Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SLOBODAN ANTIC PR SPECIJALIZOVANE DIZAJNERSKE DELATNOSTI ANTIC DESIGN KRAGUJEVAC ("Oqtalium", "we", "us") and you, and applies wherever we process personal data on your behalf in providing the Service. It reflects the parties' obligations under the Serbian Law on Personal Data Protection and, where it applies to your use, the EU and UK General Data Protection Regulation (together, "Data Protection Law"). Words defined in the Terms of Service have the same meaning here. If this DPA conflicts with the rest of the Terms on the processing of personal data, this DPA prevails. You accept this DPA when you accept the Terms; no separate signature is required.
1. Roles
You are the controller of the personal data that you or your users enter about your members, prospective members, staff and other individuals ("Customer Personal Data"), and we act as your processor for that data. Where you enter that data on behalf of another organisation, you are that organisation's processor and we are its sub-processor. Each party is responsible for complying with its own obligations under Data Protection Law. Personal data relating to your own account — such as your name and email — is handled by us as a controller under our Privacy Policy, and is not covered by this DPA.
2. What we process on your behalf
This describes the processing we carry out for you, as Data Protection Law requires us to set out:
- Subject matter and duration — processing Customer Personal Data to provide the Service, for the term of your subscription and until the data is deleted or returned under this DPA.
- Nature and purpose — hosting and storing the data, and generating analyses, drafts and suggestions at your request, so the Service can advise you on running your studio.
- Types of personal data — as chosen by you, typically members' or staff names, contact details, feedback or quotes, attendance and engagement information, and similar operational data. You must not enter special categories of data except as set out in clause 9.
- Categories of individuals — your members, prospective members, staff and any other individuals whose data you choose to enter.
3. Our obligations as your processor
We will:
- process Customer Personal Data only on your documented instructions — given by the Terms, this DPA and your use of the Service — including as to international transfers, unless the law requires otherwise (in which case we will tell you, unless legally prohibited);
- ensure that people authorised to process the data are bound by confidentiality;
- implement the security measures described in clause 4;
- engage sub-processors only as set out in clause 5;
- assist you, by appropriate measures and as far as possible, to respond to requests from individuals exercising their rights (clause 6);
- assist you, taking into account the nature of processing and the information available to us, with your obligations on security, breach notification, data protection impact assessments and prior consultation;
- at your choice, delete or return Customer Personal Data at the end of the Service and delete existing copies, unless we are required by law to keep them (clause 10); and
- make available the information needed to demonstrate our compliance with this clause, and allow for and contribute to audits as set out in clause 10.
4. Security
We implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, appropriate to the risk. These include access controls, role-based access, encryption of data in transit, and reliance on established infrastructure providers. No measures can guarantee absolute security. You are responsible for keeping your account credentials confidential, for managing who has access to your account, and for the security of any data you export from the Service.
5. Sub-processors
You give general authorisation for us to engage sub-processors to help provide the Service. Our current sub-processors are:
- Anthropic — the AI provider whose models generate the Service's outputs;
- Supabase — database and authentication;
- Vercel — application hosting; and
- Paddle — payment processing, as our merchant of record.
We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will make a means available for you to learn of any intended change to our sub-processors and to object, on reasonable data-protection grounds, within a reasonable period. If you object and we cannot reasonably accommodate the objection, you may stop using the affected part of the Service and, where that is not workable, terminate as described in the Terms.
6. Requests from individuals
If we receive a request from one of your members or other individuals seeking to exercise their data-protection rights, we will, where lawful, direct them to you and will not respond to the substance of the request except on your instruction. We will assist you, taking into account the nature of the processing, in meeting your obligation to respond — including through the Service's own export and deletion features.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to us to help you meet your own notification obligations to authorities and affected individuals. A breach will not be treated as our failure to meet an obligation where it results from your own acts, omissions or instructions.
8. International transfers
Some of our sub-processors may process personal data outside Serbia and the European Economic Area, including in the United States. Where Data Protection Law requires it, appropriate safeguards — such as standard contractual clauses or a recognised adequacy mechanism — are put in place for those transfers. By using the Service, you instruct and authorise these transfers to the extent necessary to provide it.
9. Special categories of data
The Service is not intended to process special categories of personal data — such as health, medical or biometric information. You must not enter such data about any individual unless you have the specific lawful basis that Data Protection Law requires for it, and where you do, you remain solely responsible for meeting those heightened requirements. The Service applies checks intended to reduce the entry of such data, but these are a safeguard, not a guarantee, and do not lessen your responsibility.
10. Deletion, return and audits
On expiry or termination of the Service, or on your request, we will delete or, where feasible, return Customer Personal Data and delete existing copies, unless we are required by law to retain them; you can also export your data at any time using the Service. We will make available the information necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, contribute to an audit — which we may satisfy by providing relevant documentation or independent reports where available. Audits are limited to once in any twelve-month period, unless a supervisory authority requires otherwise or one follows a breach, and are carried out at your cost.
11. Liability, term and governing law
This DPA is subject to the limitations and exclusions of liability set out in the Terms. It takes effect when you accept the Terms and continues for as long as we process Customer Personal Data on your behalf; provisions that by their nature should survive — including on deletion, confidentiality and liability — survive its end. This DPA is governed by the laws of the Republic of Serbia and is subject to the jurisdiction and general provisions of the Terms. Questions: support@oqtalium.com.
This document is also available inside the Oqtalium app, where it is kept identical to this page. It is provided for information and is not legal advice.