Data processing agreement
Version 0
Beta text (placeholder, version 0). OmnaBase wrote this agreement for the closed beta; a lawyer-reviewed version will replace it and will be put to every workspace owner with the date it takes effect. A change of sub-processor is mailed to every workspace's owner with the objection period of section 7.
This agreement under Art. 28 GDPR is between the customer running a workspace (the "controller") and Kriesi Media GmbH, Lange Gasse 50, 1080 Vienna, Austria (the "processor", "OmnaBase"). It forms part of the terms of service and applies to the personal data the controller processes with OmnaBase.
1. Subject, duration, nature and purpose
OmnaBase stores and processes the controller's customer conversations (tickets), its knowledge base and its team's work on them, so that the controller can answer its customers, with the help of an AI assistant where the controller switches it on. The processing lasts as long as the controller has a workspace, plus the deletion periods of section 9.
Data subjects: the controller's customers and the people who write to it; the controller's team members. Categories of data: names, e-mail addresses, message texts and attachments, licence keys and site addresses a customer claims, what the controller's own systems answer about a customer when connected, team members' names, addresses and their work in the workspace. The controller must not bring special categories of data (Art. 9 GDPR) into OmnaBase on purpose; where a customer sends such data in a message, the controller handles it with the deletion tools provided.
2. The processor's duties
OmnaBase:
- processes personal data only on the controller's documented instructions, which are: the terms, the settings the controller chooses in the app, and the actions its members take; OmnaBase tells the controller if an instruction in its view breaks the law;
- ensures that the people with access are bound to confidentiality;
- takes the security measures of section 5;
- engages sub-processors only as section 7 allows;
- helps the controller answer data subjects' requests, with the export and deletion tools in the app and, beyond them, on request;
- helps the controller with security, breach notification and impact assessments as far as the information available to OmnaBase goes;
- deletes or returns the data at the end, as section 9 says;
- makes the information needed to show compliance available and allows audits as section 8 says.
3. The controller's duties
The controller is responsible for the lawfulness of the processing, for informing its customers (for example in its own privacy notice, which the public form links when set), for the instructions it gives, and for the content and the settings of its workspace, including which members it invites, what it connects, and whether it switches the AI assistant, automatic replies and members' own AI on.
4. The AI assistant
Where the controller switches the assistant on, OmnaBase sends the ticket's text, excerpts of the controller's knowledge base and, for an investigation, excerpts of the controller's product code to the AI providers listed in section 7 to obtain a draft or a classification. Automatic replies carry a footer naming the assistant. The providers process the data on OmnaBase's instructions and do not use it to train their models under the agreements OmnaBase has with them. The controller's resolved tickets are used as knowledge only where the controller switches that on.
5. Members' own AI
When the controller allows its members to connect their own AI app (the switch "Members may connect their own AI", off until the owner turns it on), a connected AI receives the customer data the member may see, through OmnaBase's connector, on the member's request, and writes notes, drafts, tags, the status and the assignee as the member, each marked as the member's AI; it never sends a reply to a customer. The member's AI provider is chosen by the controller and its member, so it is not one of our sub-processors; the controller, as the controller of its customers' data, decides whether to allow it in its workspace, which members may use it, and answers for it. OmnaBase records which connected AI wrote what, and the controller can switch the feature off and revoke every connection at any time.
6. Security measures
- Encryption in transit (TLS) on every connection, including between OmnaBase's services and its database; files and backups encrypted at rest at Amazon in Frankfurt.
- Every workspace's rows are isolated by row-level security in the database; application code runs under a database role that can only see the workspace it was opened for.
- Sign-in by one-time code sent to the person's address; sessions as signed cookies; rate limits per address and per session; a bot check on sign-in and public forms.
- Access to production systems is limited to the people who run the service, by key, logged; no shared passwords; secrets are held on the server, never in the code repository.
- Attachments are checked against their declared type and served with download headers; uploaded files are capped per workspace.
- Daily database backups to a separate bucket, point-in-time recovery for 7 days, a tested restore procedure; two application copies behind the edge so a deploy does not interrupt the service.
- An audit log of settings changes per workspace; error monitoring; a public status page.
- A connected AI (section 5) and the AI providers (section 4) receive only what the person or the settings allow; product code reaches them through a filtered copy from which secret files are removed and key-shaped lines masked.
Sub-processors (section 7)
The controller authorises the following sub-processors. OmnaBase informs the controller's workspace owner by mail of an intended addition or replacement; the controller may object within 30 days of that mail on reasonable data protection grounds. If OmnaBase cannot accommodate the objection, the controller may delete its workspace before the change takes effect, with the export of section 9.
| Company | Where | What for |
|---|---|---|
| Amazon Web Services EMEA SARL | Frankfurt (eu-central-1) | the servers, the database, file storage, mail sending and receiving, queues, backups |
| Cloudflare, Inc. | the edge, EU-first routing | the domain, DDoS protection, the bot check (Turnstile), the status page |
| Google Cloud (Vertex AI) | the EU (Google's European region) | the Gemini models for classification, embeddings and drafts where chosen |
| Anthropic, PBC | United States | the Claude model for drafts and code investigations during the beta |
| Stripe Payments Europe, Ltd. | Ireland | subscriptions, card payments, invoices, VAT (the controller's billing data, not its customers' data) |
| Sentry (Functional Software, Inc.) | EU data region | error reports |
Transfers outside the EU/EEA: Anthropic processes Claude prompts in the United States under the EU standard contractual clauses in its data processing addendum. Cloudflare and Sentry hold data in the EU with the same clauses for support access from elsewhere. OmnaBase intends to move the Claude route to an EU region when it becomes available to it and will update this list then.
8. Audits and information
On request OmnaBase provides the information needed to show compliance with Art. 28 GDPR: this agreement, the security measures, the sub-processor list and its providers' certifications or reports. Where that is not enough, the controller may audit once a year, with 30 days' notice, during business hours, without disturbing the service and other customers; the controller bears the cost.
9. Breaches, deletion and the end
- OmnaBase tells the controller's workspace owner without undue delay after becoming aware of a personal data breach affecting the controller's data, with what is known at the time and what follows.
- The controller can export its workspace's data at any time as files readable without OmnaBase's software, and delete customers, team members' data or the whole workspace in the app. A deleted workspace stays recoverable for 7 days, then its rows and files are removed; a fingerprint of a deleted customer's address is kept for 35 days so that a mail delivered late does not recreate the person. Backups age out after 30 days.
- At the end of the terms OmnaBase deletes the controller's data the same way, unless the law requires it to keep some of it (billing records).
10. Liability and precedence
Liability follows the terms of service. Where this agreement and the terms differ on personal data, this agreement prevails. Austrian law applies.
Kriesi Media GmbH, Vienna, 2026.