OpenSay Data Processing Addendum (DPA)
Last edited: Sep 4, 2026
Enterprise Data Processing Addendum governing personal data processing under EU GDPR, UK GDPR, Swiss FADP, and international transfer standards. Effective September 4, 2026.
Data Processing Addendum (DPA)
Low-Touch SaaS Online Acceptance: OpenSay provides modern software-as-a-service subscriptions on a self-serve, low-touch basis without requiring manual paper contracts. By purchasing a subscription, activating a trial, installing the OpenSay application into a workspace, or using the Services, Customer legally accepts and enters into this DPA as an incorporated, binding agreement alongside our Terms of Service, our Subprocessors Registry, and our AI Usage & Data Security Policy. No separate manual contract signature is required for standard self-serve customers. Countersigned DPA copies and custom enterprise agreements remain available for enterprise-tier customers upon request.
Executive Summary & Quick Reference Matrix
For corporate legal, procurement, and compliance teams reviewing OpenSay's data protection posture, the key commercial terms and statutory safeguards of this DPA are summarized below:
| Provision | Contractual Standard & Guarantee | Section Reference |
|---|---|---|
| Online Acceptance | Accepted automatically upon purchasing a SaaS subscription, starting a trial, or installing the app into a workspace | Recitals & Execution Options |
| Customer Role | Data Controller (determines workspace purpose and authorized channels) | Section 2.1 |
| OpenSay Role | Data Processor (processes data solely per documented customer instructions) | Section 2.1 |
| Order of Precedence | This DPA strictly prevails over conflicting terms in any MSA, Terms of Service, or Order Form | Recital B |
| AI Content Moderation | Zero Model Training: Customer prompts and outputs are never used to train models. Zero PII: User identities and emails are stripped prior to safety analysis. Ephemeral Processing: In-flight edge evaluation via Cloudflare Workers AI (Llama default) or selectable Google Gemini. |
Section 3 & AI Policy |
| Cross-Border Transfers | EU: EU Standard Contractual Clauses (Decision 2021/914, Module 2: Controller-to-Processor) UK: ICO International Data Transfer Addendum (Version B1.0) U.S. Infrastructure: Certified under EU-U.S. Data Privacy Framework & UK Extension |
Section 6 & Annex 4 |
| Subprocessor Notice | 30 Calendar Days advance written notice prior to onboarding new vendors | Section 5.2 |
| Security Incident Notice | Notification without undue delay and within 72 hours of confirmed breach | Section 7.1 |
| Technical Measures (TOMs) | Enforced TLS 1.3 transit encryption, AES-256 rest encryption, one-way cryptographic hashing with random nonces and rotating peppers (rainbow table proof), and Cloudflare DDoS edge shield | Section 4 & Annex 2 |
| Data Deletion at Term | Irreversible, automated database purge within 14 calendar days of termination | Section 10.2 |
Recitals
A. Customer has entered into an agreement with OpenSay by purchasing a software-as-a-service subscription, activating a trial, installing the OpenSay application into Customer's workspace, or executing an enterprise Order Form or Master Services Agreement (the "Agreement") pursuant to which OpenSay provides workplace anonymity, whistleblower hotlines, suggestion boxes, and pulse survey applications.
B. The parties agree that this DPA supplements and is incorporated into the Agreement. For self-serve SaaS customers, this DPA is accepted and becomes legally binding upon completing an online subscription purchase, starting a trial, or installing the application into a workspace. In the event of any conflict between the Agreement and this DPA regarding the processing of Personal Data, this DPA shall control and prevail.
1. Definitions and Statutory Framework
Unless otherwise defined herein, capitalized terms shall have the meanings set forth below or in the Agreement:
- "Applicable Data Protection Law" means all worldwide privacy, data security, and data protection legislation applicable to the processing of Personal Data under the Agreement, including:
- The General Data Protection Regulation (EU) 2016/679 ("EU GDPR");
- The UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR");
- The Swiss Federal Act on Data Protection of 25 September 2020 ("Swiss FADP"); and
- The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" shall have the meanings ascribed to them in the EU GDPR and UK GDPR.
