Standard platform DPA — Art 28 UK GDPR / EU GDPR. One agreement for every Opafex customer; no per-client customisation. Forms part of the Terms of Service.
Between:
-
Opafex Ltd ("Processor", "Opafex", "we", "us"), company number 17330428, registered in England & Wales, registered office 1 Coldbath Square, Farringdon, London, EC1R 5HL;
privacy contact privacy@opafex.com; and
-
the Customer ("Controller", "you") — the individual or entity that holds an Opafex account.
Effective: on the Customer's acceptance of the Terms of Service, in-app acceptance of this DPA (Settings → Privacy & Data), or signature — whichever is first.
1. Roles and scope
The Customer is the controller and Opafex is the processor of "Customer Personal Data" — personal data contained in the content the Customer and its connected data sources route through the Service: prompts and conversation messages, uploaded documents and files, knowledge-base content, data-table records, task and workflow data, operative submissions, integration data, and message recipients. This applies across all use cases on the platform (e.g. recruitment/CV handling, facilities management, salon/appointment management, and general business automation). Opafex processes Customer Personal Data only to provide the Service and on the Customer's documented instructions, including via the Customer's configuration of agents, connections, and automations.
For Opafex's own account/billing/usage data about the Customer (not the content above), Opafex acts as an independent controller under its Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter: provision of the Opafex AI agent platform.
- Duration: the term of the Service plus the deletion period in §9.
- Nature/purpose: storage, organisation, retrieval, transmission to LLM providers and Customer- connected services, and AI-assisted processing, to perform the tasks the Customer's agents are configured to do.
- Types of Customer Personal Data: as determined by the Customer — may include identifiers, contact details, content of communications, CV/candidate data, and any data the Customer inputs. Special-category data must not be input without notifying Opafex and ensuring a lawful basis.
- Categories of data subjects: the Customer's own staff, contacts, customers, candidates, leads, and message recipients.
- Processing details for Art 28(3)/Annex I are in Annex I.
3. Processor obligations (Art 28(3))
Opafex will: (a) process only on the Customer's documented instructions, including for transfers, unless required by law (and will inform the Customer of such a requirement unless legally prohibited); (b) ensure persons authorised to process are bound by confidentiality; (c) implement the technical and organisational measures in Annex II (§6); (d) respect the sub-processor conditions in §4; (e) assist the Customer, by appropriate measures, with data-subject requests (§7); (f) assist with security, breach notification, and DPIAs (§8); (g) at the Customer's choice delete or return Customer Personal Data at the end (§9); and (h) make available the information necessary to demonstrate compliance and allow for audits (§10).
4. Sub-processors
The Customer gives general written authorisation for Opafex to engage the sub-processors listed
in the current Sub-Processor List (published at /sub-processors; Annex III). Opafex imposes
data-protection terms on each sub-processor that are no less protective than this DPA. Opafex will
give at least 30 days' notice of any new or replacement sub-processor by email and by updating
the published list; the Customer may object on reasonable data-protection grounds, in which case
the parties will work in good faith to resolve it, failing which the Customer may terminate the
affected part of the Service.
5. International transfers
The Customer→Opafex relationship is UK-to-UK (Opafex is UK-established) — no restricted transfer. Restricted transfers arise where Opafex, as processor, routes Customer Personal Data to sub-processors outside the UK/EEA. For each, the transfer safeguard is:
-
AWS (file storage, London/eu-west-2), Stripe, Resend, Sentry, SendGrid — rely on the UK Extension to the EU-US Data Privacy Framework (adequacy), each vendor certified, with EU/UK SCCs as a contractual backstop.
-
Anthropic (LLM text processing, US) — EU SCCs (Modules Two/Three) + the UK International Data Transfer Addendum, incorporated into Anthropic's DPA, supported by Opafex's Transfer Risk Assessment on file.
-
Railway (hosting/DB/cache) — EU/UK SCCs, plus an executed Data Processing Addendum dated 14 August 2026. The deployment is pinned to Railway's EU region (Amsterdam), so primary data at rest stays in the EU; control-plane and support access is covered by the SCCs.
