Status: This page is a draft template for business customers. It becomes effective only when (a) Customer and OnOffMyPC execute it in writing or by an agreed electronic acceptance flow, or (b) it is incorporated into a signed Master Service Agreement for paid B2B use. It is not a ready-to-sign contract by itself and should be reviewed by counsel before execution. Consumer self-serve accounts are governed by the Privacy Policy and Terms of Service, not this DPA, unless separately agreed.

1. Parties and roles

“OnOffMyPC” / “Processor” means the Operator of the OnOffMyPC Service. “Customer” / “Controller” means the business entity that enters an MSA or other written B2B arrangement and determines the purposes of processing Personal Data submitted to the Service.

Where OnOffMyPC processes Personal Data on Customer’s documented instructions in providing the Service, OnOffMyPC acts as Processor (or sub-processor to Customer’s customers, if applicable). Where OnOffMyPC processes data for its own account administration, security, billing, or product improvement as described in the Privacy Policy, it acts as an independent controller for that limited processing.

2. Subject matter and nature of processing

3. Instructions

Processor will process Personal Data only on Customer’s documented instructions (including configuration of the Service and this DPA/MSA), unless required by law. Customer is responsible for the lawfulness of its instructions and for notices/consents to data subjects.

4. Confidentiality and personnel

Processor ensures persons authorized to process Personal Data are bound by confidentiality and receive appropriate instructions.

5. Security measures

Processor implements technical and organizational measures appropriate to the risk, including:

Customer acknowledges that the Service is not designed for special-category data or safety-critical control, and Customer must not submit such data unless expressly agreed in writing.

6. Subprocessors

Customer authorizes Processor to use the following categories/providers:

Processor will post material subprocessor changes on this page or notify Customer’s designated contact with reasonable advance notice where practicable. Customer may object on reasonable data-protection grounds; if unresolved, Customer may terminate the affected Service as its sole remedy for the objection.

7. International transfers

Processing may occur on globally distributed infrastructure. Processor will ensure transfers rely on appropriate mechanisms used by Processor and its subprocessors (for example standard contractual clauses where required).

8. Data subject rights

Taking into account the nature of processing, Processor will provide reasonable assistance to Customer in responding to data subject requests. End users of self-serve accounts may also contact [email protected] as described in the Privacy Policy.

9. Breach notification

Processor will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.

10. Deletion and return

Upon termination of the B2B Service, or upon Customer’s written request, Processor will delete or return Customer Personal Data from active systems within a commercially reasonable period, subject to retention required by law, security backups that roll off on their normal schedule, and Polar’s retention of transaction/tax records. Account self-delete flows include a grace period before purge, as described in the Privacy Policy.

11. Audits

Upon reasonable written notice, no more than once per twelve months (unless a regulator requires otherwise), Processor will make available information reasonably necessary to demonstrate compliance with this DPA (for example security summaries or questionnaire responses). On-site audits are not offered by default; any deeper review requires mutual written agreement, confidentiality, and Customer bearing reasonable costs unless a material non-compliance is found.

12. Liability

Liability under this DPA is subject to the limitations and exclusions in the governing MSA, or if none, the Terms of Service, except where prohibited by applicable data-protection law.

13. Contact

Privacy / DPA inquiries: [email protected]. Commercial / MSA: [email protected].