This document governs the processing of personal data that Ofivia carries out on behalf of the client company when it uses the platform. It supplements the terms of service and is signed as an annex to the contract.
The party that signs it as processor is [legal entity name], a Delaware corporation, the same entity that contracts every client in the terms of service. The service is operated from Ecuador: the servers, the vault, the database and the team that runs them are there. Notices to the processor under this document go to that entity, at [registered address] and at hola@ofivia.com.
In the vocabulary of Ecuador’s Ley Orgánica de Protección de Datos Personales:
- The client company is the controller. It decides what data goes in, for what, and for how long.
- Ofivia is the processor. In this document “Ofivia” means [legal entity name]. It handles that data following the controller’s documented instructions, and nothing else.
If the client company is not a controller but a processor for a third party, an agency working with its own clients’ data for instance, Ofivia acts as a sub-processor and this document reads with that substitution: where it says controller, read the client company in whatever position it holds towards its own controller.
1. Which law applies
The processor is incorporated in the United States and the processing runs in Ecuador. Both facts count, and they point at different laws.
Ecuador’s Ley Orgánica de Protección de Datos Personales applies to the processing described here, because it is carried out by means located in Ecuador: the servers, the vault, the database and the team that operates them. Incorporating the signing entity in Delaware does not move that processing, and does not take it out of the Ecuadorian law.
The General Data Protection Regulation of the European Union applies as well when the controller is established in the Union, or when its processing falls under Article 3 of that Regulation. In that case clauses 2 to 11 of this document meet Article 28(3), and transfers are governed by Annex IV.
Where a privacy law of a United States state applies to the controller, Ofivia acts as its service provider or processor in the sense that law gives those terms, and uses the data only for the purposes of this contract.
Ofivia has not yet appointed a representative in the European Union under Article 27 of the Regulation. Signing from the United States does not remove that obligation: the representative is still required where there are clients established in the Union. Once appointed, the contact details go in the privacy policy. The placeholder is [EU representative under Article 27 GDPR].
The data protection officer that Ecuadorian rules require of anyone providing information technology services, which Ofivia does from Ecuador, is identified as [data protection officer name], reachable at [data protection officer email]. We do not publish that detail invented.
2. Subject matter, nature, purpose and duration
Subject matter. Ofivia processes the personal data the client company uploads or generates inside the platform.
Nature. The operations are the ones described in Annex I: collection, storage, indexing, retrieval, transcription, generation of text, images and video by the agents, communication between users, publication when the controller turns it on, archiving, backup and deletion.
Purpose. Providing the contracted service, and nothing else. Ofivia does not use that data for its own purposes.
Types of data and categories of data subjects. They are set out in Annex I. The controller defines them through what it chooses to upload.
Duration. The whole term of the service contract, and afterwards until the return and deletion obligations in clause 9 have been met.
3. The controller’s instructions
Ofivia processes the data only in line with the controller’s documented instructions. Ordinary use of the platform constitutes that instruction: uploading documents, indexing them, searching them, transcribing them, sharing them according to the permissions configured, running agent turns over them, generating content with the image and video tools, and publishing outward whatever the controller decides to publish.
The instructions also cover the transfers to third countries described in clause 11 and Annex IV. Any other instruction has to be in writing, and if it takes engineering work outside the product we quote it before carrying it out.
Ofivia will tell the controller immediately if, in its view, an instruction breaches data protection law, and may suspend that instruction until the controller confirms or corrects it. Suspending it is not a breach of the service contract.
Ofivia does not use the controller’s content to train artificial intelligence models, its own or anyone else’s, or for any purpose other than providing the service.
4. Confidentiality
Ofivia undertakes that every person with access to the controller’s data has given a confidentiality commitment before receiving that access. The commitment survives the end of the employment or contractual relationship. Access is limited to the people who need it to operate the service or provide support.
A platform administrator reaching a company’s data has to enter that company explicitly. It is not passive or standing access.
5. Security measures
Ofivia applies technical and organizational measures appropriate to the risk, in the sense of Article 32 of the European Regulation and of Articles 37 to 40 of the Ecuadorian law. They are described in detail on the security page, including an honest account of what does not exist yet. The main ones, in summary, make up Annex II:
- Four-layer tenant isolation: a company identifier on every row, row level security in PostgreSQL in FORCE mode across 33 tables, one directory per company in mode 0700, and a dedicated namespace in the graph.
- Authentication: passwords under argon2, a fifteen-minute access token and a seven-day refresh token signed with separate secrets, immediate revocation of every session on logout, and two brute force limits on the credential routes: a lock counted per account by email address, and a per-IP request limit in front of login and refresh.
- Exposed surface: security headers, CORS with an explicit origin list, a request body size limit, validation that rejects unknown fields, and per-minute request limits both global and per company.
