Data Processing Addendum
Last updated: May 2026
This Data Processing Addendum (DPA) governs the personal data OwnersPal processes on your behalf when you use the Service. If you're a US-based small business, you most likely don't need a signed copy — but it's here if your customers, your legal team, or your insurer asks. The terms below mirror the IAPP standard processor DPA, adjusted for OwnersPal's subprocessor list at /subprocessors.
How to use this page
Read it once. If your policies require a fully-executed instrument, download the Markdown, counter-sign, and email it to privacy@ownerspal.app. We'll counter-sign and return within five business days. Otherwise, your use of the Service constitutes acceptance.
Download DPA (Markdown)1. Scope and roles
当您使用 OwnersPal 时,您(客户)是您所提交的任何个人数据的控制者(controller)——包括您客户的评价、您在自己网站上发布的客户推荐语、潜在客户线索、联系人列表、广告账户令牌,以及您的客户通过您的 OwnersPal 网站提交的预订或预约、订单、报价请求和候补名单登记。OwnersPal 是该等数据的处理者(processor)。本 DPA 在适用于您的范围内涵盖 GDPR、英国 GDPR、CCPA/CPRA 及其他可比的隐私法律。它不涵盖 OwnersPal 作为控制者直接从您处收集的数据(账单电子邮件、登录、产品分析)——该等数据在我们已发布的隐私政策中说明。
2. Subject matter, duration, nature, and purpose
主题事项:您或您的最终用户提交至本服务的个人数据。期限:在您的订阅有效期内,外加为删除或导出所需的任何终止后保留期。性质与目的:提供本服务——内容生成、广告管理、评价监测、导入您在自己网站上发布的推荐语、潜在客户线索采集、预订与预约处理、订单与报价受理、候补名单管理、商户信息登录、分析,以及为交付上述功能而严格必需的任何辅助处理。数据主体:您的客户和潜在客户,以及使用 OwnersPal 的您自己的员工。数据类别:姓名、电子邮件地址、电话号码、邮寄地址、线索表单自由文本、预订与预约详情(例如,请求的时间和用餐人数)、订单与报价自由文本、公开评价内容、您在网站上发布的客户推荐语(包括您发布的客户姓名和原话)、公开商户信息元数据,以及您授权的广告平台访问令牌。除非我们已书面同意,否则请勿提交特殊类别数据(健康、生物识别等)。本服务还会为您已发布的网站生成汇总站点统计——每日页面浏览量和按钮点按计数器,并附带粗粒度的流量来源(引荐域名或"直接访问")。这些计数器不使用 Cookie 和设备标识符,不保留 IP 地址,无法关联到任何个人,并保留 13 个滚动月份。
3. Customer instructions
OwnersPal processes personal data only on your documented instructions. The settings you configure in the OwnersPal dashboard — platform connections, audience definitions, approval rules, administrative actions — are your documented instructions for GDPR Article 28(3)(a). If we ever think one of those instructions is unlawful, we'll tell you promptly; we don't give legal advice.
4. Subprocessors
The current list of OwnersPal subprocessors is the page at /subprocessors. It's the single source of truth — we update it whenever a vendor changes. We'll give you at least 30 days' notice before adding a new subprocessor; if you object in writing during that window and we can't reach agreement, you can terminate the affected part of the Service. OwnersPal remains responsible to you for everything our subprocessors do.
5. Security measures
OwnersPal maintains appropriate technical and organizational safeguards: TLS 1.2+ in transit and AES-256 at rest; least-privilege access with audit logging; quarterly access reviews; written confidentiality and privacy training for staff; dependency scanning and patch management; backup and disaster recovery suitable for a SaaS of this scale. The measures above are our commitments as of the date above and may evolve, but won't materially weaken.
6. Personal-data breach
If we confirm a personal-data breach that affects your data, we'll notify you without undue delay and within 72 hours. The notice will include what we know at that point: nature of the breach, categories and approximate count of affected records, likely consequences, and what we've done about it.
7. Data-subject requests
We'll help you respond to requests your customers make to exercise their rights — access, rectification, erasure, restriction, portability, objection. If we get a request directly that's about your data, we'll forward it to you and won't respond on your behalf unless we're legally required to.
8. International transfers
Where personal data leaves the EEA, UK, or Switzerland in the course of providing the Service, OwnersPal uses a valid transfer mechanism — including the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK IDTA — incorporated here by reference. You're entering the relevant module(s) of those clauses with OwnersPal and authorizing OwnersPal to enter them with our subprocessors on your behalf.
9. Audit
We make available the information necessary to show we're meeting this DPA, including written responses to reasonable security questionnaires. If we obtain a SOC 2 / ISO 27001 report, sharing that under NDA satisfies your audit right under GDPR Art. 28(3)(h). Otherwise, you can audit on-site once per twelve months with 30 days' notice, at your expense, during normal business hours — without disrupting operations or accessing other customers' data.
10. Return and deletion of data
When your subscription ends, you choose — within 45 days — between (a) a machine-readable export of your personal data, or (b) deletion with a written certificate. If we're legally required to hold something longer, we keep it under the protections of this DPA. We may also keep salted-hash audit records strictly for abuse-prevention and legal defense (the May 2026 PII-hardening pass replaced plaintext email with HMAC-SHA256 hashes for the account-deletion audit trail) — those records aren't personal data of the deleted person.
11. Term
This DPA is effective on the date above and runs for the term of your subscription. Sections 6, 7, 9, 10, and anything else that should survive by its nature, do.
Questions, audit responses, or a signed copy: