Legal
Data Processing Addendum
How Owlie processes personal data on behalf of customers in connection with the Services.
Last Updated: September 22, 2026
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Master Subscription Agreement (Terms of Service), Order Form, or other written agreement governing the provision of the Services (the “Agreement”) between Owlie, LLC (“Owlie,” “Company,” “Processor,” or “Service Provider”) and the customer identified in the applicable Agreement (“Customer,” “Controller,” or “Business”).
This DPA applies solely to the extent Owlie processes Personal Data on behalf of Customer in connection with the Services and is intended to align with the Agreement, Owlie’s Acceptable Use Policy, Service Level Agreement, Security Addendum, and Responsible AI Policy, each of which is incorporated by reference.
1. Definitions
Capitalized terms not otherwise defined in this DPA have the meanings set forth in the Agreement.
-
“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss DPA, CCPA/CPRA, and similar laws.
-
“Customer Data” has the meaning set forth in the Agreement.
-
“Personal Data” means any information relating to an identified or identifiable natural person that is processed by Owlie on behalf of Customer.
-
“Processing” has the meaning given under Applicable Data Protection Laws.
-
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
-
“Subprocessor” means a third party engaged by Owlie to process Personal Data on behalf of Customer.
2. Roles of the Parties
2.1 Customer is the Controller (or Business), and Owlie is the Processor (or Service Provider) of Personal Data processed under the Agreement.
2.2 Owlie shall process Personal Data solely on Customer’s documented instructions, including instructions inherent in its configuration and authorized use of the Services, unless applicable law requires otherwise. Where legally permitted, Owlie will inform Customer of that legal requirement before processing. Owlie will immediately inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.
2.3 Owlie shall not determine the purposes or means of processing Customer Personal Data except as necessary to provide, secure, and support the Services.
3. Scope of Processing
3.1 Subject Matter
Provision of identity governance, identity lifecycle management, access requests and reviews, authentication and authorization support, provisioning, integrations, audit logging, security monitoring, automation, and AI-assisted functionality.
3.2 Duration
For the term of the Agreement and thereafter only as necessary to complete data return and deletion or for the limited retention permitted under Section 11, subject to Applicable Data Protection Laws.
3.3 Nature and Purpose
Processing necessary to host, operate, secure, support, and maintain the Services; synchronize identity and application data; perform customer-configured workflows; facilitate access-governance activities; provide customer-directed integrations; and generate AI-assisted responses or actions requested by authorized users.
This processing includes transcription of user-submitted audio, persistence of saved conversations and workspace state, authorized staff retrieval and on-demand transcript export for support or troubleshooting, and limited product-improvement records generated through the Services. Each activity remains subject to Customer’s instructions, purpose limitations, access controls, and the return and deletion provisions of this DPA. Owlie does not use Personal Data to train general-purpose models for Owlie or third-party AI providers.
3.4 Categories of Data Subjects
- Customer employees, contractors, applicants, former workers, external collaborators, and service-account owners represented in connected systems
- Individuals communicating through customer-enabled integrations
- End users authorized by Customer
3.5 Categories of Personal Data
- Identifiers and professional information, including name, email address, username, employee identifier, title, department, manager, and employment status
- Account, group, role, permission, entitlement, and access-relationship data
- Authentication and security data, including public keys, authentication events, device information, IP addresses, and MFA-related metadata
- Access requests, reviews, approvals, policies, provisioning activity, support records, and audit logs
- Connector and integration data authorized by Customer
- Assistant prompts, conversation content, tool inputs and results, generated outputs, saved workspace artifacts, submitted audio and transcripts, and limited product-feedback or diagnostic context
- Logs, telemetry, timestamps, and diagnostic metadata
Owlie does not intentionally process Special Categories of Personal Data.
4. Customer Obligations
Customer represents, warrants, and agrees that:
- Customer is solely responsible for the accuracy, quality, and legality of Personal Data provided to Owlie.
