Back to PrimeOps

PrimeOps Data Processing Addendum

Document ID: primeops-dpa-attorney-review-v1-2026-08-26  ·  Supersedes: none (new document)  ·  Effective Date: [PUBLICATION DATE]  ·  Version: [dpa-YYYY-MM-DD]

The short version

This summary is for convenience only. It is not part of the Addendum and does not change any section below.

How this Addendum fits with your other PrimeOps terms

This Data Processing Addendum (the "Addendum") forms part of the PrimeOps Terms of Service at getprimeops.ai/terms, or any other written agreement covering your use of the Service (the "Agreement"), between PrimeOps LLC, a New Jersey limited liability company ("PrimeOps," "we," "us"), and the customer identified in the Agreement ("Customer," "you").

It applies whenever PrimeOps processes Personal Data on your behalf as part of the Service. Capitalized terms not defined here have the meanings given in the Agreement.

Precedence. For the processing of Personal Data on your behalf, this Addendum controls over any conflicting term in the Agreement or the PrimeOps Privacy Policy at getprimeops.ai/privacy. For everything else, the Agreement controls. Where an Order or a negotiated agreement gives you greater protection than this Addendum, that greater protection applies.

Definitions

These terms carry the meaning given by the privacy law that applies to a particular processing activity; where laws differ, the definition of the law being applied governs.

Who plays which role

You are the Controller. PrimeOps is the Processor. For Personal Data inside Customer Data, you decide why and how it is Processed; PrimeOps Processes it to provide the Service and follow your instructions.

You are responsible for: the accuracy and lawfulness of the Personal Data you provide or connect; having a lawful basis and any required notices or permissions from your employees, contractors, guests, vendors, and other individuals; the instructions you give us; and your own compliance with Privacy Laws as a Controller. You will not instruct us to Process Personal Data in a way that would violate Privacy Laws.

PrimeOps acts as a Controller only for the limited categories described in the Privacy Policy — account administration, billing, security, support, and our own business records. That Processing is governed by the Privacy Policy, not by this Addendum.

What we may do with your data — and what we may not

PrimeOps will Process Personal Data only:

  1. on your documented instructions, which include the Agreement, this Addendum, your configuration of the Service, the integrations you authorize, and your use of Service features; and
  2. as required by applicable law — in which case, unless the law forbids it, we will tell you before Processing.

We will not:

Certification. PrimeOps understands the restrictions in this Section and will comply with them. We will notify you promptly if we determine we can no longer meet an obligation under this Addendum or Privacy Laws, and you may then take reasonable steps to stop and remediate unauthorized Processing, including suspending the affected Processing or terminating the affected Service under the Agreement.

Aggregated and de-identified information. PrimeOps may create aggregated or de-identified information as described in the Agreement. Before doing so, we take reasonable measures designed to prevent that information from being associated with you, your locations, or any identifiable person; we publicly commit not to re-identify it except to test our own safeguards or as required by law; and we bind recipients to the same restrictions. De-identified information is not Personal Data while it remains de-identified.

The people who handle your data

PrimeOps limits access to Personal Data to personnel who need it to provide, secure, or support the Service. Those personnel are bound by written confidentiality obligations or an equivalent statutory duty that survives the end of their engagement, receive access appropriate to their role under least-privilege principles, and are trained on the handling requirements that apply to their work. We remove access promptly when it is no longer needed.

Security

PrimeOps implements and maintains the technical and organizational measures in Annex II, designed to protect Personal Data against a Security Incident and appropriate to the nature of the data and the risks of the Service. We may update those measures as the Service evolves, provided we do not materially reduce the overall level of protection during your subscription term.

You are responsible for your own side of security: configuring the Service appropriately, assigning least-privilege access, managing your users and administrators, protecting credentials, choosing which integrations to authorize, and not submitting data categories the Service is not built to handle. The Agreement lists those excluded categories.

Subprocessors

You authorize PrimeOps to engage Subprocessors to Process Personal Data. The Subprocessors in place as of the Effective Date are listed in Annex III.

Before a Subprocessor Processes Personal Data, PrimeOps will enter a written agreement with it imposing data-protection obligations no less protective than this Addendum, appropriate to the services it provides. PrimeOps remains responsible to you for a Subprocessor's performance of those obligations to the same extent as for its own.

Changes. We will give you at least 30 days' notice before a new Subprocessor begins Processing Personal Data, by email to your administrator address or through the Service. If you reasonably object on data-protection grounds within that period, by notice to the address in Section 15.1, we will work with you in good faith to offer a commercially reasonable alternative. If we cannot, you may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees for it — that is your exclusive remedy for the objection.

We may replace a Subprocessor without advance notice where required to address an urgent security risk or an unexpected loss of service, and will inform you promptly afterward.

