Privacy & data
Incorporated agreementData Processing Addendum
The roles, instructions, confidentiality, security, subprocessor, incident, rights, audit, transfer, and deletion terms for Customer Personal Data.
1. Scope and definitions
This Data Processing Addendum (“DPA”) forms part of the Agreement between Customer and Nightvault FZE, the provider of OperalonOS. It applies where Nightvault processes Customer Personal Data on behalf of Customer. Nightvault FZE is the sole service-provider obligor; OperalonOS is the product name. This DPA controls a conflict concerning protection of Customer Personal Data.
- Applicable Data Protection Law
- Every privacy or data-protection law and binding regulator requirement applicable to processing under this DPA based on the actual parties, people, processing, locations, offering, monitoring, and other facts.
- Customer Personal Data
- Customer Data constituting Personal Data that Nightvault processes on Customer’s behalf through the Services.
- Data Subject Request
- A verified request to exercise a privacy right.
- Personal Data Breach
- A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data; unsuccessful blocked attempts are excluded.
- Subprocessor
- A third party appointed by Nightvault to process Customer Personal Data on Customer’s behalf.
2. Roles, instructions, and Customer obligations
Customer is controller or business for Customer Personal Data. Nightvault FZE is Customer’s processor, service provider, or contractor through OperalonOS. Customer determines the purposes. Nightvault processes only to provide and secure the Services, according to documented configuration and instructions, as described in the Agreement and processing details, or as required by law.
If law requires processing outside instructions, Nightvault will inform Customer before processing unless notice is prohibited. Nightvault will notify Customer if an instruction reasonably appears to violate Applicable Data Protection Law and may suspend affected processing until the instruction is confirmed, modified, or withdrawn.
- Customer provides lawful and documented instructions and ensures required rights, notices, consents, and legal grounds.
- Customer configures available roles, permissions, feature-specific retention controls, and integrations appropriately and avoids unsupported sensitive or regulated data.
- Customer responds to Data Subject Requests for Customer-controlled data and assesses AI or automated use for consent, impact assessment, and human-review requirements.
- Customer is responsible for the accuracy, quality, lawfulness, and source of Customer Personal Data.
3. Confidentiality and security
Nightvault requires personnel authorized to process Customer Personal Data to be bound by confidentiality, limits access according to assigned responsibilities, and requires access to be removed when it is no longer needed. These obligations are implemented through Nightvault’s then-current access-governance and personnel processes.
Nightvault maintains measures reasonably designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage, or alteration. Controls may evolve with technology and threats provided the overall protection is not materially reduced during the subscription term. No security measure eliminates all risk.
| Control area | Control baseline |
|---|---|
| Tenant isolation | Server-derived Workspace context, membership checks, Workspace-scoped queries, tenant controls, and prevention of mixed-tenant references. |
| Identity | Secure authorization flows, issuer/audience/state/nonce/signature validation where applicable, secure sessions, single-use flows, and step-up or MFA for privileged actions. |
| Application and APIs | Bounded bodies and responses, origin and request validation, security headers, untrusted-content isolation, signed webhooks, replay prevention, idempotency, safe retries, and dead-letter handling. |
| Data and storage | Tenant-scoped database and storage access, guarded privileged operations, Workspace-bound paths, protected handling of selected secrets, and feature-specific exports. |
| Operations | Privacy-minimized evidence, restricted log access, secure development, secret scanning, reviewed dependencies, staged rollout, rollback, and documented incident-response and recovery procedures. Operating-effectiveness or recovery evidence is not an independent certification. |
4. Subprocessors
Customer generally authorizes Nightvault to appoint Subprocessors identified in the effective Register for configured production flows. Nightvault applies the confidentiality and data-protection terms available under the applicable provider agreement, remains responsible to the extent required by law and the Agreement, maintains the Register, and gives reasonable advance notice of a new material Subprocessor where practicable or as required by applicable law.
Customer may object promptly after receiving notice and before the planned activation date, where practicable, on reasonable documented data-protection grounds. The parties will attempt a good-faith resolution. If no commercially reasonable alternative exists, either party may terminate only the affected Service and Nightvault will refund unused prepaid Fees attributable to it. Urgent security, legal, or provider-failure replacements may occur sooner with prompt notice. Customer-directed integrations are not necessarily Nightvault Subprocessors.
5. Data Subject Requests and Personal Data Breaches
Taking into account the nature of processing, Nightvault provides commercially reasonable assistance for Customer to respond to verified rights requests. If Nightvault receives a request concerning Customer Personal Data, it may direct the requester to Customer, notify Customer, and act only on documented instruction unless law requires otherwise. Customer verifies the requester and decides the response.
Nightvault escalates a credible suspected compromise under its incident procedures and will notify Customer without undue delay after determining that a Personal Data Breach affecting Customer Personal Data has occurred. Information may be supplied in phases as it becomes reasonably available. No fixed notification period applies unless required by law or an activated Order.
Available notice information includes the incident nature, affected systems and data, approximate affected people or records, known consequences, containment and remediation, and an incident contact. Nightvault preserves relevant evidence, investigates, contains, remediates, and assists with legally required notices. It does not notify Customer’s Data Subjects or publicly identify Customer unless authorized or legally required.
6. Assessments, return, deletion, and government requests
Nightvault reasonably assists with impact assessments, regulator consultations, processing records, and information needed to assess security and processing. Customer determines whether an assessment or consultation is required.
