Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Opaline Terms of Service or another agreement governing the Customer's use of Opaline. It applies whenever Opaline processes Customer Personal Data on the Customer's behalf.
1. Parties and roles
The parties are the Customer identified in the applicable agreement and Opaline Labs, Inc., 2261 Market Street, San Francisco, CA 94114, United States.
"Customer Personal Data" means personal information contained in or derived from content submitted to Opaline that Opaline processes on the Customer's behalf. "Applicable Data Protection Law" means privacy and data-protection law applicable to that processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA"), other applicable U.S. state privacy laws and, where applicable, the GDPR and UK GDPR.
The Customer is the controller and Opaline is the processor. If the Customer processes Customer Personal Data for another controller, the Customer is a processor and Opaline is its subprocessor. Each party will comply with the obligations applicable to its role.
2. Scope, instructions and U.S. state privacy terms
Opaline will process Customer Personal Data only to provide, secure and support the Service; follow the Customer's documented instructions; and comply with law. The Customer's instructions consist of the agreement, its configuration and use of the Service, User actions, permission settings, support requests, deletion or export requests and other written instructions accepted by Opaline.
If Opaline believes an instruction infringes Applicable Data Protection Law, it will notify the Customer unless prohibited by law and may suspend the affected processing until the parties resolve the issue. If law requires processing beyond the Customer's instructions, Opaline will notify the Customer before processing unless legally prohibited.
The Customer is responsible for the lawfulness, accuracy and quality of Customer Personal Data and its instructions, including establishing a legal basis and providing required notices.
Where the CCPA or another U.S. state privacy law applies, Opaline acts as the Customer's service provider or processor. Opaline will not sell or share Customer Personal Data; retain, use or disclose it outside the direct business relationship with the Customer or for a commercial purpose other than providing the Service; or combine it with personal information received from another person except as permitted by law. Opaline will provide the same level of privacy protection required of service providers or processors, notify the Customer if it can no longer meet those obligations and allow the Customer to take reasonable steps to verify, stop and remediate unauthorized processing.
3. Confidentiality
Opaline will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as necessary for their authorized responsibilities.
Opaline will maintain the reasonable safeguards for Customer Personal Data required by Applicable Data Protection Law.
4. Subprocessors
The Customer gives Opaline general written authorization to engage subprocessors. Current subprocessors are listed on the Subprocessors page.
Opaline will require each subprocessor to protect Customer Personal Data through written obligations materially equivalent to those applicable to Opaline under this DPA. Opaline remains responsible for its subprocessors to the extent required by Applicable Data Protection Law.
Opaline will provide advance notice by email or through the Service before a new subprocessor begins processing Customer Personal Data. The Customer may object within 14 days on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot, the Customer may terminate the affected Service before the new subprocessor begins processing.
Where urgent replacement is necessary for security, service availability or legal compliance, Opaline may appoint a subprocessor before giving notice and will notify the Customer without undue delay.
5. International transfers
Opaline is based in the United States and may process Customer Personal Data in the United States and other countries where Opaline or its subprocessors operate. Where Applicable Data Protection Law requires a transfer mechanism, the parties will use an applicable adequacy decision, certification, standard contractual clauses or other lawful mechanism.
If the Customer needs the European Commission's Standard Contractual Clauses, UK International Data Transfer Addendum or another transfer addendum, the parties will complete the applicable module and annexes using the processing details in this DPA and current information supplied by Opaline.
6. Customer assistance
Taking into account the nature of processing and information available to it, Opaline will provide reasonable assistance with:
- data-subject requests;
- security and personal-data breach obligations;
- data-protection impact assessments and prior consultations; and
- regulatory enquiries concerning the Service.
If Opaline receives a request from a data subject concerning identifiable Customer Personal Data, it will forward the request to the Customer without undue delay and will not respond substantively unless instructed or legally required. The Customer remains responsible for its response.
Opaline may charge reasonable costs for substantial customized assistance beyond standard Service functionality, except where assistance is required because Opaline breached this DPA or Applicable Data Protection Law.
7. Personal-data breaches
Opaline will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature and likely consequences of the breach, affected data and individuals, measures taken or proposed, and a contact point.
