Data Processing Agreement
(Standard - Incorporated into OpenObserve Terms of Service)
Version 2.1 - Revised September 5, 2026. Effective as provided in Sections 1.2 and 10.4.
How This DPA Applies. This Data Processing Agreement ("DPA") is incorporated by reference into OpenObserve's Terms of Service. It applies where OpenObserve processes Personal Data on Customer’s behalf under an agreement incorporating this DPA. A signed agreement expressly governing the same processing controls over this standard DPA to the extent of a conflict. No separate signature is required. By creating an account, clicking "I agree," or otherwise accessing or using the Services, Customer agrees to be bound by this DPA. This DPA is publicly available at https://openobserve.ai/legal/dpa/.
1. Parties, Effective Date, and Scope
Parties.
- Processor: OpenObserve Inc., a Delaware corporation, with its principal place of business at 3000 Sandhill Road Building 1 Suite 260, Menlo Park, CA 94025 ("Processor").
- Controller: The legal entity or individual that creates an OpenObserve account or otherwise accesses or uses the Services ("Controller" or "Customer"). Where Customer acts as a data controller under Applicable Laws, Customer is the "Controller" for purposes of this DPA.
Effective Date. For new Customers, this DPA takes effect when accepted through the applicable agreement or account-registration process. Updates for existing Customers are governed by Section 10.4; posting a revision does not retroactively amend a signed agreement. This DPA remains applicable for as long as Processor retains Personal Data on Customer’s behalf.
Purpose. Controller and Processor have entered (or will enter) into OpenObserve's Terms of Service ("ToS") under which Processor provides observability-related services (the "Services"). In connection with those Services, Processor may receive, store, or otherwise process Personal Data on behalf of Controller. This DPA defines how Processor and Controller must handle that Personal Data in compliance with Applicable Laws.
Scope. This DPA applies only to Personal Data that Processor actually receives or accesses on Customer’s behalf in delivering the purchased Services, including hosted telemetry and support materials. Logs, metrics, and traces are not necessarily Personal Data. Customer determines their content and lawful submission. For customer-operated or self-hosted deployments, Customer is responsible for its infrastructure, storage, retention, access controls, and transfers; installing the software alone does not cause Processor to process the data stored there. If Customer is itself a processor, it represents that it has the controller’s authorization to appoint Processor as a sub-processor, and references to Controller include that Customer as appropriate. Account contacts, invoicing records, and website/marketing information that OpenObserve processes for its own purposes are addressed by its Privacy Policy, not by expanding Customer’s telemetry-processing instructions. Processor will not sell Personal Data submitted under this DPA, use it to train general-purpose models, or process it for unrelated advertising purposes.
2. Definitions
Unless otherwise defined below, capitalized terms in this DPA have the following meanings:
"Applicable Laws" means data protection and privacy laws applicable to a Party’s processing under this DPA, including the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, CCPA as amended by CPRA and applicable regulations, and other applicable privacy laws, in each case as and when legally effective. This DPA does not make otherwise inapplicable laws applicable or defer mandatory compliance deadlines.
"Standard Contractual Clauses (SCCs)" means the EU Commission's Standard Contractual Clauses for transfers of Personal Data to processors in third countries (Commission Implementing Decision (EU) 2021/914), or any approved successor instrument.
"Controller" means the party that determines the purposes and means of Processing of Personal Data.
"Processor" means the party that processes Personal Data on behalf of the Controller (i.e., OpenObserve Inc.).
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined by Applicable Laws. Data rendered truly anonymous-such that it cannot be re-identified by any reasonable means-is not Personal Data.
"Processing" means any operation or set of operations performed upon Personal Data, such as collection, recording, storage, organization, retrieval, use, disclosure, erasure, or destruction.
"Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
"Data Protection Impact Assessment (DPIA)" means the formal risk evaluation process required under GDPR Article 35 or equivalent Applicable Laws.
"Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Processor.
