OpalSpan: data processing agreement
Version and particulars/annex version: dpa-en-2026-09-28-v4. Instructions version: dpa-instructions-en-2026-09-28-v4.
Parties and applicability
Processor: Ready IT ApS, CVR 38769383, c/o Matt Luccas Phaure Jensen, Viften 18, 1. 1, 2670 Greve, Denmark; contact@readyit.dk.
Customer: the contracting customer identified in the accepted OpalSpan order, with the address and authorised contact recorded for that customer. The order and its recorded electronic acceptance identify the effective agreement date and agreement reference.
This agreement applies where Ready IT processes personal data on the customer's behalf in providing the instructed OpalSpan technical-work service. The customer is controller for data whose purposes and means it determines. Where the customer is itself a processor, Ready IT acts as an authorised subprocessor; the customer's relevant controller instructions and authority apply. References below to controller instructions include that authorised chain.
Buying as a business or a consumer does not by itself decide that data-protection role. Purely personal/household use and Ready IT's own account, security and billing purposes do not become controller-to-processor processing merely because this agreement accompanies the subscription.
Processing particulars and instructions
Subject matter and purpose: hosting and organising the customer's authorised technical-work records and enabling remote technical access, customer/case coordination and, when instructed, hosted OpalSpan Mech assistance.
Nature: receipt, recording, organisation, storage, authorised retrieval and use of customer/contact/company records, case notes and drafts, device links, selected diagnostic information, files, conversations and tool evidence; communication to the relevant enabled service providers for those functions; and return/deletion as instructed. Hosted Mech can use relevant records across cases within the authorised workspace. Separate chats are not a new confidentiality boundary.
Duration: while those processing services are provided and while completing the customer's return/deletion instructions, subject to lawful mandatory retention. Cancelling payment and continuing on Free does not end the data processing service or itself instruct deletion.
Data subjects: the customer's users/technicians, customers and their contacts, device users, and other people whose information is included in authorised case, file, diagnostic or conversation material.
Personal-data types: names and contact/business details; workspace and device identifiers; case communications and notes; selected device/account, system, software, network and diagnostic information; and personal data present in the particular authorised files, conversation context and tool results. This description is not an instruction to indiscriminately copy device contents, credentials or unrelated sensitive information. Specific additional categories and purposes must be covered by the customer's lawful instructions before inclusion.
The accepted service order, this annex, the versioned OpalSpan processing instructions and the customer's authorised workspace actions are the documented instructions. The customer determines the lawful basis and required notices for its controlled data and has the authority needed to supply it, grant technical access and issue these instructions. An upstream processor must remain within the relevant controller's instructions and permissions.
Annex: measures, recipients and end of processing
OpalSpan uses Auth0 authentication with OpalSpan-controlled workspace membership, roles and target authorisation/revocation. Native remote access uses encrypted SSH/SFTP through an outbound HTTPS relay. Hosted tools operate within the authorised human/workspace/device scope. Diagnostic collection is explicit, not routine unrestricted collection.
Conversation payloads and checkpoints use application data protection scoped to the workspace and conversation. Mech files use a private store outside public web roots with scoped access and file-integrity/version checks. Metadata-only access audit is separate from case content and conversation history. These measures do not represent a certification, an all-data encryption claim or a guarantee against every incident.
AWS supplies Bridge hosting in Stockholm (Lightsail eu-north-1) and the CloudFront front door under Ready IT's ordinary AWS account terms, including the incorporated applicable AWS DPA/SCC provisions.
OpenAI Ireland Ltd. supplies the Responses API for instructed hosted Mech
processing. The ordinary Services Agreement, updated 1 December 2025 and
effective 1 January 2026, incorporates the DPA through section 5.3. DPA section
4.1 supplies SCC or Article 45 adequacy arrangements for the EEA onward
transfers it covers. The project uses Global residency and Standard tier, with
store=false; the organisation's model-feedback, evaluation/fine-tuning and
API-input/output sharing opt-ins are all disabled. Provider abuse-monitoring
and prompt-cache retention remain distinct from OpalSpan's stored conversation
history. Neither provider is described as universally EU-only or zero retention.
