Data Processing Agreement
Version 2.0 · Last updated: 13 September 2026
1. Parties, Roles, and Subject Matter
1.1 This Data Processing Agreement ("DPA") forms part of the agreement between the customer (the "Customer") and plusRS OÜ for the use of the opexONE platform (the "Service"), as constituted by the opexONE Terms of Use and any Order (together the "Agreement"). Capitalised terms not defined here have the meaning given in the Terms of Use.
1.2 For personal data that the Customer or its Users enter into, upload to, or generate within the Service ("Customer Data", to the extent it is personal data), the Customer is the controller and plusRS is the processor within the meaning of Art. 4(7) and (8) GDPR. Where the Customer itself acts as a processor for a third-party controller, plusRS acts as sub-processor and the Customer warrants that its instructions under this DPA are covered by the instructions of that controller.
1.3 The processor is plusRS OÜ, an osaühing (Estonian private limited company), registered in the Republic of Estonia under Estonian Commercial Register code 17182790, registered office: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551 ("plusRS", the "Processor").
1.4 This DPA implements Art. 28(3) GDPR for the Processor's processing of Customer Data necessary to provide the Service. In case of conflict with the Agreement on data-protection matters, this DPA prevails; the Standard Contractual Clauses incorporated under § 10 prevail over this DPA to the extent they apply.
2. Nature, Purpose, and Duration of Processing
2.1 The Processor processes Customer Data only to provide, secure, maintain, and support the Service for the duration of the Agreement plus the return/deletion period in § 11.
2.2 Processing operations comprise the collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission within the platform, indexing for search, backup, restriction, erasure, and destruction of Customer Data within the Service, and, where the Customer uses AI Features, the transient processing of Customer Data by the AI sub-processors identified in the Sub-processor List, in European regions, under § 12 of the Terms of Use. The Processor maintains an EU AI Act Compliance Memo describing the AI Features, the Processor's role under Regulation (EU) 2024/1689, and the corresponding obligations; it is provided to the Customer on request.
2.3 Details of the processing are set out in Annex I.
3. Customer Instructions
3.1 The Processor processes Customer Data only on the Customer's documented instructions, unless required to process by Union or Member State law to which the Processor is subject, in which case the Processor informs the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
3.2 Documented instructions are: this DPA, the Agreement, the Customer's configuration of the Service (including roles, permissions, visibility scopes, retention rules, AI scopes, and deletion actions), and any additional written instructions the parties agree. Instructions that exceed the functionality of the standard Service may be declined or made subject to a separate agreement.
3.3 The Processor informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions. The Processor may suspend execution of such an instruction until it is confirmed or modified.
4. Confidentiality of Personnel
The Processor ensures that every person authorised to process Customer Data, such as employees, contractors, and other agents, is bound by a written confidentiality undertaking or an appropriate statutory obligation of confidentiality before receiving access, and is instructed on the data-protection obligations relevant to their role. Access to production systems is additionally governed by § 6a and Annex II.
5. Security of Processing (Art. 32 GDPR)
5.1 The Processor implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the risks for data subjects.
5.2 The Processor may update the measures as technology and threats evolve, provided the overall level of security is not materially reduced during the term of the Agreement.
5.3 The Processor supports the Customer's own Art. 32 obligations by providing the descriptions in Annex II, the published Sub-processor List, and, on reasonable request, further information under § 12.
6a. Operator Access to Customer Data
6a.1 The Service is standard multi-tenant software whose server-side functionality (database-enforced tenant isolation, search, reporting, AI Features) requires that Customer Data is processable in the production environment; application-level encryption that would make Customer Data unreadable to the Processor's production administrators is therefore not part of the Service.
6a.2 As the compensating control, the Processor maintains a Production Access Policy with the following commitments: production access is restricted to named, individually authenticated administrators protected by multi-factor authentication and granted on a least-privilege basis; Customer Data content is accessed only for (i) incident response and security, (ii) support at the Customer's request, (iii) compliance with a legal obligation, or (iv) billing and abuse verification, in each case with the minimum necessary scope; every such access is recorded and periodically reviewed; bulk export of Customer Data outside the platform is prohibited except for the Customer's own export or a documented legal obligation; demonstrations and testing use dedicated demo data, never Customer tenants.
