This DPA forms part of the Business Agent Agreement between Oimpact (Open Impact) (“we”, “us”, “Processor”) and the business that accepted that agreement (“you”, “Controller”). Where this DPA conflicts with the Business Agent Agreement on the handling of personal information, this DPA governs.
You are the controller of the personal information your agent handles. We are the processor. We process that information only on your documented instructions, which are: (a) this DPA, (b) the Business Agent Agreement, and (c) the configuration choices you make in the product — the agent’s instructions, the knowledge you upload, the model and privacy mode you select, and the channels you publish the agent on.
If we are ever required by Canadian or other applicable law to process the information for another purpose, we will tell you before we do, unless that law forbids us telling you.
Subject matter. Operating an AI agent you configure, on your behalf, for the people you make it available to.
Duration. For as long as your account is active, plus the retention periods in section 9.
Nature and purpose. Receiving messages from your end users, passing them with your agent’s configuration to an inference provider, returning the reply, and keeping the records needed to run, bill for, secure and support the service.
We do not ask for and do not want government identifiers, health records, biometric data, or payment card numbers. Card data goes directly to our payment processor and we never hold it.
Your own staff and account holders; the end users who talk to your agent; anyone whose personal information you choose to put into the agent’s instructions or knowledge.
We will:
Encryption in transit for all traffic. Access to production data is limited to the personnel who need it. Secrets are stored hashed. Tenant data is separated at the application layer and every request is scoped to the authenticated business. Acceptance and audit records are append-only.
We do not currently hold SOC 2 or ISO 27001 certification. We say so plainly rather than imply otherwise.
You authorise the following sub-processors:
| Sub-processor | What they do | Where |
|---|---|---|
| Cloudflare | Hosting, edge network, database | Global, incl. USA |
| Privy | Authentication and account identity | USA |
| Stripe | Subscription billing and payments | USA / global |
| Inference providers (including the model providers exposed in the product’s model picker) | Generating your agent’s replies | Varies by model, incl. USA |
We remain responsible to you for our sub-processors’ acts and omissions. We will give you notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected service.
8.1 Knowledge documents can be deleted. Documents you add as Knowledge are stored as text in our database (Cloudflare D1) with your agent, not on a decentralised append-only network. Removing a document in the app deletes that copy from the agent. Backups of the database expire on their normal cycle. Do not upload material you do not have the right to use.
8.2 What “private” mode does and does not mean. Some models and privacy modes run in hardware that keeps prompts private from the model provider. That protects the content from the provider. It does not make the content invisible to us — we operate the service and can access data we process for you in order to run, secure and support it. Do not tell your own customers that we cannot see their data.
We keep personal information for as long as your account is active. On termination we will delete or return it within 90 days, except: (a) legal acceptance records, billing records and other records we are required to keep, which we retain for the period the law requires and process for no other purpose; and (b) backups, which expire on their normal cycle.
If an end user contacts us directly with a request about information we process for you, we will not answer it ourselves — we will pass it to you, because you are the controller. We will help you respond, including by locating, exporting, or deleting the relevant records.
Our infrastructure and sub-processors are located outside Canada, including in the United States. By using the service you instruct us to make those transfers. Where personal information is transferred out of Canada or the EEA, we rely on contractual protections with our sub-processors and, for EEA data, on Standard Contractual Clauses where they apply.
Once in any twelve-month period, on 30 days’ written notice, you may ask us for the information reasonably needed to verify our compliance with this DPA. We will respond in writing. Where a written response is genuinely insufficient for a specific, documented concern, we will discuss a proportionate alternative in good faith. Audits must not compromise the confidentiality or security of other customers.
British Columbia and the federal laws of Canada that apply there, consistent with the Business Agent Agreement.
Oimpact (Open Impact)
Privacy Officer — privacy@oimpact.ai
Legal — legal@oimpact.ai