Helping you meet your own obligations

Data Subject requests. The Service gives your administrators the ability to access, correct, export, and delete Personal Data within your workspace, which is normally how you will respond to a Data Subject. If a request cannot be handled through those features, PrimeOps will provide reasonable assistance, at your expense where the assistance is substantial, taking into account the nature of the Processing.

If PrimeOps receives a request directly from a Data Subject about your Customer Data, we will not respond to it substantively except to acknowledge receipt and direct the person to you, and — unless legally prohibited — we will forward it to you without undue delay.

Assessments and consultations. Taking into account the nature of the Processing and the information available to us, PrimeOps will provide reasonable assistance with your data-protection assessments, risk assessments, and consultations with a regulator, to the extent they relate to our Processing of Personal Data on your behalf.

Government and legal requests. If PrimeOps receives a legally binding request from a public authority for Personal Data we Process on your behalf, we will — unless legally prohibited — notify you before disclosing, ask the authority to direct its request to you, and disclose only the minimum required. We will challenge a request we reasonably consider unlawful.

If there is a Security Incident

PrimeOps will notify you of a Security Incident affecting Personal Data we Process on your behalf without undue delay after becoming aware of it, and in any event within [NOTIFICATION DEADLINE — CONFIRM A NUMBER OPERATIONS CAN MEET] after confirmation.

Our notice will describe, to the extent then known: the nature of the incident and the categories and approximate volume of Personal Data and Data Subjects involved; the likely consequences; the measures taken or proposed to address it and mitigate harm; and a contact point for more information. Send us your own incident questions at the address in Section 15.1; email is the fastest route and is monitored for this purpose. Where we cannot provide everything at once, we will provide information in phases without further undue delay.

PrimeOps will take reasonable steps to contain and remediate the incident, preserve relevant evidence, and cooperate with your reasonable requests so you can meet your own notification duties to regulators and Data Subjects. Those duties are yours as the Controller; PrimeOps will not notify your Data Subjects or a regulator on your behalf unless you ask us to in writing or the law requires us to.

Notifying you or cooperating with you is not an acknowledgement of fault or liability.

Getting your data back, and deletion

On termination or expiration of the Agreement, and at your choice, PrimeOps will return or delete Personal Data it Processes on your behalf. Consistent with the Terms of Service, an authorized administrator may request an export in a commonly usable format for 30 days after termination. After that period, we may delete or de-identify Personal Data.

You may also delete Personal Data during the term through the Service's own deletion features.

PrimeOps may retain Personal Data where a law, regulation, professional obligation, legal hold, or bona fide record-retention requirement requires it, and in routine backups that cannot reasonably be isolated for deletion. Anything retained stays subject to this Addendum, is protected by the measures in Annex II, is not used for any business purpose, and is deleted when the retention requirement ends or the backup expires on its ordinary cycle.

Showing our work: information and audits

PrimeOps will make available to you the information reasonably necessary to demonstrate compliance with this Addendum, including a current description of the measures in Annex II, the Subprocessor list, and responses to a reasonable annual security questionnaire.

[AUDIT POSTURE — CONFIRM BEFORE OFFERING: whether PrimeOps will provide a third-party audit report such as SOC 2, and on what schedule. Do not promise a report the company has not commissioned.] Where PrimeOps makes a third-party audit report available, providing it satisfies this Section.

Where Privacy Laws give you a right to conduct or mandate an assessment that the materials above do not satisfy, you may — no more than once in any 12-month period, unless a Security Incident or a regulator requires otherwise — conduct an audit of PrimeOps' Processing, on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, subject to confidentiality obligations, and at your expense. An audit may not include access to another customer's data, our internal cost or personnel information, or systems whose disclosure would compromise the security of other customers.

United States state privacy terms

This Section applies where a United States state privacy law governs the Processing, and is in addition to the rest of this Addendum.

California. Where the CCPA applies, PrimeOps is a Service Provider Processing personal information on your behalf for the business purposes in Annex I. PrimeOps certifies that it understands and will comply with the restrictions in Section 4, including that it will not sell or share personal information, will not retain, use, or disclose it outside the direct business relationship or for a purpose other than the specified business purposes, and will not combine it with personal information from another source except as the CCPA permits. PrimeOps will provide the same level of privacy protection the CCPA requires of you, will notify you if it can no longer do so, and will grant you the rights described in Section 4 to remediate unauthorized use. You may take reasonable and appropriate steps to help ensure PrimeOps uses personal information consistent with your obligations.

New Jersey and comparable states. Where the New Jersey Data Privacy Act or a comparable state privacy statute applies, PrimeOps acts as a Processor and will: adhere to your instructions; ensure persons Processing the data are subject to a duty of confidentiality; delete or return Personal Data at your direction at the end of the Service, unless retention is required by law; make available the information reasonably necessary to demonstrate compliance; allow and cooperate with reasonable assessments as Section 11 provides; and engage Subprocessors only under a written contract as Section 7 provides.

