Annex I(A) List of Parties
- Data Exporter
Name: the Customer signing this DPA
Activities relevant to transfer: See Annex 1(B)
Role: Controller
- Data Importer
Name: the Provider signing this DPA
Contact person: Mohammad Algharabat, CEO
Address: 355 Bryant St, San Francisco, California 94107, USA
Activities relevant to transfer: See Annex 1(B)
Role: Processor
Annex I(B) Description of Transfer and Processing Activities
- Service
The Service is:
Open.cx is an AI-powered customer support platform designed for enterprises handling high-volume support requests. The platform enables automated, AI-driven assistance across multiple channels, including web, phone, and email, while maintaining security and compliance.
The service includes:
- AI-driven ticket resolution for Level 2 (L2) and Level 3 (L3) customer support.- Automated customer interactions via web chat, email, and AI-powered phone calls.- Secure storage, processing, and retrieval of customer inquiries and support history.- Integration with enterprise CRM, payment, and identity verification systems.
Open.cx acts as a Processor, ensuring that customer personal data is handled securely, with encryption at rest and in transit, strict access controls, and compliance with data protection regulations.
Customer data is never used to train, fine-tune, or improve any AI models, whether owned by Open.cx or any third-party providers.
All customer data is:
- Encrypted both in transit and at rest using industry-standard encryption protocols.
- Logically and physically (hardware-level) segregated from other customers’ data.
- Protected through strict access controls and continuous monitoring.
- Categories of Data Subjects
Customer's end users or customers
- Categories of Personal Data
Name
Contact information such as email, phone number, or address
- Special Category DataIs special category data (as defined in Article 9 of the GDPR) Processed?
No
- Frequency of Transfer
Continuous
- Nature and Purpose of Processing
- Receiving data, including collection, accessing, retrieval, recording, and data entry
- Holding data, including storage, organization, and structuring
- Using data, including analysis, consultation, and testing, automated decision making, and profiling to provide, secure, and improve the reliability of the service. The Provider shall not engage in automated decision-making or profiling beyond what is strictly necessary to provide, secure, and improve the reliability of the service, and such processing shall not produce legal effects on Data Subjects.
- Updating data, including correcting, adaption, alteration, alignment, and combination
- Protecting data, including restricting, encrypting, and security testing
- Returning data to the data exporter or data subject
- Erasing data, including destruction and deletion
- Duration of Processing
Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.
Annex I(C)
- Competent Supervisory Authority
The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
Annex II
- Technical and Organizational Security Measures
See Security Policy
Pseudonymization and encryption of personal data:
- Open.cx encrypts all personal data in transit and at rest using industry-standard encryption protocols (AES-256 for storage and TLS 1.2+ for data transmission).
- Open.cx does not intentionally collect or require special categories of personal data (as defined under Art. 9 GDPR). However, if such data is incidentally provided by end users during chat or email support interactions handled by our AI agent, it is automatically detected and irreversibly pseudonymized, and is not used for any purpose beyond providing the service.
- API tokens and authentication credentials are encrypted and securely stored.
- Personally Identifiable Information (PII) redaction is available as an optional feature that customers can enable from the Open.cx dashboard.
Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services:
- Data access is restricted based on the principle of least privilege (PoLP) with strict role-based access control (RBAC).
- All system components undergo regular security assessments, including vulnerability scans and penetration testing.
- Data is processed within a secure cloud Kubernetes environment with automated failover mechanisms.
- Logging and monitoring systems continuously track system health and detect anomalies in real-time.
Ability to restore the availability of and access to the Customer Personal Data in a timely manner following a physical or technical incident:
- Open.cx maintains automated and encrypted backups of all critical data with a retention policy aligned with compliance requirements.
- Incident response plans are in place, with predefined escalation paths and response times.
- Regular backup integrity checks and restoration tests ensure data recoverabilit
Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure Processing:
- Open.cx conducts routine security audits, including third-party penetration testing and compliance assessments.