During the term, Customer may use available feature-specific exports and controls. Broader return, restriction, or deletion requests are handled through a verified manual process. After termination or verified instruction, Nightvault will assess and communicate the applicable return or deletion plan, accounting for the data inventory, technical dependencies, provider backup cycles, security and billing evidence, disputes, and legal requirements. Retained data remains protected and limited to its retention purpose.
Where legally permitted and reasonably practicable, Nightvault may notify Customer before compulsory disclosure, review a request for facial validity, seek limitation of an apparently overbroad request, and disclose only reasonably required data. Nothing requires Nightvault to violate law, obstruct lawful process, or disclose a confidential government request.
7. Audits and international transfers
On written request, Nightvault provides reasonably necessary compliance information in this order: current security documentation and questionnaire; an available independent assessment or penetration-test summary if one exists and may be disclosed; a remote meeting; and a narrowly scoped audit where earlier material is insufficient or law requires it.
One routine audit may occur per 12 months, with additional audits following a substantiated breach or regulator requirement. Routine audits generally require 30 days’ notice, normal business hours, non-disruption, confidentiality, independent auditors, and no unapproved penetration testing or cross-customer access. Customer bears routine costs unless law or confirmed material noncompliance requires another allocation.
Customer acknowledges that configured providers may process data in the selected project region, the United States, the United Arab Emirates, and other locations identified in their then-current provider terms or subprocessor notices. Exact locations depend on the account and feature. Transfer requirements under UAE, EU, UK, or other law apply according to actual facts. This DPA does not itself incorporate EU Standard Contractual Clauses or the UK International Data Transfer Addendum; a restricted flow must remain limited until any required mechanism is executed or established.
8. United States service-provider and processor terms
- Nightvault processes Customer Personal Data only for the limited and specified purposes of hosting, authentication, Customer-instructed workflows and integrations, AI and reporting functions, support, security, billing, and lawful instructions.
- Nightvault does not sell or share Customer Personal Data, process it for targeted or cross-context behavioral advertising, or retain, use, disclose, or combine it outside the direct relationship and permitted purposes except as law permits or requires.
- Nightvault provides legally required privacy protection, notifies Customer if it can no longer comply, cooperates in corrective action, and uses applicable provider agreements and data-protection terms intended to impose protections appropriate to each Subprocessor’s role.
- Customer may take reasonable and appropriate steps to verify and stop unauthorized use. Nightvault FZE certifies that it understands and will comply with these restrictions.
9. Processing details and retention
- Subject matter
- Provision, security, support, billing administration, and operation of the Customer’s OperalonOS Workspace, authorized integrations, workflows, AI, reporting, and communications.
- Duration
- The subscription term and the category- and feature-specific retention actually configured or required, subject to verified instructions, disputes, security evidence, provider backup cycles, and law.
- Nature
- Collection, storage, retrieval, matching, classification, OCR, AI inference, summarization, drafting, routing, analysis, reporting, transmission, export, restriction, deletion, and security monitoring.
- Data Subjects
- Customer personnel and users; Customer’s customers and prospects; communication participants; people in tickets, orders, messages, and connected systems; suppliers, partners, business contacts, and support requesters.
- Categories
- Business contact, account, role, service communications, email, order, commerce, shipping, return, refund, CRM, collaboration, attachments, policy, prompts, Output, review evidence, usage, and operational metadata.
| Data category | Current retention basis |
|---|---|
| Active Accounts, Workspace content, communications, tickets, orders, and attachments | Retained during the subscription and afterward only as reasonably needed for verified offboarding instructions, security, disputes, recovery, or law; no universal deletion SLA is promised by this public DPA. |
| Integration tokens and secrets | Active credential access is removed locally on disconnect. Minimal inactive connection and lifecycle records, such as provider, external account reference, status, timestamps, and audit metadata, may be retained for security, reconciliation, support, disputes, or law. Provider revocation or deletion is attempted where supported and may require provider or Customer action. Backup timing follows the applicable provider cycle. |
| Analysis facts and reports | Unreferenced raw facts are generally eligible for cleanup after 180 days; daily aggregates and saved reports after 24 months; unsaved report cache after 30 days. Referenced evidence and some minimized monthly aggregates may remain longer for integrity or trend records. |
| Live Chat and operational queues | Current feature defaults include separate periods for payload scrubbing, messages, terminal delivery records, AI audit, presence, and session state; configuration and approved retention jobs control rather than a single Workspace-wide period. |
| Security, legal, billing, contract, invoice, and acceptance evidence | Retained for the period reasonably required for integrity, investigation, dispute, accounting, tax, contractual, or legal obligations. Hardline evidence is designed for at least 400 days and may remain longer until an approved controlled purge is available. |
| Protected backups | Isolated from ordinary use and expires according to the configured provider cycle. This DPA does not promise a universal 90-day maximum or automated replay of deletion instructions after every restoration. |
| Aggregated or de-identified information | May be retained while reasonable safeguards maintain the data in aggregate or de-identified form and Nightvault does not intentionally re-identify it except to validate safeguards or as law permits. |
10. De-identified data, records, liability, and term
Nightvault may use effectively de-identified data while taking reasonable measures to prevent re-identification, maintaining it in de-identified form, not attempting re-identification except to test effectiveness, and requiring recipients to preserve those protections. Nightvault maintains records reasonably necessary to demonstrate material processing activities.
Liability under this DPA is subject to the Agreement’s exclusions, caps, and procedures unless Applicable Data Protection Law prohibits their application. This DPA remains in effect while Nightvault processes Customer Personal Data on Customer’s behalf.