AWS hosting and OpenAI model processing are relevant subprocessors for the customer technical-work data they receive. Auth0's role in instructed user identity processing must be distinguished from Ready IT's own account administration. Microsoft 365/Graph receives contact correspondence and contract mail; it is a subprocessor under this agreement only to the extent Ready IT instructs it to process the customer's controlled data on the customer's behalf. Stripe's own payment/legal processing is not automatically a technical-work subprocessor relationship.
For Microsoft Exchange Online/Graph processing within this agreement's scope, the ordinary Microsoft agreement incorporates the Products and Services DPA. Its May 2026 Data Transfers provisions cover the United States and other Microsoft/subprocessor operating countries with the stated location safeguards and 2021 SCCs for EEA transfers. The DPA identifies the Microsoft Ireland Operations Limited to Microsoft Corporation SCC arrangement; those transfer entities are not an invented description of Ready IT's billing counterparty. Contract-mail application sending permissions are restricted to one mailbox.
Okta supplies Auth0 authentication and sign-in identity processing from an EU tenant; OpalSpan separately controls workspace membership and permissions. Its role in customer-instructed identity processing is distinct from Ready IT's own account administration. Supplier support and onward processing may occur outside the EEA. Okta's published processing and transfer information is at https://www.okta.com/legal/trustandcompliance/.
General subprocessor authorisation applies to the identified on-behalf processing and its applicable arrangements, not an undisclosed additional purpose. Supplier terms/safeguards can be obtained through contact@readyit.dk.
The customer may send specific instructions, rights requests and an end-of- service return/deletion choice to contact@readyit.dk. Directory/case records have no general automatic expiry; scratch-file expiry, access-audit retention and financial records follow their distinct purposes. The end-of-processing obligation below is not replaced by those application timers.
Ready IT verifies the requesting party's authority and the affected customer and workspace before carrying out a return, deletion or restriction instruction. The action and any applicable retention exception are recorded. Live service records and recovery copies may need different handling: automatic snapshots rotate over seven daily generations, while separate manual recovery copies are reviewed individually and have no automatic expiry. An end-of-processing return or deletion instruction covers the relevant recovery copies, subject to the legal-retention exception in clause 6. Before restored data is returned to use, completed deletion and restriction instructions for the affected scope are reconciled. Ready IT will explain the route and any remaining lawful exceptions for a specific request.
Required processing terms
Ready IT processes personal data only on documented controller instructions, including instructions on transfers outside the EU/EEA, unless applicable Union or Member State law requires otherwise. In that case it informs the controller of the legal requirement before processing unless that law prohibits notification on important public-interest grounds.
Persons authorised to process personal data must be committed to confidentiality or subject to an appropriate statutory confidentiality duty. Ready IT implements the measures required by GDPR Article 32.
The controller gives general written authorisation for the subprocessors identified in the completed annex. Ready IT informs the controller of intended additions or replacements so the controller has an opportunity to object. No undisclosed list or blank annex establishes authorisation for a supplier. Ready IT imposes the same applicable data-protection obligations by contract on subprocessors, including sufficient guarantees for appropriate technical and organisational measures, and remains responsible to the controller for the subprocessor's performance of those obligations.
Taking account of the nature of processing, Ready IT assists the controller through appropriate technical and organisational measures, insofar as possible, to fulfil obligations to respond to data-subject rights requests. It assists compliance with GDPR Articles 32-36, taking account of the nature of processing and information available to it.
Ready IT notifies the controller without undue delay after becoming aware of a personal-data breach. This does not replace the controller's own applicable notification and communication obligations.
At the controller's choice, Ready IT deletes or returns all personal data after the end of the processing services and deletes existing copies unless Union or Member State law requires retention. The actual return/deletion and backup arrangements must be recorded consistently with this obligation.
Ready IT makes available information necessary to demonstrate compliance with GDPR Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by it.
Ready IT immediately informs the controller if, in its opinion, an instruction infringes GDPR or other Union or Member State data-protection provisions.