Open Org Group Ltd
This Data Processing Agreement ("DPA") constitutes Schedule 2 (Data Processing) to the Open Org Workspace Terms of Service ("Terms" or "Agreement") between Open Org Group Ltd ("Open Org", "we", "us", or "our") and the Customer, and sets out the terms on which Open Org processes personal data on behalf of the Customer in connection with the Platform.
This DPA forms part of the Agreement. Capitalised terms not defined in this DPA have the meanings given to them in Schedule 1 (Definitions and interpretation) of the Terms.
1. Definitions
In this DPA:
"Data Protection Laws" means as applicable to and binding on the parties: (a) in the UK: (i) the Data Protection Act 2018; (ii) the UK General Data Protection Regulation (Retained Regulation 2016/679); (iii) the Privacy and Electronic Communications Regulations 2003; and (iv) the Data (Use and Access) Act 2025; and (b) in the EU: (i) the General Data Protection Regulation (Regulation 2016/679); and (ii) any EU member state laws implementing or supplementing the EU GDPR, each as amended or replaced from time to time.
"List of Sub-Processors" means the latest version of the list of Sub-Processors used by Open Org, set out at section 9 (Authorised sub-processors) of this DPA and available on request by emailing hello@openorg.fyi.
"Protected Data" means personal data received from or on behalf of the Customer in relation to Open Org's provision of the Platform under this Agreement, not including personal data processed by Open Org as a controller for the purpose of billing or communicating with the Customer.
"Sub-Processor" means another processor engaged by Open Org for carrying out processing activities in respect of the Protected Data.
The terms controller, data subject, personal data, personal data breach and processor shall have the meaning given to them by the Data Protection Laws.
2. Compliance and roles
2.1 Each party shall at all times during the term of this Agreement comply with the Data Protection Laws.
2.2 The Customer is the controller and Open Org is the processor in respect of the processing of the Protected Data.
3. Details of processing
3.1 Processing of the Protected Data by Open Org under this Agreement shall be for the subject-matter, duration, nature and purposes and involve the types of personal data and categories of data subjects set out in this section 3.
3.2 Subject-matter, nature and purpose of processing. Open Org will host and grant access to the Platform to assist the Customer with its HR operations, including facilitating document generation, survey analysis, job ad creation, roadmap and competency framework creation and the provision of resources and partner discounts. Processing also includes maintaining and improving the Platform (including the AI Functionality) to the extent permitted by clauses 10 and 11 of the Terms, but does not include training, fine-tuning or developing AI models (see section 7). The nature of the processing is the collection, storage, retrieval, organisation, structuring, adaptation, use, transmission to Sub-Processors, analysis and deletion of personal data.
3.3 Duration of processing. Open Org will process the personal data during the Subscription Term and until deleted or returned in accordance with section 4.1(f) of this DPA.
3.4 Categories of personal data. The types of personal data processed under this Agreement may include: (i) names, email address and other contact details; (ii) job titles, roles, and organisational information; (iii) employment history and contractual details; (iv) performance review data, objectives and feedback; (v) survey responses and engagement data; (vi) salary, compensation, and benefits information; (vii) disciplinary and grievance records; (viii) absence and leave records; (ix) training and development records; (x) diversity and inclusion data; (xi) health-related data (e.g. absence reasons or occupational health notes); (xii) racial or ethnic origin data (e.g. diversity monitoring); (xiii) trade union membership; (xiv) data concerning sexual orientation or gender identity; and (xv) any other personal data the Customer or an Authorised User may choose at their discretion to upload to the Platform.
3.5 Categories of data subject. Such types of personal data relate to the Customer's (i) Authorised Users; (ii) personnel; (iii) candidates and job applicants; (iv) contractors, consultants, and temporary workers; (v) former employees and leavers; (vi) survey respondents and feedback participants; and (vii) any other individuals whose personal data the Customer or an Authorised User uploads to the Platform.
