Data Processing Agreement

Version 1.2 · Last updated: 10 July 2026

1. Roles and Subject Matter

For personal data the Customer or its users enter into opexONE ("Customer Data"), the Customer is the controller and plusRS OÜ ("Processor") is the processor. This DPA applies to the Processor's processing of Customer Data necessary to provide opexONE under the main agreement (the "Agreement").

The Processor is plusRS OÜ, an osaühing (Estonian private limited company), registered in the Republic of Estonia under Estonian Commercial Register (Eesti äriregister) code 17182790, with its registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551.

2. Nature, Purpose and Duration

The Processor processes Customer Data only to provide, secure, maintain and support opexONE, for the duration of the Agreement plus any deletion/return period in § 11. Processing operations include collection, storage, structuring, retrieval, use, transmission, and erasure within the platform.

3. Categories of Data and Data Subjects

Customer Data may include, as configured by the Customer:

  • Identification and contact data of the Customer's users (name, email, role, site, and — where a user registers one for SMS-based sign-in or phone-number verification — a mobile phone number)
  • Operational records the Customer creates (actions, audits, incidents, meetings, etc.)
  • HR/organisational data the Customer chooses to manage in the platform

Data subjects are the Customer's employees, contractors, and other persons whose data the Customer enters. The Processor does not determine the purposes of this processing.

4. Customer Instructions

The Processor processes Customer Data only on the Customer's documented instructions (including via the platform's configuration), unless required by EU or Member-State law — in which case the Processor informs the Customer first, where legally permitted. The Processor informs the Customer if, in its opinion, an instruction infringes the GDPR.

5. Confidentiality

The Processor ensures that persons authorised to process Customer Data are bound by confidentiality and are trained on their data-protection obligations.

6. Security (Art. 32)

The Processor implements appropriate technical and organisational measures, including: tenant isolation enforced at the database layer (row-level security); encryption of data in transit (TLS) and at rest; role-based access control and least-privilege access; audit logging; regular backups; and a documented vulnerability-management and access-review process. Measures are reviewed and updated as the service evolves.

7. Sub-processors

The Customer provides general authorisation for the Processor to engage sub-processors. The current list is published at opexone.io/subprocessors. The Processor imposes data-protection obligations on each sub-processor no less protective than those in this DPA, and remains liable for their performance.

The Processor gives at least 30 days' advance notice of any intended addition or replacement of a sub-processor. The Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees.

8. Assistance to the Customer

Taking into account the nature of processing, the Processor assists the Customer by appropriate measures to: (a) respond to data-subject requests under Chapter III GDPR; and (b) meet its obligations under Art. 32–36 (security, breach notification, data-protection impact assessments, and prior consultation).

9. Personal Data Breach

The Processor notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information the Customer reasonably needs to meet its own Art. 33/34 obligations.

10. International Transfers

Customer Data is hosted in the region configured for the deployment (EU by default; other regions where the Customer selects regional hosting). Where providing the service involves a transfer outside the EEA, it is safeguarded by the EU–US Data Privacy Framework (for certified recipients) and/or the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. The Standard Contractual Clauses are incorporated by reference — Module Two (controller-to-processor) where the Customer acts as controller, and Module Three (processor-to-processor) where the Customer acts as a processor on behalf of a third-party controller — and the Annexes to this DPA (Annexes I–III) serve as the Annexes to those Clauses. In case of conflict between the Standard Contractual Clauses and any other term of this DPA or the Agreement, the Standard Contractual Clauses prevail. See opexone.io/subprocessors for the per-provider mechanism.

11. Return and Deletion

On termination of the Agreement, at the Customer's choice the Processor will return the personal data in a commonly used machine-readable format and/or delete it, and will confirm deletion in writing, unless EU or Member-State law requires retention. The Customer may export its data through the platform during the term and any wind-down period; the Processor deletes Customer Data following a 30-day grace period unless the Customer has elected return, and backups are purged on their ordinary rotation cycle.

12. Audits and Information

The Processor makes available the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates — subject to reasonable notice, confidentiality, and frequency limits. Relevant documentation and certifications are a first step toward demonstrating compliance; the Customer nonetheless retains the right to an audit or inspection on reasonable notice.

13. Liability and Precedence

Liability under this DPA is subject to the limitations in the Agreement. In case of conflict on data-protection matters, this DPA prevails over the Agreement. All other terms of the Agreement remain in force.

14. Governing Law

This DPA is governed by the law of the Republic of Estonia, without prejudice to the GDPR and any mandatory data-protection law of the Customer's jurisdiction.

15. Execution and Effect

This DPA takes effect on the date the Customer accepts the Agreement (whether by clicking to accept, signing an order form, or commencing use of opexONE), whichever is earliest, and remains in force for as long as the Processor processes Customer Data. A countersigned copy for the Customer's procurement records is available on request — on the Processor's side it is executed by a duly authorised representative of plusRS OÜ. No handwritten signature is required for this DPA to bind the parties; acceptance of the Agreement constitutes acceptance of this DPA, including the Standard Contractual Clauses incorporated under § 10 where applicable.

I. Annex I — Details of the Processing

Subject-matter. The provision of the opexONE operations-excellence SaaS platform to the Customer.

Duration. The term of the Agreement plus any wind-down, return, or deletion period under § 11.

Nature and purpose.Hosting and processing the Customer's operational data to deliver the platform on the Customer's instructions, including the operations described in § 2.

Categories of personal data. As determined by the Customer, which controls the exact content:

  • Account and identity data of the Customer's authorised users (name, business email, role, and — where the user registers one for SMS-based sign-in or phone-number verification — a mobile phone number, processed for one-time-passcode delivery via the SMS sub-processor identified in the Sub-processors list)
  • Personal data the Customer's users enter into the platform (e.g. employee records, and the participants in actions, audits, and incidents)

Categories of data subjects.The Customer's personnel, authorised users, and their business contacts.

II. Annex II — Technical and Organisational Measures

The Processor maintains the technical and organisational measures described in § 6, including:

  • Encryption of data in transit (TLS) and at rest
  • Tenant isolation enforced at the database layer (row-level security)
  • Role-based access control and least-privilege access
  • Audit logging
  • Regular backups and tested recovery
  • Secrets management
  • Vendor and sub-processor due diligence

The Processor will not materially reduce the overall level of security during the term.

III. Annex III — Sub-processors

The sub-processors authorised by the Customer are those identified in the public Sub-processors list, published at opexone.io/subprocessors and maintained current in accordance with the change-notification mechanism in § 7.

See also our terms of service, privacy policy, and sub-processor list.