Sensitive and regulated data. The Service is not built for, and you must not submit, payment-card numbers, government identifiers, health or medical information, biometric identifiers, precise geolocation, children's data, or other sensitive or specially regulated categories, unless PrimeOps has expressly agreed in a signed writing to support that category and any additional required safeguards are in place. PrimeOps is not a HIPAA business associate and this Addendum is not a business associate agreement.

Where Processing happens

PrimeOps Processes Personal Data in the United States, and its Subprocessors Process it in the locations identified in Annex III.

This Addendum does not currently include a transfer mechanism for Personal Data subject to the GDPR, UK GDPR, or Swiss data-protection law. If Personal Data subject to one of those laws will be Processed under the Agreement, the parties will execute the applicable Standard Contractual Clauses and any required addendum before that Processing begins, and those clauses will control over this Addendum where they conflict. [EU/UK/SWISS TRANSFER MODULE — ADD BEFORE ANY SUCH CUSTOMER IS ONBOARDED]

Liability

Each party's liability arising out of or relating to this Addendum is subject to the limitations and exclusions of liability in the Agreement, and any reference in the Agreement to a party's liability means that party's aggregate liability under the Agreement and this Addendum together. Nothing in this Addendum limits a liability that applicable law does not allow to be limited, or either party's obligations to a Data Subject or a regulator under Privacy Laws.

Term, changes, and general

This Addendum takes effect on the Effective Date and continues while PrimeOps Processes Personal Data on your behalf. Obligations that by their nature should survive — including Sections 4, 10, 12, and 14 — survive termination for as long as PrimeOps retains any Personal Data.

PrimeOps may update this Addendum where necessary to reflect a change in Privacy Laws, the Service, or its Subprocessors, provided the update does not materially reduce the protections it gives you. We will give reasonable notice of a material update through the Service or to your administrator address.

If a provision is held unenforceable, it is enforced to the maximum extent permitted and the rest remains effective. This Addendum is governed by the law and dispute-resolution provisions of the Agreement.

15.1 How to reach PrimeOps under this Addendum

Send anything this Addendum lets you do — a Subprocessor objection under Section 7, a Data Subject request or assistance request under Section 8, a security-incident query under Section 9, an audit or information request under Section 11, or a deletion or return instruction under Section 10 — to:

PrimeOps LLC
Attn: Privacy
72 Halsey Street
Newark, New Jersey 07102
support@getprimeops.ai

Email reaches us first and is the address to use when time matters, including a suspected Security Incident. A notice is effective when we receive it. Where this Addendum gives you a deadline to act — the Subprocessor objection window in Section 7 in particular — that period runs from when PrimeOps sends its notice to your administrator address, so keep that address current with us.


Annex I — Details of Processing

ItemDetail
Subject matterProvision of the PrimeOps hospitality operations platform under the Agreement.
DurationThe term of the Agreement, plus the post-termination export and deletion periods in Section 10.
Nature and purposeHosting, storing, transmitting, organizing, analyzing, and displaying Customer Data to: operate and secure the Service; authenticate users and preserve tenant separation; ingest and validate data from Customer-authorized systems and maintain source lineage; generate findings, estimates, prioritized issues, reports, and assigned follow-ups; provide support; detect and prevent fraud, abuse, and security threats; and comply with law.
Categories of Data SubjectsCustomer's authorized users and administrators; Customer's employees and contractors whose operational records Customer submits; Customer's vendor, supplier, and delivery-platform contacts; and other individuals whose information appears in records Customer chooses to submit.
Categories of Personal DataAccount and identity information (name, business email, identity-provider subject identifier, role, permissions, authentication and consent records); organization and location information; operational records that may contain personal information supplied by Customer (schedules, roles, hours, labor cost, payroll-related operational totals, employee or contractor identifiers, operating notes, uploaded files); vendor and supplier contact information; usage, device, and security information (IP address, device and browser type, request and session identifiers, timestamps, audit and access records); communications and support content; and outputs derived from the above.
Sensitive dataNone. The Service is not built for sensitive or specially regulated categories, and Section 12 prohibits submitting them absent a signed writing.
FrequencyContinuous, for the duration of the Agreement.

Annex II — Technical and organizational measures

Read this Annex as a contractual commitment. It is split deliberately: the first column is what PrimeOps maintains today, and the second names measures that must be in place before the Service processes production Customer Data. Nothing may move to the first column until it is verified.

