1. Parties & scope
This DPA is entered into between OVirtual Inc. ("Processor") and the Customer identified in the Services Agreement ("Controller"). It forms part of the Agreement and applies to Personal Data Processed on Controller's behalf.
2. Definitions
Capitalized terms have the meanings in the EU GDPR, UK GDPR, and equivalent laws unless otherwise defined here.
3. Roles
Customer is the Controller; OVirtual is the Processor. Each party complies with its respective obligations under Data Protection Laws.
4. Customer instructions
OVirtual Processes Personal Data only on documented Customer instructions, which include the Services Agreement, this DPA, and Customer's configuration of the Services.
5. Confidentiality
Personnel authorized to Process Personal Data are bound by confidentiality obligations or statutory duties of confidence.
6. Security
OVirtual implements the technical and organizational measures in Annex B. We review them at least annually and may update them as long as the level of protection is not reduced.
7. Subprocessors
Customer authorizes the subprocessors in Annex C. We give 30 days' notice before adding or replacing subprocessors. Customer may object on reasonable grounds.
8. Data subject rights
We assist Customer in responding to data subject requests with appropriate technical and organizational measures, and direct any request received directly to the relevant Customer.
9. Personal data breaches
We notify affected Customers without undue delay (and in any case within 72 hours of confirming a Personal Data Breach), providing the information required by Article 33(3) GDPR as it becomes available.
10. International transfers
Where transfers occur from the EEA, UK, or Switzerland to third countries without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module 2) and UK IDTA as applicable.
11. Audits
We provide audit reports (SOC 2 Type II, ISO 27001 when available) on request. Customer may conduct an audit no more than once per year on reasonable notice and at its own cost.
12. Return & deletion
On termination, we return or delete Personal Data within 30 days, subject to legal retention requirements. Backups are purged on rolling 35-day cycles.
Annex A — Processing details
Subject matter
Provision of the OVirtual Services.
Duration
For the term of the Services Agreement, plus retention periods.
Nature & purpose
Hosting, transmitting, displaying, securing, and supporting Customer's use of the Services.
Categories of data subjects
- Customer's personnel
- Customer's end-users (e.g., its customers, leads, contacts)
Categories of Personal Data
- Identifiers (name, email, phone)
- Communications content (messages, calls, voicemails, files)
- Account & usage data
- Business records (proposals, invoices)
Annex B — Technical & organizational measures
- Encryption: AES-256 at rest, TLS 1.2+ in transit.
- Access control: SSO, MFA, role-based access, least privilege.
- Network: WAF, DDoS protection, segmented VPCs.
- Logging & monitoring: centralized audit logs, SIEM with 24/7 alerting.
- Backups: daily encrypted backups, 35-day retention, regional replication.
- Vulnerability management: SAST/DAST in CI, quarterly external pentests.
- Incident response: documented runbooks, 24/7 on-call.
- Personnel: background checks, annual security training, NDAs.
- Vendor management: subprocessor security reviews.
- Business continuity: RTO 4h, RPO 15min.
Annex C — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting | US, Canada, EU |
| Cloudflare | CDN, WAF, DDoS | Global edge |
| Twilio | SMS, voice | US, EU |
| Telnyx | Voice, SIP | US, EU |
| Stripe | Payments | US, EU |
| Postmark | Transactional email | US |
| Sentry | Error monitoring | US |
| Plausible | Privacy-first analytics | EU |
| Intercom | Customer support | US, EU |