Data Processing Addendum
Last updated: May 2026
This Data Processing Addendum (DPA) governs the personal data OwnersPal processes on your behalf when you use the Service. If you're a US-based small business, you most likely don't need a signed copy — but it's here if your customers, your legal team, or your insurer asks. The terms below mirror the IAPP standard processor DPA, adjusted for OwnersPal's subprocessor list at /subprocessors.
How to use this page
Read it once. If your policies require a fully-executed instrument, download the Markdown, counter-sign, and email it to privacy@ownerspal.app. We'll counter-sign and return within five business days. Otherwise, your use of the Service constitutes acceptance.
Download DPA (Markdown)1. Scope and roles
जब आप OwnersPal का उपयोग करते हैं, तो आप (ग्राहक) उन सभी व्यक्तिगत डेटा के नियंत्रक (controller) होते हैं जिन्हें आप सबमिट करते हैं — आपके ग्राहकों की समीक्षाएँ, आपके द्वारा अपनी वेबसाइट पर प्रकाशित ग्राहक प्रशंसापत्र, लीड, संपर्क सूचियाँ, विज्ञापन-खाता टोकन, तथा वे बुकिंग या आरक्षण, ऑर्डर, कोटेशन अनुरोध और प्रतीक्षा-सूची साइन-अप जो आपके ग्राहक आपकी OwnersPal वेबसाइट के माध्यम से सबमिट करते हैं। OwnersPal उस डेटा का प्रोसेसर (processor) है। यह DPA GDPR, UK GDPR, CCPA/CPRA और अन्य तुलनीय गोपनीयता कानूनों को उस सीमा तक कवर करता है जहाँ तक वे आप पर लागू होते हैं। यह उस डेटा को कवर नहीं करता जिसे OwnersPal नियंत्रक के रूप में सीधे आपसे एकत्र करता है (बिलिंग ईमेल, लॉगिन, उत्पाद विश्लेषण) — वह हमारी प्रकाशित गोपनीयता नीति में शामिल है।
2. Subject matter, duration, nature, and purpose
विषय-वस्तु: वह व्यक्तिगत डेटा जिसे आप या आपके अंतिम उपयोगकर्ता सेवा में सबमिट करते हैं। अवधि: जब तक आपकी सदस्यता सक्रिय है, साथ ही समाप्ति के बाद विलोपन या निर्यात के लिए आवश्यक कोई भी प्रतिधारण अवधि। प्रकृति और उद्देश्य: सेवा प्रदान करना — सामग्री निर्माण, विज्ञापन प्रबंधन, समीक्षा निगरानी, आपकी अपनी वेबसाइट पर प्रकाशित प्रशंसापत्रों का आयात, लीड कैप्चर, बुकिंग और आरक्षण प्रबंधन, ऑर्डर और कोटेशन ग्रहण, प्रतीक्षा-सूची प्रबंधन, लिस्टिंग, विश्लेषण, और उन सुविधाओं को प्रदान करने के लिए कड़ाई से आवश्यक कोई भी सहायक प्रसंस्करण। डेटा विषय: आपके ग्राहक और संभावित ग्राहक, साथ ही आपका अपना स्टाफ जो OwnersPal का उपयोग करता है। डेटा की श्रेणियाँ: नाम, ईमेल पते, फ़ोन नंबर, डाक पते, लीड-फ़ॉर्म का मुक्त-पाठ, बुकिंग और अपॉइंटमेंट विवरण (उदाहरण के लिए, अनुरोधित समय और लोगों की संख्या), ऑर्डर और कोटेशन का मुक्त-पाठ, सार्वजनिक समीक्षा सामग्री, आपकी वेबसाइट पर प्रकाशित ग्राहक प्रशंसापत्र (जैसा आपने प्रकाशित किया, उसमें ग्राहक के नाम और शब्द शामिल), सार्वजनिक लिस्टिंग मेटाडेटा, और आपके द्वारा अधिकृत विज्ञापन-प्लेटफ़ॉर्म एक्सेस टोकन। विशेष-श्रेणी का डेटा (स्वास्थ्य, बायोमेट्रिक, आदि) तब तक सबमिट न करें जब तक हमने इसे लिखित रूप में सहमति न दी हो। सेवा आपकी प्रकाशित वेबसाइट के लिए समग्र साइट आँकड़े भी तैयार करती है — पृष्ठ दृश्यों और बटन टैप के दैनिक काउंटर, एक मोटे ट्रैफ़िक स्रोत (रेफ़रिंग डोमेन या "सीधे") के साथ। इन काउंटरों में न कुकीज़ होती हैं न डिवाइस पहचानकर्ता, IP पते नहीं रखे जाते, इन्हें किसी व्यक्ति से नहीं जोड़ा जा सकता, और ये 13 चालू महीनों तक रखे जाते हैं।
3. Customer instructions
OwnersPal processes personal data only on your documented instructions. The settings you configure in the OwnersPal dashboard — platform connections, audience definitions, approval rules, administrative actions — are your documented instructions for GDPR Article 28(3)(a). If we ever think one of those instructions is unlawful, we'll tell you promptly; we don't give legal advice.
4. Subprocessors
The current list of OwnersPal subprocessors is the page at /subprocessors. It's the single source of truth — we update it whenever a vendor changes. We'll give you at least 30 days' notice before adding a new subprocessor; if you object in writing during that window and we can't reach agreement, you can terminate the affected part of the Service. OwnersPal remains responsible to you for everything our subprocessors do.
5. Security measures
OwnersPal maintains appropriate technical and organizational safeguards: TLS 1.2+ in transit and AES-256 at rest; least-privilege access with audit logging; quarterly access reviews; written confidentiality and privacy training for staff; dependency scanning and patch management; backup and disaster recovery suitable for a SaaS of this scale. The measures above are our commitments as of the date above and may evolve, but won't materially weaken.
6. Personal-data breach
If we confirm a personal-data breach that affects your data, we'll notify you without undue delay and within 72 hours. The notice will include what we know at that point: nature of the breach, categories and approximate count of affected records, likely consequences, and what we've done about it.
7. Data-subject requests
We'll help you respond to requests your customers make to exercise their rights — access, rectification, erasure, restriction, portability, objection. If we get a request directly that's about your data, we'll forward it to you and won't respond on your behalf unless we're legally required to.
8. International transfers
Where personal data leaves the EEA, UK, or Switzerland in the course of providing the Service, OwnersPal uses a valid transfer mechanism — including the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK IDTA — incorporated here by reference. You're entering the relevant module(s) of those clauses with OwnersPal and authorizing OwnersPal to enter them with our subprocessors on your behalf.
9. Audit
We make available the information necessary to show we're meeting this DPA, including written responses to reasonable security questionnaires. If we obtain a SOC 2 / ISO 27001 report, sharing that under NDA satisfies your audit right under GDPR Art. 28(3)(h). Otherwise, you can audit on-site once per twelve months with 30 days' notice, at your expense, during normal business hours — without disrupting operations or accessing other customers' data.
10. Return and deletion of data
When your subscription ends, you choose — within 45 days — between (a) a machine-readable export of your personal data, or (b) deletion with a written certificate. If we're legally required to hold something longer, we keep it under the protections of this DPA. We may also keep salted-hash audit records strictly for abuse-prevention and legal defense (the May 2026 PII-hardening pass replaced plaintext email with HMAC-SHA256 hashes for the account-deletion audit trail) — those records aren't personal data of the deleted person.
11. Term
This DPA is effective on the date above and runs for the term of your subscription. Sections 6, 7, 9, 10, and anything else that should survive by its nature, do.
Questions, audit responses, or a signed copy: