# OblyssPro Data Processing Addendum (DPA)

**Version:** 1  
**Effective Date:** August 7, 2026  
**Parties:** Oblyss Incorporated (“Oblyss”, “Processor”) and the Customer entity identified in the Order or subscription (“Customer”, “Controller”)

This Data Processing Addendum (“DPA”) forms part of the OblyssPro Platform Terms of Service (the “Agreement”) and applies when Oblyss processes Customer Personal Data on behalf of Customer in connection with the Services.

## 1. Definitions

Terms not defined here have the meaning in the Agreement or applicable data protection law (including GDPR, UK GDPR, and CCPA/CPRA where applicable). “Customer Personal Data” means personal data contained in Customer Data that Oblyss processes as a processor on Customer’s behalf.

## 2. Roles

Customer is the controller (or business) of Customer Personal Data. Oblyss is the processor (or service provider). Each party will comply with its obligations under applicable data protection law.

## 3. Processing details

| Item | Description |
|------|-------------|
| Subject matter | Provision of OblyssPro SaaS for foundation repair contractors |
| Duration | Term of the Agreement plus retention periods in the Terms |
| Nature & purpose | Hosting, storage, transmission, display, backup, support, and features Customer enables |
| Types of data | Contact and job data, communications metadata, documents, signatures, payment metadata (not full card PAN), location/telemetry when enabled, AI/voice content when enabled |
| Data subjects | Customer’s end customers, employees, contractors, and other individuals Customer submits |

## 4. Processor obligations

Oblyss will:

1. Process Customer Personal Data only on documented instructions from Customer (including the Agreement and Customer’s configuration of the Services), unless required by law.
2. Ensure persons authorized to process Customer Personal Data are bound by confidentiality.
3. Implement appropriate technical and organizational measures as described at `/security`.
4. Not engage subprocessors except as listed at `/subprocessors`, with notice of material changes as described in the Terms.
5. Assist Customer, taking into account the nature of processing, with data subject requests and security/breach obligations, as set out in the Terms.
6. At Customer’s choice, delete or return Customer Personal Data after the retention period in the Terms, except where retention is required by law.
7. Make available information reasonably necessary to demonstrate compliance and allow audits as described in the Terms (including SOC 2 reports when available).

## 5. Customer instructions & responsibilities

Customer is responsible for the lawfulness of instructions, obtaining any required notices/consents (including analytics and marketing consents for end customers), and configuring Connected Services. Customer will not submit special-category data except as permitted by the Agreement.

## 6. International transfers

Where Oblyss transfers Customer Personal Data internationally, it will use appropriate transfer mechanisms (including SCCs where required) as described in the Privacy Policy and Terms.

## 7. Subprocessors

Customer authorizes Oblyss to use the subprocessors listed at `/subprocessors`. Oblyss remains responsible for subprocessors’ performance of data protection obligations.

## 8. Security incidents

Oblyss will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, consistent with the Terms and applicable law.

## 9. Order of precedence

If there is a conflict between this DPA and the Agreement regarding data protection, this DPA controls. For California “service provider” / “contractor” status, Oblyss will not sell or share Customer Personal Data or combine it outside the limited purposes permitted by the Agreement and law.

## 10. Contact

legal@oblysspro.com

---

*This template is provided for Customer review. Enterprise customers may request a countersigned PDF via legal@oblysspro.com.*
