Data Processing Agreement (DPA)
Version 1.0 · Effective 2026-10-05 · Provider: OpDesk · Site: https://opdesk.eu · Contact: support@opdesk.eu
1. Roles
You (Customer) = controller for personal data on your site / database / shop logs.
OpDesk = processor when we access such data solely to perform the Job you requested.
For your OpDesk account data (login email, etc.), OpDesk is controller — see Privacy Policy.
2. Subject matter
Categories: e.g. shop customer data, orders, emails, IPs in logs, config file contents — only to the extent they appear in the snapshot or files touched by the Job.
Purpose: diagnosis, repair prep, applying approved changes, backup/rollback, support for that Job.
Duration: for the Job and backup/audit retention as in the Privacy Policy.
3. OpDesk obligations
We process data only on your documented instructions via the product (the Job and your approvals).
We apply appropriate technical and organizational measures (encrypted credentials, restricted access, worker secret, least privilege where feasible).
We notify without undue delay of a personal-data breach we become aware of that affects data we process as processor.
We delete or return related work copies after the retention period, unless law requires retention.
4. Sub-processors
We may use cloud infrastructure, payments and AI providers as described in the Privacy Policy. By using the service you authorize those processors to the extent required for OpDesk.
We will update the legal pages when the infrastructure list changes materially.
5. International transfers
Some providers may be outside the EEA. Where applicable we rely on appropriate safeguards (e.g. provider SCCs) and data minimization.
6. Assistance
Where reasonable and technically feasible, we help you respond to data-subject requests relating to data we processed in a Job.