"Service Provider" (for California residents) means Processor acting under CCPA/CPRA as an entity that processes Personal Data on behalf of the Controller and does not "sell," "share," or retain Personal Data beyond the scope of the contract.
"Special Category Data" means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying an individual, health data, or data concerning an individual's sex life or sexual orientation, as defined under GDPR Article 9 or equivalent Applicable Laws.
"Legal Hold" means a documented obligation to preserve specific data beyond its standard retention period due to actual or reasonably anticipated litigation, regulatory investigation, audit requirement, or other legal proceeding.
"Confidential Information" means non-public information disclosed by one Party to the other that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure.
"DSAR" means a Data Subject Access Request or any other request by a Data Subject to exercise rights under Applicable Laws (access, rectification, erasure, restriction, portability, or objection).
"Offboarding Window" means the period during which retained Personal Data remains available for export under Controller’s applicable retention configuration and Section 9.2; it is not a separate fixed retention period.
3. Subject Matter, Duration, and Retention
Subject Matter. Processor processes Personal Data in telemetry, support materials, and related metadata as needed to provide, secure, and support the purchased Services on documented instructions. Customer determines the categories of Personal Data and Data Subjects submitted. Customer must not rely on Processor to identify personal information within telemetry.
Duration. Processing continues as necessary to perform the Services and the limited return, deletion, and retention obligations in Section 9.
Retention. Retention and expiration of customer telemetry follow Customer’s configured retention settings and the purchased Service’s documented retention mechanism. Termination does not restart or extend those periods, preserve expired data, or require recovery of previously deleted data. Customer must configure retention lawfully and export required data before expiration. Support copies and residual backups are governed by Section 9.3; a customer telemetry setting does not necessarily control those separate copies. Customer controls deletion in customer-operated infrastructure.
Categories of Data Subjects. The categories of Data Subjects are determined solely by the Controller based on the data it chooses to submit. They may include: Controller's employees, contractors, and agents; end users of Controller's applications; visitors to Controller's public-facing websites; and any other natural persons whose Personal Data Controller submits to Processor. Processor does not determine which individuals’ Personal Data Customer submits.
4. Controller Obligations
Lawful Basis & Instructions.
The Services are designed to ingest and process non-personal technical telemetry (logs, metrics, traces). Controller is solely responsible for determining whether data it submits constitutes Personal Data under Applicable Laws, and for ensuring it has a lawful basis to process and transfer any such data before submission.
In the self-service context, Controller's instructions are communicated through use of the Services - including account configuration, API calls, product settings, data ingestion, and support requests. Controller shall ensure those instructions are lawful. If Processor determines any instruction conflicts with Applicable Laws, Processor will suspend the relevant Processing and notify Controller without undue delay. Controller must then provide lawful instructions or authorize termination of the relevant activity.
Accuracy & Completeness. Controller is solely responsible for ensuring that all Personal Data supplied to Processor is accurate, complete, and up to date.
Restricted Data. Customer must minimize and appropriately redact Personal Data before submission and must not submit data requiring safeguards, certifications, or localization not supported by the purchased Services unless agreed in writing. Customer is responsible for necessary notices, consents, authorizations, and lawful bases, including for special-category data. The Services are not designated for regulated health information requiring a business associate agreement unless one has been executed.
Data Masking. Customer is responsible for configuring available filtering or redaction capabilities, or using its own sanitization tools before ingestion. Processor does not undertake to scan all telemetry for sensitive information or guarantee its removal. Support through email, Slack, or video calls is limited to necessary business-contact information and sanitized diagnostics. Customer must not send or display customer telemetry payloads or other Personal Data through those channels. Before support requires access to unsanitized payloads or Personal Data, the Parties must arrange an approved secure support channel and confirm the applicable provider disclosures and processing safeguards. These instructions do not exclude Personal Data actually received on Customer’s behalf from this DPA or relieve Processor of obligations that apply to that processing.
Data Subject Requests. Customer is responsible for responding to Data Subjects. Processor will refer requests concerning Customer’s Personal Data to Customer without undue delay and will not respond substantively except on instructions or as legally required. Assistance is governed by Section 7. Customer must provide accurate contact details and describe its processing in its own privacy notices as legally required.
CCPA/CPRA. To the extent the CCPA applies, Customer discloses Personal Data for the limited business purposes described in Sections 1 and 3. Processor acts as a service provider or contractor as applicable; will comply with applicable CCPA obligations and provide the same level of privacy protection required of Customer; and will not sell or share that Personal Data, retain/use/disclose it outside the specified purposes or direct business relationship except as legally permitted, or combine it with other personal information except as permitted by the CCPA. Processor certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps, consistent with Section 6 and applicable law, to ensure compliant use and to stop and remediate unauthorized use. Processor will notify Customer if it determines it can no longer meet its applicable CCPA obligations and will reasonably cooperate in remediation. Sub-processors must be bound by applicable written restrictions.
Sub-processor Objections. Controller may object to a Sub-processor change per the procedures in Sections 5.6.5 and 5.6.6.
5. Processor Obligations
5.1 Compliance with Instructions
Processor will process Personal Data only on documented instructions from Controller communicated through the agreement and use of the Services (including account configuration, API calls, product settings, and support requests), unless applicable law requires processing; in that case Processor will inform Controller of the legal requirement before processing unless that law prohibits notice. If Processor believes any instruction infringes Applicable Laws, Processor will notify Controller without undue delay and suspend the relevant Processing until Controller provides lawful instructions or authorizes termination of that activity.
5.2 Confidentiality
Processor shall ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations no less protective than those in this DPA. Access is strictly limited on a need-to-know basis, and all such personnel receive regular training on data protection. Processor will not use Controller's Confidential Information for marketing, competitive analysis, or any purpose unrelated to providing the Services.
5.3 Data Protection by Design
Taking account of the nature of the processing, Processor will use appropriate measures to limit processing to the documented purposes. Customer remains responsible for the content submitted and customer-controlled configuration.
5.4 Technical and Organizational Security Measures
Processor will maintain appropriate technical and organizational measures under Applicable Laws, taking account of the state of the art, implementation costs, nature and scope of processing, and risks to individuals. The contractual measures are described in Annex B. Public security materials describe practices and do not independently create additional warranties, certifications, uptime commitments, or recovery deadlines. Processor may update measures while maintaining materially equivalent overall protection and compliance with Applicable Laws. Available current assurance documentation may be requested under Section 6; this DPA does not represent that any particular certification is held.
5.5 Personal Data Incidents
Processor will notify Customer without undue delay after becoming aware of an Incident affecting Personal Data processed on Customer’s behalf, and within any shorter period required by Applicable Laws. An unsuccessful attack or event that does not compromise Personal Data is not an Incident for this purpose. Initial notification may be preliminary; Processor will provide available information about the nature of the Incident, affected data and individuals where ascertainable, likely consequences, measures taken or proposed, and a contact for follow-up. Processor will investigate, take reasonable containment and remediation measures, and supplement information without undue delay as material details become available. Notification is not an admission of liability. Customer is responsible for its required notifications to individuals and authorities; nothing here delays those obligations or restricts direct contact with an authority. Service-availability events are governed by the applicable SLA and are not automatically Personal Data Incidents. Contact dpo@openobserve.ai for data-protection incidents.
5.6 Sub-processing
Live Sub-processor List. Customer grants general written authorization for Processor to use the listed Sub-processors and to appoint replacements or additions under this Section’s notice and objection procedure. The authoritative, versioned list of Sub-processors is maintained at https://openobserve.ai/legal/subprocessors/. Annex A incorporates that list by reference.
Notice Periods. When Processor adds, removes, or replaces a Sub-processor, Controller will receive at least fourteen (14) days' advance written notice. Controller may object within that notice period on legitimate data protection or security grounds per Sections 5.6.5 and 5.6.6.
