omvio Data Processing Addendum
The GDPR Article 28 terms that apply when omvio processes personal data on a customer's behalf.
Version 1.0 · effective . Previous versions are available on request from legal@aa-labs.co.
This Data Processing Addendum (“DPA”) forms part of the omvio Terms of Service between A & A Labs (“Processor”) and the customer (“Controller”). It applies where the Processor processes Personal Data on the Controller’s behalf in providing omvio. It takes effect automatically when the Terms are accepted; no signature is required, though we will sign a counterpart on request to legal@aa-labs.co.
1. Definitions
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Sub-processor” and “Supervisory Authority” have the meanings given in the UK GDPR and EU Regulation 2016/679 (together, “Data Protection Law”). “Customer Personal Data” means Personal Data contained in Customer Data.
2. Roles
- The Controller determines the purposes and means of processing Customer Personal Data and is responsible for its lawfulness, including obtaining any consent required from Data Subjects before messaging them.
- The Processor processes Customer Personal Data only on the Controller’s documented instructions. The Terms, this DPA and the Controller’s use of the Service’s features constitute those instructions.
- The Processor acts as an independent Controller for account administration, billing, security and service improvement in respect of the Controller’s own account data. That processing is described in the Privacy Policy.
3. Subject matter and scope (Art. 28(3))
| Subject matter | Provision of a multi-channel business messaging inbox and related features |
|---|---|
| Duration | The term of the Terms, plus the deletion period in section 10 |
| Nature and purpose | Receiving, storing, displaying, searching, routing, enriching and transmitting messages and contacts; generating AI-assisted responses where enabled; publishing social content where enabled |
| Categories of Data Subject | The Controller’s Authorised Users; End Users who message the Controller; the Controller’s customers synced from a connected store |
| Categories of Personal Data | Names, phone numbers, email addresses, platform-scoped identifiers, profile pictures, message content and attachments, order and cart records, notes, tags and custom fields added by the Controller |
| Special categories | Not collected by design. May appear incidentally within message content submitted by Data Subjects; the Controller is responsible for the additional conditions such processing requires. |
4. Processor obligations
The Processor will:
- process Customer Personal Data only on documented instructions, including for international transfers, unless required otherwise by law — in which case it will inform the Controller first unless the law prohibits it;
- inform the Controller if, in its opinion, an instruction infringes Data Protection Law;
- ensure that persons authorised to process Customer Personal Data are bound by confidentiality;
- implement the technical and organisational measures in section 6;
- respect the conditions in section 5 for engaging Sub-processors;
- assist the Controller with Data Subject requests (section 7), with security, breach notification and data protection impact assessments (sections 8 and 9), taking into account the nature of processing and the information available to it;
- delete or return Customer Personal Data on termination (section 10);
- make available the information necessary to demonstrate compliance and allow for audits (section 11).
5. Sub-processors
The Controller grants general authorisation for the Processor to engage the Sub-processors listed at omvio Sub-processors. The Processor will:
- impose on each Sub-processor, by contract, data protection obligations no less protective than those in this DPA;
- remain fully liable to the Controller for a Sub-processor’s performance;
- give at least 30 days’ notice before adding or replacing a Sub-processor;
- where the Controller objects on reasonable data protection grounds within that period and no alternative can be offered, permit the Controller to terminate the affected part of the Service without penalty, with a pro-rata refund of prepaid fees.
6. Security measures (Art. 32)
- Encryption of Personal Data in transit (TLS) and at rest, with additional application-level encryption of connected-channel credentials.
- Logical tenant isolation, enforced at the query layer, so one workspace cannot read another’s data.
- Role-based access control within the Service; least-privilege access to production systems for personnel, reviewed periodically and logged.
- Passwords stored only as salted hashes.
- Signature verification on all inbound platform and payment webhooks.
- Audit logging of administrative actions.
- Encrypted, regularly tested backups.
- A documented incident response process, and a vulnerability disclosure channel.
Measures may be updated as technology evolves, provided the level of security is not materially reduced. The current statement is at Security Practices.
7. Data Subject requests
The Service provides the Controller with the means to access, correct, export and delete Customer Personal Data itself. Where a Data Subject contacts the Processor directly, the Processor will not respond substantively but will forward the request to the Controller without undue delay, and will assist the Controller in responding.
8. Personal data breach
The Processor will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed — to the extent known, supplemented as more information becomes available. The Controller is responsible for any notification it must make to a Supervisory Authority or to Data Subjects.
9. Impact assessments
The Processor will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities, to the extent they relate to processing by the Processor and the Controller lacks the necessary information.
10. Deletion and return
On termination the Controller may export Customer Personal Data for 30 days. After that period the Processor will delete it, including from Sub-processors, within 30 days, except where storage is required by law. Encrypted backups are purged within 90 days; data restored from a backup is not reinstated to live systems. The Processor will confirm deletion in writing on request.
11. Audits
On request and no more than once in any 12-month period (unless a Supervisory Authority requires otherwise or a breach has occurred), the Processor will provide the information reasonably necessary to demonstrate compliance with this DPA, and will co-operate with an audit conducted by the Controller or a mutually agreed independent auditor. Audits must be subject to reasonable notice and confidentiality, conducted during business hours, and must not compromise the security or privacy of other customers.
12. International transfers
Where the Processor transfers Customer Personal Data out of the UK or EEA, it does so under the European Commission’s Standard Contractual Clauses (Module Two: Controller to Processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. Docking clause: optional. Governing law and forum follow the Terms unless the Clauses require otherwise.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms, except where Data Protection Law prohibits limiting it.
14. Precedence
Where this DPA conflicts with the Terms in relation to the processing of Personal Data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.