Data Processing Addendum
Last updated: 2026-06-17
This Data Processing Addendum governs how Opora processes personal data on behalf of business customers who use the platform to process data belonging to their own customers or employees. If you use Opora to process personal data on behalf of other people, this document applies to you.
This Data Processing Addendum ("DPA") is entered into between Opora ("Processor," "we," "us") and the business entity or individual ("Controller," "you") who accesses the Opora platform under the Terms of Service. It forms part of the Terms of Service and is incorporated by reference.
Where this DPA conflicts with the Terms of Service on matters of data protection, this DPA governs.
Effective date: 2026-06-17
1. Definitions
Terms used in this DPA have the following meanings. Where a term is defined in the GDPR, CCPA, or other applicable data-protection law, that statutory meaning applies.
- Controller — the entity that determines the purposes and means of processing personal data. Under this DPA, the business customer (you) acts as Controller in respect of your End User Data.
- Processor — the entity that processes personal data on behalf of the Controller. Opora is the Processor.
- Sub-processor — a third party engaged by Opora to process personal data on Opora's behalf in connection with providing the platform services.
- End User Data — personal data belonging to the Controller's own customers, employees, or other data subjects that the Controller inputs into the Opora platform as part of tool prompts or uploaded content.
- GDPR — the EU General Data Protection Regulation (Regulation 2016/679), as applicable, including the UK GDPR as retained under the UK Data Protection Act 2018.
- Processing — any operation performed on personal data, including collection, storage, transmission, retrieval, use, deletion, and similar operations.
- Supervisory Authority — the data protection authority with jurisdiction over the Controller.
2. Subject matter, duration, and purpose
This DPA covers Opora's processing of End User Data in connection with providing the platform services described in the Terms of Service.
- Subject matter — operation of the Opora AI-powered platform tools on behalf of the Controller.
- Duration — for as long as the Controller has an active Account with Opora, or until this DPA is terminated as described in Section 13.
- Nature of processing — storage, retrieval, transmission to AI sub-processors for generation, embedding, indexing, and deletion of End User Data.
- Purpose — to provide the platform's tool functionality as instructed by the Controller.
3. Categories of data and data subjects
3.1 Categories of personal data. The types of personal data processed depend entirely on what the Controller inputs. Possible categories include:
- Contact data (names, email addresses, phone numbers)
- Business information (company names, addresses, vendor or customer details)
- Financial data (pricing, bid values, cost structures — typically not sensitive financial data such as payment card numbers or bank account numbers)
- Operational data (job scope, site addresses, employee roles)
- Any other personal data included in prompts submitted by the Controller
Opora does not request or require the Controller to submit sensitive personal data (health data, government ID numbers, biometric data) into tool prompts. The Controller is responsible for ensuring that any sensitive data is handled in accordance with applicable law before submission to the platform.
3.2 Data subjects. The data subjects are the Controller's customers, employees, contractors, or other individuals whose personal data is included in the Controller's use of the platform tools.
4. Controller / Processor roles
4.1 Opora as Processor. When a business Customer uses the Opora platform to process data belonging to its own customers or employees, Opora acts as a Processor under GDPR Article 28. Opora processes End User Data only on the documented instructions of the Controller — specifically, as necessary to provide the platform services described in the Terms of Service.
4.2 Opora as Controller for platform operations. Opora acts as a Controller in respect of its own operational data — including account data, usage logs, and the rate-limit fingerprint used for anonymous sessions. This processing is described in the Privacy Policy.
4.3 Controller obligations. The Controller represents and warrants that:
- It has a lawful basis for submitting End User Data to the platform.
- It has provided appropriate notice to data subjects about the processing described in this DPA.
- It will not submit special categories of data (Article 9 GDPR) without separately confirming that appropriate safeguards are in place.
5. Processor obligations
Opora agrees to the following as Processor.
5.1 Process only on instructions. Opora will process End User Data only as necessary to provide the platform services or as required by applicable law. If applicable law requires processing beyond the Controller's instructions, Opora will notify the Controller before such processing unless the law prohibits this.
5.2 Confidentiality. Opora will ensure that personnel with access to End User Data are bound by confidentiality obligations.
5.3 No sale of End User Data. Opora does not sell End User Data to any third party.
5.4 Notify of security incidents. Opora will notify the Controller without undue delay — and within 72 hours of discovery where feasible — of any confirmed breach involving End User Data, providing sufficient detail to meet the Controller's own notification obligations under applicable law.
5.5 Assist with data subject requests. Opora will provide reasonable technical assistance to help the Controller respond to data subject requests (access, deletion, portability, correction). Controllers may initiate data export or deletion through the platform's account settings. For requests that cannot be fulfilled through self-service, contact [email protected].
5.6 Assist with compliance obligations. On request and at the Controller's cost, Opora will provide reasonable assistance with the Controller's obligations under GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation with supervisory authorities).
