Data Processing Agreement
Last updated: 2026-04-13
This Data Processing Agreement ("DPA") forms part of the Terms of Service between OPSYNC, Inc. ("Processor") and the customer ("Controller") for the processing of personal data through the OPSYNC platform.
1. Scope & roles
The Controller determines the purposes and means of processing customer-record data uploaded to OPSYNC. OPSYNC acts as Processor and processes that data only on the Controller's documented instructions, including the Terms of Service.
2. Categories of data & data subjects
- Categories of data: contact details, communication content (calls/SMS/email), case/ticket metadata, AI-generated insights.
- Data subjects: the Controller's leads, customers, candidates, debtors, and other contacts.
- Duration: for the term of the subscription plus 30 days.
3. Sub-processors
The Controller authorizes OPSYNC to engage sub-processors (cloud hosting, telephony, transcription, email, payment, error monitoring). A current list is available at privacy@opsynchub.com. We give 30 days' notice of new sub-processors and offer the right to object.
4. Security measures
OPSYNC implements the technical and organizational measures described on the Security page, including encryption in transit/at rest, RBAC, MFA, audit logging, and incident response.
5. Data subject rights
OPSYNC will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) within reasonable timeframes.
6. Breach notification
OPSYNC will notify the Controller without undue delay (and in any case within 72 hours) after becoming aware of a personal data breach affecting Controller data, with details sufficient to meet the Controller's own notification obligations.
7. International transfers
Where personal data is transferred outside the EEA/UK, the parties rely on the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) and, for the UK, the IDTA. These are incorporated by reference.
8. Audits
OPSYNC will make available, on request, evidence of compliance (SOC 2 reports once available, security questionnaire responses, sub-processor lists). On-site audits may be arranged with reasonable notice and at the Controller's expense.
9. Deletion & return
On termination, OPSYNC will return or delete Controller data within 30 days, except where retention is required by law.
10. Governing law
This DPA is governed by the same law as the Terms of Service.
A counter-signed PDF version is available on request. Email legal@opsynchub.com.