AreaIn placeRequired before production Customer Data
Tenant separation Application-layer scoping of every query on shared tables by the tenant identifier from the authenticated session, never from a request body. Database runtime role defined as non-superuser, non-owner, and NOBYPASSRLS so it cannot bypass row-level security. Production verification that the deployed runtime role actually carries those attributes and cannot bypass row-level security (tracked as an open engineering item). This Annex does not warrant proven enforcement until that verification is complete.
Encryption TLS encryption in transit, terminated at the platform edge, with HTTP Strict Transport Security emitted only over verified-secure connections and HTTPS enforcement for application traffic. Encryption at rest as provided by the managed database and storage platforms. Confirmation and documentation of the at-rest encryption each provider actually applies, recorded in the subprocessor register.
Access control Role- and permission-scoped access within a workspace; least-privilege internal access; credentials and tokens held only through approved secret-management mechanisms, never in free-text fields; separation of development, staging, and production environments. Provider-backed identity with verified email, enforced multi-factor authentication for owners and administrators, secure account recovery, and session revocation — the controls the Service's access gate currently states are not yet activated.
Logging and audit Audit and execution records for decisions, approvals, assigned actions, and outcomes; authentication and access-decision records; operational logs designed to carry identifiers and outcomes rather than contact fields. A defined audit-log retention period, aligned with the retention schedule the Privacy Policy requires before publication.
Secure development Version-controlled changes with automated lint, type, and test gates; a migration-safety gate that quarantines a release whose database migration fails; automated secret scanning to prevent credentials reaching the repository; dependency and license review. A documented change-approval and release-authorization process, and periodic third-party security testing.
Resilience Managed-platform backups on the provider's cycle; separation of environments; health and readiness checks gating a release. A tested restore procedure with a stated recovery objective, and a documented business-continuity plan.
Incident response Monitoring and alerting on service health and security signals; an internal path for containment, remediation, and evidence preservation. A written incident-response plan naming roles, an on-call arrangement that can meet the Section 9 notification deadline, and at least one rehearsal.
Vendor management Subprocessors limited to those in Annex III; each receives only the data its function requires. An executed data-processing agreement with every Subprocessor, and a documented review of each before onboarding.
Personnel Written confidentiality obligations; access limited to those who need it; prompt removal of access when no longer needed. Documented security-awareness training and background-check policy proportionate to role.

Annex III — Subprocessors

Each row needs three separate facts before this Addendum is offered to a customer: the exact legal entity PrimeOps contracts with, where that Subprocessor Processes the data, and confirmation that a data-processing agreement binding it is actually executed. They are separated below because they have different answers and different sources — the contracting entity and the region depend on the plan and configuration of the PrimeOps account, not on what the provider publishes, and only an executed agreement satisfies Section 7. A row is not complete until all three are filled. The website-side register in docs/legal/LEGAL_REVIEW_PACKET.md remains unverified and must be reconciled with this table.

SubprocessorFunctionPersonal Data it may ProcessContracting entityProcessing locationDPA executed
RailwayApplication hosting and managed database infrastructureAll categories in Annex I, as hosted infrastructure[ENTITY — CONFIRM FROM ACCOUNT][LOCATION — CONFIRM IN PROVIDER CONSOLE][DPA — CONFIRM EXECUTED]
Auth0Identity and authentication (planned; not activated)Account and identity information, authentication records[ENTITY — CONFIRM FROM ACCOUNT][LOCATION — CONFIRM IN PROVIDER CONSOLE][DPA — CONFIRM EXECUTED]
StripePayment processing and subscription billingBilling contacts and transaction metadata; PrimeOps does not receive complete card numbers or security codes[ENTITY — CONFIRM FROM ACCOUNT][LOCATION — CONFIRM IN PROVIDER CONSOLE][DPA — CONFIRM EXECUTED]
ResendTransactional email deliveryRecipient name and email address, message content[ENTITY — CONFIRM FROM ACCOUNT][LOCATION — CONFIRM IN PROVIDER CONSOLE][DPA — CONFIRM EXECUTED]
VercelMarketing website hosting, analytics, and the consultation-request pathWebsite request metadata; consultation-form submissions[ENTITY — CONFIRM FROM ACCOUNT][LOCATION — CONFIRM IN PROVIDER CONSOLE][DPA — CONFIRM EXECUTED]
AnthropicOptional AI-assisted operating judgment. Not activated by default — the call is made only when the PRIMEOPS_GOD_MODE_LLM setting is switched on, which ships off.When enabled: the operating event under review and its evidence, the selected scenario, the internal review votes, and the track record for that bucket. Evidence may carry the operational records described in Annex I, so this row must be treated as processing Personal Data whenever the setting is on. No training on Customer Data.[ENTITY — CONFIRM FROM ACCOUNT][LOCATION — CONFIRM IN PROVIDER CONSOLE][DPA — CONFIRM EXECUTED, IF ENABLED]