Olventa

Data Processing Agreement (DPA)

Last updated: 29 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and Olfigton Technologies Ltd (“Processor”) for the Olventa service, and applies to the processing of personal data on the Controller’s behalf under UK GDPR/EU GDPR.

This document is an informational template and does not constitute legal advice. We recommend having it reviewed by qualified legal counsel before you rely on it.

1. Roles and scope

The Controller determines the purposes and means of processing Customer Data; the Processor processes it only on documented instructions from the Controller, including as set out in this DPA and the Agreement.

2. Details of processing (Annex)

  • Subject matter: provision of the Olventa service.
  • Duration: for the term of the Agreement.
  • Nature and purpose: hosting, storage and processing of business records to deliver CRM and pre-accounting features.
  • Data subjects: the Controller’s customers, suppliers, employees and contacts.
  • Data types: names, contact details, financial/transaction records, and other data the Controller chooses to enter.

3. Processor obligations

  • Process only on documented instructions.
  • Ensure persons authorised to process are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Assist the Controller with data subject requests and compliance obligations.

4. Sub-processors

The Controller authorises the Processor to engage sub-processors, currently: Supabase (hosting/database), Stripe (payments), Google (analytics), Microsoft (Clarity), PostHog (product analytics). The Processor remains responsible for their performance and will inform the Controller of intended changes, allowing objection.

5. Data subject rights

Taking into account the nature of processing, the Processor will assist the Controller by appropriate measures to respond to data subject requests.

6. Security

The Processor implements measures appropriate to the risk, including encryption in transit, access control, tenant isolation (row-level security), and computed (non-stored) balances to reduce sensitive derived data.

7. Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information to help the Controller meet its obligations.

8. International transfers

Where personal data is transferred outside the UK/EEA, the parties rely on appropriate safeguards (UK IDTA / EU Standard Contractual Clauses).

9. Return or deletion

On termination, the Processor will, at the Controller’s choice, delete or return Customer Data, save where retention is required by law.

10. Audit

The Processor will make available information necessary to demonstrate compliance and allow for reasonable audits by the Controller or its mandated auditor.

11. Contact

Processor: Olfigton Technologies Ltd, United Kingdom — contact@olfigtontech.com.