6a.3 On request, the Processor provides the Customer with a current summary of the Production Access Policy and the roster size of authorised administrators.
6. Sub-processors
6.1 The Customer grants a general authorisation for the engagement of sub-processors. The current list, including entity, purpose, location, and transfer safeguard per sub-processor, is published at opexone.io/subprocessors (the "Sub-processor List") and reproduced as a snapshot in Annex III.
6.2 The sub-processors engaged by the Processor are technical infrastructure and service providers that do not process Customer Data for their own purposes and that operate under their own standalone data-processing agreements and published security standards and certifications. The Processor imposes on each sub-processor, by contract, data-protection obligations no less protective than those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
6.3 The Processor announces the intended addition or replacement of a sub-processor at least 30 days in advance by updating the Sub-processor List, which the Customer can monitor and to which the Customer may subscribe for change notifications. Changes announced in Annex III as "pre-announced" count as notified upon acceptance of this DPA.
6.4 The Customer may object within the notice period on reasonable, documented data-protection grounds. The parties will then seek a solution in good faith (e.g. a feature configuration that avoids the sub-processor). If none is found, the Customer may terminate the affected part of the Service — or, where the sub-processor is essential to the Service as a whole, the Agreement — with effect from the date the change takes effect, and receives a pro-rata refund of prepaid fees for the terminated scope.
6.5 Emergency replacements required to maintain security or availability may take effect immediately; the Processor then notifies the Customer without undue delay and the objection mechanism of § 6.4 applies from the notification.
7. Assistance to the Customer
7.1 Data-subject rights (Art. 12–23 GDPR). Taking into account the nature of the processing, the Processor assists the Customer by appropriate technical and organisational measures — primarily the Service's built-in functions (search, export, rectification, deletion, and access management) — in fulfilling the Customer's obligation to respond to data-subject requests. If a data subject contacts the Processor directly regarding Customer Data, the Processor does not respond on the merits but refers the request to the Customer without undue delay.
7.2 Art. 32–36 GDPR. The Processor assists the Customer, insofar as this is possible for a provider of standard multi-tenant software, with the Customer's obligations regarding security, breach notification, data-protection impact assessments, and prior consultation, by providing the information in this DPA and its Annexes and further reasonably available information on request.
7.3 Assistance beyond the Service's standard functions and reasonable information requests may be charged at reasonable rates agreed in advance.
8. Personal Data Breach
8.1 The Processor notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data.
8.2 The initial notification describes at least the nature of the breach and, to the extent then known, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available; the Processor documents the breach and its handling and updates the Customer without undue delay.
8.3 The notification is sent to the Customer's administrative contact(s) on file. The Processor's notification is not an acknowledgement of fault or liability.
8.4 The Customer remains responsible for its own notifications to supervisory authorities (Art. 33) and data subjects (Art. 34).
9. Records; Cooperation with Authorities
The Processor maintains a record of processing activities carried out on behalf of the Customer (Art. 30(2) GDPR) and cooperates, on request, with the competent supervisory authority in the performance of its tasks.
10. International Transfers
10.1 Customer Data is stored at rest within the European Union / EEA (current default region: AWS eu-central-1); § 26 of the Terms of Use applies. The Processor will not transfer primary storage of Customer Data outside the EU/EEA.
10.2 Where providing the Service involves a transfer of Customer Data to a third country (e.g. a sub-processor's support access, SMS delivery, or a group entity of an EU-contracted sub-processor), the transfer is safeguarded by, in order of application: an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified recipients), or the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (the "SCCs"). The per-provider mechanism is stated in the Sub-processor List.
10.3 The SCCs are incorporated into this DPA by reference: Module Two (controller-to-processor) where the Customer acts as controller, and Module Three (processor-to-processor) where the Customer acts as processor, in each case with plusRS as data importer where plusRS processes from outside the EEA (not currently the case), and otherwise as the contractual framework flowed down to sub-processors in third countries. Annexes I–III of this DPA serve as the Annexes to the SCCs; the optional docking clause applies; option 2 of Clause 9(a) (general authorisation, 30 days) applies; the governing-law and forum clauses follow § 14.
