Data Processing
Addendum.
This DPA forms part of the Master Service Agreement between you (the controller) and OEAN.ai Pte. Ltd. (the processor) and applies whenever we process personal data on your behalf.
Scope and roles
You are the controller of personal data processed in your tenant. We act as the processor and process such data only on documented instructions from you, which include the use of the service and any configuration you apply.
Subject matter and duration
Subject matter: provision of the OEAN.ai ERP service. Nature: storage, retrieval, transmission, aggregation. Duration: the term of the agreement plus the export and deletion period.
Categories of data and subjects
Categories may include identifiers, contact details, employment records, financial transactions, vendor and customer records. Subjects may include your employees, contractors, customers and suppliers.
Security measures
We maintain the technical and organizational measures described at /security, including AES-256 encryption at rest, TLS 1.3 in transit, signed audit logs, RBAC, SSO and 24/7 on-call. We perform pentests twice yearly and maintain SOC 2 Type II.
Sub-processors
We engage sub-processors for hosting (AWS, Cloudflare), email (Postmark), error monitoring (Sentry), payments (Stripe) and analytics (PostHog Cloud EU). The current list with locations is available at privacy@oean.ai. We give 30 days' notice before adding or replacing a sub-processor; you may object on reasonable grounds.
International transfers
Where personal data is transferred outside the EEA, UK or Singapore, transfers rely on Standard Contractual Clauses (EU 2021/914), the UK Addendum and ASEAN Model Contractual Clauses as applicable.
Data-subject requests
We provide tooling in the admin console to access, export and delete personal data. Where you cannot satisfy a request through the product we will provide reasonable assistance at no additional charge.
Breach notification
We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your tenant, with the information required by Article 33(3) GDPR.
Audits
You may audit our compliance once per year on 30 days' notice by reviewing our SOC 2 Type II report and responses to your reasonable written questionnaire. On-site audits are available for enterprise customers under separate engagement letter.
Return and deletion
At the end of the agreement we provide a 30-day window for export through the product and the API. Thereafter we delete personal data within a further 30 days unless retention is required by law.