Version: v2026-06-06
Controller: Dario Sebastian Luna (OpStack Pro)
CUIT: 20-28655269-3
Contact: contact@opstack.pro
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions of Service between OpStack Pro (“Processor”) and the Customer (“Controller”) for the provision of the OpStack Pro platform.
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on Personal Data, including collection, storage, use, and deletion.
- Data Subject: The person to whom the Personal Data relates.
- Controller: The Customer who determines the purposes and means of Processing.
- Processor: OpStack Pro, who Processes Personal Data on behalf of the Controller.
- Sub-processor: A third party engaged by the Processor to assist in Processing activities.
2. Processing details
- Nature and purpose: Provision of AI-powered business advisory platform, including data storage, analysis, and query processing.
- Duration: The term of the Customer's account plus 90 days post-termination for data retrieval, after which data is deleted per the Privacy Policy.
- Categories of data subjects: Customer's employees, contractors, and clients whose data is uploaded to the platform.
- Types of personal data: Names, email addresses, business information, documents, and communications as described in the Privacy Policy.
3. Obligations of the Processor
OpStack Pro shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure personnel authorized to process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Not engage Sub-processors without prior notice and the opportunity to object
- Assist the Controller in fulfilling its obligations regarding data subject rights
- Notify the Controller of any Personal Data breach without undue delay
- Delete or return all Personal Data at the end of the service term
4. Data subject rights
OpStack Pro will assist the Controller in responding to data subject requests. Data subjects may exercise their rights directly by submitting a request at our Privacy page or via email to contact@opstack.pro.
5. Sub-processors
The Controller authorizes the engagement of Sub-processors listed in our Sub-processors page. OpStack Pro will notify the Controller 30 days in advance of any new Sub-processor engagement.
6. Security measures
OpStack Pro maintains the following technical and organizational measures:
- Encryption in transit (TLS 1.3) and at rest (AES-256-GCM)
- Role-based access control with least privilege principle
- Regular security audits and penetration testing
- Incident response and breach notification procedures
- Data backup and disaster recovery procedures
- Rate limiting and input validation on all API endpoints
- Personnel training on data protection practices
7. International transfers
Personal Data may be transferred to and processed in countries other than the Controller's country of residence. OpStack Pro ensures adequate safeguards through Standard Contractual Clauses (SCCs) or equivalent mechanisms.
Current processing locations: Argentina (controller), United States (Supabase, Netlify, Google Cloud Run), and European Union (select services).
8. Liability and indemnification
Each party's liability under this DPA is subject to the limitations set forth in the Terms and Conditions. The Controller is responsible for ensuring that the Processing instructions comply with applicable data protection laws.
9. Governing law
This DPA shall be governed by the laws of the Province of Córdoba, Argentina. Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms and Conditions.
10. Contact
For DPA inquiries or to request an executed copy, contact us at contact@opstack.pro.