OpenDD

Data Processing Agreement

Last updated: July 21, 2026 · Effective date: July 21, 2026
This Data Processing Agreement ("DPA") supplements and forms part of the Terms of Service between OpenDD and the customer. It applies to the extent OpenDD processes Personal Data on the customer's behalf that is subject to the EU or UK General Data Protection Regulation ("GDPR") or comparable data-protection law. This is a template provided for transparency; it is not legal advice. Customers with specific requirements may contact us to execute a countersigned copy.
1. Definitions 2. Roles & Scope 3. Processing Instructions 4. Confidentiality 5. Security Measures 6. Sub-processors 7. Data-Subject Requests 8. Personal-Data Breaches 9. DPIAs & Consultation 10. Deletion & Return 11. Audits 12. International Transfers 13. Liability & Term Annex I — Details of Processing Annex II — Security Measures Annex III — Sub-processors

1. Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data that OpenDD Processes on behalf of the Customer under the Terms of Service. "Data Protection Law" means the EU GDPR, the UK GDPR and Data Protection Act 2018, and other applicable data-protection or privacy laws. "Sub-processor" means a third party engaged by OpenDD to Process Customer Personal Data. "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission for the transfer of Personal Data to third countries.

2. Roles & Scope

As between the parties, the Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and OpenDD is the Processor of Customer Personal Data. OpenDD processes very limited Personal Data: primarily account contact details (email address; in future, telephone number) and any Personal Data contained in documents or search inputs the Customer chooses to submit. Payment card data is processed directly by our payment provider (Stripe) as an independent controller/processor and is not handled by OpenDD. This DPA applies to OpenDD's Processing of Customer Personal Data and does not apply to information sourced by OpenDD from public records, which OpenDD processes as an independent Controller.

3. Processing Instructions

OpenDD will Process Customer Personal Data only on the Customer's documented instructions, including as set out in the Terms of Service, this DPA, and the Customer's use of the Service, unless required otherwise by law (in which case OpenDD will, where legally permitted, inform the Customer). OpenDD will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. OpenDD will not sell Customer Personal Data or Process it for its own independent purposes, and does not use Customer-uploaded documents to train artificial-intelligence models.

4. Confidentiality

OpenDD ensures that persons authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality and are subject to appropriate access controls, and Process such data only as necessary to provide the Service.

5. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, OpenDD implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II. OpenDD regularly reviews and, where appropriate, improves these measures.

6. Sub-processors

The Customer provides general authorization for OpenDD to engage Sub-processors to Process Customer Personal Data. OpenDD maintains a current list of Sub-processors at opendd.onrender.com/subprocessors. OpenDD imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for its Sub-processors' performance. OpenDD will give the Customer reasonable prior notice of the addition or replacement of a Sub-processor (for example, by updating the Sub-processor page or by email where the Customer has subscribed to notifications), and the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service.

7. Assistance with Data-Subject Requests

Taking into account the nature of the Processing, OpenDD will assist the Customer by appropriate technical and organizational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests to exercise Data-Subject rights (access, rectification, erasure, restriction, portability, and objection). If OpenDD receives such a request directly from a Data Subject relating to Customer Personal Data, it will, where lawful, direct the Data Subject to the Customer or forward the request without undue delay.

8. Personal-Data Breaches

OpenDD will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal-Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to assist the Customer in meeting its own notification obligations. OpenDD will take reasonable steps to mitigate and remediate the breach.

9. Data-Protection Impact Assessments

OpenDD will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with supervisory authorities, in each case solely in relation to OpenDD's Processing of Customer Personal Data and taking into account the information available to OpenDD.

10. Deletion & Return

Upon termination of the Service, or at the Customer's request, OpenDD will delete or return Customer Personal Data (including documents uploaded to the Customer's account) within a reasonable period, and delete existing copies unless retention is required by law. Documents uploaded to a Customer's account can be deleted by the Customer at any time from within the Service, and account deletion removes the Customer's associated Personal Data.

11. Audits

OpenDD will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To satisfy this obligation, OpenDD may provide relevant third-party certifications, audit reports (such as a SOC 2 report when available), and completed security questionnaires. Audits are subject to reasonable notice, confidentiality, and frequency limits, and must not compromise the security or data of other customers.

12. International Transfers

OpenDD and its Sub-processors may Process Customer Personal Data in countries outside the EEA or UK. Where such a transfer would otherwise lack an adequate level of protection, the parties agree that the applicable Standard Contractual Clauses (including the UK Addendum and Swiss adaptations where relevant) are incorporated into this DPA by reference and apply to the transfer, with OpenDD as data exporter/importer as applicable. OpenDD's key Sub-processors (including Anthropic and Stripe) provide their own SCC-backed transfer mechanisms, which OpenDD relies upon in addition to those in this DPA.

13. Liability & Term

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA takes effect when the Customer accepts the Terms of Service and continues while OpenDD Processes Customer Personal Data. In the event of a conflict between this DPA and the Terms of Service regarding the Processing of Personal Data, this DPA prevails.

Annex I — Details of Processing

Subject matterProvision of the OpenDD due-diligence platform.
DurationFor the term of the Terms of Service and until deletion/return of Customer Personal Data.
Nature & purposeHosting an account; authenticating users; running due-diligence searches; analyzing documents the Customer uploads; generating reports; and related support.
Categories of Data SubjectsThe Customer's authorized users; and any individuals whose Personal Data appears in documents or search inputs the Customer chooses to submit.
Types of Personal DataAccount contact data (email; in future, telephone number); authentication data; usage/log data; and any Personal Data contained in Customer-submitted documents or search inputs. OpenDD does not require and does not intend to Process special-category data; the Customer should avoid submitting it unless necessary and lawful.
Payment dataProcessed directly by Stripe; not stored by OpenDD (OpenDD receives only limited transaction metadata such as status).

Annex II — Technical & Organizational Measures

OpenDD maintains measures appropriate to the risk, including: encryption of data in transit (TLS); access controls and least-privilege access to production systems; hashed and salted password storage; session-based authentication; segregation of customer data by account; logging and monitoring; use of reputable cloud infrastructure and sub-processors with their own recognized security programs; secure software-development practices; and data-deletion capabilities available to customers. OpenDD is pursuing formal certification (SOC 2) and will make the report available under audit obligations when complete.

Annex III — Sub-processors

The current list of Sub-processors, including each Sub-processor's role, the data it processes, and its location, is maintained at opendd.onrender.com/subprocessors and forms part of this Annex.

Need a countersigned DPA, or have questions about our data-processing terms? Reach us through our Contact page.