6. Sub-processors
Opora uses the following sub-processors to process personal data in connection with platform operations. The Controller hereby provides general authorization for Opora to engage these sub-processors, subject to the notification obligation below.
| Sub-processor | Data processed | Purpose | Jurisdiction |
|---|---|---|---|
|
Cloudflare, Inc. (Workers, D1, KV, R2, Vectorize) |
All user content, account data, embeddings, voice audio | Compute, database, key-value store, file storage, vector index | US |
| Clerk, Inc. | Email address, display name, authentication metadata | Authentication, magic link delivery, session management | US |
| Anthropic, PBC | User prompts and tool inputs | AI generation (Claude models) | US |
| OpenAI, LLC | User prompts and tool inputs | AI generation and embeddings | US |
| Cohere, Inc. | Text from saved Artifacts | Embedding and reranking for semantic search | Canada / US |
| Klaviyo, Inc. | Email address, display name, behavioral events | Transactional and marketing email delivery | US |
|
Google LLC (Workspace) |
Email (operator-side only — not End User Data) | Internal operator email and support communications | US |
|
U.S. General Services Administration (SAM.gov) |
Federal contracting search queries (no PII) | Win history overlay and RFP search | US |
| Shopify Inc. | Page rendering, customer accounts (e-commerce) | E-commerce platform | Canada / US |
6.1 Sub-processor change notification. Opora will provide the Controller with at least 15 days' advance written notice (via account email and platform banner) before adding or replacing any sub-processor that processes personal data. The Controller may object in writing within 15 days. If Opora cannot accommodate the objection, the Controller may terminate the agreement as described in Section 13.
6.2 Sub-processor obligations. Opora contractually requires each sub-processor to comply with data protection obligations equivalent to those in this DPA. Opora remains liable for the acts and omissions of its sub-processors to the same extent as if Opora performed the processing directly.
7. Security measures
Opora implements the following technical and organizational security measures, which the Controller acknowledges are appropriate to the risk profile of the platform.
- Encryption in transit — TLS 1.3 for all connections between end users and the platform, and between the platform and sub-processors.
- Secrets management — API keys and credentials stored as encrypted environment secrets in Cloudflare Workers. Not stored in source code or version control.
- Access control — authenticated endpoints require a valid Clerk session JWT. Anonymous access is rate-limited by fingerprint.
- Audit logging — account lifecycle events logged in D1 for security investigation and compliance purposes.
- Rate limiting — per-user and per-IP rate limits enforced at the edge to prevent abuse and unauthorized bulk access.
- SOC 2 Type II — in progress. We will update this DPA when certification is achieved.
Opora will review and update these measures as the threat landscape and platform architecture evolve.
8. Data subject request handling
The Controller is primarily responsible for responding to data subject requests relating to End User Data. Opora provides the following self-service mechanisms to assist:
- Data export — download a JSON package of all Account data and Artifacts at /account/settings/data.
- Account deletion — permanently delete the Account and initiate the 30-day data purge at /account/settings/data.
- Artifact deletion — delete individual Artifacts from the library, which also removes the corresponding embeddings from Vectorize.
For requests that cannot be fulfilled through self-service tools, the Controller may submit a written request to [email protected]. Opora will respond within 30 days.
9. Audits and inspections
Opora will, on reasonable written notice and no more than once per calendar year, provide the Controller with documentation and information reasonably necessary to demonstrate compliance with this DPA. Opora may fulfill this obligation by providing a copy of an applicable audit report (e.g., SOC 2 Type II — in progress) or similar third-party attestation in lieu of direct inspection.
On-site audits or inspections may be requested where the Controller has a demonstrable compliance need that cannot be addressed through documentation. Such audits are conducted at the Controller's expense and are subject to reasonable scheduling and confidentiality requirements.
10. International data transfers
Opora and most of its sub-processors are based in the United States. Processing of End User Data from the EU, UK, or EEA involves a transfer to the United States. Opora relies on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) — Opora incorporates the EU Commission's Module 2 SCCs (Controller-to-Processor) into this DPA by reference for transfers of personal data from the EU/EEA. UK IDTA (International Data Transfer Agreement) for transfers from the UK.
- Sub-processor SCCs — Opora requires its sub-processors to maintain lawful transfer mechanisms for onward international transfers.
The SCCs in their current form as approved by the European Commission are incorporated by reference. The Controller and Opora agree that the SCCs prevail over any conflicting provisions of this DPA to the extent required by EU law.
11. Term and termination
11.1 Term. This DPA remains in effect for as long as Opora processes End User Data on behalf of the Controller.
11.2 Termination. Either party may terminate this DPA by terminating the underlying Terms of Service. The Controller may also terminate this DPA if Opora materially breaches its obligations and fails to cure the breach within 30 days of written notice.
11.3 Return and deletion of data. On termination, Opora will:
- Make End User Data available for export via /account/settings/data for 30 days following the termination notice.
- Permanently delete all End User Data within 30 days after the export window closes, unless applicable law requires longer retention.
- Provide written confirmation of deletion on request.
12. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability to data subjects under GDPR Article 82 or under any applicable national data-protection law that cannot be excluded by contract.
To the extent permitted by applicable law, each party is liable to the other for breaches of this DPA to the same extent as for equivalent breaches of the Terms of Service.
13. Governing law
This DPA is governed by the laws of the State of New York, without regard to conflict-of-laws principles, except that the GDPR's provisions and Standard Contractual Clauses are governed by the laws specified therein to the extent required by EU law.
14. Contact
For DPA-related inquiries, data breach notifications, sub-processor objections, or audit requests:
Opora
Atlanta, Georgia
Email: [email protected]
Website: oporasupply.com
Effective date: 2026-06-17. This DPA forms part of the Opora Terms of Service and supersedes any prior data processing addendum or agreement.