10.4 In case of conflict between the SCCs and this DPA or the Agreement, the SCCs prevail.
11. Return and Deletion of Customer Data
11.1 During the term, the Customer can export Customer Data at any time through the Service's export functions (§ 29 Terms of Use).
11.2 Upon termination or expiry of the Agreement, the Customer may export Customer Data until the effective date and, on request, during a 30-day wind-down period thereafter.
11.3 After the wind-down period, or earlier at the Customer's documented request, the Processor deletes all Customer Data from the production systems, unless Union or Member State law requires further storage. Upon written request, the Processor confirms completion of deletion in writing.
11.4 Customer Data contained in encrypted backups is purged automatically by backup rotation and leaves all backup sets no later than 30 days after deletion from production. Backups are not used to restore deleted data except for platform-level disaster recovery.
11.5 Records the Processor retains under its own legal obligations (e.g. invoices, contract-formation records) are retained as controller under its Privacy Policy and are not affected by this Section.
12. Information and Audit Rights (Art. 28(3)(h) GDPR)
12.1 The Processor makes available to the Customer all information necessary to demonstrate compliance with the obligations of Art. 28 GDPR. Information first: the Customer's audit rights are satisfied first by the Processor providing: this DPA and its Annexes, the current Sub-processor List, the Production Access Policy summary (§ 6a.3), the Processor's EU AI Act Compliance Memo for the AI Features, available on request, available third-party attestations and certifications of the Processor's infrastructure providers (e.g. ISO/IEC 27001, SOC 2 reports of the hosting sub-processors), and written answers to reasonable, specific audit questionnaires (at most once per 12 months, absent cause).
12.2 Where the information under § 12.1 is demonstrably insufficient to verify compliance, or where a competent supervisory authority or a documented personal data breach affecting the Customer gives specific cause, the Customer or an independent auditor mandated by it (not a competitor of the Processor, bound to confidentiality) may conduct an audit, including an inspection, under the following conditions: at most once per 12 months (except for cause); at least 30 days' prior written notice (except for cause); during business hours; remote/documentation-based where sufficient; limited in scope to Customer Data processing under this DPA; not extending to other customers' data, to systems or information of other tenants, or to internal security details whose disclosure would itself create a risk; and conducted so as not to disrupt the Processor's operations.
12.3 Costs: each party bears its own costs. The Processor's cooperation beyond one person-day per calendar year is charged at reasonable rates, except for audits triggered by a personal data breach attributable to the Processor or by a supervisory authority's binding request, which are free of charge.
12.4 Audit findings are the Customer's confidential information about the Processor (§ 34 Terms of Use) and may be shared with the Customer's supervisory authority where required.
13. Liability and Precedence
13.1 Liability under this DPA is subject to the limitations and exclusions of the Agreement (§ 38 Terms of Use), except where mandatory data-protection law provides otherwise (in particular Art. 82 GDPR toward data subjects).
13.2 As between the parties, Art. 82(5) GDPR recourse remains available: each party is liable toward the other in proportion to its responsibility for the damage.
13.3 In case of conflict on data-protection matters, this DPA prevails over the Agreement; § 10.4 applies to the SCCs.
14. Term, Governing Law, Jurisdiction
14.1 This DPA takes effect upon acceptance of the Agreement and remains in force for as long as the Processor processes Customer Data under it.
14.2 This DPA is governed by the law of the Republic of Estonia, without prejudice to the GDPR and mandatory data-protection law of the Customer's jurisdiction. The forum clause of the Agreement applies (§ 47 Terms of Use). For the SCCs, the governing law is the law of Estonia and disputes are resolved before the courts of Estonia (Clauses 17 and 18 SCCs, Option 1).
15. Execution and Effect
15.1 This DPA is accepted together with the Terms of Use by the click-acceptance described in § 4 of the Terms of Use; no handwritten signature is required for it to bind the parties. It applies from the first processing of Customer Data.
