Data Processing Agreement
This Data Processing Agreement ("Agreement") is the Article 28 contract between the organization customer ("Controller") and OpenApp ("Processor") for personal data the Controller stores in the OpenApp service.
It forms part of the Terms of Service when the Controller uses OpenApp for an organization (not only a personal workspace). If this Agreement conflicts with the Terms on processing of Controller personal data, this Agreement controls.
Privacy contact: tomer+privacy@openapp.house.
This document is an operational Article 28 template. Counsel should confirm registered company details, liability caps, and insurance before a signed customer contract.
1. Roles
The Controller determines the purposes and means of processing resident, visitor, invitation, intercom-session, directory, and access-event data in the Service.
OpenApp processes that data only on documented instructions from the Controller (configuration in the product, APIs, and this Agreement), plus processing required to provide, secure, and maintain the Service.
OpenApp is a separate controller of account credentials, End-User License Agreement records, product security logs, and sales/feedback inquiries, as described in the Privacy Policy.
2. Details of processing (GDPR Art. 28(3) and Art. 30)
- Subject matter: hosting and operating physical access control, virtual intercom, invitations, directories, and audit for the Controller's sites.
- Duration: the subscription term plus the retention periods in the Privacy Policy and this Agreement.
- Nature: storage, transmission, display, access-control evaluation, push notification, optional AI directory enrich, and optional customer-connected integrations.
- Purpose: provide the Service the Controller ordered.
- Categories of data subjects: residents, household members, visitors, invitees, staff, and administrators the Controller enters or invites.
- Categories of personal data: names, contact details, photos the Controller uploads, invitation metadata, access and call-session metadata (not server-side recordings of live video or voice), guest session identifiers, push tokens, and locations the Controller stores.
- Special category data: the Service is not designed to extract biometric templates. Live video is transmitted for the call and is not stored server-side as a recording. The Controller must not instruct OpenApp to process special-category data unless a lawful basis is documented.
3. Processor obligations
OpenApp shall:
- process Controller personal data only on documented instructions, including for transfers, unless required by EU or member-state law;
- ensure persons authorized to process the data are bound by confidentiality;
- take the Article 32 security measures described in the Privacy Policy (TLS in transit, encryption at rest for primary stores, access control);
- respect the conditions for engaging subprocessors (section 4);
- assist the Controller with data-subject requests, taking into account the nature of processing and information available (in-product export/delete for the Controller's users, and privacy contact tomer+privacy@openapp.house);
- assist with Articles 32–36 (security, breach, data-protection impact assessment, prior consultation) as reasonably needed;
- delete or return Controller personal data after the end of services, at the Controller's choice, unless EU or member-state law requires storage (including the audit keep-set in section 7);
- make available information necessary to demonstrate compliance and allow audits as described in section 8.
4. Subprocessors
The Controller authorizes OpenApp to engage the subprocessors listed at Subprocessors. OpenApp will post material changes to that list and give the Controller a reasonable opportunity to object before a new subprocessor processes Controller personal data (except emergency security replacements, which will be notified as soon as practicable).
Customer-connected products the Controller enables (for example PalGate Cloud at palgate.com) are not OpenApp-operated subprocessors. The Controller is responsible for that vendor relationship. OpenApp transmits the data categories the integration requires.
Customer-configured audit webhook URLs are destinations the Controller chooses. The Controller is controller of those onward transfers.
5. International transfers
Primary hosting is Amazon Web Services eu-central-1. Extra-European Economic
Area subprocessors OpenApp engages (Google, Apple push, and similar) are listed
on the subprocessor page with the transfer tool used (Standard Contractual
Clauses and/or EU–US Data Privacy Framework for participating organizations).
6. Controller instructions and data-subject rights
The Controller is responsible for notices to residents, visitors, and people added by an administrator (GDPR Art. 13/14), for lawful bases, and for responding to data-subject requests about Controller data.
OpenApp provides Controller tools: user and invitation administration, audit export, retention override within the platform maximum, and deletion of the Controller's residents and visitors (subject to permissions). Personal-workspace users may self-serve erasure of their own account data.
Visitor and guest requests about building data should be directed to the Controller. OpenApp will assist as processor.
7. Retention and erasure
Default retention:
- account and resource rows: while active, then typically 60 days after soft-delete before purge;
- audit events: 30 days queryable in Postgres; about 7 years in object storage (Controller may set a shorter org retention, not longer than the platform maximum);
- store catalog after delete: up to 1 year;
- operational logs: typically 14 days.
After erasure of a person, new audit rows for that identity keep event type, outcome, timestamp, and technical identifiers — not display names — where Article 17(3) requires the log to survive (security, legal claims, proof of access).
8. Audits
Upon reasonable written notice, OpenApp will provide information reasonably necessary to demonstrate Article 28 compliance (policies, this Agreement, the public privacy audit mapping, and available security summaries). On-site audits are limited to what is proportionate, do not unreasonably disrupt operations, and may be replaced by independent reports when they address the same questions.
This Agreement is not an ISO/IEC 27001, ISO/IEC 27701, or SOC 2 certification.
9. Personal-data breaches
OpenApp will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data, with the information reasonably available to help the Controller meet GDPR Articles 33 and 34 (72-hour supervisory notice where required, and communication to data subjects when required). Details: breach-notification.md in this package and the public mapping page.
10. Liability
Liability between the parties for this Agreement follows the limitation of liability in the Terms of Service, except that nothing excludes liability that cannot be limited under applicable data-protection law.