Data processing agreement

Version 0

Beta text (placeholder, version 0). OmnaBase wrote this agreement for the closed beta; a lawyer-reviewed version will replace it and will be put to every workspace owner with the date it takes effect. A change of sub-processor is mailed to every workspace's owner with the objection period of section 7.

This agreement under Art. 28 GDPR is between the customer running a workspace (the "controller") and Kriesi Media GmbH, Lange Gasse 50, 1080 Vienna, Austria (the "processor", "OmnaBase"). It forms part of the terms of service and applies to the personal data the controller processes with OmnaBase.

1. Subject, duration, nature and purpose

OmnaBase stores and processes the controller's customer conversations (tickets), its knowledge base and its team's work on them, so that the controller can answer its customers, with the help of an AI assistant where the controller switches it on. The processing lasts as long as the controller has a workspace, plus the deletion periods of section 9.

Data subjects: the controller's customers and the people who write to it; the controller's team members. Categories of data: names, e-mail addresses, message texts and attachments, licence keys and site addresses a customer claims, what the controller's own systems answer about a customer when connected, team members' names, addresses and their work in the workspace. The controller must not bring special categories of data (Art. 9 GDPR) into OmnaBase on purpose; where a customer sends such data in a message, the controller handles it with the deletion tools provided.

2. The processor's duties

OmnaBase:

3. The controller's duties

The controller is responsible for the lawfulness of the processing, for informing its customers (for example in its own privacy notice, which the public form links when set), for the instructions it gives, and for the content and the settings of its workspace, including which members it invites, what it connects, and whether it switches the AI assistant, automatic replies and members' own AI on.

4. The AI assistant

Where the controller switches the assistant on, OmnaBase sends the ticket's text, excerpts of the controller's knowledge base and, for an investigation, excerpts of the controller's product code to the AI providers listed in section 7 to obtain a draft or a classification. Automatic replies carry a footer naming the assistant. The providers process the data on OmnaBase's instructions and do not use it to train their models under the agreements OmnaBase has with them. The controller's resolved tickets are used as knowledge only where the controller switches that on.

5. Members' own AI

When the controller allows its members to connect their own AI app (the switch "Members may connect their own AI", off until the owner turns it on), a connected AI receives the customer data the member may see, through OmnaBase's connector, on the member's request, and writes notes, drafts, tags, the status and the assignee as the member, each marked as the member's AI; it never sends a reply to a customer. The member's AI provider is chosen by the controller and its member, so it is not one of our sub-processors; the controller, as the controller of its customers' data, decides whether to allow it in its workspace, which members may use it, and answers for it. OmnaBase records which connected AI wrote what, and the controller can switch the feature off and revoke every connection at any time.

6. Security measures

Sub-processors (section 7)

The controller authorises the following sub-processors. OmnaBase informs the controller's workspace owner by mail of an intended addition or replacement; the controller may object within 30 days of that mail on reasonable data protection grounds. If OmnaBase cannot accommodate the objection, the controller may delete its workspace before the change takes effect, with the export of section 9.

Company Where What for
Amazon Web Services EMEA SARL Frankfurt (eu-central-1) the servers, the database, file storage, mail sending and receiving, queues, backups
Cloudflare, Inc. the edge, EU-first routing the domain, DDoS protection, the bot check (Turnstile), the status page
Google Cloud (Vertex AI) the EU (Google's European region) the Gemini models for classification, embeddings and drafts where chosen
Anthropic, PBC United States the Claude model for drafts and code investigations during the beta
Stripe Payments Europe, Ltd. Ireland subscriptions, card payments, invoices, VAT (the controller's billing data, not its customers' data)
Sentry (Functional Software, Inc.) EU data region error reports

Transfers outside the EU/EEA: Anthropic processes Claude prompts in the United States under the EU standard contractual clauses in its data processing addendum. Cloudflare and Sentry hold data in the EU with the same clauses for support access from elsewhere. OmnaBase intends to move the Claude route to an EU region when it becomes available to it and will update this list then.

8. Audits and information

On request OmnaBase provides the information needed to show compliance with Art. 28 GDPR: this agreement, the security measures, the sub-processor list and its providers' certifications or reports. Where that is not enough, the controller may audit once a year, with 30 days' notice, during business hours, without disturbing the service and other customers; the controller bears the cost.

9. Breaches, deletion and the end

10. Liability and precedence

Liability follows the terms of service. Where this agreement and the terms differ on personal data, this agreement prevails. Austrian law applies.

Kriesi Media GmbH, Vienna, 2026.