- Secrets: encrypted with pgcrypto and never returned by any endpoint; they are listed by name.
- Code execution: the container where code runs is ephemeral and rootless, with no network, a read-only root, no kernel capabilities, no privilege escalation and a twenty second wall-clock kill. The container where the agent itself runs does have outbound internet, because it needs it to reach the model provider, and there is no destination allowlist today.
- Traceability: a per-company hash chain over every tool the agent runs, and a monthly usage log that records the size of the text covered, never its content.
- Continuity: daily backups with fourteen-day rotation and incremental vault snapshots by hardlink.
- Network: internal services listen on the loopback interface and are only reachable through the reverse proxy.
Ofivia may change these measures, and will when the risk or the technology changes, but no change can lower the agreed level of protection.
The controller acknowledges two limits of this architecture:
- Ofivia does not encrypt documents at the application layer at rest. Protection at that layer depends on mode 0700, on access control to the server, and on whatever encryption the disk provides.
- Older media is archived to a third party’s object storage. Video more than seven days old and other large files more than thirty days old are copied to S3 storage, and what stays on the server is a stub under one kilobyte. From that moment the primary copy of that file lives with the storage provider, not in the 0700 directory.
6. Sub-processors
The controller gives general authorization for the use of sub-processors. The current categories are:
| Category | Purpose |
|---|---|
| Infrastructure and hosting | Running the platform and storing the database and the vault |
| Artificial intelligence model providers | Serving the agent’s turns and generating images and video |
| Object storage | Archiving older media off the server |
| Outbound email | Verifications, security notices, notifications and the mail companies send |
| Network and DNS | Publishing the service and the controller’s own domain records |
| Browser notifications | Delivering alerts to the subscribed device |
| Payments | Charging the subscription and issuing the invoices |
The current, named list is published at sub-processors, with the provider, what it is used for, what data it touches, the country it processes in and a link to its own policy. That page is Annex III of this contract.
Ofivia gives thirty days’ notice of any addition or replacement, by email to the controller’s administrative contact and by updating that page. The controller may object within fifteen days of the notice, in writing and on reasoned data protection grounds. If it does not object within that window, the change counts as accepted.
Faced with an objection, Ofivia looks for a reasonable alternative or a measure that resolves the concern. If there is none within thirty days, the controller may terminate the affected part of the service, or the whole contract, with no penalty and with the return set out in clause 9. If a security or continuity emergency forces a provider to be replaced without the thirty days’ notice, Ofivia gives notice as soon as it can and the right to object survives unchanged.
Ofivia imposes obligations equivalent to those in this document on every sub-processor and answers to the controller for their conduct as if it were its own.
7. Assistance to the controller
Ofivia will assist the controller, by appropriate technical measures and with the information available to it, in order to:
- Handle data subject requests for access, rectification, updating, deletion, objection, suspension, portability and the other rights in Chapter III of the European Regulation. Portability is direct: the vault is Markdown files and the database is standard PostgreSQL. If a data subject writes to Ofivia about data held inside a company’s account, Ofivia does not answer on its own: it passes the request to the controller within two business days.
- Meet Articles 32 to 36 of the European Regulation and their Ecuadorian equivalents, meaning security of processing, breach notification, impact assessment and prior consultation with the authority.
- Provide the technical information the controller needs to explain a decision an agent influenced, present the assessment criteria used and handle a challenge to it.
- Demonstrate compliance with the security obligations.
Ofivia answers a documented request for assistance within five business days. That window exists so the controller can meet its own: fifteen days for data subject rights under Ecuadorian law, one month under the European Regulation.
8. Security breaches
If Ofivia becomes aware of a security breach affecting the controller’s personal data, it will notify the controller without undue delay and, at the latest, within 48 hours of becoming aware, with the information available:
- The nature of the incident and the systems compromised.
- The categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed to contain and mitigate it.
- An Ofivia contact for the follow-up.
If information is missing at the time of notice, Ofivia sends what it has and completes the rest in stages rather than waiting to have everything.
Notifying the authority and the data subjects is the controller’s job. Ofivia supports whatever is needed to do it. The deadlines the controller has to meet are its own and are shorter than they look: seventy-two hours to a European supervisory authority, five working days to Ecuador’s data protection superintendency and to the telecommunications regulator, and three working days to the data subject where the breach carries a risk to their rights. Ofivia’s 48 hours exist so those deadlines stay reachable.
Ofivia documents every security breach, its effects and the corrective measures, and hands that record to any controller who asks for it.
9. Return and deletion
When the contract ends, and at the controller’s choice, Ofivia will hand over the complete vault and a dump of the database, or delete that information. The choice is communicated in writing within thirty days of termination; if the controller says nothing in that window, Ofivia hands over and then deletes.
