Data Processing Addendum
- Last updated
- 2026-07-16
- Effective
- 2026-04-26
This page summarises the pre-release Osyra Data Processing Addendum (DPA) package. An executed DPA binds Osyra, Inc. as a processor where applicable; this public page is an operational summary and is not a signed agreement. To request the current review copy, email dpa@osyra.ai. Final terms and signature timing are confirmed during contracting.
01Scope and parties
The DPA applies whenever Osyra processes Personal Data on behalf of the customer under the Master Service Agreement (MSA). Osyra is the data processor; the customer is the data controller. The DPA does NOT apply to data Osyra processes for its own purposes — billing records, audit logs, security telemetry, etc. — which are governed by the privacy policy under Osyra's controller obligations.
Parties named in the DPA:
- Processor — Osyra, Inc., a Delaware C-Corp.
- Controller — the customer entity that signed the MSA. Affiliated entities under the customer's control are co-controllers per a controller-to-controller schedule attached to the DPA.
02Categories of data and data subjects
The DPA enumerates the categories of Personal Data Osyra may process. Customers control what flows through the platform; the DPA documents the upper bound of what Osyra is contracted to handle.
- Authentication data — email addresses, federated-identity IDs, hashed passwords, MFA secrets (encrypted at rest with workspace-scoped KMS keys).
- Customer Content — prompt text, completion text, embeddings, attached files. Processed in transit; persisted only when the workspace policy enables retention.
- Operational metadata — request IDs, timestamps, model selection, cost, latency, policy verdicts. Persisted in the audit log per workspace retention.
- End-user identifiers — when the customer attaches an end-user-id to a request (e.g. for per-user rate-limiting). Treated as Personal Data and subject to the Art. 15 access-request flow.
Categories of data subjects: customer employees + agents (controllers' workforce), end-users of the customer's product (when the customer attaches an end-user-id), and individuals named in Customer Content.
03Sub-processors
The canonical sub-processor register lives at /legal/subprocessors. The launch plan contains 5 providers: Amazon Web Services (compute, storage, networking, kms, and audit-log retention); Stripe (payment processing, invoicing, and subscription billing); Resend (transactional email delivery for account verification, billing receipts, and alerts); Plausible (privacy-friendly web analytics without cookies or cross-site tracking); Sentry (application error monitoring and performance traces). Osyra has not launched a production service or placed production Customer Content with these providers. This register documents the engineering launch data-flow plan; every provider remains subject to security, privacy, and contract review before activation.After launch, Customers receive 30 days' notice before a new provider is activated; the notification opt-in lives at /trust under the sub-processor change-notification section.
Production activation is gated on the security, privacy, and contract review stated in the canonical register. Request the current evidence package from dpa@osyra.ai.
04International transfer mechanism
If an executed customer agreement enables a transfer from the EEA, UK, or Switzerland, the applicable transfer terms must be established before production processing. The pre-release DPA package provides for:
- Standard Contractual Clauses (2021/914) — Module 2 (controller → processor) and Module 3 (processor → processor), selected according to the data flow documented in the executed DPA.
- UK International Data Transfer Addendum — included where the executed agreement covers UK-origin data.
- Swiss FADP supplemental clauses — included where Swiss law applies.
The transfer review and any required supplementary measures must be completed before an affected route is activated. Customers may request the current review materials under NDA.
The launch plan includes an Enterprise EEA option in Amazon Web Services eu-west-1 (Ireland). The Sentry EU telemetry option remains subject to the same activation review. See the Trust Center "Data residency" section for the full posture.
05Security measures
Annex II of the DPA enumerates the technical and organisational measures Osyra applies. The same set is documented at /legal/security. Highlights:
- Encryption at rest — AES-256-GCM via Amazon Web Services KMS. Workspace-scoped customer-managed keys are part of the Enterprise launch plan.
- Encryption in transit — TLS 1.3 minimum on every public surface; mTLS on cluster-internal traffic.
- Access control — workspace isolation, role-based permissions, step-up re-auth on sensitive operations, hardware-key MFA support.
- Audit log — an append-only, hash-chained audit ledger retained per workspace policy is being delivered; today the audit pipeline covers the wired events. Signed per-call receipts on Pro and Enterprise tiers are on the same roadmap.
- Incident response — a documented severity and notification flow; the executed agreement establishes customer-specific response targets.
06Data subject rights
The DPA codifies the Art. 28(3)(e) obligation to assist the controller in responding to data-subject requests under Art. 15-22 + the equivalent CCPA / CPRA rights.
- Right of access (Art. 15 / right to know) — Osyra assists the controller in retrieving the Personal Data it processes about a named end-user. Direct self-serve export tooling for these requests is being delivered; in the interim Osyra fulfils them as part of its Art. 28(3)(e) assistance obligation.
- Right to erasure (Art. 17 / right to delete)— Osyra assists the controller in erasing an end-user’s Personal Data, subject to the audit-log retention window the customer configured on the workspace and any legal-hold override. Self-serve erasure tooling is being delivered; in the interim Osyra fulfils erasure requests as part of the same assistance obligation.
- Right to portability (Art. 20) — Customer Content exports produce a JSON archive in OAP-MEM bundle format (the Memory Architecture and Provenance Layer format) so it can be imported into a competing system.
- Objection / restriction (Art. 18, 21) — handled by pausing the workspace; customers can also request individual end-user-id suspensions.
07Audit rights
Per Art. 28(3)(h), customers may audit Osyra's compliance with the DPA. The DPA offers three audit modalities:
- Documentation — the canonical security policy plus audit and penetration-test evidence as those independent programmes produce it.
- Questionnaire — Osyra responds to SIG-Lite, CAIQ, or custom vendor-security questionnaires within 10 business days.
- On-site / virtual audit — Enterprise tier and above. Reasonable notice + commercially reasonable scope per the DPA. Osyra reserves the right to charge for engineer time on audits exceeding two business days per year.
08Incident notification
The pre-release DPA package requires notification without undue delay after Osyra becomes aware of a Personal Data Breach. The executed DPA controls the applicable deadlines and update cadence.
- Initial notification— delivered to the contact named in the customer's notification schedule within the executed contractual window.
- Updates — material facts are provided as the investigation develops, subject to legal and security constraints.
- Post-incident report — root-cause and remediation information is provided according to the executed DPA.
Vulnerability reports + suspected incidents go to security@osyra.ai.
09How to request and sign the DPA
- Email dpa@osyra.ai from your authorized signatory's address with the contracting entity's full legal name + the workspace ID(s) the DPA should cover.
- Osyra provides the current pre-release DPA package and identifies any terms that still require customer-specific review.
- The parties resolve applicable terms and their authorised signatories execute the final DPA before production Customer Content is processed.
- Effective date is the latest of the two signatures. The executed DPA prevails over any conflicting terms in the MSA on data-protection topics.
For customers under an existing MSA, the DPA is incorporated by reference under the "Data Protection" section. Customers may upgrade to a newer DPA version at any time; the executed copy on file binds until replaced.