Back
Open Org Workspace
Updated June 11, 2026Legal

Data Processing Agreement

See also:Terms of ServicePrivacy Policy

Open Org Group Ltd

This Data Processing Agreement ("DPA") constitutes Schedule 2 (Data Processing) to the Open Org Workspace Terms of Service ("Terms" or "Agreement") between Open Org Group Ltd ("Open Org", "we", "us", or "our") and the Customer, and sets out the terms on which Open Org processes personal data on behalf of the Customer in connection with the Platform.

This DPA forms part of the Agreement. Capitalised terms not defined in this DPA have the meanings given to them in Schedule 1 (Definitions and interpretation) of the Terms.

1. Definitions

In this DPA:

"Data Protection Laws" means as applicable to and binding on the parties: (a) in the UK: (i) the Data Protection Act 2018; (ii) the UK General Data Protection Regulation (Retained Regulation 2016/679); (iii) the Privacy and Electronic Communications Regulations 2003; and (iv) the Data (Use and Access) Act 2025; and (b) in the EU: (i) the General Data Protection Regulation (Regulation 2016/679); and (ii) any EU member state laws implementing or supplementing the EU GDPR, each as amended or replaced from time to time.

"List of Sub-Processors" means the latest version of the list of Sub-Processors used by Open Org, set out at section 9 (Authorised sub-processors) of this DPA and available on request by emailing hello@openorg.fyi.

"Protected Data" means personal data received from or on behalf of the Customer in relation to Open Org's provision of the Platform under this Agreement, not including personal data processed by Open Org as a controller for the purpose of billing or communicating with the Customer.

"Sub-Processor" means another processor engaged by Open Org for carrying out processing activities in respect of the Protected Data.

The terms controller, data subject, personal data, personal data breach and processor shall have the meaning given to them by the Data Protection Laws.

2. Compliance and roles

2.1 Each party shall at all times during the term of this Agreement comply with the Data Protection Laws.

2.2 The Customer is the controller and Open Org is the processor in respect of the processing of the Protected Data.

3. Details of processing

3.1 Processing of the Protected Data by Open Org under this Agreement shall be for the subject-matter, duration, nature and purposes and involve the types of personal data and categories of data subjects set out in this section 3.

3.2 Subject-matter, nature and purpose of processing. Open Org will host and grant access to the Platform to assist the Customer with its HR operations, including facilitating document generation, survey analysis, job ad creation, roadmap and competency framework creation and the provision of resources and partner discounts. Processing also includes maintaining and improving the Platform (including the AI Functionality) to the extent permitted by clauses 10 and 11 of the Terms, but does not include training, fine-tuning or developing AI models (see section 7). The nature of the processing is the collection, storage, retrieval, organisation, structuring, adaptation, use, transmission to Sub-Processors, analysis and deletion of personal data.

3.3 Duration of processing. Open Org will process the personal data during the Subscription Term and until deleted or returned in accordance with section 4.1(f) of this DPA.

3.4 Categories of personal data. The types of personal data processed under this Agreement may include: (i) names, email address and other contact details; (ii) job titles, roles, and organisational information; (iii) employment history and contractual details; (iv) performance review data, objectives and feedback; (v) survey responses and engagement data; (vi) salary, compensation, and benefits information; (vii) disciplinary and grievance records; (viii) absence and leave records; (ix) training and development records; (x) diversity and inclusion data; (xi) health-related data (e.g. absence reasons or occupational health notes); (xii) racial or ethnic origin data (e.g. diversity monitoring); (xiii) trade union membership; (xiv) data concerning sexual orientation or gender identity; and (xv) any other personal data the Customer or an Authorised User may choose at their discretion to upload to the Platform.

3.5 Categories of data subject. Such types of personal data relate to the Customer's (i) Authorised Users; (ii) personnel; (iii) candidates and job applicants; (iv) contractors, consultants, and temporary workers; (v) former employees and leavers; (vi) survey respondents and feedback participants; and (vii) any other individuals whose personal data the Customer or an Authorised User uploads to the Platform.