- "Personal Data Breach" means any confirmed breach of OpenSay's security controls leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or processed by OpenSay.
- "Subprocessor" means any authorized third-party vendor engaged by OpenSay that processes Customer Personal Data in connection with the delivery of the Services.
- "Standard Contractual Clauses" or "EU SCCs" means the standard contractual clauses approved under European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (Module 2: Controller-to-Processor).
- "UK International Data Transfer Addendum" or "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (ICO) under section 119A(1) of the Data Protection Act 2018.
2. Scope, Roles & Documented Instructions
- Roles of the Parties: The parties acknowledge that with respect to Customer Personal Data, Customer is the Data Controller and OpenSay is the Data Processor acting solely on Customer's behalf.
- Documented Instructions: OpenSay shall process Personal Data exclusively on documented instructions from Customer, including with respect to transfers to third countries, unless required to do so by applicable EU, Member State, UK, or other applicable law. In such case, OpenSay shall inform Customer of that legal requirement before processing, unless prohibited by law on important grounds of public interest.
- Customer Instructions: The Agreement, this DPA, and Customer's ongoing configuration of settings in the OpenSay Dashboard constitute Customer's complete, documented instructions to OpenSay for the processing of Personal Data.
- Infringement Notification: OpenSay shall immediately inform Customer if, in its reasonable opinion, an instruction given by Customer infringes Applicable Data Protection Law.
3. Artificial Intelligence & Automated Content Moderation
OpenSay incorporates Artificial Intelligence (AI) and Large Language Models (LLMs) to perform automated pre-flight safety screening, toxicity filtering, and workspace policy enforcement on messages submitted by users. The parties agree to the following mandatory contractual safeguards:
- Zero Model Training Guarantee: OpenSay contractually guarantees that Customer prompts, message submissions, whisper conversations, survey responses, and AI moderation outputs are never used to train, retrain, improve, or fine-tune foundational AI models by OpenSay, Google LLC, Cloudflare, Inc., Meta Platforms, Inc., or any other third party.
- Zero-PII Data Minimization: OpenSay implements automated server-side data minimization prior to dispatching text to any AI moderation endpoint. User identifiers (including Slack user IDs, real names, email addresses, workspace domain names, and client IP addresses) are irreversibly excluded from moderation payloads. Only the isolated text content and objective safety rules are evaluated.
- Ephemeral In-Flight Processing: All AI content moderation is executed in-flight. Prompts and outputs are processed ephemerally in volatile memory and purged immediately upon classification. No customer content submitted for AI moderation is retained for post-hoc analysis.
- Enterprise Service Tiers & Engines: OpenSay executes moderation via Cloudflare Workers Enterprise AI (Meta Llama default for ultra-low latency) and Google Cloud Gemini API Paid Services Quota (selectable via dashboard). All third-party AI APIs are procured exclusively under commercial enterprise agreements that legally disclaim model training and enforce data processing terms.
- Incorporation of AI Usage Policy: The technical details, security boundaries, and transfer mechanisms governing OpenSay's AI systems are set forth in the OpenSay AI Usage & Data Security Policy, which is incorporated into this DPA by reference.
4. Technical and Organizational Security Measures (TOMs)
- Implementation of TOMs: Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, OpenSay shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
- Standard Controls: OpenSay's TOMs include, without limitation:
- Encryption in Transit: Enforced TLS 1.3 protocol across all external endpoints, webhook receivers, and API integrations.
- Encryption at Rest: AES-256 bit encryption across all database records, file stores, and backups within Google Cloud Platform.
- Nonce-Salted Cryptographic Hashing: Irreversible SHA-256 one-way hashing combining user identifiers with per-interaction random nonces and an isolated, weekly rotating 256-bit secret pepper (stored outside the database). This structure mathematically neutralizes rainbow table attacks and precomputed dictionary lookups, preventing database records from correlating interactions to user identities.
