OPSLY LEGAL
Data Processing Addendum
Effective August 23, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer using Opsly (“Customer”) and Opsly for the services. It applies when Opsly processes personal data for Customer. Capitalized terms not defined here have the meaning in the agreement or applicable data protection law.
1. Roles and scope
Customer is the controller, business, or equivalent party that determines why and how Customer Data is processed. Opsly is the processor, service provider, or equivalent party. Customer Data includes personal data submitted to Opsly by Customer, its users, or people who contact Customer through connected channels. Processing lasts for the term of the services and the applicable retention period.
2. Customer instructions
Opsly will process Customer Data only to provide, secure, support, and improve the contracted services; comply with documented Customer settings and requests; and meet legal obligations. The agreement, Customer's use of product controls, and written support requests are documented instructions. Opsly will notify Customer if an instruction appears to violate applicable data protection law unless prohibited from doing so.
3. Customer responsibilities
Customer will provide required privacy notices, maintain lawful bases and consents, honor suppression requests, configure access appropriately, and avoid sending data it has no right to process. Customer is responsible for its users, connected provider accounts, and decisions made from AI-generated output.
4. Confidentiality and personnel
People authorized by Opsly to process Customer Data are bound by confidentiality obligations and receive access only as needed for their responsibilities.
5. Security measures
Opsly maintains technical and organizational measures designed for the risk, including encrypted transport; tenant-scoped authorization and row-level controls; least-privilege service access; server-only provider credentials; application-encrypted credential envelopes where credentials are stored in the database; action, recovery, and reconciliation records; dependency and database security review; incident-response and rollback procedures; and backup, export, and restore controls. Database recovery and media-object storage are handled as separate systems. Recovery objectives and availability goals are operating targets unless an order form makes them contractual.
6. Subprocessors
Customer gives general authorization for Opsly to use the providers listed at Subprocessors. Opsly will require subprocessors to protect Customer Data through written terms appropriate to their processing and remains responsible for its obligations under this DPA. Opsly will post material additions before they take effect where reasonably practicable. Customer may object on reasonable data-protection grounds by emailing david@opslyapp.com; the parties will work in good faith on a reasonable alternative.
7. Data-subject requests
Taking into account the nature of the processing, Opsly will provide reasonable assistance for verified access, correction, portability, objection, restriction, or deletion requests. Customer remains responsible for responding to the person. If Opsly receives a request about Customer-controlled data, Opsly may direct the requester to Customer unless law requires otherwise.
8. Security incidents
Opsly will notify Customer without undue delay after confirming a security incident involving Customer Data, provide information reasonably available for Customer's legal obligations, take reasonable containment and remediation steps, and provide updates as material facts become available. Notification is not an admission of fault.
9. Return, export, and deletion
Workspace owners can generate scoped exports. On termination or a verified request, Opsly will return or delete Customer Data in accordance with the agreement, product retention controls, applicable law, legal holds, and backup rotation. Deletion is approval-gated to prevent accidental or cross-tenant loss. Provider credentials and encryption material are excluded from customer exports.
10. International transfers
Each party will comply with law applicable to international transfers. Where required, the parties will use a valid transfer mechanism, including applicable standard contractual clauses or a recognized certification relied on by the relevant provider.
11. Audit information
Upon reasonable written request, Opsly will provide available information needed to demonstrate compliance. If that information is insufficient and law requires an audit, the parties will agree on a narrowly scoped, confidential audit that avoids exposing other customers' data and does not unreasonably disrupt operations. Customer bears its audit costs unless a material breach by Opsly is found.
12. Order of precedence
If this DPA conflicts with the agreement about processing personal data, this DPA controls. The agreement's liability terms apply to this DPA unless applicable law requires otherwise.
Processing details
Subject matter: hosting and operating field-service CRM, communications, scheduling, documents, billing records, reporting, and configured AI assistance. Data subjects: Customer users, employees and contractors; Customer's prospects, customers, and contacts. Data types: identity and contact data, service addresses, communications, photos and files, job and scheduling records, commercial and payment-status records, account activity, and configuration. Payment card data is handled by the payment processor and is not stored by Opsly. Frequency: continuous or as initiated by Customer. Purpose: provide and secure the services under Customer's instructions.
Contact
Opsly, Orlando, Florida. david@opslyapp.com.