Flow-Down Obligations. Processor shall ensure every Sub-processor: (a) is contractually bound by terms at least as protective as this DPA; (b) processes Personal Data only on Processor's instructions; (c) enforces equivalent obligations on any downstream processors; and (d) provides appropriate security measures for the processing assigned to it.
Processor Liability. Processor remains responsible for Sub-processor acts or omissions as if Processor itself performed those services, subject to Section 8. Controller may request a list of known fourth parties; Processor will provide available information within a reasonable period, taking account of legally required deadlines.
Security and Legal Exception. If an urgent Sub-processor change is necessary to address an active security threat or comply with Applicable Laws and fourteen (14) days’ advance notice is not reasonably practicable, Processor may provide shorter notice only to the extent permitted by Applicable Laws and applicable transfer clauses. Processor will give as much advance written notice as practicable, or, if advance notice is not legally permitted or practicable, notice without undue delay after implementation when legally permitted. The notice will explain the change and urgency. Customer may object on legitimate data protection or security grounds within fourteen (14) days after receiving that notice, including where implementation precedes notice. This exception does not dispense with any mandatory prior authorization or other legal safeguard.
Controller Objections. Customer may object in writing on legitimate data protection or security grounds within the applicable fourteen (14) day period under Section 5.6.2 or 5.6.5. Processor will acknowledge the objection within five (5) business days and attempt to resolve it in good faith within fifteen (15) days. If the objection cannot be resolved, Customer may terminate the affected Services with thirty (30) days’ written notice, with return and deletion governed by Section 9. Customer remains responsible for fees accrued before termination; prepaid fees attributable to the unused terminated Services will be refunded. Pending resolution, Processor will maintain the safeguards required by Applicable Laws and applicable transfer clauses and will not continue any processing they prohibit.
5.7 International Transfers and Customer-Selected Regions
Customer selects its deployment/storage region from the available options. Processor will not relocate stored customer-submitted data to another region without Customer’s instructions or agreement. A customer-selected region does not, by itself, determine whether an international transfer occurs under Applicable Laws; actual recipients, initial submissions, and authorized access must also be considered. Transfer safeguards apply only to Personal Data actually subject to a restricted transfer involving Processor or its Sub-processors. They do not apply merely because software is installed in Customer’s environment.
Where a restricted transfer requires contractual safeguards rather than an applicable adequacy decision or another lawful mechanism, the Parties shall complete the applicable transfer terms in Annex C before that transfer. Neither this DPA nor region selection represents that Processor holds a Data Privacy Framework certification or has already completed a transfer assessment for Customer. Processor will provide reasonably available information needed for applicable transfer assessments and cooperate with legally required supplementary safeguards. Customer must not instruct processing requiring an unavailable localization arrangement or transfer mechanism without prior written agreement. Requirements of India, China, or another jurisdiction apply according to the actual processing and applicable law, not merely an individual’s nationality or residence.
5.8 Government and Law Enforcement Requests
Where Processor receives a legally binding request from a government authority, law enforcement agency, court, or regulatory body for access to or disclosure of Controller's Personal Data, Processor shall:
Challenge overbroad requests. Where permitted by law, Processor shall challenge any request that Processor reasonably believes to be overbroad, disproportionate, or otherwise unlawful before any disclosure.
Notify Controller. Where not prohibited by law or court order, Processor shall notify Controller of the request as soon as reasonably practicable and before any disclosure, providing sufficient detail to enable Controller to seek a protective order or other appropriate relief.
Minimum disclosure. Where disclosure is legally compelled and notification is prohibited, Processor shall disclose only the minimum Personal Data required to satisfy the legal obligation, and shall notify Controller as soon as the legal prohibition on notification lapses.
Cooperation. Processor shall reasonably cooperate with Controller in contesting or limiting the scope of any such request, at Controller's expense.