4. Open Org's obligations

4.1 In relation to the Protected Data, Open Org shall:

(a) unless required to do otherwise by applicable laws, only process the Protected Data in accordance with the Customer's documented instructions and in accordance with section 3 of this DPA;

(b) taking into account the nature of the processing, implement appropriate technical and organisational measures to protect the Protected Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure (the measures currently in place are described in section 8 of this DPA);

(c) not, without the prior written consent of the Customer, transfer any Protected Data to a country or territory outside the United Kingdom or European Economic Area unless such country or territory has been deemed to provide an adequate level of protection to personal data or adequate contractual or other assurances have first been put in place such as will enable each party to comply with the requirements of the Data Protection Laws;

(d) take reasonable steps to ensure the reliability of its personnel who have access to any Protected Data and ensure that Protected Data shall only be accessible by its personnel to the extent they need to know or require access for the purpose of performing their duties in relation to this Agreement and who are bound to maintain its confidentiality;

(e) notify the Customer without undue delay (and in any event within 72 hours) of any personal data breach that it becomes aware of relating to the Protected Data, and provide reasonable assistance to the Customer in respect of any such personal data breach;

(f) within thirty (30) days of the end of the Subscription Term (including any period of free Subscription) delete or return all Protected Data processed in relation to this Agreement, unless Open Org is required to retain the Protected Data to comply with applicable laws; and

(g) subject to the Customer paying Open Org's reasonable costs (unless prohibited by applicable law), provide such cooperation and assistance to the Customer as the Customer reasonably requires (taking into account the nature of processing and the information available to Open Org) in ensuring compliance with:

(i) the Customer's obligations to respond to any complaint or request from any applicable data protection authority or data subjects seeking to exercise their rights under the Data Protection Laws, including by notifying the Customer of each data subject request Open Org receives in respect of the Protected Data;

(ii) the Customer's obligations to (A) carry out a data protection impact assessment in respect of the Protected Data; and (B) consult the relevant supervisory authority prior to any processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the Customer to mitigate the risk; and

(iii) demonstrating Open Org's compliance with the obligations placed on it under this DPA, by making available to the Customer such information that is in its possession or control as is necessary to demonstrate such compliance, and allowing for audits on mutually agreed dates, at the Customer's cost, by the Customer (or another independent auditor mandated by the Customer) for this purpose (subject to a maximum of one (1) audit request in any twelve (12) month period).

4.2 Open Org shall inform the Customer without undue delay if Open Org believes that a processing instruction infringes Data Protection Laws, provided that to the maximum extent permitted by applicable law, Open Org shall have no liability howsoever arising (whether in contract, tort (including negligence) or otherwise) for any losses arising from or in connection with any processing in accordance with the Customer's unlawful processing instructions.

5. Sub-processors

5.1 The Customer authorises the appointment of each of the Sub-Processors identified on the List of Sub-Processors at the Subscription Start Date. Open Org shall give the Customer thirty (30) days' prior written notice of any change to the List of Sub-Processors. In the event the Customer reasonably believes that any such change materially impacts it negatively in any manner it may by notice elect to terminate its Subscription provided it exercises such right within fourteen (14) days of receipt of the change notification and notifies Open Org in writing at the time of exercising such right of the negative impact which has caused it to exercise this right.

5.2 Prior to any Sub-Processor authorised in accordance with section 5.1 carrying out any processing activities in respect of the Protected Data, Open Org shall appoint each Sub-Processor under a written contract containing materially the same obligations as under this DPA.

5.3 Open Org shall remain fully liable for all the acts and omissions of each Sub-Processor as if they were its own.

6. Customer's obligations

6.1 The Customer warrants, represents and undertakes that all:

(a) Protected Data provided by the Customer to Open Org under this Agreement shall comply in all respects, including in terms of its collection, storage and processing, with Data Protection Laws; and

(b) processing instructions given by it to Open Org in respect of Protected Data shall at all times comply with Data Protection Laws.

7. AI model training and Platform improvement

7.1 Open Org's AI Sub-Processors (currently Anthropic and OpenAI) do not use Protected Data to train, fine-tune or otherwise improve their general-purpose AI models:

  • Anthropic: Under Anthropic's Commercial Terms of Service (Section B) and Data Processing Addendum, Anthropic is contractually prohibited from training models on Customer Content submitted through its commercial API services.

  • OpenAI: Under OpenAI's Enterprise Privacy Policy, Data Processing Addendum, and API Platform Data Controls, data submitted via the API is not used for model training by default. Open Org confirms that it has not opted in to any OpenAI data sharing or model improvement programme.

7.2 Open Org does not use Protected Data to train, fine-tune or develop any AI or machine learning model. Open Org may use Protected Data to maintain and improve the Platform (including the AI Functionality) only to the extent permitted by clauses 10 (Intellectual property rights) and 11 (Intellectual property rights in AI Output) of the Terms, which the parties agree constitute the Customer's documented instructions for this purpose, and in each case in accordance with the Data Protection Laws - but not to train AI models. How Open Org uses personal data as a controller is described in our Privacy Policy.

7.3 AI Sub-Processors may retain API inputs and outputs for a limited period (currently up to 30 days) solely for abuse and safety monitoring purposes, after which they are deleted. This temporary retention does not constitute model training.

8. Technical and organisational security measures

Open Org maintains the following technical and organisational measures to protect Protected Data. Open Org may update these measures from time to time, provided that the updated measures provide no less protection than the measures in place at the time this DPA takes effect.