- Network Defense & DDoS Shielding: Edge serverless ingestion via Cloudflare Anycast with automated Layer 3/4/7 DDoS mitigation, SSL termination, and Web Application Firewall (WAF) filtering.
- Least Privilege Access: Multi-factor authentication (MFA) and role-based access control (RBAC) enforced on all administrative access to production systems.
- Security Documentation: A comprehensive description of OpenSay's security controls is set forth in Annex 2 and at the OpenSay Security Portal.
5. Subprocessors & Supply Chain Oversight
- General Authorization: Customer hereby grants OpenSay general written authorization to engage the subprocessors listed in the OpenSay Subprocessors Registry.
- Advance Notification of Changes: OpenSay shall provide Customer with at least thirty (30) calendar days' advance written notice of any intended changes concerning the addition or replacement of a subprocessor. Notification shall be delivered via updates to the public registry, email notifications, and in-dashboard announcements.
- Right to Object: Customer may object to a new subprocessor on reasonable data protection grounds by notifying OpenSay in writing within thirty (30) calendar days of receiving notice. In the event of an objection, the parties shall cooperate in good faith to resolve the concern. If no mutually acceptable resolution can be reached, Customer may terminate the affected Services upon written notice without penalty.
- Subprocessor Obligations: OpenSay shall impose data protection terms on each subprocessor that provide at least the same level of protection for Customer Personal Data as those in this DPA. OpenSay remains fully liable to Customer for the performance of each subprocessor's obligations.
6. International Data Transfers
- Global Infrastructure & Transfer Safeguards: OpenSay operates on enterprise-grade, globally distributed cloud infrastructure. To the extent Customer Personal Data is processed outside the European Economic Area or the United Kingdom, OpenSay ensures that appropriate transfer mechanisms and statutory safeguards are established in full compliance with Chapter V of the EU GDPR and UK GDPR.
- Transfers from the EEA: Where Personal Data subject to the EU GDPR is transferred to a country not recognized as providing an adequate level of protection, the parties agree that the EU Standard Contractual Clauses (Decision 2021/914, Module 2: Controller-to-Processor) shall apply, as detailed in Annex 4.
- Transfers from the United Kingdom: Where Personal Data subject to the UK GDPR is transferred to a third country, the parties agree that the UK International Data Transfer Addendum (Version B1.0) issued by the ICO shall apply, as set forth in Annex 4.
- U.S. Data Privacy Framework: OpenSay verifies that its primary U.S. subprocessors (Google LLC and Cloudflare, Inc.) maintain active certifications under the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
7. Personal Data Breach Notification & Response
- Breach Notification: OpenSay shall notify Customer in writing without undue delay, and in any event within seventy-two (72) hours, upon confirming a Personal Data Breach affecting Customer Personal Data.
- Notification Content: The notification shall, to the extent available, provide:
- A description of the nature of the breach, including categories and approximate numbers of data subjects and records concerned;
- The identity and contact details of OpenSay's Data Protection Officer;
- The likely consequences of the security incident; and
- The remediation measures taken or planned to mitigate potential adverse effects.
- Remediation & Assistance: OpenSay shall immediately take all commercially reasonable steps to contain, remediate, and mitigate the effects of any Personal Data Breach, and shall reasonably assist Customer in fulfilling its statutory notification obligations to supervisory authorities and affected individuals.
8. Audits, Compliance Certifications & Inspections
- Audit Evidence: OpenSay shall make available to Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. OpenSay shall satisfy this obligation primarily by providing copies of independent third-party audit reports (such as SOC 2 Type II or ISO 27001 certifications) and completed industry security questionnaires (e.g., CAIQ or SIG).
- On-Site Audits: If Customer reasonably requires an on-site inspection or technical audit, Customer may conduct such audit upon at least thirty (30) business days' prior written notice, during normal business hours, subject to reasonable confidentiality and security protocols, and at Customer's sole expense.