- It has obtained and will maintain a valid legal basis for the collection and transfer of Personal Data to Owlie;
- Its instructions comply with Applicable Data Protection Laws;
- It is responsible for providing all required notices and obtaining any necessary consents from Data Subjects;
- It will not instruct Owlie to process Personal Data in violation of Applicable Law.
5. Owlie Obligations
Owlie shall:
- Process Personal Data in accordance with this DPA, the Agreement, and Applicable Data Protection Laws;
- Ensure personnel authorized to process Personal Data are bound by confidentiality obligations;
- Implement appropriate administrative, technical, and organizational security measures as described in the Security Addendum;
- Assist Customer, to the extent required by law, with responding to Data Subject requests;
- Provide reasonable assistance, to the extent required by Applicable Law and technically feasible, with data protection impact assessments and regulatory inquiries related solely to the Services
6. Subprocessors
6.1 General Authorization
Customer authorizes Owlie to engage Subprocessors to process Personal Data as reasonably necessary to provide, secure, support, maintain, and improve the Services. Owlie shall remain responsible for the performance of its Subprocessors to the same extent Owlie is responsible for its own actions or omissions under this DPA.
6.2 Subprocessor Obligations
Owlie shall:
- enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those set forth in this DPA and as required by Applicable Data Protection Laws;
- ensure that each Subprocessor has implemented appropriate technical and organizational security measures consistent with the Security Addendum;
- restrict Subprocessors’ access to Personal Data only to what is strictly necessary for the performance of the subcontracted services;
- conduct initial and ongoing due diligence to evaluate security, privacy, and compliance risks associated with the Subprocessor; and
- monitor Subprocessor compliance on a periodic basis through certifications, attestations, or other industry-standard assurance mechanisms.
6.3 Subprocessor List and Notifications
Owlie shall maintain a current public Subprocessor List at https://trust.owlie.com/ (opens in new tab). The list will identify each subprocessor’s purpose, relevant data categories, and processing location or region where reasonably available.
6.4 Notification of Changes
Owlie shall notify Customer of any intended addition, removal, or material change in the processing activities of a Subprocessor at least thirty (30) days before such change becomes effective (“Change Notice”), unless a shorter period is required due to legitimate operational or security needs.
6.5 Right to Object
Customer may object to the engagement of a new Subprocessor on reasonable data protection grounds by providing written notice to Owlie within fifteen (15) days of receiving a Change Notice.
- If Customer objects, Owlie will work in good faith to:
- address Customer’s concerns,
- provide an alternative Subprocessor, or
- implement technical measures to avoid using the Subprocessor for Customer-specific processing.
- If the parties cannot reach a mutually acceptable resolution within a commercially reasonable period (not to exceed 30 days), Customer may terminate the directly affected Services only and receive a pro-rata refund for the remaining term of the affected Services.
- Customer acknowledges that objections that are not based on reasonable data protection concerns may impede Service delivery.
6.6 Emergency Replacement
Owlie may replace a Subprocessor without prior notice where required for:
- maintaining Service continuity,
- addressing urgent security issues,
- responding to force majeure events, or
- resolving failures or service disruptions caused by a Subprocessor.
- Owlie will notify Customer of the change as soon as reasonably practicable.
6.7 Affiliates as Subprocessors
Owlie may engage its Affiliates as Subprocessors, provided such Affiliates comply with the requirements applicable to Subprocessors under this DPA.
6.8 International Subprocessors
Where a Subprocessor processes Personal Data outside the EEA, UK, or Switzerland, Owlie shall ensure that a valid and lawful transfer mechanism is in place, including Standard Contractual Clauses (“SCCs”) or other government-approved legal frameworks, consistent with Section 7 of this DPA.
6.9 Liability for Subprocessors
Owlie remains fully liable for the actions and omissions of its Subprocessors to the same extent it would be liable if performing the relevant processing itself, subject to the limitations of liability set forth in the Agreement.
