Data Processing Agreement

Last updated: 2026-09-22

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between BGMS Consultants Limited, trading as OpenDQV Cloud (“we”, “us”, the “processor”) and the customer (“you”, the “controller”). It applies whenever you process personal data through the Service — for example, when records you validate, or the audit metadata they generate, contain personal data.

For that data, you are the controller and we are your processor under Article 28 UK GDPR / EU GDPR. For our own records about your account — signup, billing, technical logs, and the statistics described in §3 — we are the controller, as described in our Privacy Policy; that processing is outside this DPA.

2. Details of the processing

  • Subject matter — write-time validation of data records against the data quality contracts you configure, and the audit metadata this generates.
  • Duration — the life of your account, plus the deletion window in §11. Audit metadata is retained for your plan's audit retention window (Privacy Policy §3) and removed on a rolling basis before then.
  • Nature and purpose — evaluating records you submit against your rules and returning the result; recording validation metadata in your audit trail; no other purpose, save the statistics described in §3.
  • Types of personal data and categories of data subjects — determined and controlled by you: whatever personal data is present in the records you choose to validate. Validation payloads are held in memory only while they are validated and are not written to the audit trail, backups, application logs, the engine's durable audit queue, or metrics (§5); audit metadata is limited to the fields described in Privacy Policy §2.2.

3. Your instructions

We process personal data only on your documented instructions. Your instructions are: the data quality contracts you configure, the validation requests you (and your team and systems) submit through the API, dashboard, and MCP connector, your region selection at signup, and the settings you choose in the product — plus any further written instructions we agree to, unless we are required to process by law to which we are subject, in which case we will inform you of that requirement before processing unless the law prohibits it. We will tell you if, in our opinion, an instruction infringes data protection law.

We do not use Customer Data — validation payloads, audit metadata, or contract content — to train, fine-tune, or otherwise develop or improve any machine-learning or artificial-intelligence model, whether ours or a third party’s, and we do not disclose Customer Data to any third party for that purpose.

We do not use Customer Data for any purpose other than providing the Service and producing the statistics described in this paragraph. Those statistics are counts derived from your audit metadata, grouped by the sector and size you gave us at signup, and we hold them as our own records, of which we are controller under our Privacy Policy; the names of your top failing rules are held only for your own reports and are never published. You may exclude your workspace from our published findings at any time, free of charge, using the report setting in your workspace profile; we honour that setting for every edition whose cut-off falls while your account is open. When your account closes, its figures are reduced to sector totals attributable to no workspace — or discarded, if it was excluded when it closed — and no total we keep or publish rests on fewer than ten workspaces. Findings already published are not withdrawn. The prohibition on model training is unchanged.

4. Confidentiality of personnel

Access to personal data processed under this DPA is limited to personnel authorised to operate the Service, who are bound by confidentiality obligations.

5. Security

We implement appropriate technical and organisational measures, including: encryption in transit (TLS) on every customer-facing surface; encryption at rest on every cloud provider we run on; validation payloads held in memory only while they are validated and not written to the audit trail, backups, application logs, the engine's durable audit queue, or metrics; your audit trail stored only in the region you selected (your contract definitions (the YAML you author) are stored on Amazon S3 in the jurisdiction you selected, whichever cloud runs your engine), isolated per account, and protected by a sealed, tamper-evident hash chain that makes alteration or deletion detectable and independently verifiable; restricted, authenticated access to production systems; and role-based access controls within your account.

6. Sub-processors

You give general authorisation for the sub-processors we use to provide the Service. The canonical current list, with a dated change log, is maintained at /subprocessors. The sub-processors as at the date of this DPA are: Cloudflare (hosting, routing, and coordination — no validation content), the cloud provider of the region you selected (infrastructure for your engine and audit trail), Amazon Web Services (object storage for your contract definitions, in the jurisdiction you selected, whichever cloud runs your engine), Stripe (billing — no validation data), and Resend (transactional email — sign-in links, account, billing and lifecycle notices; processes account holder names and email addresses, no validation data — in use since launch; its listing here corrects an earlier omission from this list, not the addition of a new sub-processor). We will notify you by email at least 30 days before adding or replacing a sub-processor; if you do not accept the change, you may cancel under the Terms of Service before it takes effect. Any sub-processor is bound by data protection obligations at least as protective as this DPA, and we remain responsible to you for its performance.

