Skip to main content
OVirtual OVirtual
Product Features Pricing Customers FAQ
Sign in Start free→
Product Features Pricing Customers FAQ
Sign in Start free trial
Home / Data Processing Agreement

Data Processing Agreement

The processor agreement governing OVirtual's handling of personal data on your behalf.

Last updated · January 8, 2026·Effective · January 15, 2026
On this page
  1. Parties & scope
  2. Definitions
  3. Roles
  4. Customer instructions
  5. Confidentiality
  6. Security
  7. Subprocessors
  8. Data subject rights
  9. Personal data breaches
  10. International transfers
  11. Audits
  12. Return & deletion
  13. Annex A — Processing details
  14. Annex B — Security measures
  15. Annex C — Subprocessor list

1. Parties & scope

This DPA is entered into between OVirtual Inc. ("Processor") and the Customer identified in the Services Agreement ("Controller"). It forms part of the Agreement and applies to Personal Data Processed on Controller's behalf.

2. Definitions

Capitalized terms have the meanings in the EU GDPR, UK GDPR, and equivalent laws unless otherwise defined here.

3. Roles

Customer is the Controller; OVirtual is the Processor. Each party complies with its respective obligations under Data Protection Laws.

4. Customer instructions

OVirtual Processes Personal Data only on documented Customer instructions, which include the Services Agreement, this DPA, and Customer's configuration of the Services.

5. Confidentiality

Personnel authorized to Process Personal Data are bound by confidentiality obligations or statutory duties of confidence.

6. Security

OVirtual implements the technical and organizational measures in Annex B. We review them at least annually and may update them as long as the level of protection is not reduced.

7. Subprocessors

Customer authorizes the subprocessors in Annex C. We give 30 days' notice before adding or replacing subprocessors. Customer may object on reasonable grounds.

8. Data subject rights

We assist Customer in responding to data subject requests with appropriate technical and organizational measures, and direct any request received directly to the relevant Customer.

9. Personal data breaches

We notify affected Customers without undue delay (and in any case within 72 hours of confirming a Personal Data Breach), providing the information required by Article 33(3) GDPR as it becomes available.

10. International transfers

Where transfers occur from the EEA, UK, or Switzerland to third countries without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module 2) and UK IDTA as applicable.

11. Audits

We provide audit reports (SOC 2 Type II, ISO 27001 when available) on request. Customer may conduct an audit no more than once per year on reasonable notice and at its own cost.

12. Return & deletion

On termination, we return or delete Personal Data within 30 days, subject to legal retention requirements. Backups are purged on rolling 35-day cycles.

Annex A — Processing details

Subject matter

Provision of the OVirtual Services.

Duration

For the term of the Services Agreement, plus retention periods.

Nature & purpose

Hosting, transmitting, displaying, securing, and supporting Customer's use of the Services.

Categories of data subjects

  • Customer's personnel
  • Customer's end-users (e.g., its customers, leads, contacts)

Categories of Personal Data

  • Identifiers (name, email, phone)
  • Communications content (messages, calls, voicemails, files)
  • Account & usage data
  • Business records (proposals, invoices)

Annex B — Technical & organizational measures

  • Encryption: AES-256 at rest, TLS 1.2+ in transit.
  • Access control: SSO, MFA, role-based access, least privilege.
  • Network: WAF, DDoS protection, segmented VPCs.
  • Logging & monitoring: centralized audit logs, SIEM with 24/7 alerting.
  • Backups: daily encrypted backups, 35-day retention, regional replication.
  • Vulnerability management: SAST/DAST in CI, quarterly external pentests.
  • Incident response: documented runbooks, 24/7 on-call.
  • Personnel: background checks, annual security training, NDAs.
  • Vendor management: subprocessor security reviews.
  • Business continuity: RTO 4h, RPO 15min.

Annex C — Subprocessors

SubprocessorPurposeLocation
Amazon Web ServicesCloud hostingUS, Canada, EU
CloudflareCDN, WAF, DDoSGlobal edge
TwilioSMS, voiceUS, EU
TelnyxVoice, SIPUS, EU
StripePaymentsUS, EU
PostmarkTransactional emailUS
SentryError monitoringUS
PlausiblePrivacy-first analyticsEU
IntercomCustomer supportUS, EU
Privacy Policy →Terms of Service →Fair Usage Policy →Security →
OVirtualOVirtual

The unified workspace for service businesses. One screen. One bill. One source of truth.

Product
Unified InboxBusiness PhoneVideoProposalsCRMHelp Center
Company
AboutCustomersCareersPressContact
Resources
BlogChangelogDocsMigrationStatus
Legal
Privacy PolicyTerms of ServiceFair Usage PolicyDPASecurity
© 2026 OVirtual Inc. Made in Toronto · Shipped daily