Data Processing Agreement
Effective date: July 20, 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Opal Terms of Use (or the applicable Order Form / enterprise agreement) (the "Agreement") between Opal Technologies ("Opal," "Processor"), Suite 1100 – 715 5 Ave SW, Calgary, Alberta, T2P 2X6, Canada, and the Customer ("Controller"). It applies where Opal Processes Personal Data on behalf of Customer through the Service.
If there is a conflict between this DPA and the Agreement regarding data protection, this DPA controls.
1. Definitions
- "Applicable Data Protection Laws" means all laws applicable to the Processing of Personal Data under the Agreement, including, as applicable: Canada's PIPEDA and substantially similar provincial laws (e.g., Alberta PIPA, Quebec Law 25); the EU GDPR and UK GDPR; and US state privacy laws (e.g., CCPA/CPRA).
- "Personal Data," "Controller," "Processor," "Processing," "Data Subject," "Personal Data Breach," and "Supervisory Authority" have the meanings given under Applicable Data Protection Laws.
- "Customer Personal Data" means Personal Data contained in Customer Data that Opal Processes on Customer's behalf.
- "Sub-processor" means a third party engaged by Opal to Process Customer Personal Data.
- "SCCs" means the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914); "UK Addendum" means the UK ICO's International Data Transfer Addendum to the SCCs.
2. Roles and Scope
2.1 The parties acknowledge that, for Customer Personal Data, Customer is the Controller (or a Processor acting for another controller) and Opal is the Processor (or Sub-processor). Where US laws apply, Customer is the "business" and Opal is a "service provider" that Processes Personal Data only for the permitted business purposes.
2.2 Opal will Process Customer Personal Data only on Customer's documented instructions (including via configuration of the Service), except where required by law (in which case Opal will notify Customer unless prohibited).
2.3 The subject-matter, duration, nature, purpose, data types, and categories of Data Subjects are described in Annex A.
3. Opal's Obligations
Opal will:
- Process Customer Personal Data only as instructed and as needed to provide the Service;
- not "sell" or "share" Customer Personal Data (as defined by CCPA/CPRA) and not retain, use, or disclose it for any purpose other than performing the Service or as permitted by law;
- ensure persons authorized to Process Customer Personal Data are bound by confidentiality;
- implement and maintain the technical and organizational security measures in Annex B;
- assist Customer, taking into account the nature of Processing, in responding to Data Subject requests (Section 6) and in meeting Customer's obligations regarding security, breach notification, data protection impact assessments, and prior consultation (GDPR Arts. 32–36);
- notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach, with available details; and
- make available information reasonably necessary to demonstrate compliance and allow for audits (Section 7).
4. AI-Specific Processing Terms
4.1 No model training. Opal does not use Customer Personal Data to train its own or any third party's machine-learning or foundation models, and Opal requires (through its AI gateway provider) that model providers do not use Customer Personal Data (inputs or Output) to train their models.
4.2 Model-provider data retention; retention badges. Opal accesses AI models exclusively through a third-party AI gateway and, by default, routes requests to model providers that operate on a zero data-retention (ZDR) basis, under which inputs and Output are not retained beyond what is necessary to return a response and are not used for the provider's own purposes. Certain models do not support ZDR. Any model that retains inputs or Output is identified in the platform with a retention badge displayed at the point of model selection, disclosing that the model retains data and the applicable retention period (currently up to thirty (30) days, solely for security, abuse-detection, and legal-compliance purposes, and not for model training). Unless a model is marked in the platform with a retention badge indicating otherwise, data routed to that model is subject to zero data retention. The current model providers and their retention policies are identified in Annex C.
4.3 Where the Service routes data to third-party model providers or connected systems selected or authorized by Customer, those providers act as Sub-processors (or, where Customer connects them directly, as the Customer's own processors), as identified in Annex C.
4.4 Customer is responsible for ensuring it has a lawful basis and, where required, has provided notices/obtained consent for Personal Data it submits for Agent/AI Processing, for selecting models consistent with its own data-retention requirements (including whether to use models bearing a retention badge), and for configuring appropriate human oversight for automated decisions.
5. Sub-processors
5.1 Customer provides general authorization for Opal to engage Sub-processors, listed in Annex C.
5.2 Opal will impose data-protection obligations on Sub-processors substantially equivalent to this DPA and remains responsible for their performance.
5.3 Opal will give Customer at least thirty (30) days' notice (via the platform, email, or a subscribed list) before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected Service as its sole remedy.
6. Data Subject Rights
Taking into account the nature of Processing, Opal will provide features enabling Customer to access, correct, delete, restrict, or export Customer Personal Data, and will assist Customer with Data Subject requests it cannot fulfill itself. If Opal receives a request directly, it will (unless legally required to act) refer the Data Subject to Customer.