-
OpenAI / ClickHouse (Langfuse) — used only if enabled; EU SCCs + UK Addendum, EU regions preferred.
The Customer may reduce transfer exposure using BYOK (its own provider key), Private Mode (BYO database + local models), and region-pinned processing where offered.
6. Security measures (Art 32)
The technical and organisational measures are set out in Annex II below and reflect what is implemented in the Service. A summary is available on request.
7. Data-subject requests
Taking into account the nature of processing, Opafex assists the Customer, by appropriate technical
and organisational measures, to respond to data-subject requests, and provides self-service tooling
to export and erase a data subject's records across the Service, including files in object
storage, with post-erasure read-back verification (Settings → Privacy & Data; /api/compliance/privacy).
8. Breach and DPIA assistance
Opafex will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, with the information the Customer needs to meet its own Art 33/34 duties, and will assist with DPIAs and prior consultations.
9. Deletion / return
On termination, Opafex will, at the Customer's choice, delete or return Customer Personal Data and delete existing copies within 60 days, except where law requires retention. Backups are overwritten on their normal cycle. The Customer may also trigger export/erasure at any time under §7.
10. Audit
Opafex will make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates, subject to reasonable confidentiality, notice and frequency limits, and the option to satisfy audits via third-party reports/certifications.
11. Liability / order of precedence
This DPA forms part of, and is subject to, the Terms of Service. In case of conflict on data-protection matters, this DPA prevails.
Annex I — Processing details (Art 28(3) / Art 30)
- Controller: the Customer. Processor: Opafex Ltd.
- Subject matter / duration / nature / purpose: §§1–2.
- Categories of data subjects: the Customer's staff, contacts, customers, candidates, leads, message recipients.
- Categories of personal data: identifiers and contact details; content of communications; documents/files (which may include CVs/candidate data); Customer-configured integration data; and any personal data the Customer chooses to input. Special-category data only by prior arrangement.
- Frequency: continuous, for the term of the Service.
- Sub-processors: Annex III (
/sub-processors).
Annex II — Technical and organisational security measures (Art 32)
Implemented in the Service (state only what is shipped):
- Encryption in transit: all traffic over TLS/HTTPS.
- Encryption at rest: connection secrets, API keys and OAuth tokens encrypted with AES-256-GCM in an application vault; uploaded files in object storage encrypted with AES-256 (S3 SSE-S3), enforced in code; database/disk at-rest encryption provided by the hosting platform.
- LLM data-safety: production Customer Personal Data is structurally prevented from reaching a training/retention-tier LLM provider — PII-bearing calls are pinned to a paid, no-training provider at both routing choke points, and a fallback can't leak it (BYOK excepted, being the Customer's own choice).
- Tenant isolation: every request's identity is taken from a verified license key injected by the edge (which strips any client-supplied identity headers), with per-resource ownership checks on agent- and product-scoped routes; business data is scoped per tenant.
- Access control & authentication: authenticated access with signed session tokens; optional multi-factor authentication; role-based access and governance postures; least-privilege.
- Audit logging: security and skill-execution events are logged (
skill_audit_log, access logs). - Log minimisation: PII is redacted from audit, telemetry, and error paths.
- Data-subject tooling: self-service export and erasure across all stores including object storage, with read-back verification (§7).
- Retention / minimisation: agent-observed data is distilled and aged out on a bounded, differentiated schedule by default; an opt-in retention TTL is available for user-authored content such as candidate CVs (auto-deletes rows + files past the window).
- AI transparency: users are told they are interacting with AI, that outputs may be inaccurate, and that content is processed by third-party AI providers (EU AI Act Art 50).
- Incident response: a breach-notification process with 72-hour customer notification (§8).
- Backups: host-managed database backups, overwritten on their normal cycle.
Annex III — Sub-processors
See the current Sub-Processor List at /sub-processors (kept up to date and independently
maintainable). It names each sub-processor, purpose, data processed, location, and transfer mechanism.