9. Data Subject Rights & Regulatory Assistance
- Data Subject Requests: Taking into account the nature of processing, OpenSay shall provide reasonable technical and organizational assistance to enable Customer to respond to requests by Data Subjects exercising their statutory rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection).
- Direct Requests: If OpenSay receives a request directly from a Data Subject, OpenSay shall promptly notify Customer and advise the Data Subject to submit their request directly to Customer as Controller.
- DPIA & Consultation Assistance: OpenSay shall provide reasonable assistance to Customer in conducting Data Protection Impact Assessments (DPIAs) and prior consultations with competent supervisory authorities, to the extent required under Applicable Data Protection Law.
10. Term, Data Return & Irreversible Deletion
- Term: This DPA shall remain in full force and effect for the duration of the Agreement and until all Customer Personal Data has been returned or permanently deleted by OpenSay.
- Data Deletion at Termination: Within fourteen (14) calendar days following the expiration or termination of the Agreement (or upon uninstallation of the OpenSay application from all workspaces), OpenSay shall irreversibly delete all Customer Personal Data in its possession or control, including database records, user profiles, and backups, unless applicable law requires continued retention.
11. Governing Law & Dispute Resolution
- Governing Law: This DPA and any non-contractual obligations arising out of or in connection with it shall be governed by:
- The laws of Ireland for claims and disputes arising under the EU GDPR;
- The laws of England and Wales for claims and disputes arising under the UK GDPR; and
- The governing law specified in the Agreement for all other matters.
- Jurisdiction: Any dispute arising under this DPA shall be submitted to the exclusive jurisdiction of the competent courts in the governing jurisdiction identified above.
Annex 1: Details of Data Processing
- Data Exporter (Controller): Customer (as identified in the Order Form, subscription record, or Agreement).
- Data Importer (Processor): Heterodox Ltd., d/b/a OpenSay (Contact: [email protected] / [email protected]).
- Categories of Data Subjects: Authorized workspace users of Customer's collaboration platforms (Slack, Microsoft Teams, Google Chat), including employees, contractors, consultants, and workspace administrators.
- Categories of Personal Data:
- Workspace & Channel Identifiers: Slack Workspace ID, team domain, channel IDs, and channel names.
- User Profile Metadata: First and last name, business email, username, avatar URL, and Slack User ID (collected via OAuth for administrative login and roster synchronization).
- Communication Payloads: Message text, replies, whispers, and poll choices submitted by users.
- Billing Details: Business contact name, email, billing address, and tax/VAT number (processed directly by merchant of record Paddle).
- Special Categories of Data (Article 9 GDPR): OpenSay does not intentionally collect, solicit, or require any sensitive or special categories of data. Users are advised against submitting sensitive personal data to anonymous channels.
- Nature and Purpose of Processing: Processing text submissions to provide workplace anonymous communication, whistleblower whisper reporting, continuous suggestion boxes, peer kudos, and pulse surveys.
- Duration of Processing: For the active term of the Agreement, plus a fourteen (14) calendar day grace period following uninstallation to permit orderly data purge.
Annex 2: Technical and Organizational Security Measures (TOMs)
OpenSay enforces enterprise-grade security controls designed to guarantee data confidentiality, integrity, availability, and resilience:
- Cryptographic Standards:
- Data in Transit: Forced HTTPS with TLS 1.3 encryption across all public endpoints, REST APIs, and Slack webhooks.
- Data at Rest: AES-256 bit encryption across all Google Cloud Firestore databases, storage buckets, and encrypted snapshots.
- Nonce-Salted Cryptographic Hashing for Polls & Pseudonyms:
- Poll votes, karma ratings, and thread pseudonyms are generated via one-way SHA-256 cryptographic hashing combining user IDs with unpredictable per-interaction random nonces and an isolated, rotating 256-bit secret pepper (
ROTATIONAL_SECRET_PEPPER). - Rainbow Table Attack Immunity: By combining unpredictable context nonces with an external secret pepper, OpenSay mathematically invalidates precomputed rainbow tables and brute-force dictionary attacks, ensuring user IDs cannot be dehashed or deanonymized even with direct database access.