5.9 DPIA Assistance
Where Controller is required to conduct a DPIA, Processor shall provide reasonable assistance, including: (a) a written description of Processor's relevant processing activities; (b) a summary of security measures implemented under Section 5.4; (c) information on Sub-processors and transfer mechanisms; and (d) responses to reasonable written queries within a reasonable period, taking account of legally required deadlines.
6. Audit Rights
Reports First. On written request, Processor will provide reasonably available information necessary to demonstrate compliance, including relevant current independent assurance reports or security summaries where available, under confidentiality restrictions. Customer shall first use these materials and reasonable written questions to evaluate compliance. Processor may redact information concerning other customers, privileged matters, or security-sensitive details while providing sufficient alternative evidence of compliance.
Additional Audits. If those materials are insufficient to meet Customer’s rights under Applicable Laws, Processor will allow and contribute to a reasonably scoped audit, including inspection where legally required, by Customer or a qualified independent auditor bound by confidentiality obligations. Audits require reasonable advance notice, coordination during business hours, safeguards for other customers and security, and minimal disruption. Routine audits are limited to once annually, except following a material Incident, reasonable evidence of material noncompliance, or where Applicable Laws or a competent authority require otherwise. No penetration testing or access to other customers’ data is authorized.
Hosting Infrastructure and Costs. Processor cannot grant physical access it does not control at third-party facilities; it will facilitate relevant provider assurance documentation and other legally required assistance. Customer bears its audit costs and Processor’s reasonable assistance costs disclosed in advance, except where Applicable Laws require otherwise. These procedures do not limit mandatory regulator or Data Subject rights or override applicable transfer clauses.
7. Data Subject Rights and Compliance Assistance
Taking account of the nature of processing and information available, Processor will provide appropriate technical and organizational assistance with Data Subject requests, security obligations, breach notifications, DPIAs, and prior consultation as required by Applicable Laws. Customer should first use available product functionality to locate, export, or delete its data. Processor is not required to reconstruct expired data or identify individuals in telemetry it cannot reasonably associate with them. Requests may be sent to dpo@openobserve.ai. Ordinary self-service functionality is included in the purchased Services; Processor may charge reasonable, disclosed fees for additional assistance unless prohibited by Applicable Laws. Charges or administrative procedures will not prevent mandatory assistance within legally required deadlines. Retention and lawful preservation exceptions remain applicable.
8. Limitation of Liability and Indemnification
Liability Cap. Each Party’s total cumulative liability under or in connection with this DPA shall not exceed the fees paid by Customer for the affected Services in the twelve (12) months preceding the first event giving rise to liability. Related events and claims are treated as one event for this purpose; defense costs and indemnification payments count toward, and do not increase, this aggregate cap. For claims under this DPA, this twelve-month limit replaces any shorter general limit in the public ToS, and amounts paid for overlapping claims count toward both applicable limits without double recovery or stacking. The limit expressly stated in a signed agreement controls. Contractual fee-payment obligations remain payable independently of this damages cap. This cap applies to all claims including indemnification under Section 8.3, except for: (i) liability that cannot be excluded under Applicable Laws; or (ii) damages arising from fraud or willful misconduct. Nothing in this Section limits mandatory Data Subject rights, supervisory-authority powers, or liabilities under mandatory transfer clauses.
Exclusion of Consequential Damages. Neither Party shall be liable for indirect, incidental, special, punitive, or consequential damages arising under this DPA, even if advised of the possibility of such damages, except as required by Applicable Laws.
Mutual Indemnification.
- Controller shall indemnify, defend, and hold harmless Processor against third-party claims arising from: (a) Controller's breach of Section 4; (b) Controller's processing outside the scope of this DPA; or (c) Data Subject claims arising from Controller's failure to provide adequate notice or obtain valid consent before submitting Personal Data.
