Data Processing
Addendum
GDPR Article 28 DPA — available free with any paid plan. Request the countersigned copy at [email protected].
Standard DPA template covering processor roles, sub-processor authorisation, security measures, breach notification, and international data transfers under Standard Contractual Clauses. Primary data residency is in the EU (Germany); some sub-processors operate in the US or globally under appropriate safeguards, and you can request a copy of those safeguards at [email protected].
What the template covers
Processor roles
You are the controller; Omega is the processor. We process personal data only on your documented instructions, including with regard to transfers.
Sub-processor authorisation
General authorisation for the listed sub-processors, with notice before any addition or replacement.
Security measures
Technical and organisational measures: encryption in transit and at rest, access controls, and the safeguards described in our security page.
Breach notification
Notification without undue delay after becoming aware of a personal-data breach affecting your data.
International transfers
Primary data residency is in the EU (Germany). Some sub-processors — including AI model providers, authentication, payments, email, source hosting, and CDN (see the full list at /subprocessors) — operate in the US or globally; personal data is transferred to them under appropriate safeguards (Standard Contractual Clauses and/or adequacy). Request a copy of the safeguards at [email protected].
Get the full template
Full PDF available on request — email [email protected].
Processor: OmegaHQ Ltd (full identity in the signed document and on the Terms page). To execute this DPA for your organisation, email [email protected] — we countersign and return a signed copy.