Notification is not an admission of fault. The Customer is responsible for notifications to authorities and individuals unless law assigns that responsibility directly to Opaline.
8. Return and deletion
The Customer may delete sessions, accounts and workspaces through available Service functionality. On termination, Opaline will, at the Customer's choice, return Customer Personal Data through available export functionality or delete it. If the Customer does not request return before termination or within a reasonable period specified by Opaline, deletion is the default.
Opaline will remove Customer Personal Data from active systems without undue delay. Residual copies may remain in protected backups until overwritten through the ordinary backup cycle, provided they remain protected, are not used for ordinary processing and deletion instructions are reapplied if a backup is restored. Opaline may retain data required by law only for the legally required purpose.
9. Information and audits
Opaline will make information reasonably necessary to demonstrate compliance with Applicable Data Protection Law available to the Customer. The Customer should first use this DPA, Opaline's Privacy notice, subprocessor information, reasonable written responses and available independent reports or certifications.
If that information is insufficient, the Customer may request an audit. Audits must concern processing relevant to the Customer, occur no more than once in 12 months unless a material incident or authority requires otherwise, use at least 30 days' notice where practicable, avoid unreasonable disruption and protect other customers' and Opaline's confidential information. Opaline may satisfy a request through a reasonably sufficient remote review.
The Customer bears its audit costs and Opaline's reasonable costs of supporting an exceptional audit unless it identifies a material breach by Opaline. Nothing limits the powers of a competent supervisory authority.
10. Government requests
If Opaline receives a legally binding public-authority request for Customer Personal Data, it will, where permitted, notify the Customer, review whether the request is lawful and proportionate, challenge an apparently unlawful request where appropriate and disclose only what is legally required.
11. Liability, priority and term
Liability under this DPA is governed by the liability section of the Terms, subject to liability that cannot be limited under Applicable Data Protection Law. Nothing limits the rights of individuals or regulators.
This DPA controls if it conflicts with the Terms about processing Customer Personal Data. A valid transfer mechanism controls a particular transfer where it imposes stricter requirements.
This DPA ends when Opaline no longer processes Customer Personal Data for the Customer, except for provisions that must continue while retained copies remain.
Schedule 1 — Processing details
Subject matter and duration
Opaline processes Customer Personal Data to provide hosted coding-agent session ingestion, storage, display, analytics and workspace management for the agreement's term and the limited period afterward needed to return, delete or lawfully retain it.
Nature and purpose
Processing includes collecting, validating, organizing, parsing, storing, retrieving, displaying and analyzing session information; extracting metadata and generating workspace analytics; enforcing access controls; supporting the Customer; transmitting data to authorized subprocessors; and exporting, restricting, backing up and deleting data.
Opaline does not process substantive session contents for advertising, AI-model training, independent research or cross-customer benchmarking.
Data subjects
Customer Personal Data may concern the Customer, Users, employees, contractors, consultants, developers, administrators, the Customer's clients and end users, people communicating with the Customer, and others whose information appears in a coding-agent session.
Categories of personal data
Data may include names, usernames, email addresses, account and organization identifiers, project and repository information, source code, file contents and paths, prompts and model responses, system messages, terminal commands and output, tool calls, URLs, version-control information, timestamps, usage records, model and token information, classifications, technical identifiers, business information, communications and other personal data appearing in or derived from a session.
Sensitive data
The Service is not intended for intentional processing of sensitive personal information such as government identifiers, payment-card information, protected health information, biometric or genetic data, precise geolocation, credentials or private keys. Such information may nevertheless appear incidentally in complete session data. The Customer must not intentionally submit it unless Opaline agrees in writing and appropriate safeguards are established.
Frequency and retention
Processing occurs when Users upload sessions, enable an upload hook, use dashboards or transcripts, manage permissions, create public shares, request support, or issue export or deletion instructions. Recurring submissions may occur while an upload hook is enabled.
Data is retained until the relevant session, account or workspace is deleted, the agreement ends or another lawful instruction requires deletion. Public-share snapshots remain available until deleted, replaced or automatically expired. Protected backup copies expire through ordinary backup cycles.