- Processor shall indemnify, defend, and hold harmless Controller against third-party claims arising from Processor’s material breach of its processing obligations under this DPA, but only to the extent the claim is caused by that breach and not by Customer’s unlawful instructions, submitted data, or customer-controlled systems.
An indemnified Party must promptly notify the indemnifying Party (delay excuses obligations only to the extent materially prejudicial), permit it to control the defense, and provide reasonable cooperation at its expense. No settlement may admit the indemnified Party’s fault or impose nonmonetary obligations on it without its reasonable written consent. These indemnities cover finally awarded damages and approved settlements, subject to this Section’s limitations.
- Regulatory Cooperation. If a supervisory authority investigates Controller in connection with Processor's confirmed material breach, Processor shall cooperate and provide requested documentation under the confidentiality obligations in Section 5.2 without undue delay and within legally required deadlines. Each Party remains independently responsible for fines assessed against it.
9. Termination and Data Return
Effect of Termination. After termination Processor will process Personal Data only as necessary for return, deletion, limited preservation required by law, or other surviving lawful obligations described here. This DPA continues to protect retained copies.
Retention-Based Export. Customer should export needed data during the active subscription and before its retention expires. After termination, on timely request Processor will make data still retained under Customer’s applicable retention mechanism available for return through then-available standard export functionality, subject to lawful security restrictions. The Offboarding Window ends as the relevant data expires or is deleted under that mechanism. It is not a guaranteed minimum access period, does not suspend rolling expiration, and does not extend retention. Customer may instead instruct deletion. No new ingestion or continued production use is included. Return and deletion rights required by Applicable Laws remain available; fees and usage charges validly accrued remain payable.
Deletion and Residual Copies. At Customer’s choice, Processor will return or delete Personal Data after the Services end and delete existing copies, except where Applicable Laws require storage. Active copies will be deleted without undue delay following completion of return or a deletion instruction, or as applicable retention expires. Residual backups will be isolated from ordinary use, remain protected by this DPA, and be deleted through the applicable documented backup rotation/deletion lifecycle; Processor will provide that lifecycle on request. Backups will not be retained indefinitely or restored for ordinary business use, and restored data remains subject to outstanding deletion instructions. Support copies will be deleted when no longer needed for the support purpose or surviving lawful obligations. Legally required preservation is restricted to the required data, purpose, and period, followed by deletion without undue delay. Processor will reasonably confirm completed deletion on request. Customer controls copies in its own infrastructure.
Additional Assistance. Custom migration, format conversion, dedicated infrastructure, and extraordinary export work are not included. Assistance is subject to availability and a written agreement on scope and fees, without limiting mandatory return/deletion obligations. Customer is responsible for its destination and transmission costs under the purchased Services.
Survival. Obligations concerning retained Personal Data, confidentiality, liability, return/deletion, applicable transfer safeguards, and dispute resolution survive as necessary to give them effect.
10. General Provisions
Governing Law. This DPA is governed by the laws of the State of Delaware, without regard to conflict-of-law rules, except where Applicable Laws mandate otherwise for specific provisions.
Dispute Resolution. The Parties shall attempt to resolve disputes by good-faith negotiation for thirty (30) days before initiating formal proceedings. Disputes follow the governing agreement’s dispute-resolution provisions. Mandatory Data Subject and regulator rights and the dispute provisions of applicable transfer clauses remain unaffected.
Entire Agreement. This DPA, together with the ToS, constitutes the entire agreement between the Parties concerning Personal Data processing and supersedes all prior agreements on that subject. In the event of conflict between this DPA and the ToS, this DPA governs with respect to Personal Data processing obligations. A signed agreement expressly governing the same subject controls over this standard DPA to the extent of a conflict; mandatory transfer clauses and Applicable Laws retain their required priority.
