Data Processing Terms

OmniSpect · Last updated 3 October 2026 · Draft pending review by counsel

These Data Processing terms form part of the Terms of Service between Provider and Customer and apply where Customer Data includes personal data.

Roles

Customer is the controller of personal data in Customer Data. Provider is the processor and processes it only on Customer's documented instructions, which are the Terms and Customer's use of the Service's features.

Subprocessors

Railway, Cloudflare, Clerk, Stripe, OpenAI and Apple, as listed in the Privacy Policy. Provider will give 30 days' notice of a new subprocessor; Customer may object on reasonable grounds.

Security measures

Per-company data segregation enforced on every data route; tokenised, revocable media links; append-only reading history; activity and export logs; encrypted transport; managed hosting with health-gated deployments and rollback; database row-level security as a second layer is scheduled before public self-serve availability.

Assistance

Provider will assist Customer, through the Service's export functions and reasonable support, with data subject requests, security incidents and impact assessments relating to Customer Data.

Incidents

Provider notifies Customer without undue delay, and within 72 hours of confirmation, of a personal data breach affecting Customer Data, with the information Customer needs to meet its own obligations.

Deletion and return

On termination, export for 30 days, then deletion within 90 days except as persisted in routine backups that expire on their own schedule.

Audit

On written request, no more than once a year, Provider will provide documentation of its security measures and respond to reasonable questions. On-site audits are by agreement.

Transfers

Data is hosted in the United States. Where Customer's data is subject to transfer rules, the parties will apply the applicable standard contractual terms on request.