DPA

Data Processing Addendum

Processor terms for customer workspace data, including subprocessors, transfers, audit support, and security measures.

Last updated: July 25, 2026

This DPA is between Matthew Andrew Terblanche, trading as OptiGPU ("OptiGPU"), and Customer and supplements the Terms of Service. Matthew Andrew Terblanche, trading as OptiGPU Torenallee 101, 5617 BR Eindhoven, Netherlands KVK 42060575 · VAT NL005463593B43 Version 2026-07-25-v1

1. Definitions

Terms have the meaning given in the GDPR (Regulation (EU) 2016/679). "Customer Personal Data" means personal data processed by OptiGPU on behalf of Customer through the Service.

2. Roles

2.1 OptiGPU acts as processor for Customer Personal Data uploaded to or generated within Customer's workspace, including cloud-billing data.

2.2 OptiGPU acts as controller for account profile and login data, billing/invoicing data, support-ticket metadata, security and audit logs, and marketing data (subject to applicable legal basis). The Privacy Notice applies to that processing.

3. Processing instructions

OptiGPU processes Customer Personal Data only on Customer's documented instructions as set out in the Terms of Service, this DPA, and Customer's use of the Service. OptiGPU will notify Customer if it considers an instruction to infringe data-protection law.

4. Confidentiality

OptiGPU ensures persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security

OptiGPU implements appropriate technical and organisational measures as set out in Annex II (TOMs).

6. Subprocessors

6.1 Customer grants OptiGPU general authorisation to engage subprocessors. The current list is maintained at https://optigpu.ai/subprocessors.

6.2 OptiGPU will give Customer 30 days' prior notice (by email to the account's billing contact, by an update to the subprocessor page with a notification subscription, or by in-app notification) of any intended addition or replacement of a subprocessor.

6.3 Customer may object on reasonable data-protection grounds within 30 days. The parties will discuss in good faith. If no resolution is reached, Customer's sole remedy is to terminate the affected Service for the period after the new subprocessor goes live, with a pro-rata refund of pre-paid fees.

6.4 OptiGPU imposes on each subprocessor data-protection obligations substantially equivalent to those in this DPA.

7. Data subject requests

OptiGPU will, taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests for exercising data-subject rights. Direct data-subject requests will be forwarded to Customer without undue delay.

8. Assistance with controller obligations

OptiGPU assists Customer in complying with Articles 32-36 GDPR taking into account the nature of processing and information available, including security, breach notification, DPIAs, and prior consultation.

9. Personal data breach

OptiGPU will notify Customer of a confirmed Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of confirmation, providing the information reasonably necessary for Customer to comply with Articles 33/34 GDPR (or equivalent).

10. Deletion or return

On termination of the Service, OptiGPU will, at Customer's choice, delete or return all Customer Personal Data unless retention is required by law. Default behaviour: deletion 30 days after termination, subject to backup retention of up to a further 60 days.

11. Audits

OptiGPU will make available to Customer all information necessary to demonstrate compliance with Article 28 GDPR. OptiGPU will allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, on at least 30 days' notice, no more than once per 12-month period (save for cause or following a Personal Data Breach), subject to NDA and at Customer's cost, and in a manner that does not disrupt the Service.

12. International transfers

12.1 Where OptiGPU transfers Customer Personal Data from the EEA to a Third Country lacking an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller-to-processor) and Module 3 (processor-to-processor where applicable), are incorporated into this DPA by reference and apply.

12.2 Where Customer Personal Data is transferred from Switzerland, the Swiss FADP supplement to the EU SCCs is incorporated by reference and applies.

12.3 Where the parties sign the SCCs, the docking clause permits accession by additional controllers/processors.

13. Term

This DPA applies for the duration of the Service and survives to the extent OptiGPU continues to process Customer Personal Data.


Annex I - Description of processing

Subject matter: Provision of the Service. Duration: For the term of the Service plus the deletion period in Section 10. Nature and purpose: Hosting, storing, analysing, transmitting cloud-billing and account data on Customer's instructions. Type of personal data: Identifiers (name, work email), professional information (role, organisation), usage data, and any personal data Customer uploads. Categories of data subjects: Customer's authorised users, Customer's personnel referenced in uploaded billing data. Frequency: Continuous.

Annex II - Technical and organisational measures (TOMs)

Access control

  • MFA-protected administrative access through hosting, repository, payment, email, and monitoring providers
  • Role-based access on least-privilege where supported by each provider
  • Single-operator personnel model with access changes reviewed when provider accounts, vendors, or launch scope change

Encryption

  • TLS 1.2+ for all data in transit
  • Encryption at rest through managed hosting, database, payment, email, and monitoring providers
  • Secret storage through managed environment-variable and credential-vault controls

Network

  • Segmentation between environments
  • Edge, WAF, and DDoS protections through hosting and DNS providers where configured
  • Public-facing endpoints rate-limited

Application security

  • SDLC with review before release
  • Dependency scanning (Dependabot or equivalent)
  • Secret scanning (gitleaks or equivalent)
  • Periodic security testing and launch-critical regression checks

Logging and monitoring

  • Redacted application error monitoring through Sentry and hosting-provider logs
  • Operational alerting for health checks and critical billing/reporting failures where configured
  • Log retention follows the configured provider and deployment policy

Backups

  • Managed database backup controls where enabled by the hosting provider
  • Restore drills are tracked as launch evidence before paid public launch

Personnel

  • Access is limited to the founder/operator and any approved professional advisors or contractors
  • Advisors and contractors must be under confidentiality obligations before receiving Customer Personal Data

Incident response

  • Documented runbook
  • 48-hour customer notification (Section 9)
  • Post-incident review and remediation

Annex III - Subprocessor list

See current list at https://optigpu.ai/subprocessors.