Processor obligations for U.S. customers — CCPA / CPRA aligned.
Effective: May 9, 2026
This Data Processing Agreement ("DPA") forms part of the Master Terms of Service and applies when OmegaFP processes Personal Data on behalf of Customer in the course of providing the Services. This DPA is designed for United States customers and U.S. data subjects and is aligned with the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable U.S. state privacy laws.
Geographic scope — U.S. only
The Services are offered to U.S.-domiciled customers for the processing of Personal Data relating to U.S. data subjects. Customer shall not submit, upload, or otherwise cause OmegaFP to process Personal Data of individuals located in the European Economic Area, the United Kingdom, or Switzerland ("EU/EEA/UK Personal Data"). OmegaFP does not act as a "processor" within the meaning of the EU/UK General Data Protection Regulation, and this DPA is not intended to make EU/UK GDPR applicable to OmegaFP or the Services. If Customer requires processing of EU/EEA/UK Personal Data, Customer must obtain OmegaFP's prior written consent and execute a separate written agreement covering such processing; absent that, any submission of EU/EEA/UK Personal Data is at Customer's sole risk and constitutes a material breach of this Agreement.
2.1 Customer as Controller. Customer is the Controller of all Personal Data submitted to the Services. Customer determines what data is collected, why it is collected, and how it is used. Customer is responsible for ensuring it has a lawful basis to process the Personal Data it submits to the Services.
2.2 OmegaFP as Processor. OmegaFP processes Personal Data only on Customer's behalf and in accordance with Customer's documented instructions (as set out in this DPA and the Master Terms). OmegaFP does not sell Personal Data and does not use Customer's Personal Data for OmegaFP's own commercial purposes or to train its own AI models.
2.3 AI Model Providers. When Customer uses AI features powered by third-party models made available through Amazon Bedrock (such as Anthropic Claude), prompts and context are transmitted to Amazon Bedrock inference endpoints. OmegaFP configures the service with no-training data-use policies where available. Customer should avoid submitting highly sensitive Personal Data in AI prompts where possible.
3.1 Categories of Personal Data. OmegaFP may process the following categories of Personal Data on Customer's behalf:
3.2 Data Subjects. The Data Subjects whose Personal Data is processed include Customer's clients, household members, and authorized Users.
3.3 Purpose of Processing. Personal Data is processed solely to provide and improve the Services as described in the Master Terms, including CRM management, AI-assisted features, communications, billing, and compliance archival.
4.1 OmegaFP shall:
OmegaFP implements the following technical and organizational security measures:
6.1 Customer, as Controller, is responsible for responding to Data Subject rights requests (such as access, correction, deletion, or portability requests) under applicable law.
6.2 OmegaFP will, upon Customer's written request, provide reasonable technical assistance to help Customer fulfill Data Subject rights requests within the Services, to the extent technically feasible and within OmegaFP's control.
6.3 Right to Delete. Customer may delete Customer Data through the platform's built-in deletion features. OmegaFP will process deletion requests and remove data from active systems. Note that S3 WORM-archived data subject to a compliance retention period or legal hold cannot be deleted until the retention period expires.
7.1 OmegaFP will notify Customer of a confirmed Security Breach affecting Customer's Personal Data within 72 hours of OmegaFP confirming the breach, to the extent permitted by applicable law.
7.2 The notification will include, to the extent known at the time:
7.3 Customer is solely responsible for its own regulatory notifications to supervisory authorities and Data Subjects under applicable U.S. federal and state law.
8.1 Active Data. OmegaFP retains Customer's Personal Data in active systems for the duration of the subscription and for 30 days after termination, during which Customer may export data.
8.2 Compliance Archives. Retention of SMS and meeting-recording archives depends on the retention mode Customer selects for its firm:
8.3 Backups. Automated database backups are retained for up to 7 days for paid subscribers.
8.4 Post-Termination. After the 30-day data export window, OmegaFP will delete Customer Data from active systems. OmegaFP may retain anonymized or aggregated data derived from Customer Data for product analytics, provided such data cannot reasonably identify Customer or any Data Subject.
8.5 Legacy Recording Archives. Meeting recordings and transcripts archived before July 30, 2026 were written to immutable storage (S3 Object Lock, COMPLIANCE mode) with a seven (7) year retention period, irrespective of the retention mode configured for Customer's firm. Those specific archives cannot be deleted before their retention period expires by any party, including OmegaFP. The deletion commitments in Sections 6.3 and 8.4 and any erasure request under Section 6 therefore cannot be fully satisfied as to those archives; OmegaFP will delete all associated records and identifiers from its active systems and will confirm, on request, which archives remain subject to retention and the date each expires. Archives written on or after July 30, 2026 follow Section 8.2.
