Data Processing Addendum
For customers and organizations that require a DPA under the GDPR or UK GDPR.
1. Parties & scope
This DPA applies when OmegaVault, Inc. (“Processor”) processes personal data on behalf of a customer (“Controller”) in order to provide the service.
2. Roles
Typically the customer is the Controller and OmegaVault is the Processor. Where the customer is itself a Processor acting on behalf of a third-party Controller, the same obligations flow through.
3. Categories of data
- Account identifiers (email, user ID)
- Memories the customer chooses to store
- Operational metadata (timestamps, request logs)
4. Processing instructions
OmegaVault processes personal data only to provide the service, as documented in the Terms and Privacy Policy, and in accordance with the customer's documented instructions.
5. Subprocessors
Current subprocessors are listed at Subprocessors. We provide at least 30 days' notice before adding a new subprocessor, and the customer may object.
6. Security measures
See Security for the technical and organizational measures in place.
7. International transfers
Cross-border transfers rely on the European Commission's Standard Contractual Clauses (or an applicable adequacy decision).
8. Data subject requests
OmegaVault assists the customer with data subject requests — export, deletion, access — using the self-serve controls documented under Export and Delete.
9. Contact
To execute this DPA or ask questions, email hello@omegavault.app.