8.1 Access control

MeasureDescription
AuthenticationSupabase Auth with JWT token verification on all protected API endpoints; support for email/password and Google OAuth
AuthorisationRow Level Security (RLS) policies on database tables, ensuring users can only access their own data
Role-based accessService role keys used only server-side and never exposed to client-side code; admin access restricted to designated email addresses
Session managementJWT-based sessions with token expiry and refresh mechanisms

8.2 Data protection in transit

MeasureDescription
Encryption in transitAll traffic encrypted via HTTPS/TLS
API securityCORS configured to permit requests only from production Platform domains
Webhook verificationStripe webhook signatures verified using signing secrets to prevent forgery

8.3 Data protection at rest

MeasureDescription
Database encryptionPostgreSQL database encrypted at rest as standard (AES-256, managed by Supabase infrastructure)
Object storageFile uploads stored in private storage buckets with access restricted by user identity
Secrets managementAPI keys, database credentials, and other secrets stored as environment variables; not committed to source code

8.4 Application security

MeasureDescription
File upload validationFile type and size validation on all uploads; path traversal prevention
API input validationRequest body validation on API endpoints
Error handlingStructured error responses; sensitive details excluded from client-facing error messages

8.5 Monitoring and incident response

MeasureDescription
Error monitoringSentry integration for real-time error detection and alerting
Performance monitoringApplication performance monitoring via Sentry and PostHog
Audit loggingAdmin access and key operations logged
Incident responseBreach notification without undue delay and in any event within 72 hours as per section 4.1(e); internal escalation procedures

8.6 Organisational measures

MeasureDescription
ConfidentialityAll personnel with access to Protected Data are subject to confidentiality obligations
Access limitationAccess to production systems and Protected Data limited to authorised personnel on a need-to-know basis
Sub-processor managementDue diligence conducted on Sub-Processors before engagement; contractual data protection obligations imposed

9. Authorised sub-processors

The following Sub-Processors are authorised to process Protected Data as of the date of this DPA. Open Org will provide at least 30 days' written notice before engaging any new Sub-Processor or materially changing an existing Sub-Processor's role (see section 5). Customers may subscribe to Sub-Processor change notifications by emailing hello@openorg.fyi.

Sub-ProcessorPurposeData processedLocationData processing terms
Supabase Inc.Database, authentication, and file storageAll Protected Data stored within the Platform (chat history, uploaded files, AI Output, user profiles, team data)United Kingdom (London region)DPA
Anthropic PBCPrimary AI provider - chat responses, document generation, and document processingChat messages, conversation history, uploaded file contents (including PDFs), contextUnited StatesDPA · Commercial Terms
OpenAI, LLCSecondary AI provider - chat responses, text embeddings, Code InterpreterChat messages, conversation history, uploaded file contents, contextUnited StatesDPA · Enterprise Privacy
Stripe, Inc.Payment processing and subscription managementCustomer's user ID, email address, subscription metadata (no payment card data is stored by Open Org)United StatesDPA
Vercel Inc.Application hosting and serverless API executionProtected Data in transit via HTTP requests and responses; server logsUnited States / Global edgeDPA
The Rocket Science Group LLC (Mailchimp)Email marketing and subscriber management (opt-in only)Email address, name, subscription status, tagsUnited StatesDPA
Loops Inc.Transactional email deliveryEmail address, gift and referral metadata, team invitation detailsUnited StatesDPA
PostHog Inc.Product analytics and feature usage trackingPseudonymised user identifier, usage events, page views (EU-hosted instance)European Union (Frankfurt)DPA · Privacy
Functional Software Inc. (Sentry)Error monitoring and performance trackingError data, stack traces, request metadata (may incidentally include personal data in error context)European Union (Frankfurt)DPA
Jina AI GmbHURL content extraction (when users reference external URLs in chat)URL content fetched at the Customer's request for AI contextGermany / GlobalTerms · Privacy

Open Org Group Ltd · Registered in England and Wales · openorg.fyi

Contents

  • 1. Definitions
  • 2. Compliance and roles
  • 3. Details of processing
  • 4. Open Org's obligations
  • 5. Sub-processors
  • 6. Customer's obligations
  • 7. AI model training and Platform improvement
  • 8. Technical and organisational security measures
  • 9. Authorised sub-processors

About

Open Org Workspace is a platform for planning, building and shipping your People team projects, faster.

Subscribe to our newsletter

Quick Links

Terms of ServicePrivacy PolicyData Processing AgreementDocumentationLinkedIn

Open Org Ecosystem

Culture SupportOpenverseCommunity
©2026Open Org Group Ltd
Built with ♥️ by John & Adam