OttoLegal

Data Processing Agreement

Draft — must be reviewed by a qualified lawyer in the EU before publishing.

Words in [SQUARE BRACKETS] are placeholders to fill in. Notes marked Review, Decision, Verify or Engineering are for the reviewing lawyer and for Max; remove every one of them before publishing.

Version: Draft 0.1 · 30 September 2026 · In force from [EFFECTIVE DATE]

This Data Processing Agreement ("DPA") is part of the contract between [COMPANY LEGAL NAME], [REGISTERED ADDRESS], [CHAMBER OF COMMERCE / CRO NUMBER] ("Otto", the processor) and the business that uses Otto ("the Client", the controller) under Otto's Terms of Service. It meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). The Client accepts it together with the Terms; no separate signature is needed. A signed copy is available on request from [PRIVACY EMAIL].

1. Roles and scope

1.1 This DPA applies to personal data that Otto processes on the Client's behalf while providing Otto: the personal data in the Client's website, materials, social and ad accounts, and in the content Otto makes for the Client ("Client Personal Data"). Annex I describes it.

1.2 For Client Personal Data, the Client is the controller and Otto the processor. If the Client is itself a processor for someone else (for example an agency acting for its own clients), Otto is the Client's sub-processor, and the Client confirms that its own controller has authorised this.

1.3 Otto is a controller, not a processor, for the data it processes for its own purposes: the Client's account and sign-in data, billing, security and audit logs, statistics about its own website, and combined usage statistics that identify neither the Client nor any person. Otto's Privacy Policy covers that data. Review: check these controller/processor edges, in particular sign-in and approval data, and the use of combined, de-identified statistics to improve Otto.

1.4 GDPR terms used here (personal data, processing, controller, processor, data subject, personal data breach, supervisory authority) have their GDPR meaning.

2. Instructions

2.1 Otto processes Client Personal Data only on the Client's documented instructions. The instructions are: the Terms and this DPA; the Client's setup answers, settings, approvals and requests in the Otto app, by e-mail or in Telegram; and any other written instruction the Client gives that fits the service.

2.2 Otto tells the Client straight away if, in its opinion, an instruction breaks the GDPR or other data protection law, and may pause that instruction until the Client confirms or changes it.

2.3 Otto may process Client Personal Data other than on instructions only where EU or member-state law requires it, and then tells the Client first unless that law forbids it.

3. Confidentiality

Everyone at Otto who can access Client Personal Data is bound by confidentiality, by contract or by law, and has access only as far as their work needs it.

4. Security

4.1 Otto takes the technical and organisational measures in Annex II. They take into account the state of the art, the cost, the nature of the processing and the risks to people.

4.2 Otto may change the measures, as long as the overall level of protection does not go down.

5. Sub-processors

5.1 The Client gives Otto general authorisation to use sub-processors. The current list is in Annex III and on Otto's Sub-processors page.

5.2 Otto tells the Client at least 30 days before adding or replacing a sub-processor, by e-mail to the account address and by updating that page. The Client may object within that time on reasonable data-protection grounds. If Otto cannot meet the objection, the Client may end the affected part of the service before the change, and Otto refunds fees paid for the time after the end.

5.3 Otto puts each sub-processor under a written contract with data protection obligations at least as strict as this DPA, and remains responsible to the Client for its sub-processors' performance.

6. Transfers outside the EU

6.1 Otto stores Client Personal Data on servers in Germany. Some sub-processors process it outside the European Economic Area (Annex III). Otto makes such transfers only with a valid safeguard under Chapter V GDPR: an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or the EU standard contractual clauses (Commission Decision 2021/914, module 3 between Otto and its sub-processor), together with a transfer impact assessment and extra measures where needed.

6.2 Review: if the contracting Otto entity is established outside the EU (for example in Israel, which has an EU adequacy decision), confirm how the Client-to-Otto transfer is covered and whether module 2 or 4 clauses are needed anywhere.

7. Helping the Client

7.1 Data subject requests. Otto passes any request it receives from a data subject about Client Personal Data to the Client within five business days and does not answer it itself unless the Client asks. Otto helps the Client answer requests for access, correction, deletion, restriction, portability and objection, as far as the service allows.

7.2 Other obligations. Otto helps the Client with security, breach notification, data protection impact assessments and prior consultation of a supervisory authority (Articles 32 to 36 GDPR), taking into account the information Otto has. Help beyond what the service normally provides may be charged at reasonable cost, agreed in advance.

8. Personal data breaches

8.1 Otto informs the Client without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data.

8.2 The notice describes, as far as known then: what happened, the categories and approximate number of people and records concerned, the likely consequences, what Otto has done or proposes to do, and a contact person. Otto sends more information as it learns it.

8.3 Otto records every breach, its effects and the measures taken. Telling the Client about a breach is not an admission of fault.

9. End of the service

9.1 While the plan is active, and for 90 days after it ends, the Client can ask for an export of its data (Terms, section 17).

9.2 90 days after the plan ends, Otto deletes Client Personal Data from its live systems. It leaves Otto's encrypted backups as they roll over, within about 8 weeks after that. Where EU or member-state law requires Otto to keep some data, Otto keeps only that data, only for as long as required, and keeps it confidential. On request, Otto confirms the deletion in writing.

10. Audits and information

10.1 Otto makes available the information needed to show that it meets Article 28 GDPR, starting with this DPA, its annexes and answers to reasonable security questionnaires.

10.2 If that is not enough, the Client (or an independent auditor bound by confidentiality) may audit Otto once a year, with at least 30 days' notice, during business hours, without disrupting the service, and at the Client's cost. Audits after a breach, or ordered by a supervisory authority, are not limited to once a year.

