Legal

Data Processing Agreement

Last updated July 2026

For business customers we provide a signable DPA on request. This page describes its substance and forms part of the Terms.

When you build apps with opix, your app may collect personal data from its own end-users. For that data you are the controller and opix is your processor. This DPA governs that relationship and forms part of the Terms.

1. Scope & roles

opix processes end-user personal data only on your documented instructions, as needed to host and run your project and provide the Service.

2. Subprocessors

You authorise opix to engage the subprocessors listed in our Privacy Policy. We will inform you of changes and remain responsible for their compliance.

3. Security

  • encryption in transit; secrets stored server-side and never exposed to the browser;
  • isolated execution of generated code;
  • access controls, least-privilege, and audit logging;
  • generated apps default to secure patterns (hashed passwords, HTTP-only sessions, parameterised queries).

4. International transfers

Where data leaves the EU/Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses.

5. Data subject requests & breaches

We assist you in responding to data-subject requests and will notify you without undue delay of any personal-data breach affecting your end-users’ data.

6. Deletion & return

On termination, we return or delete end-user personal data at your choice, subject to legal retention obligations.

Contact

To request a signed DPA: fabiano.frascati@gmail.com.