Data Processing Agreement
This agreement applies where you use Ommelo to process personal data on behalf of your organisation. It sets out our respective roles and obligations under applicable data protection law.
Effective 31 July 2026
Scope and roles
This Data Processing Agreement ("DPA") forms part of, and is subject to, our Terms of Service and applies to business and team customers whose use of Ommelo involves processing personal data. For that processing you are the controller and Ommelo is the processor. Where you are itself a processor for your own customer, Ommelo acts as a sub-processor and the same obligations flow down. It is shaped to meet Article 28 of the EU/UK GDPR and equivalent obligations under the Australian Privacy Act.
Nature and purpose of processing
Subject matter and duration: processing of the personal data contained in the audits and recordings you submit, for the duration of your subscription and until deletion or return as described below. Nature and purpose: hosting, storing, and analysing that content to generate UX audit findings and reports for you. Categories of data subjects: your end users and any individuals whose personal data appears on the sites you audit or in the sessions you record. Categories of personal data: identifiers and any personal data present in captured screenshots, DOM text, action and timing metadata, and connected analytics counts — you control what is submitted, so you must not submit special-category data unless you have a lawful basis to do so.
Our obligations as processor
- ·Process personal data only on your documented instructions, including as to international transfers, unless required by law (and then we will tell you unless the law forbids it).
- ·Ensure people authorised to process the data are bound by confidentiality.
- ·Implement appropriate technical and organisational security measures (see below).
- ·Engage sub-processors only under the conditions in this DPA, and remain responsible for them.
- ·Assist you, taking into account the nature of processing, to respond to data-subject requests and to meet your security, breach-notification, and impact-assessment obligations.
- ·Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- ·Delete or return the personal data at the end of the service, and delete existing copies unless retention is required by law.
- ·Make available the information reasonably necessary to demonstrate compliance with these obligations, and allow for and contribute to audits as described below.
Security measures
Ommelo maintains, at a minimum: encryption of personal data in transit and at rest; encrypted secret storage (Supabase Vault) for test credentials and analytics tokens, accessible only to the service role; row-level security isolating each tenant's data; and best-effort redaction of password and card values in extension recordings before upload. Measures may be updated over time provided the level of protection is not reduced. Further detail is in our Privacy Policy.
Sub-processors
You authorise Ommelo to engage the sub-processors listed on our subprocessors page, each bound by data protection terms no less protective than this DPA. The current list is:
- ·Supabase — Database, authentication, file/object storage, and encrypted secrets (Vault). (Australia (ap-southeast-2))
- ·Anthropic — Claude API — analyses audit and extension content to generate findings. (United States)
- ·Vercel — Application hosting and content delivery. (United States)
- ·Lemon Squeezy — Payments and subscription management (merchant of record). (United States)
- ·Google — Google sign-in (OAuth); our own GA4 web analytics on the marketing site and sign-in flow (opt-in only, see Cookie Policy); and, where a customer connects it, read-only GA4 analytics on their own property. (United States)
- ·Sentry — Error monitoring on server routes. (United States)
We will give you advance notice of any new or replacement sub-processor so that you have the opportunity to object on reasonable data-protection grounds before it begins processing.
International transfers
Ommelo's primary data store is in Australia (Supabase, ap-southeast-2), and some sub-processors process data in the United States (Anthropic, Vercel, Lemon Squeezy, Google, Sentry). Where personal data is transferred out of the EEA or the UK, the transfer is made under an appropriate safeguard — the European Commission's Standard Contractual Clauses (with the UK Addendum or IDTA where the UK GDPR applies), or an adequacy mechanism such as the EU–US Data Privacy Framework where a sub-processor is certified. The relevant clauses are incorporated into this DPA by reference.
Data-subject requests and assistance
If a data subject contacts Ommelo directly about data we process on your behalf, we will refer them to you and, unless legally required otherwise, will not respond ourselves. We will provide reasonable assistance for you to fulfil access, correction, deletion, and portability requests, using the product's own export and deletion controls where possible.
Audit rights
On reasonable prior written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will make available the information needed to demonstrate compliance with this DPA and will cooperate with an audit of that compliance, subject to confidentiality and to not compromising other customers' security or data.
Deletion and return
On termination of the service, or on your request, we will delete or return the personal data we process on your behalf and delete existing copies, unless applicable law requires us to keep it — in which case we will keep it only for as long as required and continue to protect it. You can also delete audits, recordings, and your account within the product at any time.
Liability and term
This DPA takes effect while you use Ommelo to process personal data and continues until all such data has been deleted or returned. Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Where there is a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails.
How to put this in place
Team and agency customers who need a countersigned copy can request one at alifnoushad.96@gmail.com. Using Ommelo to process personal data on your organisation's behalf constitutes acceptance of these terms in the meantime.