Cloud Data Processing Addendum
Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer using Okapi Cloud (“Customer”) and Justas Raudonius, operating Okapi as an individual business activity in Lithuania (“Okapi”). It applies when Okapi processes personal data contained in events, logs, releases, source maps, project configuration, or related customer content on Customer’s behalf.
Customer is the controller or processor that determines the permitted use of customer content. Okapi acts as Customer’s processor or subprocessor for that content. Account, billing, security, and service-operation data that Okapi determines how to use is covered by the Privacy Policy.
Documented instructions
Okapi processes customer content only to provide, secure, maintain, support, and improve the contracted service; to follow Customer’s configuration and lawful requests; and as required by applicable law. The Terms, this DPA, product configuration, and Customer’s documented support requests together constitute Customer’s instructions.
Customer is responsible for ensuring that its instructions, collection, and submission of personal data are lawful and that it has given required notices and obtained required rights or consents.
Confidentiality and security
People authorized to process customer content are bound by confidentiality obligations. Okapi maintains technical and organizational measures appropriate to the risk, including access controls, encryption in transit, tenant isolation, security logging, data-retention controls, backups, vulnerability and dependency maintenance, and procedures for responding to security incidents.
Current security information is published on the Security page. Customer remains responsible for its project keys, agent tokens, account access, retention choices, and the security of systems that send data to Okapi.
Subprocessors
Customer authorizes Okapi to use subprocessors needed to provide infrastructure, content delivery and security, deployment, communication, support, and payment services. Okapi remains responsible for requiring subprocessors that process customer content to protect it under obligations consistent with this DPA.
Okapi will provide reasonable notice of a material new subprocessor where required by applicable data-protection law. Customer may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable solution.
International transfers
Where customer content is transferred from the European Economic Area, United Kingdom, or Switzerland to a country without an applicable adequacy decision, Okapi will use a legally recognized transfer mechanism, including applicable standard contractual clauses, and supplementary measures where required.
Assistance and incidents
Taking into account the nature of the processing and information available to it, Okapi will provide reasonable assistance with data-subject requests, security obligations, breach notifications, impact assessments, and consultations with supervisory authorities when Customer cannot reasonably fulfill the obligation through the service.
Okapi will notify Customer without undue delay after becoming aware of a personal-data breach affecting customer content and will provide available information reasonably needed for Customer’s response. Notification is not an admission of fault or liability.
Deletion and return
During the subscription, Customer may delete projects and content using the service’s available controls. After termination, Okapi will delete or return customer content on request where reasonably practicable, unless applicable law requires retention. Residual backup copies age out through the backup-retention cycle and remain protected until deletion.
Audit and compliance information
Okapi will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Customer should first use current documentation, security information, and written answers. If those are insufficient and applicable law requires more, the parties may arrange a proportionate audit that protects other customers, confidential information, and service security.
Customer bears its audit costs unless the audit identifies a material breach of this DPA by Okapi. Audits may not unreasonably disrupt the service or include access to another customer’s data.
Term and conflict
This DPA applies for as long as Okapi processes customer content on Customer’s behalf. If this DPA conflicts with the Terms on the processing of customer content, this DPA controls. Mandatory data-protection law controls over both documents.
Contact
Privacy and DPA questions may be sent to useokapi@gmail.com.