Legal

Data Processing Agreement

Standard terms, version 1.0, July 2026. This DPA supplements our Terms of Service when OTW Motion processes personal data on behalf of a customer. To execute a signed copy, email melinda@otwmotion.com.

1. Roles and scope

For personal data the customer submits to the service (account contacts, business details, API inputs), the customer is the controller and OTW Motion Inc. ("OTW") is the processor. OTW processes such data only on the customer's documented instructions, as expressed through use of the service, and for no other purpose.

2. Details of processing

Subject matter: providing AI-visibility measurement, reports, dashboards, and API access. Duration: the term of the agreement plus the retention periods in our privacy policy. Categories of data: account contact details, business information, usage data, payment records (processed by Stripe). Data subjects: customer personnel and, where the customer submits them, the customer's own contacts.

3. Security measures

OTW implements the technical and organizational measures described on our security page, including encryption in transit, hashed credentials, access controls, rate limiting, audit logging, automatic backups, and a documented incident response process. These measures may improve but will not materially degrade during the term.

4. Confidentiality and personnel

Persons authorized to process personal data are bound by confidentiality obligations. Access is limited to what operating the service requires.

5. Subprocessors

The customer authorizes the subprocessors listed on our security page. OTW will update the list before adding a subprocessor that processes personal data and, for customers with an executed DPA, provide at least 14 days' notice by email, during which the customer may object on reasonable data-protection grounds.

6. International transfers

Where processing involves transfers from the EEA, UK, or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (module two, controller to processor) and the UK Addendum, completed with the processing details above. Transfers to subprocessors rely on those subprocessors' own SCC-based frameworks.

7. Assistance and rights requests

Taking into account the nature of processing, OTW assists the customer in responding to data-subject requests. Export and deletion are self-serve in the product; OTW responds to requests it cannot automate within 30 days.

8. Personal data breach

OTW notifies the customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the customer's data, with the information reasonably available to support the customer's own notification duties.

9. Deletion and return

On termination, or earlier through the product's self-serve tools, OTW deletes personal data processed for the customer, except payment transaction records retained in anonymized form to meet legal obligations.

10. Audits

OTW makes available information reasonably necessary to demonstrate compliance with this DPA, including this documentation, our security page, and responses to security questionnaires. Audits beyond documentation review require reasonable notice, at most once annually, at the customer's expense.

This standard DPA is offered for review and signature. If your organization requires its own DPA template, send it to melinda@otwmotion.com for review.