15.2 A countersigned copy for the Customer's procurement records is available on request from privacy@plusrs.com and is executed on the Processor's side by a duly authorised representative of plusRS OÜ.
15.3 Should individual provisions of this DPA be invalid, the remainder remains unaffected; § 46.5 of the Terms of Use applies.
Annex I — Details of the Processing (also Annex I to the SCCs)
A. List of parties. Data exporter: the Customer (controller; contact details as provided at registration and in the Workspace). Data importer / processor: plusRS OÜ, Ahtri tn 12, 15551 Tallinn, Estonia; contact: privacy@plusrs.com.
B. Description of the processing.
Item | Description |
|---|---|
Subject matter | Provision of the opexONE operations-excellence SaaS platform |
Duration | Term of the Agreement plus the wind-down and deletion periods of § 11 |
Nature and purpose | Hosting, storage, structuring, retrieval, display, transmission within the platform, indexing for search, backup, and deletion of Customer Data to deliver the Service on the Customer's instructions; transient AI processing where the Customer enables AI Features |
Frequency | Continuous, for the duration of the Agreement |
Categories of data subjects | The Customer's employees and contractors (Users and persons referenced in records), other authorised Users, and business contacts of the Customer referenced in Customer Data (e.g. supplier or customer contact persons, visitors) |
Categories of personal data | Account and identity data of Users (name, business email, role, site assignment, language, and, where registered for SMS sign-in/verification, mobile phone number); organisational and HR data the Customer manages in the platform (e.g. employee master data, positions, qualifications, shift assignments); operational records referencing persons (actions, audits, incidents, meetings and minutes, approvals, documents, EHS records); files and attachments uploaded by Users; usage-related metadata within the Workspace (e.g. record authorship, timestamps, activity trails) |
Special categories (Art. 9) | Not required by the Service; may occur where the Customer chooses to record them (e.g. health-related details in incident, absence, or EHS records). The Customer ensures a valid Art. 9 basis; the Processor applies the safeguards of Annex II to all Customer Data uniformly |
Retention | Determined by the Customer through use and configuration of the Service; on termination, § 11 applies (deletion after the 30-day wind-down; backup purge ≤ 30 days thereafter) |
Sub-processor transfers | As per the Sub-processor List (Annex III): subject matter, nature, and duration of each sub-processor's processing are stated there per provider |
C. Competent supervisory authority (Clause 13 SCCs). The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), Tatari 39, 10134 Tallinn, Estonia, as the authority of the Member State of the data exporter's EU representative or, for EU-established exporters, of their establishment; for Customers established in another EU/EEA state, the supervisory authority of that state remains competent for them.
Annex II — Technical and Organisational Measures (Art. 32 GDPR; also Annex II to the SCCs)
1. Physical and environmental security. All production infrastructure runs in professional data centres of the hosting sub-processors (AWS; Supabase on AWS) in the EU, which maintain certified physical security programmes (ISO/IEC 27001, SOC 2). plusRS operates no physical servers holding Customer Data.
2. Encryption. All data in transit is encrypted (TLS 1.2+; HTTPS-only with HSTS). All Customer Data at rest — databases, file storage, and backups — is encrypted with AES-256 at the infrastructure layer. Secrets and credentials are held exclusively in a managed secrets store, never in source code.
3. Access control and authentication (personnel). Production access is governed by the Production Access Policy (§ 6a): named individual accounts only, multi-factor authentication mandatory, least-privilege roles, purpose-bound access to Customer Data content, an access journal with periodic review, same-day revocation on departure, and written confidentiality undertakings before access (§ 4).
4. Tenant separation. Every Customer Workspace is logically isolated. Isolation is enforced at the database layer through row-level security policies on every table carrying tenant data — the database itself, not only the application, rejects cross-tenant access. Automated consistency checks verify that new tables carry isolation policies.
5. Application-layer access control. A role- and permission-based authorisation model governs every read and write within a Workspace, including site-level scoping for multi-site customers and masking of records marked private. AI Features execute strictly within the requesting User's own authorisation context — there is no separate, elevated AI access path.
6. Input control and auditability. User actions on records are captured in in-application activity and audit trails (authorship, timestamps, changes). Infrastructure-level administrative actions are logged by the providers' audit services (e.g. AWS CloudTrail).