4. Open Org's obligations
4.1 In relation to the Protected Data, Open Org shall:
(a) unless required to do otherwise by applicable laws, only process the Protected Data in accordance with the Customer's documented instructions and in accordance with section 3 of this DPA;
(b) taking into account the nature of the processing, implement appropriate technical and organisational measures to protect the Protected Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure (the measures currently in place are described in section 8 of this DPA);
(c) not, without the prior written consent of the Customer, transfer any Protected Data to a country or territory outside the United Kingdom or European Economic Area unless such country or territory has been deemed to provide an adequate level of protection to personal data or adequate contractual or other assurances have first been put in place such as will enable each party to comply with the requirements of the Data Protection Laws;
(d) take reasonable steps to ensure the reliability of its personnel who have access to any Protected Data and ensure that Protected Data shall only be accessible by its personnel to the extent they need to know or require access for the purpose of performing their duties in relation to this Agreement and who are bound to maintain its confidentiality;
(e) notify the Customer without undue delay (and in any event within 72 hours) of any personal data breach that it becomes aware of relating to the Protected Data, and provide reasonable assistance to the Customer in respect of any such personal data breach;
(f) within thirty (30) days of the end of the Subscription Term (including any period of free Subscription) delete or return all Protected Data processed in relation to this Agreement, unless Open Org is required to retain the Protected Data to comply with applicable laws; and
(g) subject to the Customer paying Open Org's reasonable costs (unless prohibited by applicable law), provide such cooperation and assistance to the Customer as the Customer reasonably requires (taking into account the nature of processing and the information available to Open Org) in ensuring compliance with:
(i) the Customer's obligations to respond to any complaint or request from any applicable data protection authority or data subjects seeking to exercise their rights under the Data Protection Laws, including by notifying the Customer of each data subject request Open Org receives in respect of the Protected Data;
(ii) the Customer's obligations to (A) carry out a data protection impact assessment in respect of the Protected Data; and (B) consult the relevant supervisory authority prior to any processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the Customer to mitigate the risk; and
(iii) demonstrating Open Org's compliance with the obligations placed on it under this DPA, by making available to the Customer such information that is in its possession or control as is necessary to demonstrate such compliance, and allowing for audits on mutually agreed dates, at the Customer's cost, by the Customer (or another independent auditor mandated by the Customer) for this purpose (subject to a maximum of one (1) audit request in any twelve (12) month period).
4.2 Open Org shall inform the Customer without undue delay if Open Org believes that a processing instruction infringes Data Protection Laws, provided that to the maximum extent permitted by applicable law, Open Org shall have no liability howsoever arising (whether in contract, tort (including negligence) or otherwise) for any losses arising from or in connection with any processing in accordance with the Customer's unlawful processing instructions.
5. Sub-processors
5.1 The Customer authorises the appointment of each of the Sub-Processors identified on the List of Sub-Processors at the Subscription Start Date. Open Org shall give the Customer thirty (30) days' prior written notice of any change to the List of Sub-Processors. In the event the Customer reasonably believes that any such change materially impacts it negatively in any manner it may by notice elect to terminate its Subscription provided it exercises such right within fourteen (14) days of receipt of the change notification and notifies Open Org in writing at the time of exercising such right of the negative impact which has caused it to exercise this right.
5.2 Prior to any Sub-Processor authorised in accordance with section 5.1 carrying out any processing activities in respect of the Protected Data, Open Org shall appoint each Sub-Processor under a written contract containing materially the same obligations as under this DPA.
5.3 Open Org shall remain fully liable for all the acts and omissions of each Sub-Processor as if they were its own.
6. Customer's obligations
6.1 The Customer warrants, represents and undertakes that all:
(a) Protected Data provided by the Customer to Open Org under this Agreement shall comply in all respects, including in terms of its collection, storage and processing, with Data Protection Laws; and
(b) processing instructions given by it to Open Org in respect of Protected Data shall at all times comply with Data Protection Laws.
7. AI model training and Platform improvement
7.1 Open Org's AI Sub-Processors (currently Anthropic and OpenAI) do not use Protected Data to train, fine-tune or otherwise improve their general-purpose AI models:
-
Anthropic: Under Anthropic's Commercial Terms of Service (Section B) and Data Processing Addendum, Anthropic is contractually prohibited from training models on Customer Content submitted through its commercial API services.
-
OpenAI: Under OpenAI's Enterprise Privacy Policy, Data Processing Addendum, and API Platform Data Controls, data submitted via the API is not used for model training by default. Open Org confirms that it has not opted in to any OpenAI data sharing or model improvement programme.
7.2 Open Org does not use Protected Data to train, fine-tune or develop any AI or machine learning model. Open Org may use Protected Data to maintain and improve the Platform (including the AI Functionality) only to the extent permitted by clauses 10 (Intellectual property rights) and 11 (Intellectual property rights in AI Output) of the Terms, which the parties agree constitute the Customer's documented instructions for this purpose, and in each case in accordance with the Data Protection Laws - but not to train AI models. How Open Org uses personal data as a controller is described in our Privacy Policy.
7.3 AI Sub-Processors may retain API inputs and outputs for a limited period (currently up to 30 days) solely for abuse and safety monitoring purposes, after which they are deleted. This temporary retention does not constitute model training.
