Overview
This addendum explains how personal data is handled when the OpsRabbit provider processes it on a customer’s behalf. It should be read with the customer agreement and the deployment-specific data flow.
The sections below define the parties, permitted processing, security measures, incident support, deletion, audits, transfers and subprocessor arrangements.
1. Scope and parties
This Data Processing Addendum (“DPA”) forms part of the written agreement between Applied AI Consulting (“Provider”) and the customer governing the customer’s use or evaluation of OpsRabbit. It applies only where Provider processes Personal Data on the customer’s behalf in providing OpsRabbit.
The customer is the Controller or Business; Provider is the Processor or Service Provider, except where applicable law assigns a different role. “Personal Data,” “processing,” “Controller,” “Processor,” “Business,” and “Service Provider” have the meanings in applicable data protection law.
2. Processing instructions
- Provider will process Personal Data only on documented customer instructions, including the agreement, this DPA and authorized product configuration.
- The customer determines the permitted data sources, integrations, users, purposes and retention settings for a customer-hosted deployment.
- Provider will notify the customer if an instruction appears to violate applicable law, unless prohibited from doing so.
3. Confidentiality and personnel
Provider limits access to authorized personnel with a business need, confidentiality obligations and appropriate security and privacy training.
4. Security measures
Provider will maintain measures appropriate to the processing and deployment model, as described in the Security and Organizational Measures. Controls include least privilege, managed secrets, secure development, logging, vulnerability management, incident response and encryption where supported by the applicable environment.
5. Subprocessors and model providers
Provider will disclose Provider-appointed subprocessors used to process customer data, provide notice of material changes, and impose written data-protection obligations appropriate to the service. In a customer-hosted deployment, cloud and model endpoints selected and contracted directly by the customer are customer-managed providers, not Provider-appointed subprocessors. See the current disclosure.
6. Security incidents
Provider will notify the customer without undue delay after confirming a Personal Data Breach affecting data processed by Provider for OpsRabbit, provide information reasonably available for the customer’s assessment, take appropriate containment and remediation steps, and cooperate with reasonable customer obligations. Notification is not an admission of fault.
7. Data-subject and regulator support
Taking into account the nature of the processing, Provider will provide reasonable assistance with data-subject requests, security assessments, impact assessments and regulator consultations where required by applicable law and relevant to Provider’s processing.
8. Return and deletion
At the end of the applicable service, Provider will delete or return Personal Data processed by Provider as instructed by the customer, except to the extent retention is required by law. Data resident in customer-controlled infrastructure remains subject to the customer’s deletion, backup and retention processes.
9. Audit and evidence
Provider will provide available security documentation and reasonable questionnaire responses. If that evidence is insufficient to demonstrate compliance, the customer may request a proportionate audit subject to reasonable notice, confidentiality, scope, frequency, operational-impact and cost safeguards. See the Audit and Assurance Policy.
10. International transfers
Where Provider transfers Personal Data across borders, the parties will use an applicable lawful transfer mechanism. The final mechanism, annexes and country-specific terms must be completed during legal review based on the actual deployment and contracting parties.
11. Order of precedence and liability
If this DPA conflicts with the agreement on protection of Personal Data, this DPA controls for that subject. Liability remains governed by the agreement unless applicable law requires otherwise.
Definitions
For this DPA, Customer Data means information submitted to or accessed through OpsRabbit under the customer’s authority. Customer Personal Data means Customer Data that is Personal Data. Data Protection Laws means privacy and data-protection laws applicable to the relevant processing. Security Incident means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Provider. Subprocessor means a third party appointed by Provider to process Customer Personal Data on the customer’s behalf. Capitalized terms not defined here have the meaning in the agreement.
Schedule 1 — Details of processing
| Subject matter | Provision, evaluation, configuration, support and security of OpsRabbit. |
|---|---|
| Duration | For the agreement or service term, plus the limited period needed for return, deletion, security investigation or legal retention. |
| Nature and purpose | Retrieval and analysis of customer-authorized operational signals; evidence correlation; model inference; generation of recommendations; audit logging; support and security. |
| Data subjects | Customer users, administrators, personnel referenced in tickets or operational records, and other individuals whose information the customer makes available. |
| Data categories | Names, business contact identifiers, usernames, roles, IP addresses, device or host identifiers, ticket content, logs, alerts, service metadata, audit records, and other information selected by the customer. |
| Sensitive data | Not required for ordinary use. The customer must not provide regulated sensitive data unless expressly approved in writing with appropriate safeguards. |
Schedule 2 — Security measures
Provider maintains controls appropriate to its role and the approved deployment, including:
- Role-based, least-privilege access and documented joiner, mover and leaver processes for Provider-controlled access.
- Confidentiality obligations and security, privacy and responsible-AI training for relevant personnel.
- Encryption in transit and use of customer-platform encryption at rest where supported by the deployment.
- Managed secrets and connections; credentials must not be intentionally inserted into prompts or general logs.
- Secure development, peer review, dependency management, controlled releases and separation of development and customer environments.
- Security logging for user, agent, model, tool, approval, error and administrative events, subject to data minimization.
- Vulnerability identification, risk-based remediation and independent penetration testing.
- Incident triage, containment, investigation, recovery, communication and corrective action.
- Continuity and recovery planning for Provider-controlled components, with customer responsibilities documented for customer-hosted infrastructure.
Schedule 3 — Subprocessor authorization
The customer gives general authorization for Provider to use subprocessors disclosed in the current Subprocessor and AI Provider Disclosure. Provider will provide notice of a material new Provider-appointed subprocessor before it begins processing Customer Personal Data when required by the agreement. A customer may object on reasonable data-protection grounds during the stated notice period. The parties will work in good faith on a commercially reasonable resolution; unresolved objections are handled under the agreement.
Customer-selected cloud, identity, model and integration providers contracted directly by the customer are not Provider-appointed subprocessors merely because OpsRabbit interoperates with them.
Jurisdiction-specific terms
If an international transfer mechanism, United States state privacy addendum, EU Standard Contractual Clauses, UK Addendum, India-specific processing term or other jurisdictional attachment is legally required, the parties will complete the applicable module and annexes using the actual processing facts. Those legal modules must be approved before this DPA is incorporated into a production agreement.