- The secret pepper is injected exclusively at runtime in Cloudflare Workers edge memory and is segregated from Firestore databases, with historical peppers permanently purged upon weekly rotation.
- Poll votes, karma ratings, and thread pseudonyms are generated via one-way SHA-256 cryptographic hashing combining user IDs with unpredictable per-interaction random nonces and an isolated, rotating 256-bit secret pepper (
- Network & Perimeter Defense:
- Front-end ingestion managed by Cloudflare Workers serverless runtime across a globally distributed Anycast network.
- Automated Layer 3/4/7 DDoS protection, rate-limiting, and Web Application Firewall (WAF) rule sets.
- Access Control & Identity Security:
- Multi-Factor Authentication (MFA) mandatory for all engineering personnel accessing internal infrastructure.
- Role-Based Access Control (RBAC) enforcing least-privilege principles.
- Zero direct public database exposure; all access requires short-lived IAM credentials.
- Vulnerability Management & SDLC:
- Continuous automated dependency vulnerability scanning via automated CI/CD pipelines.
- Automated code quality reviews and Jest test suites ensuring Block Kit UI integrity and schema validation.
- Incident Response & Resilience:
- Formal incident management playbooks with 24/7 on-call engineering escalation.
- Contractual commitment to 72-hour breach notification to affected Controllers.
Annex 3: Subprocessors Registry
A live, auditable registry of all approved third-party subprocessors is maintained at:
Every subprocessor is bound by a formal DPA incorporating Article 28 GDPR obligations, strict confidentiality, and certified international transfer safeguards (EU-U.S. DPF, UK Extension, and EU SCCs).
Annex 4: Standard Contractual Clauses & UK Addendum
-
European Union Transfers (EU SCCs 2021/914): For transfers from the European Economic Area to third countries without an adequacy decision, the European Commission Standard Contractual Clauses (Decision 2021/914, Module 2: Controller-to-Processor) are incorporated by reference:
- Clause 7 (Docking Clause): Included.
- Clause 9 (Use of Subprocessors): Option 2 (General written authorization) applies with a thirty (30) calendar day advance notification window.
- Clause 11 (Redress): The optional dispute resolution mechanism is omitted.
- Clause 17 (Governing Law): The laws of Ireland.
- Clause 18 (Choice of Forum): The courts of Ireland.
- Annex I & II: Populated with the details set forth in Annex 1 and Annex 2 of this DPA.
-
United Kingdom Transfers (UK Addendum): For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0) issued by the ICO is incorporated:
- Table 1 (Parties): Populated with Customer (Data Exporter) and OpenSay / Heterodox Ltd. (Data Importer).
- Table 2 (Selected SCCs): The Approved EU SCCs (Module 2) referenced above.
- Table 3 (Appendix Information): Annex 1 and Annex 2 of this DPA.
- Table 4 (Ending the Addendum): Both parties may end the Addendum in accordance with Section 19 of the UK Addendum.
- Governing Law & Forum: The laws of England and Wales; exclusive jurisdiction in the courts of England and Wales.
-
Swiss Transfers (Swiss FADP): For transfers subject to the Swiss FADP, the EU SCCs shall apply with necessary adaptations as mandated by the Federal Data Protection and Information Commissioner (FDPIC).
Execution & Integration Options
/dpa/ in your Order Form or Master Services Agreement automatically incorporates this DPA without requiring separate signatures.Option B (Enterprise Countersigned PDF Envelope): If your organization's legal or enterprise procurement policy requires a bespoke countersigned copy of this DPA and the UK Addendum / EU SCCs, please submit your company details and authorized signee information to [email protected]. Our compliance team will promptly issue a countersigned electronic envelope via DocuSign or Adobe Sign.