8. Technical and organisational security measures
Open Org maintains the following technical and organisational measures to protect Protected Data. Open Org may update these measures from time to time, provided that the updated measures provide no less protection than the measures in place at the time this DPA takes effect.
8.1 Access control
| Measure | Description |
|---|---|
| Authentication | Supabase Auth with JWT token verification on all protected API endpoints; support for email/password and Google OAuth |
| Authorisation | Row Level Security (RLS) policies on database tables, ensuring users can only access their own data |
| Role-based access | Service role keys used only server-side and never exposed to client-side code; admin access restricted to designated email addresses |
| Session management | JWT-based sessions with token expiry and refresh mechanisms |
8.2 Data protection in transit
| Measure | Description |
|---|---|
| Encryption in transit | All traffic encrypted via HTTPS/TLS |
| API security | CORS configured to permit requests only from production Platform domains |
| Webhook verification | Stripe webhook signatures verified using signing secrets to prevent forgery |
8.3 Data protection at rest
| Measure | Description |
|---|---|
| Database encryption | PostgreSQL database encrypted at rest as standard (AES-256, managed by Supabase infrastructure) |
| Object storage | File uploads stored in private storage buckets with access restricted by user identity |
| Secrets management | API keys, database credentials, and other secrets stored as environment variables; not committed to source code |
8.4 Application security
| Measure | Description |
|---|---|
| File upload validation | File type and size validation on all uploads; path traversal prevention |
| API input validation | Request body validation on API endpoints |
| Error handling | Structured error responses; sensitive details excluded from client-facing error messages |
8.5 Monitoring and incident response
| Measure | Description |
|---|---|
| Error monitoring | Sentry integration for real-time error detection and alerting |
| Performance monitoring | Application performance monitoring via Sentry and PostHog |
| Audit logging | Admin access and key operations logged |
| Incident response | Breach notification without undue delay and in any event within 72 hours as per section 4.1(e); internal escalation procedures |
8.6 Organisational measures
| Measure | Description |
|---|---|
| Confidentiality | All personnel with access to Protected Data are subject to confidentiality obligations |
| Access limitation | Access to production systems and Protected Data limited to authorised personnel on a need-to-know basis |
| Sub-processor management | Due diligence conducted on Sub-Processors before engagement; contractual data protection obligations imposed |
9. Authorised sub-processors
The following Sub-Processors are authorised to process Protected Data as of the date of this DPA. Open Org will provide at least 30 days' written notice before engaging any new Sub-Processor or materially changing an existing Sub-Processor's role (see section 5). Customers may subscribe to Sub-Processor change notifications by emailing hello@openorg.fyi.
| Sub-Processor | Purpose | Data processed | Location | Data processing terms |
|---|---|---|---|---|
| Supabase Inc. | Database, authentication, and file storage | All Protected Data stored within the Platform (chat history, uploaded files, AI Output, user profiles, team data) | United Kingdom (London region) | DPA |
| Anthropic PBC | Primary AI provider - chat responses, document generation, and document processing | Chat messages, conversation history, uploaded file contents (including PDFs), context | United States | DPA · Commercial Terms |
| OpenAI, LLC | Secondary AI provider - chat responses, text embeddings, Code Interpreter | Chat messages, conversation history, uploaded file contents, context | United States | DPA · Enterprise Privacy |
| Stripe, Inc. | Payment processing and subscription management | Customer's user ID, email address, subscription metadata (no payment card data is stored by Open Org) | United States | DPA |
| Vercel Inc. | Application hosting and serverless API execution | Protected Data in transit via HTTP requests and responses; server logs | United States / Global edge | DPA |
| The Rocket Science Group LLC (Mailchimp) | Email marketing and subscriber management (opt-in only) | Email address, name, subscription status, tags | United States | DPA |
| Loops Inc. | Transactional email delivery | Email address, gift and referral metadata, team invitation details | United States | DPA |
| PostHog Inc. | Product analytics and feature usage tracking | Pseudonymised user identifier, usage events, page views (EU-hosted instance) | European Union (Frankfurt) | DPA · Privacy |
| Functional Software Inc. (Sentry) | Error monitoring and performance tracking | Error data, stack traces, request metadata (may incidentally include personal data in error context) | European Union (Frankfurt) | DPA |
| Jina AI GmbH | URL content extraction (when users reference external URLs in chat) | URL content fetched at the Customer's request for AI context | Germany / Global | Terms · Privacy |
Open Org Group Ltd · Registered in England and Wales · openorg.fyi