Skip to content
OpsSense
LEGAL

Data Processing Addendum

Last updated 2026-07-01

This document is a working draft prepared for review by legal counsel and has not yet been adopted. [confirm with counsel before launch]

Roles

For platform data, the customer is the controller and OpsSense the processor. This addendum incorporates the safeguards required by applicable data-protection law, including Saudi PDPL and, where relevant, EU GDPR Article 28 terms.

Processing scope

Processing is limited to documented customer instructions: providing the platform, support, and contracted services. Categories of data and data subjects are described in the annex of the executed DPA.

Sub-processors

A current sub-processor list is available on request and maintained with advance notice of changes. Sub-processors are bound by equivalent obligations.

Security measures

Technical and organizational measures include encryption in transit and at rest, access controls, audit logging, and tested backup and restore procedures, as detailed in the security annex.

Incidents, audits, deletion

Personal data breaches are notified without undue delay. Audit rights, assistance obligations, and end-of-contract deletion or return terms follow the executed DPA.

See your operations run themselves.

A 30-minute walkthrough with an operations engineer. Your assets, your workflows, your questions.