7. International Data Transfers
Where a transfer requires safeguards under Applicable Data Protection Laws, Owlie will put an applicable lawful transfer mechanism in place before the transfer. If SCCs are used, the relevant modules, options, and annexes must be completed and incorporated into a binding arrangement; applicable UK and Swiss adaptations will also be completed where required. A general reference to SCCs or a provider certification does not itself complete these instruments. Mandatory transfer terms prevail over inconsistent provisions of the Agreement or this DPA.
8. Security Measures and Incident Response
8.1 Security Program
Owlie shall maintain a comprehensive, written information security program (“Security Program”) that is aligned with industry standards (such as SOC 2 Type II, ISO 27001, NIST CSF, or comparable frameworks). The Security Program shall include administrative, technical, and physical safeguards appropriate to the nature, scope, and risks associated with processing Personal Data.
8.2 Technical and Organizational Measures
Owlie’s Security Program includes controls appropriate to the nature and risk of the Services. Applicable controls may include:
- Access Controls
- Role-based access controls and least-privilege principles
- Multi-factor authentication for administrative access
- Logging and monitoring of privileged account activity
- Data Security
- Encryption of Personal Data in transit and at rest
- Secure key management practices
- Segregation of customer data in a multi-tenant architecture
- Network & Infrastructure Security
- Firewalls, intrusion detection and prevention systems
- Endpoint protection and network segmentation
- Regular vulnerability scanning and remediation
- Application Security
- Secure development lifecycle (SDLC) practices
- Code reviews, automated testing, and dependency scanning
- Independent penetration testing by qualified third parties, as described in Section 8.4, with its current status stated in the Security Addendum and applicable assurance documentation.
- Operational Security
- Security logging, monitoring, and anomaly detection
- Anti-malware and anti-exploitation controls
- Vendor risk management for Subprocessors
- Business Continuity & Disaster Recovery
- Documented business continuity and disaster recovery plans
- Regular testing and updates of continuity plans
- Redundant infrastructure and backup routines
- Personnel Security
- Background checks as permitted by law
- Security training and confidentiality obligations
- Termination/role-change access revocation procedures
8.3 Security Updates
Owlie may update and enhance its security controls from time to time, provided such updates do not materially reduce the overall level of protection for Personal Data.
8.4 Security Testing
Owlie shall periodically test, assess, and evaluate the effectiveness of its Security Program using methods appropriate to the relevant risks. These activities may include independent assurance examinations, vulnerability scanning, incident-response exercises, and independent penetration testing. The current status of independent penetration testing is stated in the Security Addendum and applicable assurance documentation.
8.5 Security Incident Management
Owlie shall maintain an incident response plan aligned with industry standards and designed to detect, assess, contain, respond to, and remediate potential or actual Security Incidents.
8.6 Notification of Security Incidents
In the event Owlie becomes aware of a Security Incident affecting Personal Data, Owlie shall:
- notify Customer without undue delay, and in any event within a timeframe that enables Customer to meet its legal obligations;
- provide information reasonably necessary for Customer to assess the impact of the Security Incident; and
- provide updates as further information becomes available or as reasonably requested by Customer.
8.7 Owlie Responsibilities Following a Security Incident
Following a Security Incident, Owlie shall:
- take appropriate steps to contain, mitigate, and remediate the Security Incident;
- conduct an internal investigation to determine root cause and scope;
- implement corrective actions to prevent recurrence;
- cooperate with Customer’s incident response inquiries to the extent reasonably required and permitted by law.
8.8 Limitations on Notifications
Owlie shall not be required to:
- notify Data Subjects directly unless explicitly agreed or required by applicable law;
- disclose information that would compromise security, privilege, or confidentiality obligations;
- share internal proprietary information such as detailed architectural designs, exploit details, logs of other customers, or internal investigation reports.
8.9 Customer Responsibilities
Customer is responsible for:
- securing its own systems, devices, and end-user access points;
- protecting credentials, API keys, and identities under its control;
- configuring the Services in accordance with documentation and security best practices;
- promptly notifying Owlie of any suspected compromise of Customer-controlled credentials or systems.
8.10 No Acknowledgment of Fault
Owlie’s notification of or response to a Security Incident shall not be construed as an admission by Owlie of fault or liability.
