Data Processing Addendum
Last updated: July 26, 2026
This Data Processing Addendum (“DPA”) forms part of the Subscription Agreement between Olympas LLC (“Olympas”) and the customer (“Customer”) and applies to Olympas’s processing of personal data on Customer’s behalf in connection with the Services.
It reflects the parties’ agreement on the processing of personal data in accordance with applicable data protection laws, including the EU and UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). Capitalized terms not defined here have the meanings given in the Subscription Agreement.
Definitions
“Personal Data,” “processing,” “data subject,” “controller,” “processor,” “service provider,” “business,” “sub-processor,” and “personal data breach” have the meanings given in applicable data protection laws. “Customer Personal Data” means personal data contained within Customer Data that Olympas processes on Customer’s behalf.
Roles of the Parties
For Customer Personal Data, Customer is the controller (or business) and Olympas is the processor (or service provider). Under the CCPA, Olympas acts as a service provider and will not sell or share Customer Personal Data, and will not retain, use, or disclose it except to perform the Services or as otherwise permitted by the CCPA. Olympas certifies that it understands and will comply with these restrictions.
Scope and Purpose of Processing
Olympas processes Customer Personal Data only: (a) to provide, secure, and support the Services; (b) in accordance with Customer’s documented instructions, including this DPA and the Subscription Agreement; and (c) as required by law, in which case Olympas will inform Customer unless legally prohibited. The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are determined by Customer through its use of the Services.
Customer Responsibilities
Customer is responsible for the accuracy and lawfulness of Customer Personal Data, for establishing a legal basis for processing, for providing any required notices, and for obtaining any required consents. Customer’s instructions to Olympas must comply with applicable data protection laws.
Confidentiality of Personnel
Olympas ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities.
Security Measures
Olympas maintains appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include, as appropriate: encryption of data in transit, access controls and least-privilege access, logical separation of customer environments, monitoring and logging, secure software development practices, and due diligence over vendors. Measures may evolve over time but will not materially decrease the overall level of protection during the term.
Sub-processors
Customer authorizes Olympas to engage sub-processors to support the provision of the Services. Olympas imposes data-protection obligations on its sub-processors that are no less protective than those in this DPA and remains responsible for their performance. Current categories of sub-processors include cloud hosting and infrastructure, email and communications delivery, customer relationship and lead management, payment processing, and, where enabled, analytics and error monitoring.
A current list of named sub-processors is available on request by contacting contact@olympasapps.com. Olympas will provide a means for Customer to be notified of new sub-processors and a reasonable opportunity to object on legitimate data-protection grounds.
Data Subject Requests
Taking into account the nature of the processing, Olympas will provide reasonable assistance, including appropriate technical and organizational measures, to help Customer respond to requests from data subjects to exercise their rights (such as access, correction, deletion, portability, and objection). If Olympas receives such a request directly, it will, unless legally required otherwise, refer the data subject to Customer.
Assistance to Customer
Olympas will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with supervisory authorities, and security obligations, in each case taking into account the nature of processing and the information available to Olympas.
Personal Data Breach
Olympas will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to Olympas to help Customer meet its own notification obligations.
Return and Deletion of Data
On termination or expiration of the Services, Olympas will, at Customer’s choice, delete or return Customer Personal Data within a reasonable period, except to the extent Olympas is required by law to retain it. This is consistent with the data-export provisions of the Subscription Agreement.
Audits
Olympas will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits. This obligation may be satisfied by providing relevant documentation or third-party certifications. Any on-site audit will be limited to reasonable, pre-arranged terms that do not compromise the security of other customers.
International Transfers
To the extent Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy decision, the parties will rely on an appropriate transfer mechanism, including the applicable European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where applicable.
CCPA Service Provider Terms
With respect to personal data subject to the CCPA, Olympas is a service provider and certifies that it will not: (a) sell or share the personal data; (b) retain, use, or disclose the personal data for any purpose other than the business purposes specified in the Subscription Agreement, or as otherwise permitted by the CCPA; or (c) combine the personal data with data from other sources, except as permitted by the CCPA.
Liability and Order of Precedence
Each party’s liability under this DPA is subject to the limitations of liability in the Subscription Agreement. In the event of a conflict between this DPA and the Subscription Agreement regarding the processing of personal data, this DPA controls.
Contact Us
For any data-protection matter or to request our current sub-processor list, contact us at contact@olympasapps.com, or by mail at 111 Calvin St, Savoy, IL 61874.