Data Processing Agreement (DPA)
Last updated: September 20, 2026
This document is provided for information and will be signed on request. It has not yet been reviewed by a lawyer.
1. Parties
Processor: Organize IT SRL, Rue du Mont-Lassy 54, 1380 Lasne, Belgium, company number and VAT BE 0650.555.046, publisher of the UpBoard.ai platform. Contact: info@upboard.ai.
Controller: the customer, meaning the company holding the UpBoard.ai account, for the personal data it processes through the service, in particular data from its ERP.
This agreement supplements the terms of sale and implements Article 28 of the GDPR (EU Regulation 2016/679). For the data we process for our own purposes (sign-up, billing, website audience measurement) we act as a controller, and the privacy policy applies instead.
2. Subject matter and duration
Subject matter: providing the UpBoard.ai platform, which queries the customer's Odoo ERP, produces analyses, scores and alerts, and proposes actions the customer approves.
Duration: processing lasts as long as the customer's trial or subscription. It ends when the account closes, and the data is deleted within the period set out in article 9.
3. Nature and purpose of the processing
- Read-only querying of the customer's ERP through Odoo's standard JSON-RPC API. We do not copy the database: data is read at the moment of analysis.
- Analysis of that data by specialized agents, including 92 automated data quality checks, producing alerts, scores and recommendations.
- Retention of analysis results and of the agents' contextual memory, so later analyses take the customer's context into account.
- Where applicable, writing to the ERP, only after an explicit approval by one of the customer's users (human validation is mandatory for any creation, update or deletion).
- Technical support and incident diagnosis, at the customer's request.
We process this data only on the customer's documented instructions. Those instructions consist of this agreement, the terms of sale, the settings the customer defines in the platform, and the rights the customer grants to the dedicated Odoo user. Customer data is never used to train any artificial intelligence model.
4. Categories of data and of data subjects
Data subjects: the customer's users and staff, and the individuals whose details appear in its ERP (customer and supplier contacts, ticket requesters, salespeople).
Categories of ERP data: names and business contact details, references and amounts of business documents (quotes, orders, invoices, payments, stock moves), content and history of support tickets, point of sale session data and seller identity, VAT numbers and addresses of third parties.
Categories of account data: name, business email address, company, hashed password, conversations with the agents, preferences, usage metrics, technical logs, and encrypted ERP connection credentials.
The service is not designed to process special categories of data within the meaning of Article 9 GDPR. The customer refrains from bringing such data into the analysed scope.
5. Processor obligations
5.1 Documented instructions
We process the data only on the customer's documented instructions, including for the transfers outside the European Union described in article 10. If we consider that an instruction infringes the GDPR or another data protection rule, we inform the customer without delay.
5.2 Confidentiality
Only the people who need it have access to the data, and they are bound by confidentiality. Organize IT SRL is a small company: the list of authorised people is short and is shared with the customer on request.
5.3 Security measures
The technical and organisational measures in place are described in detail on the Security page, which forms part of this agreement. In summary:
- end-to-end TLS encryption, including to the ERP when its URL uses https;
- ERP credentials encrypted at rest (Fernet), with a key rotation mechanism;
- passwords hashed (bcrypt), never stored in clear text;
- access through short sessions and roles (owner, admin, member); two-factor authentication by email available, and enforceable across the organisation by an admin;
- strict data isolation per customer, checked automatically in continuous integration;
- read-only access by default; every write to the ERP goes through human validation;
- sensitive Odoo models refused (system parameters, mail servers, user API keys) and secret fields masked;
- emails, phone numbers, IBANs and national ID numbers masked in the application logs;
- daily backups encrypted (AES-256) before they leave the server;
- access and action logging.
UpBoard.ai holds neither SOC 2 nor ISO 27001 certification to date. Our hosting provider, Infomaniak, is ISO 27001 certified. An internal security audit was carried out in June 2026 and its fixes are deployed in production.
5.4 Sub-processors
The customer authorises the sub-processors listed in article 7. We impose on them, by contract, data protection obligations equivalent to those in this agreement, and we remain liable to the customer for their failures.
Any significant change to that list (an addition or a replacement) is announced to the customer by email before it takes effect. A customer who objects may cancel the subscription at no cost before the change takes effect.
5.5 Assistance with data subject rights
When a data subject contacts us while belonging to the customer's scope, we refer them to the customer rather than handling the request ourselves. We help the customer answer requests for access, rectification, erasure, restriction, objection and portability, taking the nature of the processing into account: the customer has its data in the platform, and for anything not reachable there we answer within a reasonable time, at no cost for normal volumes.
5.6 Personal data breach notification
We notify the customer of any personal data breach affecting it without undue delay after becoming aware of it, by email to the account holder's address. The notification describes the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, and the measures taken or proposed. We assist the customer with its own notifications to the supervisory authority and to data subjects.
5.7 Assistance with compliance
We help the customer, as far as reasonable and given the information available to us, to meet its own obligations on security, breach notification and data protection impact assessments.
6. Audit and information
On written request, we make available to the customer the information needed to demonstrate compliance with this agreement: a description of the security measures, the list of sub-processors, where the data is located, and answers to a security questionnaire. Such requests are handled within a reasonable time, up to once a year, and after a security incident or at a supervisory authority's request.
An on-site audit remains possible, by appointment agreed in advance and at the customer's expense, without disrupting the service and while protecting other customers' confidentiality. For the infrastructure we pass on the material published by our hosting provider, including its ISO 27001 certification, rather than producing new evidence.
7. List of sub-processors
The current list, with each provider, its location and its purpose, is published in section 5 of the privacy policy and forms part of this agreement. It currently covers hosting (Infomaniak, Switzerland), artificial intelligence models (Anthropic and OpenAI, United States), payment (Stripe, United States), email delivery (Brevo, France), error tracking (Sentry, United States), the off-site copy of backups (Google Drive, United States, encrypted before upload), website audience measurement (Google Ireland Limited) and bot protection for the forms (Cloudflare, United States).
8. Location and international transfers
The platform and its database are hosted in Switzerland, with Infomaniak, in the Geneva area. Switzerland benefits from a European Commission adequacy decision, so this is not a transfer requiring additional safeguards.
Analyses are produced by Anthropic's models, and the agents' memory is indexed by OpenAI; both involve a transfer to the United States. The same applies to payment (Stripe), error tracking (Sentry) and the off-site copy of backups (Google Drive, encrypted before upload, with no key handed over). These transfers are governed by the Standard Contractual Clauses approved by the European Commission. Transactional emails go through Brevo, in France.
9. Deletion or return at the end of the contract
The customer can export its data from the platform at any time and ask for its deletion in writing at info@upboard.ai.
When the subscription ends, or when the trial expires without a subscription, all account data (users, ERP connections, conversations, analysis results, agent memory) is deleted 90 days later, unless the customer subscribed in the meantime. A sign-up that was never completed is deleted 90 days after it was created. These deletions are carried out by a daily automated job, not by hand.
Deleted data then disappears from our encrypted backups as they rotate. Billing data the law requires to be kept is kept by Stripe, our payment provider, not by us.
10. Miscellaneous
In the event of a conflict between this agreement and the terms of sale, this agreement prevails for everything concerning the processing of personal data. It is governed by Belgian law, and the competent courts are those of Brussels. Changes to this agreement are announced like changes to the terms of sale: by email, at least 30 days before they take effect.
The competent supervisory authority is the Belgian Data Protection Authority (www.autoriteprotectiondonnees.be).
11. Signature
To receive a signed copy of this document, write to info@upboard.ai with the signatory's company name, address and company number.