Compliance 16 min read

Data Processing Addendum — OpsIQ

Data Processing Addendum — OpsIQ

Overview This Data Processing Addendum (DPA) outlines the terms under which OpsIQ processes personal data on behalf of its customers. It details the roles, documented instructions, security measures, sub-processors, breach handling, and safeguards for international data transfers.

Effective Date: August 7, 2026 Version: 2026.08 Reviewed by: OpsIQ Legal

---

Key Highlights

  1. You Stay in Control
  • You are the data controller; OpsIQ acts as the processor, following your documented instructions.
  1. Secured by Design
  • Data is protected using AES-256 encryption at rest and TLS 1.3 in transit, with additional security measures like signed webhooks and tenant isolation.
  1. No AI Training
  • OpsIQ does not train AI models on your data; inference is directed only to the AI provider you choose.
  1. Transfers Safeguarded
  • EU/UK data is hosted in the EU by default, with cross-border transfers governed by Standard Contractual Clauses.

---

Structure of the DPA

  • 1. Definitions
  • Clarifies key terms such as Controller, Processor, Sub-processor, Personal Data, and Data Subject.
  • 2. Roles & Scope
  • Defines the relationship between OpsIQ and the customer, emphasizing that the customer is the controller of their data.
  • 3. Processing Instructions
  • OpsIQ processes data strictly according to the customer’s documented instructions.
  • 4. Duration of Processing
  • Data processing continues for the duration of the contract, with provisions for post-termination data handling.
  • 5. Confidentiality
  • All personnel with access to personal data are bound by confidentiality agreements.
  • 6. Security Measures
  • Details the technical and organizational measures in place to protect personal data.
  • 7. Sub-processors
  • Lists approved sub-processors and outlines the process for adding new ones.
  • 8. Data Subject Rights Assistance
  • OpsIQ assists customers in responding to data subject requests.
  • 9. Personal Data Breach
  • Procedures for handling data breaches are outlined.

---

Categories of Data

  • Data Subjects
  • Includes website visitors, registered users, contacts, and customer staff.
  • Personal Data Categories
  • Identifiers (e.g., name, email), online identifiers (e.g., IP address), location data, usage data, and communications content.

---

Security and Compliance

OpsIQ implements robust security measures, including encryption, access controls, and audit logs, to ensure the protection of personal data. The DPA is designed to comply with applicable data protection laws, including GDPR and CCPA.

For further details, refer to the annexes that provide a comprehensive data map, security measures, and a list of approved sub-processors.

---

Contact Information For inquiries regarding this DPA, please contact OpsIQ at [email protected].

Discussion

Loading the discussion…