This Data Processing Agreement ("DPA") forms part of the Terms of Service at https://omnistra.io/terms-of-service between Omnistra (Private) Limited, Flat: A1, Chandrawdip Tower-4, Mandy Dental Road 10, Baroikhali, Hazaribag Park, Dhaka, Bangladesh ("Omnistra" or the "Processor") and the Customer (the "Controller"). It applies whenever Omnistra processes personal data on the Customer's behalf in providing the Service, and reflects the requirements of Article 28 of the GDPR, the UK GDPR, the Bangladesh Personal Data Protection Act 2026, and equivalent laws.
1. Definitions
Terms such as "personal data," "processing," "data subject," "controller," "processor," "personal data breach," and "supervisory authority" have the meanings given in the GDPR or, for data subjects in Bangladesh, the equivalent meanings under the PDPA (where "controller" reads as "data fiduciary"). "Customer Personal Data" means personal data the Customer submits to the Service or that flows through AI Agents on the Customer's behalf.
2. Roles and Scope
2.1 Roles
The Customer is the controller of Customer Personal Data; Omnistra is the processor. Where the Customer is itself a processor for a third party, the Customer warrants it has authority to engage Omnistra as a sub-processor.
2.2 Details of processing
- Subject matter: provision of the Omnistra Autonomous Commerce platform.
- Duration: the term of the Terms of Service plus the deletion period in Section 9.
- Nature and purpose: hosting; routing, generating, transcribing, and recording conversations across voice, SMS, WhatsApp, Messenger, Instagram, and web chat; order and delivery synchronisation; analytics and reporting.
- Categories of data subjects: the Customer's End Users (as defined in the Terms of Service) and prospects; the Customer's staff who use the Service.
- Categories of data: name, phone number, email, social handles and platform IDs, delivery address, order history, payment status (not card numbers), conversation content and recordings, delivery outcomes.
2.3 Scope carve-out: COD Buyer Reliability Score
Where the Customer enables the COD Buyer Reliability Score, Omnistra processes the pooled delivery-outcome and order-event records described in Section 6 of the Terms of Service as an independent controller, on the terms set out there and in the Privacy Policy, and that processing is outside the scope of this DPA. All other processing of Customer Personal Data, including the delivery-outcome data Omnistra processes to provide the Service to the Customer itself, remains processor activity under this DPA.
3. Processor Obligations
Omnistra will:
- (a) process Customer Personal Data only on the Customer's documented instructions, including as configured in the Service and as set out in the Terms of Service, unless required otherwise by law, in which case Omnistra will inform the Customer unless the law prohibits it;
- (b) inform the Customer if, in Omnistra's opinion, an instruction infringes applicable data protection law, and Omnistra may suspend execution of that instruction until the Customer confirms or modifies it in writing; Omnistra is not liable for the consequences of a suspension under this clause;
- (c) ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations;
- (d) implement the technical and organisational measures in Annex 1;
- (e) respect the sub-processing conditions in Section 5;
- (f) taking into account the nature of processing, assist the Customer with appropriate technical and organisational measures in fulfilling data subject rights requests;
- (g) assist the Customer with security, breach notification, data protection impact assessments, and prior consultations, taking into account the information available to Omnistra;
- (h) delete or return Customer Personal Data at the end of the engagement as set out in Section 9; and
- (i) make available information necessary to demonstrate compliance with this DPA and allow audits as set out in Section 8.
4. Customer Obligations
The Customer warrants that: (a) it has provided all notices and obtained all consents and lawful bases required for Omnistra to process Customer Personal Data as contemplated by the Terms of Service, including for automated calls, call recording, and messaging; (b) its instructions comply with applicable law; and (c) it will not submit sensitive or special-category data except as permitted by the Acceptable Use Policy.
5. Sub-processors
5.2 Sub-processor list and objections
The current sub-processor list is available at omnistra.io/subprocessors or on request to privacy@omnistra.io. Omnistra will give at least 14 days' notice of any new sub-processor (by updating the list and notifying subscribed Customers), during which the Customer may object on reasonable data-protection grounds. If the objection cannot be resolved, the Customer may terminate the affected Service with a pro-rata refund of prepaid fees.
5.3 Sub-processor obligations
Omnistra imposes data-protection obligations on each sub-processor materially equivalent to this DPA and remains liable for its sub-processors' performance.
6. International Transfers
6.1 Where we process
Omnistra processes data primarily from Bangladesh and through sub-processors in other jurisdictions, including the United States and the European Union.