Amendments. Processor may update this DPA at any time by posting a revised version at https://openobserve.ai/legal/dpa/ with at least thirty (30) days' advance notice to Controller (via email to the account address or prominent notice within the Services), unless a shorter period is required to comply with Applicable Laws. Updates apply prospectively through the governing agreement’s amendment process and do not reduce protection required by Applicable Laws or amend mandatory transfer clauses. Continued use after valid notice constitutes acceptance only to the extent permitted by the governing agreement and law. If Controller does not accept an updated DPA, Controller must cease using the Services and notify Processor at legal@openobserve.ai before the effective date of the update. Controllers who require a negotiated, countersigned DPA may contact legal@openobserve.ai.
Severability. If any provision is found invalid or unenforceable, it shall be modified to the minimum extent necessary to remain enforceable; remaining provisions continue in full force.
Waiver. No failure or delay in exercising any right under this DPA constitutes a waiver of that right.
Force Majeure. Neither Party shall be liable for delays caused by circumstances beyond its reasonable control, provided the affected Party gives prompt written notice and uses commercially reasonable efforts to mitigate impact. If a force majeure event results in material ongoing inability to meet Section 5.4 measures for more than sixty (60) days, Controller may terminate without penalty.
EU/UK Representative. Processor acts as a data processor under this DPA, not as an independent controller of EU/EEA or UK residents' Personal Data. Processor will appoint a representative where and when required by Applicable Laws; processor status alone does not establish an exemption. For GDPR inquiries, contact Processor's data protection team at dpo@openobserve.ai.
Notices. All notices shall be in writing sent by email with delivery confirmation. Data protection notices (DSARs, breach notifications, DPIA requests, supervisory authority matters) shall be sent to dpo@openobserve.ai. Contract and legal notices (amendments, termination, disputes) shall be sent to legal@openobserve.ai. Notices to Controller shall be sent to the email address used to register the Controller's account, or as otherwise specified in writing by Controller.
Acceptance. This DPA takes effect as described in Section 1.2, with updates governed by Section 10.4. No physical or electronic signature is required. Controllers that require a countersigned DPA for their own compliance purposes may request one by contacting legal@openobserve.ai; the terms of that countersigned version will govern over this standard version for that Controller.
Annex A - Authorized Sub-processors
The authoritative, versioned list of Sub-processors is maintained at https://openobserve.ai/legal/subprocessors/. Changes to that list are governed by the notice and objection procedures in Section 5.6.
Annex B - Technical and Organizational Measures
Within Processor-controlled Services, measures appropriate to the processing include access authorization and least privilege; personnel confidentiality; encryption of transmitted and stored Personal Data where appropriate to the service architecture; monitoring and incident response; vulnerability and change management; logical separation of customer environments/data; and retention, deletion, and resilience procedures. Customer is responsible for identity configuration, access grants, agents, destinations, backups, and infrastructure it controls. Details of the measures applicable to the purchased deployment and current available assurance materials may be requested under Section 6. No uptime, recovery deadline, certification, or customer-infrastructure commitment is created by this Annex. Measures will be maintained at the level required by Section 5.4 and Applicable Laws.
Annex C - Conditional Transfer Documentation
This Annex applies only if Section 5.7 identifies a restricted transfer requiring contractual safeguards. Before that transfer, the Parties must complete the relevant instrument and its annexes, identifying exporter/importer roles, contacts, actual transfers, processing/data-subject categories, security measures, competent supervisory authority, and authorized Sub-processors. Contact legal@openobserve.ai to complete the package. Customer must not initiate a restricted transfer requiring an incomplete mechanism.
For EU transfers, use the applicable Module Two (controller to processor) or Module Three (processor to processor) of Commission Implementing Decision (EU) 2021/914 according to actual roles and legal applicability. For UK transfers, complete the approved UK Addendum to those SCCs or another valid UK mechanism; for Swiss transfers, make the modifications required under Swiss law. Mandatory clauses prevail over conflicting commercial provisions. These references do not by themselves assert that incomplete annexes are effective, that every transfer is restricted, or that consent or customer region selection substitutes for required safeguards.