Overview
This disclosure distinguishes the OpsRabbit product provider from services selected and contracted directly by the customer. That distinction determines who performs due diligence, configures the service and manages contractual data-protection obligations.
The current register is followed by the assessment, change-notification and customer-responsibility process.
Current register
| Provider category | Current party | Role | Status |
|---|---|---|---|
| OpsRabbit product provider | Applied AI Consulting | Product delivery, support and agreed processing | Provider / processor as applicable |
| Cloud / hosting | Customer-selected | Runs customer-hosted infrastructure and storage | Customer-managed provider |
| Foundation model endpoint | Customer-selected | Performs inference under customer configuration | Customer-managed provider |
| Customer integrations | Customer-selected | Provides authorized operational signals and actions | Customer-managed provider |
Change management
If OpsRabbit provider appoints a subprocessor to process customer data, this page will identify the entity, purpose, processing location and relevant service dependency. OpsRabbit provider will provide notice of material additions or replacements as required by the applicable DPA and agreement.
Definitions and decision rules
An OpsRabbit provider-appointed subprocessor is a third party engaged by OpsRabbit provider to process customer personal data for OpsRabbit. A customer-managed provider is selected, contracted or directly controlled by the customer. An AI provider supplies a model or inference endpoint. Classification depends on the contractual relationship and actual processing, not simply on technical interoperability.
Provider assessment
Before appointing a subprocessor, OpsRabbit provider evaluates the service purpose, information involved, hosting and processing locations, security posture, access model, retention and deletion, incident obligations, business continuity, subcontracting and international-transfer implications. Approval must be documented before customer data is enabled.
Required register fields
- Legal entity and service name
- Purpose and OpsRabbit feature dependency
- Categories of data and data subjects
- Processing and hosting countries
- Whether the provider is optional or required
- Retention and deletion behavior
- Model training or service-improvement settings, when applicable
- Effective date and material-change notice date
Change notification and objections
Material additions or replacements of OpsRabbit provider-appointed subprocessors are communicated through the contractual notice channel or this register as required by the DPA. Customers may raise a reasoned data-protection objection within the contractual period. OpsRabbit provider will assess configuration alternatives, additional safeguards or, where no reasonable resolution exists, the contractual termination remedy.
Customer obligations
The customer must evaluate and contract with customer-managed cloud, identity, model and integration providers; configure retention and training settings; and notify OpsRabbit provider of restrictions that affect OpsRabbit. OpsRabbit provider will provide product data-flow information needed for that assessment but does not make warranties on behalf of those providers.