7. Availability and resilience. Redundant managed infrastructure of the hosting sub-processors; automated daily backups stored encrypted within the EU; documented restore capability; provider-level DDoS mitigation; monitoring and alerting for availability and abnormal load.
8. Data lifecycle. Self-service export in machine-readable formats; deletion on termination per § 11 with backup purge within 30 days; media sanitisation and disposal handled by the certified hosting providers.
9. Secure development and vendor management. Code review and automated checks for security-relevant invariants (tenant isolation, permission gating) before deployment; separation of staging and production; development and testing against dedicated demo/E2E data, never Customer tenants; documented due diligence and data-processing agreements with every sub-processor (§ 6.2).
10. Incident management. A documented incident-response process covering detection, containment, assessment, customer notification per § 8 (48 hours), and post-incident review.
11. No material reduction. The Processor will not materially reduce the overall level of security described in this Annex during the term.
Annex III — Sub-processors (also Annex III to the SCCs)
The authorised sub-processors are those identified in the published Sub-processor List at opexone.io/subprocessors, maintained current per § 6. Each is a technical infrastructure or service provider engaged under its own standalone data-processing agreement and security standards, as described in § 6.2.
The Sub-processor List, the pre-announced changes, and the third-party embeds that form the rest of this Annex are published at opexone.io/subprocessors.
Annex IV — Suggested Wording for the Customer's Employee Privacy Notice (non-binding)
This Annex is provided for the Customer's convenience only. It is drafting assistance, not legal advice, and forms no part of the Processor's contractual obligations. The Customer remains the controller and is responsible for the accuracy, completeness, and legal basis of its own privacy notice. Text in square brackets is to be completed by the Customer.
Suggested wording (for the Customer to adapt, in the Customer's own voice, addressed to its employees):
opexONE — our operations platform
We use opexONE, a cloud-based operations platform provided by plusRS OÜ (Estonia), to organise and document our day-to-day operational work. This section explains what personal data about you is processed in that platform and why.
What we process. Your account and identity details (name, work email address, job role, site assignment, interface language and, if you use SMS sign-in or phone verification, your mobile number); organisational and HR-related records we maintain in the platform (such as your position, qualifications and shift assignments); operational records that refer to you (for example actions, audits, incidents, meetings and minutes, approvals, documents and health-and-safety records); files and attachments you upload; and activity information generated as you work in the platform (such as who created or changed a record and when).
Why we process it. To plan, carry out and document our operational activities; to manage access and permissions; to meet our legal obligations, including health-and-safety and record-keeping duties; and to investigate incidents. Our legal bases are [our legitimate interests in operating and documenting the business / compliance with a legal obligation / performance of your employment contract].
Special category data. Where an incident, absence or health-and-safety record necessarily includes health-related information about you, we process it on the basis of [Art. 9(2)(b) GDPR - employment, social security and social protection law].
Who can see it. Access inside our organisation is role-based: colleagues see only what their role, site and permissions allow, and records marked private are restricted further. plusRS acts strictly as our service provider under a data processing agreement and does not use the data for its own purposes. Its administrators can access content only for defined reasons, incident response and security, support we request, a legal obligation, or billing and abuse checks, with every access logged and reviewed.
Where it is stored. Data is stored within the European Union. Certain supporting providers may process limited data outside the EU (for example SMS delivery and product-feedback handling); where that happens it is protected by an EU adequacy decision or the European Commission's Standard Contractual Clauses.
AI features. AI assistance operates only within your existing permissions, it cannot surface records you could not otherwise see. Content sent for AI processing is processed in European regions, is not retained by the AI service, and is not used to train AI models.
How long we keep it. For as long as needed for the purposes above and to meet our retention obligations. When our agreement with plusRS ends, the data is deleted from the platform and removed from backups within 30 days thereafter.
Your rights. You can ask us for access to your data, or for correction, deletion, restriction, objection or portability, and you may complain to a supervisory authority. Requests are handled by us, not by plusRS.
See also our terms of use, privacy policy, and sub-processor list.