OTA-Pulse

Data Processing Agreement

⚠ Draft — this page is a placeholder pending legal review. It does not yet reflect OTA-Pulse's actual terms/policies and should not be relied upon. Contact hello@ota-pulse.com with questions.

This page describes, on an illustrative basis, the terms that would govern OTA-Pulse's processing of personal data on behalf of a customer ("Customer") in connection with the hosted Cloud or Enterprise Services, where applicable data protection law requires such an agreement. It is provided for informational purposes only and is not an executed contract — a signed Data Processing Agreement ("DPA") for your organization is available on request and would be incorporated into, and form part of, the applicable master agreement or order form between OTA-Pulse and Customer.

Scope & Roles

This DPA would apply where OTA-Pulse processes personal data on Customer's behalf in the course of providing the Services. For such processing, Customer acts as the data controller (or, where applicable, processor acting on behalf of its own customers) and OTA-Pulse acts as the data processor (or sub-processor), processing personal data only on documented instructions from Customer and as necessary to provide the Services, except where otherwise required by applicable law.

Subprocessors

OTA-Pulse may engage third-party subprocessors (such as infrastructure hosting and email delivery providers) to support delivery of the Services. Where this DPA is executed, OTA-Pulse would maintain a list of current subprocessors available on request, provide advance notice of material changes, and remain responsible for subprocessor compliance with data-protection obligations substantially equivalent to those in this DPA.

Security Measures

OTA-Pulse maintains technical and organizational security measures appropriate to the risk, including encrypted transport, access controls, and audit logging, as described on our Security page. An executed DPA would incorporate a more detailed security-measures exhibit specific to Customer's deployment.

Data Subject Requests

Where OTA-Pulse receives a request from an individual to exercise their data protection rights (such as access, correction, or deletion) regarding data processed on Customer's behalf, OTA-Pulse would notify Customer and provide reasonable assistance to help Customer respond, without responding directly except as instructed by Customer or required by law.

Breach Notification

If OTA-Pulse becomes aware of a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data processed on Customer's behalf, OTA-Pulse would notify Customer without undue delay and provide available information to help Customer meet its own notification obligations under applicable law.

International Transfers

Where personal data is transferred across borders in connection with the Services, OTA-Pulse would rely on appropriate safeguards recognized under applicable data protection law (such as standard contractual clauses) to the extent required for the relevant transfer.

Term & Termination

This illustrative DPA reflects terms that would remain in effect for as long as OTA-Pulse processes personal data on Customer's behalf under the applicable master agreement, and would terminate automatically upon expiration or termination of that agreement, subject to any data-return or deletion obligations described in an executed version.

Contact

To request a copy of our current DPA for execution, or to ask questions about our data processing practices, contact us at hello@ota-pulse.com .