Data Processing Agreement

Last updated: 2026-04-13

This Data Processing Agreement ("DPA") forms part of the Terms of Service between OPSYNC, Inc. ("Processor") and the customer ("Controller") for the processing of personal data through the OPSYNC platform.

1. Scope & roles

The Controller determines the purposes and means of processing customer-record data uploaded to OPSYNC. OPSYNC acts as Processor and processes that data only on the Controller's documented instructions, including the Terms of Service.

2. Categories of data & data subjects

  • Categories of data: contact details, communication content (calls/SMS/email), case/ticket metadata, AI-generated insights.
  • Data subjects: the Controller's leads, customers, candidates, debtors, and other contacts.
  • Duration: for the term of the subscription plus 30 days.

3. Sub-processors

The Controller authorizes OPSYNC to engage sub-processors (cloud hosting, telephony, transcription, email, payment, error monitoring). A current list is available at privacy@opsynchub.com. We give 30 days' notice of new sub-processors and offer the right to object.

4. Security measures

OPSYNC implements the technical and organizational measures described on the Security page, including encryption in transit/at rest, RBAC, MFA, audit logging, and incident response.

5. Data subject rights

OPSYNC will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) within reasonable timeframes.

6. Breach notification

OPSYNC will notify the Controller without undue delay (and in any case within 72 hours) after becoming aware of a personal data breach affecting Controller data, with details sufficient to meet the Controller's own notification obligations.

7. International transfers

Where personal data is transferred outside the EEA/UK, the parties rely on the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) and, for the UK, the IDTA. These are incorporated by reference.

8. Audits

OPSYNC will make available, on request, evidence of compliance (SOC 2 reports once available, security questionnaire responses, sub-processor lists). On-site audits may be arranged with reasonable notice and at the Controller's expense.

9. Deletion & return

On termination, OPSYNC will return or delete Controller data within 30 days, except where retention is required by law.

10. Governing law

This DPA is governed by the same law as the Terms of Service.


A counter-signed PDF version is available on request. Email legal@opsynchub.com.

Ready to replace
your entire ops stack?

Get access

Request access · Onboarding done for you