Legal
Data Processing Addendum
Last updated: August 25, 2026
This DPA is a working draft for customers who need GDPR/CCPA-style processor terms in place — typically enterprise customers with their own compliance requirements. It should be reviewed by qualified counsel, and formally executed (referencing the Terms of Service it supplements) before either party relies on it.
1Purpose & Roles
This Data Processing Addendum ("DPA") supplements the ReliabilityOS Terms of Service (the "Agreement") between Customer and ReliabilityOS LLC, a South Carolina limited liability company, ("ReliabilityOS"). For personal data that Customer submits to the Service as Customer Data, Customer is the Controller (or Business, under CCPA) and ReliabilityOS is the Processor (or Service Provider). Capitalized terms not defined here have the meaning given in the Agreement or applicable data protection law.
2Processing Instructions
ReliabilityOS will process personal data within Customer Data only to provide the Service, in accordance with Customer's documented instructions (which the Agreement and Customer's configuration of the Service constitute), and as required by applicable law. ReliabilityOS will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
3Confidentiality & Personnel
ReliabilityOS ensures that personnel authorized to process personal data are bound by confidentiality obligations and are trained on their data-protection responsibilities.
4Subprocessors
Customer authorizes ReliabilityOS to engage the subprocessors listed in our Privacy Policy (currently: Supabase for database/auth/storage, Stripe for billing, Resend for transactional email, and Anthropic for optional AI features), each bound by data-protection terms materially as protective as this DPA. We will notify Customer of any new subprocessor with at least 10 days' notice, during which Customer may object on reasonable data-protection grounds.
5Security Measures
ReliabilityOS maintains technical and organizational measures appropriate to the risk, including:
- Per-organization data isolation enforced at the database layer (row-level security), so one customer's data is never queryable by another.
- Role-based access control limiting each user to the data and actions appropriate to their role.
- Encrypted storage for uploaded files and photographs, served via time-limited signed URLs rather than public links.
- An in-product audit trail recording key account and record-level actions for security and compliance review.
- Encryption of data in transit via TLS.
6Data Subject Requests
ReliabilityOS will provide reasonable assistance to help Customer respond to a data subject's request to exercise their rights (access, correction, deletion, portability) under applicable data protection law, to the extent Customer cannot fulfill the request using the Service's own tools.
7Breach Notification
ReliabilityOS will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of a confirmed personal data breach affecting Customer Data, and will provide the information reasonably available to help Customer meet its own notification obligations.
8Audits & Compliance
On reasonable written request, no more than once per 12 months absent a suspected breach, ReliabilityOS will make available the information reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to audits, including inspections, conducted by Customer or an independent auditor mutually agreed by the parties, subject to reasonable confidentiality, scheduling, and cost-allocation terms to be agreed between the parties.
9International Transfers
Where personal data is transferred outside the jurisdiction in which it was collected, the parties will rely on an appropriate transfer mechanism (such as Standard Contractual Clauses) as required by applicable law.
10Return or Deletion of Data
On termination of the Agreement, ReliabilityOS will make Customer Data available for export and will delete remaining copies in accordance with the data-export and retention terms of the Terms of Service, except where retention is required by law.
11Liability
Each party's liability arising out of this DPA is subject to the limitation of liability set out in the Agreement.