- Internal security reviews and code audits are performed regularly to identify and mitigate potential risks.
- Employee security awareness training is conducted periodically to reinforce data protection best practices.
User identification and authorization process and protection:
- All authentication processes use secure hashing algorithms (bcrypt) and OAuth 2.0 for token-based authentication.
- Failed login attempts and suspicious activities trigger automated security alerts and potential account lockdown.
Protecting Customer Personal Data during transmission (in transit):
- All data in transit is encrypted using TLS 1.2+ to prevent interception and tampering.
- Secure WebSockets (WSS) are used for real-time communications.
- Mutual TLS authentication is enforced for API interactions with external systems.
- HTTP Strict Transport Security (HSTS) is implemented to prevent protocol downgrade attacks.
Protecting Customer Personal Data during storage (at rest):
- All stored data is encrypted using AES-256 encryption.
- Access to stored data is restricted using least-privilege access controls.
- Customer data is stored in a logically separated multi-tenant environment to prevent cross-tenant access.
- Automated backup encryption ensures that backup files remain secure.
Physical security where Customer Personal Data is processed:
Open.cx relies on cloud providers with industry-standard physical security controls (e.g., AWS, GCP, Azure).- Data centers are SOC 2 compliant.- Security policies enforce restricted physical access, biometric authentication, and 24/7 surveillance.- Physical media containing customer data is securely destroyed when decommissioned.
Events logging:
- Open.cx maintains an audit log of all security-relevant events, including authentication, authorization changes, and data access.
- Logs are immutable and stored in a centralized, tamper-proof system.
- Anomaly detection systems analyze logs in real time to identify potential security threats.
- Logs are retained based on compliance requirements and regulatory guidelines.thi
Systems configuration, including default configuration:
- Open.cx enforces secure-by-default system configurations, minimizing exposure to potential threats.
- Infrastructure-as-Code (IaC) is used to maintain consistent and secure configurations across all environments.
- Regular configuration audits are performed to identify and remediate misconfigurations.
- All cloud-based environments follow hardened baseline configurations based on CIS benchmarks.
Ensuring data minimization:
- Open.cx follows the principle of data minimization by only collecting and processing the necessary customer data.
- Customers can configure data retention settings from the Open.cx dashboard to limit the storage of personal data.
- Automated processes remove unnecessary data based on predefined retention policies.
- PII redaction features are available for customers to enable on-demand.
Ensuring data quality:
- Data validation mechanisms ensure the accuracy, completeness, and consistency of stored customer data.
- Regular integrity checks are performed to prevent data corruption or unauthorized modifications.
- Customer support tools allow users to update or correct inaccurate data as needed.
- Logging and auditing mechanisms track data modifications for accountability.
Ensuring limited data retention:
- Open.cx enforces a data retention policy that allows customers to define how long their data is stored.
- Automated deletion mechanisms ensure that expired data is securely erased after the retention period.
- Backups are retained only for the required duration and are encrypted to prevent unauthorized access.
- Compliance with GDPR and other regulations ensures that personal data is not stored longer than necessary.
Ensuring accountability:
- A clear audit trail logs all access, modifications, and deletions of customer data.
- Role-based access control (RBAC) ensures that data access is limited to authorized personnel only.
- Security training is provided to employees to maintain a culture of accountability and awareness.
- Incident response procedures include root cause analysis to prevent recurring security issues.
Allowing data portability and erasure:
- Open.cx provides customers with the ability to export their data in a structured, machine-readable format.
- Customers can request data deletion from the Open.cx dashboard, ensuring compliance with GDPR’s right to erasure.
- Secure deletion mechanisms, including cryptographic erasure, ensure that deleted data is not recoverable.
- Support for interoperability allows customers to migrate their data to other platforms when necessary.
Version history
Each version keeps its own permanent link. A signed DPA stays on the version it references.
| Version | Effective date | What changed |
|---|---|---|
| 1.1 | 22 September 2026 |
|
| 1.0 | 22 September 2026 |
|