8.11 Regulatory Correspondence
Owlie will cooperate reasonably with Customer in responding to inquiries or requests from data protection regulators related to a Security Incident, to the extent such inquiries relate directly to Customer Personal Data and to the extent permitted by law.
9. Audits and Compliance
9.1 Demonstration of Compliance
Owlie shall make available information reasonably necessary to demonstrate compliance with this DPA, including its current SOC 2 report, available independent assurance information, security summaries, and the documentation described in the Agreement or Security Addendum. The report identifies its type, scope, and covered period; other certifications are not represented as held unless expressly documented.
9.2 Third-Party Reports as Primary Audit Mechanism
Customer agrees that Owlie’s third-party audit reports, certifications, and attestations will serve as the primary means of assessing Owlie’s compliance with this DPA and its security obligations. Customer acknowledges that these reports constitute “audit rights” for purposes of applicable data protection laws to the fullest extent permitted by law.
9.3 Customer-Initiated Audits
If additional audit rights are required under Applicable Data Protection Laws and third-party reports are insufficient to satisfy such requirements, Customer may conduct an audit of Owlie’s processing activities subject to the following conditions:
The notice, frequency, auditor-selection, access, and cost conditions below apply only to the extent permitted by Applicable Data Protection Laws and do not prevent an audit or regulator access required by law. Where urgent circumstances or a regulator’s deadline require shorter notice, the parties will cooperate accordingly. Owlie will provide a reasonable alternative means of verification where direct access would expose other customers’ data or create a security risk.
-
Notice Requirement
Customer must provide Owlie with at least thirty (30) days’ prior written notice of its intent to conduct an audit, including a detailed proposed scope, purpose, and methodology.
-
Frequency
Customer may conduct such audits no more than once every twelve (12) months, unless:
- required by a competent supervisory authority, or
- following a confirmed Security Incident affecting Customer Personal Data.
-
Scope and Limitations
Audits shall be strictly limited to:
- facilities, systems, and processing activities directly related to the Services;
- documentation reasonably required to verify compliance with this DPA; and
- personnel with operational responsibility for data processing.
Audits may not include:
- proprietary information unrelated to Customer Personal Data;
- other customers’ data; shared infrastructure will be assessed through reasonable methods that protect those customers while permitting verification of applicable controls;
- details whose disclosure would create a material security risk, provided Owlie supplies alternative evidence sufficient to verify applicable controls where required by law;
- physical access to data centers unless required by law and permitted by the data center operator.
-
Conduct of Audit
Audits must be conducted during normal business hours, in a manner that minimizes disruption to Owlie’s business operations, and subject to Owlie’s security and confidentiality requirements.
-
Use of Independent Auditor
Audits shall be performed by a qualified, independent third-party auditor that:
- is not a competitor of Owlie;
- is mutually agreed upon by the parties;
- has executed a confidentiality agreement acceptable to Owlie.
9.4 Cost Responsibility
Customer shall bear all costs associated with any audit it initiates. However, if the audit identifies a material breach of this DPA or applicable data protection law, Owlie will reimburse Customer for reasonable and documented third-party auditor fees directly related to the finding.
9.5 Results and Remediation
Owlie will review findings from any permitted audit and will remediate any confirmed non-compliance within a commercially reasonable timeframe. Audit results are considered Confidential Information under the Agreement.
9.6 Regulator Access
If a supervisory authority requests information about Owlie’s processing of Personal Data, Owlie may provide such information directly to the authority to the extent legally required. Owlie shall notify Customer of such requests unless prohibited by law.
10. Data Subject Rights
10.1 Assistance with Requests
To the extent Customer cannot fulfil a Data Subject Request through native functionality of the Services, Owlie shall provide reasonable assistance to Customer in complying with its obligations under Applicable Data Protection Laws, including requests to:
- access Personal Data,
- rectify inaccurate Personal Data,
- delete Personal Data,
- restrict processing,
- object to processing,
- port Personal Data, or
- verify identity or authority of the requester.
