Data Processing Addendum
The data-processing framework available to customers that use Omega to process personal data.
Published following operator-authorized Omega privacy, security, claims, and operational review. External counsel review is not recorded.
Data Processing Addendum is public procurement information, not an executed agreement. Qualified external counsel must review the customer-specific agreement before signature or reliance.
How this addendum applies
This page describes Omega's standard DPA framework. It becomes binding only when incorporated into an executed agreement, order form, or DPA accepted by Omega and the customer. The executed document controls over this summary.
Roles and scope
The customer is controller or business and Omega is processor or service provider for Customer Personal Data, except where Omega independently determines purposes for account, security, billing, or legal-compliance information. Processing is limited to the services, term, data categories, subjects, and instructions in the agreement.
Documented instructions
Omega processes Customer Personal Data only on documented instructions, including instructions inherent in configured features, unless law requires otherwise. Omega will inform the customer if it believes an instruction violates applicable data-protection law, unless prohibited.
Confidentiality and personnel
Omega limits access to authorized personnel and contractors who need it for the service and who are bound by confidentiality obligations. Access is reviewed and may be removed when no longer required.
Security measures
Omega maintains risk-based technical and organizational measures appropriate to the service, including identity and access controls, encrypted transport, managed storage protection, secret custody, logging, change review, vulnerability response, backup controls, and incident procedures.
Subprocessors
The customer gives general authorization for the subprocessors listed on the Subprocessors page or in the executed DPA. Omega remains responsible for required contractual protections and provides change notice and objection rights as stated in the executed DPA.
International transfers
Where required, the parties will use an applicable transfer mechanism, such as standard contractual clauses or another legally recognized safeguard, together with supplementary measures appropriate to the transfer.
Individual requests
Taking into account the nature of processing, Omega will reasonably assist the customer with requests for access, correction, deletion, restriction, portability, objection, or other rights. Omega may direct a requester to the customer when the customer controls the data.
Security incidents
Omega will notify the customer without undue delay after confirming a breach of Customer Personal Data, provide information reasonably available for the customer's obligations, and take appropriate containment and remediation steps. Notice is not an admission of fault.
Deletion, return, and audit
At the end of services, Omega will delete or return Customer Personal Data as the executed agreement requires, subject to backups, legal holds, and legal retention. Omega will provide reasonable compliance information and support proportionate audits under confidentiality, security, frequency, and cost controls in the executed DPA.
Contact
To request an executable DPA or discuss transfer terms, contact legal@omeganeural.com and identify the customer entity, service, and intended processing.
Read this page with the related policy, trust, and service information that applies to your use of Omega.