11. Liability and term

11.1 The limits of liability in the Terms apply to this DPA, to the extent the law allows. Review: whether data protection claims should share the general cap.

11.2 This DPA lasts as long as Otto processes Client Personal Data. If the Terms and this DPA conflict about personal data, this DPA prevails. It is governed by the same law, and disputes go to the same court, as the Terms.

Annex I — The processing

Subject and natureReading the Client's public website; storing and structuring the Client's brand information; generating posts, captions, images, videos and ads with AI; sending drafts to the Client for approval; publishing approved content and running approved campaigns in the Client's own accounts; reading performance results; reporting; deletion.
PurposeProviding Otto's marketing service to the Client under the Terms.
DurationWhile the Client's plan is active, plus 90 days, plus up to about 8 weeks in encrypted backups (section 9).
FrequencyContinuous.
Who the data is about(a) the Client's customers and prospects whose words or names appear on the Client's website (reviews, testimonials, customer quotes); (b) people shown or named in the Client's website and materials (for example staff on a team page); (c) creators who appear in videos for the Client; (d) people who engage with the Client's posts and ads, only in the form of totals; (e) people who appear in competitors' public ads that Otto collects for the Client.
Kinds of dataNames or initials and the text of reviews and quotes; photos and footage of people; creators' names, likeness, voice and consent records; aggregate post and ad results (reach, clicks, likes, comment counts, leads and purchases as numbers); search terms that triggered the Client's Google ads; public ads of competitors (text and images).
What Otto does not do todayOtto does not upload customer lists or build custom audiences (ad targeting uses location and age only); it does not download lead-form answers (they stay in the Client's Meta account); it does not read the text of comments or messages. If any of this changes, Otto updates this annex and tells the Client first.
Special categoriesNot intended. Reviews on the websites of health, clinic or wellbeing businesses can reveal health information. The Client decides which reviews may be used; for health brands Otto's rules block posts that single out a condition. Review: is a verbatim health-related review used in an ad a special-category processing, and what does that require of the Client?
Sub-processorsAnnex III.

Annex II — Technical and organisational measures

These are the measures Otto takes today, as built into its server and software. Review: items marked Engineering are not in place yet; each must be done, or its sentence removed, before publishing.

Where the data is

Network

Who can get in

Keeping clients apart

Software and changes

Encryption and backups

Monitoring and logs

People and process

Annex III — Sub-processors

The current list, which Otto keeps up to date on its Sub-processors page under section 5.

Sub-processorWhat it does for OttoPersonal data it receivesWhereTransfer safeguard
Hetzner Online GmbH, GermanyHosts the Otto server; daily server snapshots; encrypted off-site backups (Storage Box)Everything Otto stores; backups are encrypted before they leave the serverGermany (Nuremberg and Falkenstein data centres) Verify: Storage Box locationInside the EU
Cloudflare, Inc., USADNS, encrypted connections, firewall and rate limits, delivery of our pages, our team's sign-in to the owner console (Cloudflare Access)Connection data of every visit, including IP addresses; our team's sign-in e-mail addressesGlobal network; company in the USAEU–US Data Privacy Framework; standard contractual clauses in Cloudflare's DPA
Google Ireland Limited, Ireland (with Google LLC, USA)Authentication: Sign in with Google for the Otto appThe sign-in happens on Google's page; Google tells Otto the user's e-mail address, name and Google account IDEU and USAEU–US Data Privacy Framework; standard contractual clauses Review: Google acts as an independent controller for the user's Google account
Anthropic, PBC, USAClaude AI models: strategy, captions, ad texts, briefs, summariesBrand profile, website text, the client's answers and instructions, drafts, performance summaries; this can include names quoted from the client's websiteUSAStandard contractual clauses Verify: DPF status, no training on API data, retention period
Leonardo Interactive Pty Ltd (Leonardo.ai), AustraliaImage generation as a fallback when Higgsfield is unavailable, including OpenAI's GPT Image models, to which Leonardo passes the promptImage prompts (descriptions of the brand, product and scene); reference images where usedVerify: processing location; OpenAI in the USAStandard contractual clauses Verify: generations private and not used for training
ElevenLabs, USA Verify: contracting entitySynthetic voice-over for reelsThe voice-over scriptUSA Verify: EU data residency optionVerify: DPF or standard contractual clauses
Higgsfield AI, USA Verify: contracting entityImage generation for posts, reel scenes and ads (OpenAI's GPT Image 2, to which Higgsfield passes the prompt); voice-over and video generation for some reelsImage prompts (descriptions of the brand, product and scene); reference images where used (e.g. the client's product photo); scripts and visual promptsUSA; OpenAI in the USA VerifyVerify: DPA with standard contractual clauses; generations private and not used for training
Telegram Verify: contracting entity, only for clients who choose TelegramDelivers approval cards, reports and alertsPost previews and captions, report text, the client's Telegram user IDVerifyReview: Telegram offers no data processing agreement; treat it as a channel the client chooses, or offer it outside the EU only
[EMAIL PROVIDER], from the launch of e-mail approvalsSends approval and report e-mailsRecipient e-mail address, message contentVerifyVerify
Stripe Payments Europe, Ltd., Ireland (with Stripe, Inc., USA)Payment processing for Otto's own subscriptions: the payment form inside Otto's Billing page, subscriptions, invoices and receipts, VAT calculation (Stripe Tax)Billing contacts of clients (name, e-mail, billing address, VAT ID), plan and payment history; card and bank details go to Stripe directly and never to OttoEU and USAEU–US Data Privacy Framework; standard contractual clauses in Stripe's DPA Review: Stripe is a processor for billing, invoicing and tax, and an independent controller for payment processing, fraud prevention and its legal duties (Stripe's DPA and privacy policy)

Back to top