Legal
Data Processing Agreement
How we process the personal data inside your workspace, on your instructions and nobody else's — the controller/processor split, the security measures, subprocessors, breach notification, transfers, and return and deletion. It forms part of the Terms and needs no signature to protect you.
Last updated 9 September 2026
OFIVIO (SMC-PRIVATE) LIMITED · Lahore, Pakistan
1. What this document is
This Data Processing Agreement (DPA) forms part of the Terms of Service between you and OFIVIO (SMC-PRIVATE) LIMITED and applies automatically to every customer. There is nothing to sign before you can rely on it.
It governs our processing of personal data contained in Your Content — the records you put into your Workspace about your employees, clients, tenants and suppliers. Where this DPA and the Terms conflict on the processing of personal data, this DPA governs.
Words defined in the Terms carry the same meaning here.
2. Who is the controller and who is the processor
The split runs through everything below, so it comes first:
- For the business data inside your Workspace you are the controller and we are the processor. You decide what to collect about your own people and clients and why; we process it on your instructions to provide the Services.
- For your own account and our public site we are the controller — the name and email of the person who signed up, billing records, and the logs we need to run and secure the platform. That processing is described in the Privacy Policy.
You confirm that you have a lawful basis for the personal data you put into the Services, and that you have given the people it concerns whatever notice the law where you are requires.
3. Processing on documented instructions
We process Your Content only on your documented instructions. Your instructions are: this DPA, the Terms, the configuration choices you make in the application, and any lawful written instruction you give us afterwards.
We do not process Your Content for our own purposes. We do not sell it, we do not advertise against it, and we do not use it to train AI models — see section 7 and AI and your data.
If we are required by law to process Your Content beyond your instructions, we will tell you before doing so unless the law forbids telling you.
4. What is processed, for how long, and about whom
| Scope | |
|---|---|
| Subject matter | Providing the Services described in the Terms. |
| Duration | For as long as your subscription is active, plus the retention window in section 9. |
| Nature and purpose | Storing, organising, retrieving, displaying, transmitting and deleting the records you enter, so that the Services work. |
| Categories of data subject | Your employees and contractors; your clients and their contacts; your tenants; your suppliers; and anyone else you choose to record. |
| Categories of personal data | Names and contact details; employment records including roster, attendance, payroll, advances and letters; client and tenancy records; correspondence and documents you upload; and usage records tied to a named seat. |
| Special category data | The Services are not designed for special category data and we ask you not to enter it. If you do, you remain the controller of it. |
5. Confidentiality and the people who can reach it
Access to Your Content is limited to the people who need it to operate or support the Services, and everyone with such access is under a duty of confidentiality that survives their leaving.
Support staff do not browse customer workspaces. Where we need to enter a Workspace to investigate a fault you have reported, we do it on your request, and the actions are written to the same audit trail your own are — see Security.
6. Security measures
The technical and organisational measures are described in full and kept current on the Security page, which forms part of this DPA. In summary, and as at the date below:
- Encryption in transit (TLS) and at rest (AES-256), including uploaded files.
- Workspace isolation enforced on the server and again by database rules, so a request for another organisation's record fails at the source rather than being hidden in the interface.
- A second factor on every sign-in, with an optional authenticator app per person, and Enterprise SSO on agreement.
- Role-based access, plus per-dashboard locks that keep a room shut even to a role that holds it.
- An immutable audit trail that cannot be edited from the application, including by an administrator.
- Rate limiting on authentication, uploads, the API and VO.
We may change a measure for one at least as protective. We will not materially weaken the protection of Your Content during your subscription.
7. AI processing
Where you use VO, the content needed to answer your request — your question and the records the asking person's own role may read — is transmitted to a language-model provider listed in section 8 and the answer is returned.
- It is not used for training. Our agreements with those providers forbid using it to train or improve their models.
- VO cannot exceed the permissions of the person asking. A record invisible to that person cannot be retrieved, summarised or acted on by VO.
- Speech is transient. Audio is processed to produce or interpret speech and is not retained by us.
An Enterprise agreement can disable VO for a Workspace entirely. Full detail: AI and your data.
8. Subprocessors
You give us general authorisation to engage subprocessors. The current list — each one named, with what it does and what it receives — is published at Subprocessors and forms part of this DPA.
Each subprocessor is engaged under a written contract imposing data protection obligations no less protective than these, and we remain responsible to you for their performance.
Changes. We will update that page before a new subprocessor begins processing Your Content, and give notice as described in the Privacy Policy. If you object on reasonable data protection grounds, tell us at contact@ofivio.com and we will work with you to find an alternative; if none exists, you may terminate the affected Services and receive a refund of the unused portion of any prepaid term.
9. Your obligations, and our help with them
Data subject requests
The Services give you the tools to find, correct, export and delete the records in your own Workspace, which is how most requests are answered. Where you cannot do it yourself, we will assist you within a reasonable time, at no charge for a proportionate volume of requests.
If a person whose data sits in your Workspace comes to us directly, we will not answer for you — we will tell them to ask you, and tell you they asked.
Assessments and audits
We will give you the information reasonably necessary to demonstrate compliance with this DPA, and to carry out a data protection impact assessment, through this page, the Security page and written answers to a reasonable questionnaire.
We do not currently hold an independent SOC 2 or ISO 27001 audit report, and we will not present our infrastructure provider's certifications as our own — see Security. An on-site audit right can be agreed in an Enterprise contract.
10. Personal data breach
If we become aware of a personal data breach affecting Your Content we will notify you without undue delay — with what we know, what is affected, what we are doing and what you may need to do — and we will not wait for a complete picture before telling you that something happened. We will assist you with your own notification obligations to authorities and to affected people.
11. International transfers
The platform runs on Google Cloud in the us-central1 region in the United States, and the AI and speech providers in section 8 process in the United States and Europe. If you are outside those places, providing the Services requires an international transfer. Those transfers rely on the providers' standard contractual clauses and equivalent safeguards, and we contract with each provider on that basis. See Privacy, section 7.
12. Return and deletion
You can export a full copy of your Workspace at any time, in machine-readable form, without asking us.
When a subscription ends the Workspace is suspended rather than deleted: Your Content is retained for 90 days, remains exportable throughout, and is restored exactly as it was if you resubscribe within that window. After 90 days it is permanently deleted, and it ages out of backups on their own rotation.
We keep only what the law requires us to keep — billing and tax records, and security logs where we need them to investigate abuse.
13. If you need it counter-signed
This DPA applies to you as published, and the version you agreed to is the one dated below. If your procurement process requires a counter-signed copy, or your own paper, write to contact@ofivio.com with the subject line DPA and tell us the entity name and the jurisdiction; that is handled as part of an Enterprise agreement.
OFIVIO (SMC-PRIVATE) LIMITED
Lahore, Pakistan
contact@ofivio.com