10.2 Processor Role
Owlie shall not independently respond to any Data Subject request relating to Customer Personal Data unless:
- Customer expressly authorizes Owlie to do so in writing; or
- Owlie is legally required to respond, in which case Owlie shall, where legally permissible, notify Customer prior to responding.
10.3 Customer Responsibility
Customer is solely responsible for:
- validating the identity and authority of the Data Subject,
- ensuring the request is lawful,
- determining whether a response is required, and
- instructing Owlie in writing regarding its desired response actions.
10.4 Limitations
Owlie may limit assistance where:
- a limitation is permitted by Applicable Data Protection Laws; technical limitations alone do not excuse a mandatory assistance obligation;
- compliance would compromise the security or integrity of Owlie systems;
- doing so would violate law, court order, or the rights of other individuals.
11. Data Return and Deletion
11.1 Customer Election
Upon termination or expiration of the Agreement, Customer may elect to have its Personal Data returned in a mutually agreed, industry-standard export format or deleted in accordance with this Section. Closure of a tenant account by an authorized Customer representative constitutes Customer’s documented instruction to delete that tenant’s Personal Data under this Section.
11.2 Data Return and Account Closure
Account closure starts a thirty (30)-day retention and data-return request period. During this period, the tenant’s Personal Data remains in the operational database, but Customer has no self-service export path. Customer may request return of Personal Data during this period by contacting legal@owlie.com. Owlie personnel will manually retrieve and securely return the requested Personal Data without reactivating ordinary tenant operations. A timely return request will be fulfilled before deletion of the requested data; any legally required extension will be limited to the data and time necessary to complete the return.
If the Agreement terminates or expires without Customer closing its tenant account, Customer retains the thirty (30)-day period to request return of Personal Data, unless otherwise specified in the Agreement. After that period, Owlie will delete remaining Personal Data from active systems without undue delay, subject to Sections 11.4 through 11.6. Where the tenant account is closed, the thirty (30)-day period in Section 11.3 runs from account closure and is not followed by an additional thirty (30)-day retrieval period.
11.3 Tenant Halt and Database Deletion
Upon account closure, Owlie immediately soft-deletes the tenant account and places it in a halted state. All tenant functionality stops, including user and API access, scheduled jobs, and automated tenant operations. The halt does not prevent the limited processing necessary to secure retained data, fulfill a permitted return request, complete deletion, or comply with Applicable Data Protection Laws.
On day thirty-one (31), following the thirty (30)-day period beginning at account closure, Owlie permanently deletes the tenant and its associated Personal Data from the operational database, subject to Section 11.2 and legally required retention under Section 11.6. Soft deletion and the halt are interim restrictions and do not themselves constitute permanent deletion. Personal Data in other active storage or held by Subprocessors remains subject to Owlie’s return and deletion obligations under this DPA and will be securely deleted without undue delay; the database deletion deadline does not represent that all backup copies are erased at the same time.
11.4 Backups and Restores
Personal Data in backups or disaster recovery copies may remain until deleted through the applicable backup retention cycle. Until deletion, such data remains protected under this DPA and isolated from ordinary use. If a backup is restored, Owlie will immediately check the separately maintained deletion receipts described in Section 11.5 and remove the tenants identified in those receipts and their associated Personal Data from the restored data before making it available to users or resuming ordinary processing. A restore must not reactivate a deleted tenant or return its Personal Data to service.
11.5 Limited Deletion Receipts
Owlie retains a limited deletion receipt outside the operational database to record the tenant identifier, the identity of the person who requested or performed deletion, relevant timestamps, and the minimum additional metadata necessary to evidence deletion and enforce it following a restore. The receipt is not a copy of the tenant’s operational dataset and will not contain substantive tenant content beyond the limited identifying and deletion metadata needed for these purposes.
Owlie will protect receipts with appropriate access restrictions and security measures and use them only to evidence and enforce deletion or comply with applicable legal obligations. Customer instructs Owlie to retain the minimum receipt information needed to prevent restoration of deleted data while a relevant backup remains capable of restoration. Owlie will review the continued need for receipt information and delete or anonymize it when no longer necessary for these purposes, unless retention is required by law. Receipt information identifying an individual remains subject to applicable data protection requirements.
