GDPR Article 28 Compliance for B2B Customers
Contact: privacy@optixlog.com
This agreement is binding upon use of our services. No separate signature is required.
You (Customer) are the Data Controller - you decide what data to process and how.
OptixLog is the Data Processor - we process data according to your instructions.
Currently: AWS us-east-2 (Ohio, USA) via Supabase with Standard Contractual Clauses (SCCs)
GDPR Article 28 compliant, SCCs for EU-US transfers, sub-processor transparency
This Data Processing Agreement ("DPA") forms part of the Service Agreement between Customer ("Controller") and OptixLog ("Processor") and governs the processing of Personal Data in connection with the OptixLog photonics simulation platform (the "Service").
GDPR Compliance: This DPA meets the requirements of Articles 28 and 46 of the General Data Protection Regulation (EU 2016/679).
Provision of OptixLog photonics simulation platform and related services
Employees, contractors, students, researchers, collaborators of Controller
OptixLog uses the following vetted sub-processors. All have executed Data Processing Agreements with Standard Contractual Clauses (SCCs).
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Supabase/AWS | Database & storage | US (Ohio) | DPA + SCCs, ISO 27001, SOC 2 |
| Stripe | Payment processing | US (global) | DPA + SCCs, PCI DSS Level 1 |
| OAuth auth | US (global) | Google Cloud DPA + SCCs | |
| OpenAI | Code analysis (optional) | US | OpenAI DPA, SOC 2 |
| Vercel | Hosting & analytics | US + global CDN | Vercel DPA, ISO 27001 |
We will notify you at least 30 days in advance of any new sub-processor via email and notice on this page. You have 30 days to object on reasonable data protection grounds.
When Personal Data is transferred from the EEA to the United States, OptixLog relies on:
OptixLog implements the following technical and organizational measures (GDPR Article 32):
OptixLog will assist Controller in fulfilling data subject requests:
Response time: Within 5 business days of Controller's request
Personal Data retained for as long as Controller's account is active
Option 1 (default): Delete all Personal Data within 90 days
Option 2: Return Personal Data to Controller in JSON format, then delete
In the event of a Personal Data breach, OptixLog will:
Note: Controller is responsible for notifying affected data subjects and Supervisory Authority as required by GDPR Articles 33-34.