The handover is the files as they are, Markdown and binaries, plus the dump in standard PostgreSQL format. There is nothing to convert, no exit fee, and we do not hold data as leverage.
Deleting a company cascades through its usage logs, permissions, sessions, messages, notifications, secrets and conversation threads, and automated tests verify that no orphaned records remain. Backups containing that information rotate out and disappear within the following fourteen days. Ofivia confirms the deletion in writing when the controller asks.
Ofivia will keep only what a legal obligation requires it to keep, and only for that period. Whatever is kept stays covered by this document.
10. Audits and inspections
Ofivia makes available to the controller the information needed to demonstrate compliance with these obligations, answers its technical questions in writing, and allows and contributes to audits and inspections carried out by the controller or by an auditor it appoints.
Ofivia holds no SOC 2 or ISO 27001 certification today, and no third-party audit report. We would rather say so in the contract than in the review.
The rules for an audit of your own, and this is where the controller gives something up:
- Once every twelve months, unless a supervisory authority asks for it or a breach affecting the controller has occurred, in which case there is no frequency limit.
- With thirty days’ notice, in business hours and under confidentiality.
- The appointed auditor cannot be a competitor of Ofivia, and signs confidentiality before starting.
- The scope reaches the systems and areas that serve the controller. It does not include access to other companies’ data on the platform, or to information that would identify them, because that restriction is the same one protecting the controller from someone else’s audit.
- Intrusive or destructive testing is agreed in writing beforehand, under the acceptable use clause of the terms.
- The controller bears the cost of the audit, unless it finds a material breach of this document, in which case Ofivia bears it.
For stricter audit requirements, the alternative is self-hosting on the controller’s own infrastructure.
11. International transfers
Two things get confused in practice and have to be kept apart.
Engaging a processor is not a transfer. The controller handing data to Ofivia, and Ofivia handing it to a sub-processor, is processing on instruction in the sense of Article 34 of the Ecuadorian law and of the superintendency’s secondary rules. It is governed by this contract and by the equivalent contracts Ofivia signs with each sub-processor, not by the transfer regime. For a controller domiciled in Ecuador that holds even though the processor is incorporated abroad: the data is stored and processed on the infrastructure in Ecuador, and what crosses the border is the contract, not the database.
A transfer to a third party acting as a controller is one. Where that happens, it relies on a country recognized as adequate or on the safeguards the Ecuadorian law requires, including the recipient’s express submission to the jurisdiction, the rules and the decisions of the Ecuadorian authority. Ofivia keeps the documentation supporting each transfer for at least three years.
For a controller established in the European Union, handing data to Ofivia is a Chapter V transfer. The importer is [legal entity name], in the United States. From there the data is processed on the infrastructure in Ecuador and by the sub-processors in Annex III. No leg of that chain rests on an adequacy decision: Ecuador has none, and the European Commission’s decision of 10 July 2023 for the United States covers only the organizations certified to the EU-US Data Privacy Framework, and [legal entity name] is not one of them. The transfer therefore relies on the standard contractual clauses. The instrument, the modules, the parties and the state of the impact assessment are in Annex IV.
Ofivia does not guarantee data residency in any given country under the managed offering. A controller who needs that guarantee can choose self-hosting.
12. Precedence and changes
On data protection matters this document prevails over the terms of service and over any other annex, unless the signed contract says otherwise in so many words.
If this document changes, we update the date in the header. Where the change materially affects either party’s obligations, we give thirty days’ notice by email.
Annex I. Description of the processing
- Categories of data subjects: the controller’s staff with an account on the platform; people named in the documents, audio or video the controller chooses to upload; contacts the controller writes to from the platform’s mail or chat; and anyone who receives a link or a page the controller publishes.
- Categories of data: identification and professional contact details, role within the organization, access credentials, session and usage records, and the content the controller uploads or generates, whose scope it decides. That content includes documents, notes, messages, audio recordings, transcripts, images, video, attachments and the mail held in the mailboxes of its domain.
- Sensitive data: the platform is not designed to process special categories of data. If the controller decides to upload them, it must say so in writing so additional measures can be agreed and so we can assess whether a prior impact assessment applies.
- Operations: collection, storage, indexing and search, retrieval, audio transcription, generation of text, images and video by the agents, communication between users, calls, sending and receiving mail, outward publication when the controller turns it on, archiving to object storage, backup and deletion.
- Duration: the one in clause 2.
- Frequency: continuous, for as long as the service is active.
- Recipients: the sub-processors in Annex III, each limited to what its function requires.
Annex II. Technical and organizational measures
The ones in clause 5, with the detail and the declared gaps on the security page. That annex is updated when the measures change, and the controller receives the current version on request.
