Data Processing Terms
OmniSpect · Last updated 3 October 2026 · Draft pending review by counsel
These Data Processing terms form part of the Terms of Service between Provider and Customer and apply where Customer Data includes personal data.
Roles
Customer is the controller of personal data in Customer Data. Provider is the processor and processes it only on Customer's documented instructions, which are the Terms and Customer's use of the Service's features.
Subprocessors
Railway, Cloudflare, Clerk, Stripe, OpenAI and Apple, as listed in the Privacy Policy. Provider will give 30 days' notice of a new subprocessor; Customer may object on reasonable grounds.
Security measures
Per-company data segregation enforced on every data route; tokenised, revocable media links; append-only reading history; activity and export logs; encrypted transport; managed hosting with health-gated deployments and rollback; database row-level security as a second layer is scheduled before public self-serve availability.
Assistance
Provider will assist Customer, through the Service's export functions and reasonable support, with data subject requests, security incidents and impact assessments relating to Customer Data.
Incidents
Provider notifies Customer without undue delay, and within 72 hours of confirmation, of a personal data breach affecting Customer Data, with the information Customer needs to meet its own obligations.
Deletion and return
On termination, export for 30 days, then deletion within 90 days except as persisted in routine backups that expire on their own schedule.
Audit
On written request, no more than once a year, Provider will provide documentation of its security measures and respond to reasonable questions. On-site audits are by agreement.
Transfers
Data is hosted in the United States. Where Customer's data is subject to transfer rules, the parties will apply the applicable standard contractual terms on request.