9.1 Authorized Sub-processors. Customer authorizes OmegaFP to engage the Sub-processors listed in Schedule A below. OmegaFP will enter into data processing or equivalent agreements with each Sub-processor that impose data protection obligations equivalent in substance to those in this DPA.
9.2 Changes. OmegaFP will give Customer 30 days' advance notice of any new or replacement Sub-processor (by email and/or by updating Schedule A in this DPA). If Customer objects in writing to a new Sub-processor within that period and OmegaFP cannot accommodate the objection, Customer may terminate the Services for cause by providing 30 days' written notice, and OmegaFP will refund any prepaid fees for the remaining unused subscription period.
10.1 Customer Data is stored and processed in the United States. OmegaFP does not currently offer non-U.S. hosting regions.
10.2 Because EU/EEA/UK Personal Data is out of scope under this DPA (see the geographic-scope notice above), no international transfer mechanism such as the EU Standard Contractual Clauses or the UK International Data Transfer Agreement is contemplated. OmegaFP does not undertake to enter into any such mechanism under this DPA.
11.1 To the extent OmegaFP processes Personal Information of California residents as a "Service Provider" under the CCPA/CPRA, OmegaFP agrees not to:
11.2 OmegaFP will assist Customer in fulfilling verified consumer requests under the CCPA/CPRA to the extent technically feasible.
Upon Customer's written request (no more than once per year) and at Customer's expense, OmegaFP will provide reasonable written information to support Customer's verification of OmegaFP's compliance with this DPA, which may include completed security questionnaires or third-party audit summaries. OmegaFP may decline on-site audits due to operational and confidentiality constraints but will provide equivalent documentation where practicable.
This DPA is governed by the laws of the State of Delaware (without regard to conflict-of-law principles), and disputes arising out of or relating to this DPA are resolved as set forth in Section 14 of the Master Terms of Service (binding arbitration in Wilmington, Delaware, with exclusive Delaware venue for permitted court proceedings).
14.1 OmegaFP acknowledges that Customer may be subject to books-and-records requirements under securities regulations, including but not limited to FINRA Rules 4510/4511 and SEC Rules 17a-3/17a-4, and that these requirements may affect data retention and deletion schedules.
14.2 OmegaFP's standard data retention and deletion schedules (Section 8) will accommodate Customer's configured retention periods within the platform. Customer is responsible for configuring appropriate retention periods that meet its regulatory obligations.
14.3 Compliance archive data stored under S3 Object Lock (WORM) will not be deleted before the configured retention period expires, even upon termination of Customer's account. The standard data deletion provisions of Section 8.4 do not apply to data subject to an active WORM retention period or regulatory hold.
14.4 Upon request, OmegaFP will provide reasonable assistance to Customer in responding to regulatory inquiries or examinations that require access to compliance archive data stored within the Services.
Each Sub-processor below is bound by a written agreement imposing data protection obligations equivalent in substance to this DPA. OmegaFP will provide 30 days' advance notice of any new or replacement Sub-processor as set forth in Section 9.
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: RDS PostgreSQL database hosting, S3 document storage, Cognito authentication, SES transactional email, KMS encryption, ElastiCache Redis caching, CloudWatch logging and monitoring, two-way SMS / 10DLC delivery via AWS End User Messaging (Pinpoint SMS Voice V2) | All Customer Data (encrypted at rest with AWS-managed and customer-managed KMS keys; in transit via TLS 1.2+). For SMS: recipient phone numbers and message content carried over U.S. mobile carrier networks (AT&T, T-Mobile, Verizon, US Cellular). | United States (us-east-1 / us-west-2) |
| AWS Bedrock (Anthropic Claude, Amazon Titan, Amazon Nova models) | AI language model and embedding inference for chat, meeting summaries, document analysis, and advisor assistance through the AWS service boundary. OmegaFP-controlled model-invocation logs, where enabled, follow the approved retention schedule; Bedrock Guardrails and the application PII boundary are applied. | Text minimized for the requested feature and tokenized or redacted by the application PII boundary before model invocation where the configured workflow requires it | United States (AWS us-east-1) |
| Stripe, Inc. | Payment processing and subscription billing | Firm billing information, payment method details | United States |
| Recall.ai | Meeting recording bot and transcription | Meeting audio / video, participant names, transcripts | United States |
Questions about Sub-processors or requests for data processing agreements should be sent to legal@omegafp.com.