7. Assistance with data subject rights

Taking into account the nature of the processing — transient payloads, and audit metadata that contains personal data only where your records place it there — we assist you in responding to data subject requests through the product itself: your audit trail is exportable at any time, and deletion is available as described in §11. We will also provide such further reasonable assistance as you request, taking into account the nature of the processing and the information available to us. If a data subject contacts us directly about data you control, we will refer them to you without undue delay and will not respond on your behalf except on your instruction or where required by law.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will provide information reasonably available to us to help you meet your own notification obligations.

9. Data protection impact assessments

We will provide reasonable assistance with data protection impact assessments and prior consultations, to the extent the required information is available to us, taking into account the nature of the processing.

10. International transfers

Your validation is processed, and your audit trail stored, only in the region you selected at signup, and your contract definitions (the YAML you author) are stored on Amazon S3 in the jurisdiction you selected, whichever cloud runs your engine; we never move either to another region. Requests transit Cloudflare's global edge network under its data processing addendum, incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. If your choice of region gives rise to a restricted transfer under data protection law that applies to you, that choice is your instruction, and — where UK or EU GDPR applies — the EU Standard Contractual Clauses (Module 2, controller to processor), as amended by the UK International Data Transfer Addendum where relevant, are incorporated into this DPA by reference, with you as data exporter and us as data importer.

For the purposes of the incorporated Clauses: Annex I is completed by §2 of this DPA together with the parties' account details; Annex II is completed by §5; Annex III is completed by §6 and the canonical list at /subprocessors. For the sub-processor clause, the general-written-authorisation option applies with the notice period in §6. The competent supervisory authority is that of the data exporter. The tables of the UK Addendum are completed by the same information, and either party may end the UK Addendum as set out in its terms. Where you act as a processor for your own clients, references to “controller” in this DPA include you in that capacity, we act as your sub-processor, and Module 3 (processor to processor) of the Clauses applies in place of Module 2.

Where the region you select is operated by a cloud sub-processor outside the UK and the European Economic Area, our agreement with that sub-processor incorporates the transfer safeguards it publishes — including Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum, where required.

11. Return and deletion

You can export your contracts and your full retained audit log at any time from the dashboard or the API. Thirty days after a paid account closes (seven days after a trial ends), all personal data processed under this DPA is permanently deleted — engine, contracts, audit history, and backups — except records we are legally required to keep, which are retained only as long as the law requires, as described in the Terms of Service and Privacy Policy.

12. Audit and information

On request, we will make available the information reasonably necessary to demonstrate compliance with this DPA — documentation of the measures in §5, our sub-processor list, and the tamper-evident verification of your own audit trail, which you can run yourself at any time through the product. We will allow and contribute to audits, including inspections, conducted by you or your mandated auditor: no more than once in any 12-month period (except after a personal data breach affecting your data or where required by your regulator), on at least 30 days’ written notice, at your cost, during business hours, and without access to other customers’ data or to systems that would compromise their security — in which case we will provide equivalent evidence by other means.

13. California Consumer Privacy Act

Where the California Consumer Privacy Act (as amended) applies to personal information you process through the Service, we act as your service provider. We do not sell or share that personal information as those terms are defined by the CCPA; we will not retain, use, or disclose it for any purpose other than performing the Service for you or as otherwise permitted by the CCPA; we will not combine it with personal information received from other sources except as the CCPA permits a service provider to do; and we certify that we understand and will comply with these restrictions. We will notify you if we determine that we can no longer meet our obligations under the CCPA, and you may take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information. References in this DPA to “controller” and “processor” include “business” and “service provider” where the CCPA applies.

14. Liability, changes and precedence

This DPA is subject to the limitations of liability in the Terms of Service. Changes to this DPA follow the same process as changes to the Terms of Service (Terms §14): material changes are notified by email at least 30 days before they take effect, and you may cancel before a change takes effect. If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of personal data under it, this DPA prevails. Questions about this DPA: privacy@opendqv.com.

OpenDQV Cloud — Terms of Service · Privacy Policy