11.6 Legally Required Retention
Except for the limited backup and receipt retention described above, Owlie may retain Personal Data after the applicable deletion deadline only to the extent required by applicable law. Owlie will limit such retention to the necessary data and period, continue to protect and restrict processing of that data, and delete it when the legal requirement ends. Where legally permitted, Owlie will inform Customer of the basis for and scope of such retention.
11.7 Confirmation of Deletion
Upon written request, Owlie will provide written confirmation of completed deletion from active datasets, identifying the scope and completion date and disclosing any remaining backup copies, deletion receipts, or legally required retained data and the applicable retention criteria. Confirmation of database deletion will not be represented as confirmation that all copies have already been erased. This Section does not limit obligations or shorter deadlines required by Applicable Data Protection Laws, including obligations concerning individual Data Subject requests under Section 10.
12. CCPA / CPRA Provisions
12.1 Service Provider/Contractor Status
To the extent California privacy laws apply, Owlie acts as Customer’s Service Provider or Contractor, and Customer acts as the “Business.”
12.2 Restrictions on Processing
Owlie shall not:
- sell or share Personal Data;
- retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement;
- combine Customer Personal Data with information obtained from other sources or its own interactions with individuals, except as expressly permitted by applicable California privacy law;
- use Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Personal Data outside the direct business relationship with Customer or for unrelated commercial purposes, except as expressly permitted by applicable California privacy law.
12.3 Certifications
Owlie certifies that it:
- understands the CPRA restrictions,
- will comply with them, and
- will notify Customer if it determines it can no longer meet its obligations.
12.4 Consumer Requests
Owlie shall provide reasonable assistance to Customer in fulfilling consumer rights requests under the CPRA, as outlined in Section 10.
12.5 Monitoring and Enforcement
Customer may take reasonable steps to monitor Owlie’s compliance with CPRA obligations through:
- reviewing reports,
- requesting additional information, or
- conducting permitted audits in accordance with Section 9.
Owlie will provide the same level of privacy protection required by applicable California privacy law. Customer may take reasonable and appropriate steps to ensure compliant processing and, upon notice, stop and remediate unauthorized use. Owlie will cooperate with applicable consumer requests and legally required Customer risk assessments and cybersecurity audits to the extent required by that law.
13. Liability
13.1 Limitation of Liability
Liability arising under or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement. No separate or additional liability caps apply unless required by applicable law.
13.2 Carve-Outs
Where Applicable Data Protection Laws prohibit limiting liability for specific violations, such laws may override the Agreement’s limitation provisions only to the minimum extent required.
13.3 Shared Responsibility
Customer acknowledges that:
- compliance with data protection laws is a shared responsibility,
- Customer controls its configurations, identity governance settings, and access management rules,
- Owlie is not responsible for losses arising from Customer misconfigurations or the actions of Authorized Users.
13.4 Indirect Damages
Unless prohibited by law, neither party shall be liable for consequential, incidental, special, or punitive damages arising under this DPA.
14. Governing Law
14.1 Primary Governing Law
This DPA shall be governed by the same law and jurisdiction applicable to the Agreement unless required otherwise by Applicable Data Protection Laws.
14.2 EU/EEA Requirements
To the extent the GDPR requires the application of EU Member State law to specific provisions (such as the validity of processing or supervisory authority jurisdiction), such law applies in those specific respects.
14.3 UK GDPR Requirements
Where UK GDPR applies, the laws of England and Wales govern interpretation of UK-specific obligations, unless otherwise mandated by law.
14.4 Conflicts With Mandatory Law
If any provision of this DPA conflicts with a mandatory requirement of Applicable Data Protection Laws, that law shall control only to the extent of the conflict, and all remaining provisions will continue in effect.
15. Contact Information
Owlie, LLC
Attn: Privacy / Data Protection Officer
Email: legal@owlie.com