Data Processing Agreement
Placeholder draft · Last updated 6 July 2026
Placeholder draft — this Data Processing Agreement scaffold has not completed legal review, is not legal advice and is not legally final. It is intended for later use as part of customer contracting; the exact terms must be reviewed and finalised by qualified legal counsel before execution.
1. Parties and scope
This agreement is expected to form part of the customer agreement between the customer and the OgmaQ contracting entity. The contracting entity details, and the precise relationship between this DPA and the wider customer agreement, are to be confirmed during legal review.
2. Customer as controller
The customer is expected to act as controller of the personal data contained in its workspace content. The customer decides what personal data its users enter into the service and for what purposes.
3. OgmaQ as processor
OgmaQ is expected to act as processor of customer workspace content, processing it only to provide and support the service. The exact processor obligations will be set out during legal review.
4. Subject matter and duration
The subject matter of processing is customer workspace content, processed for the duration of the customer agreement. The precise subject matter and duration terms are to be defined during legal review.
5. Nature and purpose of processing
The nature and purpose of processing are expected to include hosting, storage, display, workflow processing, audit-support trail maintenance, support and service operation. Where the customer enables published data links, processing is also expected to include serving a read-only operational data feed to the holders of a link URL at the customer's instruction, together with metadata-only access logging for that feed. The final characterisation is to be confirmed during legal review.
6. Categories of personal data
The categories of personal data are expected to include user account and profile data (name, work email, role/site/department assignments) and any personal data customer users enter into workspace content. The customer controls what personal data is submitted. Unless separately agreed in writing, OgmaQ is not intended for special-category personal data, patient data or protected health information (PHI) — see the Acceptable Use Policy. The final categories are to be confirmed during legal review.
7. Categories of data subjects
The categories of data subjects are expected to include the customer's authorised users and individuals mentioned in workspace content entered by those users.
8. Customer instructions
OgmaQ expects to process customer workspace content only on documented customer instructions, with the customer agreement and this DPA forming the baseline instruction set. The process for additional instructions will be set out during legal review.
Where the feature is used, enabling published data links for a workspace and creating an individual link are each expected to be treated as a documented customer instruction to make the scoped operational data available to the holders of that link URL until the link expires or is revoked. This characterisation is to be confirmed during legal review.
9. Confidentiality
Persons authorised to process the data are expected to be bound by confidentiality obligations, whether contractual or statutory. The exact confidentiality terms are to be defined during legal review.
10. Security measures / technical and organisational measures
A technical and organisational measures (TOMs) annex is to be defined during legal review. The current design measures are described in the Security Overview.
11. Subprocessors
The current subprocessor list is published at ogmaq.com/subprocessors. The authorisation, notification and objection process for subprocessor changes is to be defined during legal review.
12. International transfers
Transfer mechanisms (such as the EU Standard Contractual Clauses) are to be assessed and documented during legal review. The primary Supabase project region is EU (eu-central-1).
13. Assistance with data subject requests
OgmaQ expects to support the customer, as controller, in responding to data subject requests that affect workspace content, including through the in-app privacy request workflow. The scope of this assistance will be set out during legal review.
14. Assistance with DPIAs and consultations
OgmaQ is expected to assist the customer with data protection impact assessments and prior consultations, to the extent the customer cannot obtain the needed information itself. The details of this assistance are to be defined during legal review.
15. Personal data breach notification
Notification obligations, timelines and content are to be defined during legal review. OgmaQ intends to notify affected customers without undue delay after becoming aware of a personal data breach affecting their workspace content.
16. Return or deletion of data
The expected offboarding path is export first, then reviewed deletion, subject to legal holds and retention obligations. See the Data Retention Policy; the exact return-or-deletion terms will be set out during legal review.
17. Audit and information rights
The scope and mechanics of customer audit and information rights are to be defined during legal review.
18. Customer responsibilities
The customer remains responsible for its own GMP/QMS decisions, official records, validation decisions for its intended use, user access administration, and the lawfulness of the data its users enter into the service.
Where the customer enables published data links, the customer also remains responsible for determining the recipients of link URLs and for the distribution of those links; OgmaQ provides expiry, revocation, inventory and access-logging controls for the customer to manage them. The allocation of responsibility is to be confirmed during legal review.
19. OgmaQ GMP/QMS boundary
OgmaQ is operational escalation-support software and is not provided as a validated GMP system of record by default. Unless separately agreed in writing and validated by the customer for a defined intended use, official GMP records remain in the customer's validated QMS or other controlled systems.
20. AI and customer data
OgmaQ's customer-facing product currently has no AI functionality. OgmaQ does not process customer tenant data through AI providers, no AI vendor is currently a subprocessor of customer tenant data, and customer workspace content is not used to train AI models. Any future customer-facing AI-assisted functionality would require separate documentation, configuration, customer-facing disclosure and review before being enabled. Internal company tooling used outside the customer-facing product is separately scoped and controlled, and does not involve customer tenant data.
21. Contact and execution process
This DPA is expected to be executed as part of customer contracting; the execution process will be set out during legal review. Contact [email protected] (general contact: [email protected]). These role-based aliases route to the OgmaQ team; [email protected] is the general contact if you are unsure which to use.