6.2 Standard Contractual Clauses
For transfers of personal data subject to the GDPR or UK GDPR to countries without an adequacy decision (including Bangladesh), the parties incorporate the EU Standard Contractual Clauses (Decision (EU) 2021/914): Module Two applies where the Customer is a controller and Module Three where the Customer is a processor. The parties select: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorisation, 14 days' notice); Clause 11 optional redress language not included; Clause 17 Option 1 with the law of Ireland; Clause 18 the courts of Ireland. Annex I.A and I.B are completed by Section 2.2 of this DPA and the parties' account details; Annex I.C: the supervisory authority of the EU member state where the Customer is established or, where none, the Irish Data Protection Commission; Annex II is completed by Annex 1 to this DPA; Annex III is the sub-processor list at omnistra.io/subprocessors. For UK transfers, the UK International Data Transfer Addendum applies with its tables completed by the same information and with neither party able to end the Addendum on ICO changes except as the Addendum allows. The SCCs and Addendum are deemed executed on acceptance of this DPA and prevail over conflicting terms.
6.3 Bangladesh transfers
For personal data of data subjects in Bangladesh, Omnistra transfers data outside Bangladesh only as permitted by the PDPA and stores data in Bangladesh where the PDPA's residency rules require it.
6.4 CCPA
Where Customer Personal Data includes personal information subject to the CCPA/CPRA, Omnistra acts as the Customer's service provider. Omnistra will not sell or share that personal information, will not retain, use, or disclose it for any purpose other than providing the Service or as the CCPA permits, will not combine it with personal information from other sources except as the CCPA permits, and certifies that it understands these restrictions. Omnistra will notify the Customer if it can no longer meet its obligations under the CCPA.
7. Personal Data Breach
Omnistra will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to Omnistra about the nature of the breach, the categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken or proposed. Omnistra will not notify data subjects or authorities on the Customer's behalf unless required by law or agreed in writing. Where the Bangladesh PDPA or the National Data Governance Authority imposes notification, registration, or cooperation duties directly on Omnistra as processor, Omnistra will comply and will coordinate the content and timing of any regulator notification with the Customer to the extent the law allows.
8. Audits
Omnistra will make available on request documentation reasonably necessary to demonstrate compliance with this DPA (including summaries of third-party audits or certifications where available). Where that is insufficient, the Customer may conduct an audit, at most once per 12 months, on at least 30 days' notice, during business hours, under confidentiality, at the Customer's cost, and without access to other customers' data. Audits do not extend to sub-processor premises (Omnistra will instead pass through available third-party audit reports for sub-processors), to other customers' data, or to any access that would compromise the security or confidentiality of the Service, and any third-party auditor must not be a competitor of Omnistra and must sign a confidentiality agreement.
9. Deletion and Return
On termination or expiry of the Terms of Service, the Customer may export Customer Personal Data for 30 days. After that period, Omnistra deletes Customer Personal Data within 90 days, except where retention is required by law, in which case the data remains protected under this DPA until deleted. Deletion requests from data subjects during the term are handled on the timelines in the Privacy Policy; this Section governs deletion after termination or expiry.
10. Liability and Order of Precedence
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where applicable data protection law does not permit such limits. If this DPA conflicts with the Terms of Service, this DPA prevails for data protection matters; the SCCs prevail over both where they apply.
Nothing in this DPA limits the rights of data subjects. As between the parties, the Customer will indemnify Omnistra against claims by data subjects or regulators (including under Article 82 of the GDPR or the compensation and penalty provisions of the PDPA) to the extent the claim arises from the Customer's instructions, the Customer's breach of Section 4, or the Customer's failure to establish a lawful basis or give required notices. Omnistra remains responsible for claims arising from its breach of this DPA, subject to the Terms of Service limits where the law permits.
Annex 1: Technical and Organisational Measures
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest.
- Role-based access control on the principle of least privilege; authentication required for all staff access to production systems; access logged.
- Logical separation of each Customer's data.
- Continuous monitoring for security events; documented incident-response procedures.
- Vendor security review of sub-processors before engagement.
- Regular backups with routine purge schedules; recovery procedures tested.
- Personnel confidentiality undertakings and security training.
- Secure software development practices, including code review and dependency scanning.
Contact
Omnistra (Private) Limited · Flat: A1, Chandrawdip Tower-4, Mandy Dental Road 10, Baroikhali, Hazaribag Park, Dhaka, Bangladesh 1209 · privacy@omnistra.io