Legal

Data Processing Agreement

Last updated: June 6, 2026

A Data Processing Agreement (DPA) is available to Business customers who process personal data through OpusImg as part of their use of the Service.

Placeholder. The full DPA, including the list of sub-processors and Standard Contractual Clauses, is being finalized with counsel and will be published here. Business+ customers who need an executed DPA today can request one from legal@opusimg.com.

1. Scope & availability

This DPA forms part of the agreement between OpusImg (processor) and the customer (controller) for Business plans, and applies where OpusImg processes personal data on the customer’s behalf. It will reference and incorporate our Terms of Service and Privacy Policy.

2. Subject matter & roles

The customer is the data controller and OpusImg is the data processor for personal data contained in customer content processed through the Service. [Detailed roles, duration, nature, and purpose of processing to be completed in legal review.]

3. Processor obligations

  • Process personal data only on documented instructions from the controller.
  • Ensure persons authorized to process data are under confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist the controller with data-subject requests and security obligations.
  • Delete or return personal data at the end of the engagement.

4. Sub-processors

OpusImg uses vetted sub-processors (e.g. hosting, storage, email, monitoring). The authoritative list and change-notification process will be published here. [Sub-processor list pending.]

5. International transfers

Where personal data is transferred across borders, OpusImg will rely on appropriate safeguards such as the EU Standard Contractual Clauses. [SCC module selection and annexes to be finalized.]

6. Security & breach notification

OpusImg maintains security controls described in our Privacy Policy and will notify the controller without undue delay after becoming aware of a personal-data breach affecting their data.

7. Audits

OpusImg will make available information necessary to demonstrate compliance and, subject to confidentiality, allow for audits as required by applicable law. SOC 2 reports will be available to qualifying customers under NDA.

8. Contact

To request or execute a DPA, contact legal@opusimg.com.