveOps will confirm deletion upon written request where feasible.

11. Canadian Privacy Law (PIPEDA)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and similar Canadian privacy laws:

  • Customer remains the organization responsible for the collection and use of Personal Information
  • OliveOps acts as a service provider on behalf of Customer
  • OliveOps will not disclose Personal Information to third parties except as necessary to provide the Service
  • OliveOps will implement security safeguards appropriate to the sensitivity of the information
  • OliveOps will comply with Data Subject requests facilitated by Customer
  • OliveOps will notify Customer of Privacy Commissioner complaints or inquiries related to Customer's Personal Information

12. GDPR Provisions

To the extent GDPR applies to the processing of Personal Data, the following additional provisions apply:

  • Customer is the "Controller" and OliveOps is the "Processor"
  • This DPA constitutes an adequate written contract under GDPR Article 28
  • OliveOps will process Personal Data only on documented instructions from Customer
  • OliveOps will ensure that persons authorized to process Personal Data are subject to confidentiality obligations
  • OliveOps will implement Technical and Organizational Measures (TOMs) as described in this DPA
  • OliveOps will not engage subprocessors without prior specific or general written authorization from Customer
  • OliveOps will assist Customer in fulfilling GDPR rights (access, rectification, erasure, etc.)
  • OliveOps will assist Customer in complying with GDPR obligations (data protection impact assessments, privacy notices, etc.)
  • OliveOps will delete or return Personal Data in accordance with the applicable agreement, legal obligations, and normal backup retention processes
  • OliveOps will make available to Customer all information necessary to demonstrate compliance with GDPR Article 28

13. Audits and Information Rights

Customer has the right to:

  • Request information about OliveOps' security practices and compliance measures
  • Audit OliveOps' compliance with this DPA (with reasonable notice and during business hours)
  • Request reports or documentation related to security incidents or data handling
  • Receive copies of OliveOps' privacy policies and subprocessor agreements

OliveOps will provide reasonable cooperation with audits and information requests, subject to:

  • Reasonable notice (minimum 14 days)
  • Reasonable scheduling to avoid operational disruption
  • Confidentiality obligations for sensitive information
  • Reimbursement of excessive audit costs if audits occur more than annually

14. Contact Information

For questions about this DPA, security practices, or data processing inquiries, contact:

Privacy and Legal Contact:
support@oliveops.ca

Questions about this policy?

Contact us with any concerns or questions about this policy.