7. Audits
Opal will make available compliance information and, on reasonable notice (no more than once per 12 months except following a Breach or regulator requirement), permit audits by Customer or its independent auditor under confidentiality, during business hours, without unreasonably disrupting operations. Opal may satisfy audit requests by providing current third-party certifications or reports (e.g., SOC 2 / ISO 27001) where available.
8. International Transfers
8.1 Opal is located in Canada. For transfers of Personal Data subject to EU/UK GDPR to a country without an adequacy decision, the parties agree that the SCCs (and, for UK data, the UK Addendum) are incorporated by reference and apply, with:
- Module Two (Controller-to-Processor) where Customer is a controller, and Module Three (Processor-to-Processor) where Customer is a processor;
- Clause 7 (docking) included;
- Clause 9 general authorization for Sub-processors with the notice period in Section 5.3;
- Clause 11 optional redress excluded;
- Clause 17 governing law: Ireland; Clause 18 forum: Ireland;
- Annexes populated by Annexes A–C of this DPA.
8.2 For Canadian transfers, the parties rely on PIPEDA/PIPA accountability and comparable-protection obligations, supported by the measures in Annex B.
9. Deletion and Return
On termination or expiry of the Agreement, Opal will, at Customer's choice, delete or return Customer Personal Data within sixty (60) days, and delete existing copies except where retention is required by law (in which case Opal continues to protect it and Processes it only for the required purpose).
10. Liability and Term
10.1 Each party's liability under this DPA is subject to the limitations of liability in the Agreement.
10.2 This DPA takes effect on the effective date of the Agreement and continues until Opal ceases to Process Customer Personal Data.
Annex A – Details of Processing
- Subject-matter: Provision of the Opal agentic operations platform.
- Duration: For the term of the Agreement plus the retention period in Section 9.
- Nature and purpose: Hosting, storage, processing, and generation of Output; agent/workflow execution; knowledge management; support.
- Categories of Data Subjects: Customer's personnel, Users, and any individuals whose Personal Data Customer includes in Customer Data / Knowledge.
- Categories of Personal Data: Identifiers, contact details, business content, and usage data, as determined and controlled by Customer. Special category / sensitive data: the Service is not designed to process special-category or sensitive data, and Customer must not submit such data except where expressly agreed in writing.
- Data location / residency: Customer Data is hosted in Canada, in the Amazon Web Services Canada (Central) region (
ca-central-1). Customer Data is transmitted outside Canada only when Customer routes it to an AI model provider via the AI gateway (see Annex C). - Frequency: Continuous during the term.
Annex B – Technical and Organizational Security Measures
- No model training on Customer Data.
- Model-provider retention: Opal accesses AI models via a third-party AI gateway and prioritizes zero data-retention (ZDR) providers; non-ZDR models may retain inputs/Output for up to 30 days for security/abuse-detection only, never for training (see Annex C).
- Data residency: Customer Data is hosted in the AWS Canada (Central) region (
ca-central-1). - Encryption in transit (TLS) and at rest.
- Access controls (RBAC and EBAC), least-privilege, and MFA for administrative access.
- Network security, logging, monitoring, and vulnerability management.
- Secure SDLC and change management.
- Personnel confidentiality and security training.
- Backup, resilience, and disaster recovery.
- Incident response and breach detection/notification processes.
- Physical/environmental security of hosting facilities (via cloud provider, AWS).
- Certifications: SOC 2 Type II, ISO/IEC 27001, and ISO/IEC 42001 audits and certification are in progress and not yet complete as of the effective date. Opal will make current attestations/reports available once issued.
Annex C – Approved Sub-processors
Current as of the effective date; the platform / a subscribed list reflects the live set. Model providers are accessed only through the Vercel AI Gateway.
| Sub-processor | Purpose | Location | Retention |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud hosting and storage of Customer Data | Canada (Central) region (ca-central-1) | Retained for the term; deleted/returned per Section 9 |
| Vercel Inc. (Vercel AI Gateway) | AI model routing / gateway | United States | Zero data retention at the gateway; does not retain Customer Data beyond processing |
| AI model providers accessed via the Vercel AI Gateway | AI model inference | Varies by provider (e.g., US, EU) | Most providers operate under zero data retention (ZDR) — no retention beyond returning a response and no training. Certain models do not support ZDR (notably anthropic/claude-fable-5), for which the provider retains inputs/Output for up to 30 days for abuse detection only, and not for training. Any non-ZDR model is flagged in-platform with a retention badge at the point of model selection; current per-model ZDR status is shown in-platform and in the gateway provider's published ZDR documentation. |
| Stripe, Inc. | Payment / billing processing | United States | Retains transaction and billing data per Stripe's terms |
| Opal first-party analytics | Product / usage analytics | AWS Canada (ca-central-1) | Retained per Opal's retention policy |
Questions
For questions about this DPA or to request a countersigned copy, contact legal@deployopal.com.