Annex III. Sub-processors
The sub-processors page, in the version current at the date of the contract, with the updates notified under clause 6.
Annex IV. Transfers, standard contractual clauses and impact assessment
Starting point
The chain is this: a controller established in the European Union, an importer in the United States which is [legal entity name], the processor that signs this document, and the processing itself carried out on the infrastructure in Ecuador and by the sub-processors in Annex III.
No adequacy decision covers that chain.
- Ecuador has no adequacy decision from the European Commission. Verified on 18 August 2026 against the official list of adequacy decisions.
- The United States has one, adopted on 10 July 2023, but it reaches only the organizations that self-certify to the EU-US Data Privacy Framework and appear on the list the Department of Commerce keeps. [legal entity name] is not certified and is not on that list, so that decision does not cover this transfer.
Every handover of data from a controller established in the Union to Ofivia therefore needs a safeguard under Article 46 of the Regulation, and the safeguard used is the standard contractual clauses.
Instrument, modules and parties
The parties incorporate the standard contractual clauses of Commission Implementing Decision (EU) 2021/914, with these selections:
| Item | Selection |
|---|---|
| Module | Module Two, controller to processor, where the client company is a controller. Module Three, processor to processor, where the client company acts as a processor for a third party |
| Data exporter | The client company, with the details recorded in the signed contract |
| Data importer | [legal entity name], a Delaware corporation, [registered address], [tax ID], represented by [authorized signatory], acting as processor |
| Onward transfers | The processing carried out from Ecuador and the sub-processors in Annex III, under clause 8.8 of the clauses and clause 6 of this document |
| Clause 7, docking | Included |
| Clause 9, sub-processors | Option 2, general written authorization, with the thirty days’ notice in clause 6 of this document |
| Clause 11, redress | No independent dispute resolution body |
| Clause 17, governing law | The law of [Member State under clause 17 of the standard contractual clauses] |
| Clause 18, forum | The courts of that same Member State |
| Annex I to the clauses | Annex I to this document |
| Annex II to the clauses | Annex II to this document |
| Annex III to the clauses | Annex III to this document |
| Competent supervisory authority | [competent supervisory authority] |
Disputes arising from those clauses go to the courts of the Member State named in their clause 18. That route is carved out of the arbitration agreement in the terms of service: neither the agreement to arbitrate before the American Arbitration Association nor the class action waiver applies to a claim brought under these clauses.
A limit we would rather declare. Recital 7 of Decision 2021/914 says those clauses may be used only to the extent that the importer’s processing does not fall under the European Regulation. The importer is not established in the Union, but its processing can still be caught by Article 3(2) where it offers the service to data subjects in the Union. The Commission has announced an additional set of clauses for importers in that position, and as at the date of this document it has not adopted them. Until they exist, the parties use the 2021 clauses together with the direct obligations in this document, and Ofivia undertakes to migrate the contracts within ninety days of the new set being adopted.
Transfer impact assessment: not documented yet
Recommendations 01/2020 of the European Data Protection Board ask the exporter and the importer to assess, in writing, the law of the destination country and the supplementary measures the transfer needs. Ofivia has not documented that assessment yet. It is on the pending list, and Ofivia undertakes to have it written before onboarding the first client with personal data from the European Union. We are not going to promise a document that does not exist.
What it will have to cover, and where the position stands today:
- What is transferred and where. The controller’s content to the United States, where the importer is, from there to Ecuador, where the servers and the vault are, and from there to the sub-processors in Annex III. The current destinations are listed on that page with their country.
- On what instrument. The standard contractual clauses described above for the European controller’s leg, and equivalent processing contracts with every sub-processor.
- What the destination countries’ law says. The United States retains signals intelligence powers under Section 702 of FISA and Executive Order 12333, which the Court of Justice of the European Union examined in Schrems II. Executive Order 14086 added proportionality limits and created the Data Protection Review Court as a redress route, and that route does not depend on the importer being certified, but it does not replace the Article 46 instrument for an importer that is not. Ecuador has a data protection law with an active supervisory authority and a penalty regime that has been enforced since May 2023, and its rules on government access require a court order.
- Supplementary measures. Encryption in transit on every leg; minimizing what leaves, since indexing, search and transcription run on our own infrastructure and that content reaches no provider at all; short-lived signed links for the files a generation provider has to download; a contractual ban on training with the controller’s content; a commitment to notify the controller of any foreign authority’s request where the law allows, and to challenge it where there are grounds; and self-hosting for anyone who does not accept this arrangement.
- Procedural steps. The clauses are signed as an annex to the contract and their annexes are completed with each controller’s details.
- Review. At least once a year, and every time a sub-processor is added or replaced.
This annex describes the position as it stands today. It does not replace review by a qualified lawyer, which is still pending.