// loading
Loading the page…// loading
Loading the page…Effective 2026-07-17 · Last updated 2026-07-17
This Data Processing Agreement ("DPA") forms part of the Terms of Service (see ollie.cloud/terms) or other written agreement (the "Agreement") between Ollie.Cloud LLC ("Ollie," "we," "us," or "Processor") and the customer that accepts it ("Customer" or "Controller"), and governs Ollie's processing of Customer Personal Data on Customer's behalf when Customer uses the Ollie platform (the "Service"). Ollie.Cloud LLC is a New Jersey limited liability company located at 28 Spring St #5161, Princeton, NJ 08542.
How to execute. This DPA applies automatically to Customers that process personal data subject to the GDPR, UK GDPR, or U.S. state privacy laws through the Service; no signature is required for it to take effect. If you require a countersigned copy, complete the signature block below and email it to support@ollie.cloud.
Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Laws.
For Customer Personal Data, Customer is the Controller (or a processor acting on behalf of a third-party controller) and Ollie is the Processor. Ollie will process Customer Personal Data only as a Processor (a "Service Provider" under the CCPA/CPRA), solely to provide the Service and as instructed by Customer. Ollie separately processes account, website, and analytics data described in our Privacy Policy as an independent controller; that processing falls outside this DPA and is governed by the Privacy Policy and our Subprocessors list.
Ollie will process Customer Personal Data only on Customer's documented instructions — including as set out in the Agreement, this DPA, and Customer's use of the Service's features (for example, choosing to run AI processing on particular pages, or leaving automatic sheet-naming enabled or turning it off in organization settings) — unless required by law. Ollie will inform Customer if it believes an instruction violates Data Protection Laws, without any obligation to provide legal advice.
Ollie will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and are limited to those who need access in order to provide the Service.
Ollie will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art and the risks involved. These measures include those described in Annex II, currently including:
Authorization. Customer authorizes Ollie to engage the Subprocessors listed at ollie.cloud/subprocessors to process Customer Personal Data in connection with the Service. That page identifies each Subprocessor, its purpose, the categories of data it processes, and its processing location. Ollie remains responsible for its Subprocessors.
New Subprocessors. Ollie maintains the current list at ollie.cloud/subprocessors and provides a mechanism to be notified of additions or replacements. Ollie will give Customer prior notice (by updating that list and/or by email to subscribers) before a new Subprocessor begins processing Customer Personal Data, giving Customer a reasonable opportunity to object on reasonable data-protection grounds.
Flow-down and liability. Ollie will impose data-protection obligations on each Subprocessor that are materially no less protective than those in this DPA, and remains responsible for its Subprocessors' performance of those obligations.
AI processing. Ollie's AI features rely on Anthropic (Claude) as a Subprocessor. Local processing steps run first, and only items those steps cannot resolve are sent to Anthropic. Under Ollie's commercial terms with Anthropic, Customer Content sent to Anthropic is not used to train Anthropic's models, and Ollie does not use Customer Content to train its own AI models.
Taking into account the nature of the processing, Ollie will assist Customer — by appropriate technical and organizational measures, and insofar as possible — to respond to requests from Data Subjects to exercise their rights under Data Protection Laws (including access, correction, deletion, portability, and objection). Ollie provides this assistance through a manual, best-effort process. If Ollie receives such a request directly from a Data Subject, it will, unless legally prohibited, direct that person to Customer. Requests may be sent to support@ollie.cloud.
Ollie will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information reasonably available to it to help Customer meet its own notification obligations. Ollie will take reasonable steps to mitigate and, where possible, remedy the breach. Suspected security issues may also be reported to support@ollie.cloud.
Ollie will provide Customer with reasonable assistance for data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the information available to Ollie.
Ollie processes Customer Personal Data in the United States. Where Customer transfers Customer Personal Data originating in the EEA, United Kingdom, or Switzerland to Ollie, the parties incorporate into this DPA by reference the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), including Module Two (Controller-to-Processor) and Module Three (Processor-to-Processor, where Customer is itself a processor), together with the UK International Data Transfer Addendum and, for Switzerland, the applicable Swiss adaptations. Where there is any conflict on transfer matters, the SCCs prevail.
On termination or expiry of the Agreement, and at Customer's choice, Ollie will delete or return Customer Personal Data and delete existing copies, except where retention is required by law. Consistent with how the Service operates, when an organization is closed any active subscription is canceled and a roughly 30-day recovery window applies, during which the closure may be undone or a copy of the organization's data may be requested from support@ollie.cloud; after that window, Ollie permanently purges the organization's data (including settings, folders, activity logs, chat threads, billing references, stored files, and related assets). Deletion initiated directly through the identity provider (Clerk) is applied immediately, without the recovery window. Backups are overwritten in the ordinary course of operations.
Ollie will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. To minimize disruption, the parties will agree on reasonable scope, timing, and confidentiality, and Ollie may satisfy audit requests by providing relevant third-party certifications or reports where available.
This DPA is governed by the same law as the Agreement, except where Data Protection Laws require otherwise. If any provision conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls. Except as amended here, the Agreement remains in full force and effect.
Agreed by the parties. To request a countersigned copy of this DPA, email support@ollie.cloud. The signature block below may be completed by both parties:
| Ollie.Cloud LLC (Processor) | Customer (Controller) | |
|---|---|---|
| Signature | ||
| Name | ||
| Title | ||
| Date |
The technical and organizational measures described in Section 5, as updated from time to time to maintain an appropriate level of protection. These currently include encryption in transit (TLS) and at rest, with at-rest encryption provided by our infrastructure providers (Neon, Cloudflare R2, Upstash) under their certifications; organization-scoped access controls enforced at the application layer, with database row-level security as an additional defense-in-depth measure; a least-privilege application database role; signed, time-limited links for access to stored files; authentication that fails closed; signed, idempotent webhooks; logging and monitoring; and internal security reviews.
The Subprocessors listed at ollie.cloud/subprocessors, as updated in accordance with Section 6. That page identifies each Subprocessor, its purpose, the categories of data it processes, and its processing location.