Data Processing Addendum
Draft template — July 2026
Status: This page is a draft template for business customers. It becomes effective only when (a) Customer and OnOffMyPC execute it in writing or by an agreed electronic acceptance flow, or (b) it is incorporated into a signed Master Service Agreement for paid B2B use. It is not a ready-to-sign contract by itself and should be reviewed by counsel before execution. Consumer self-serve accounts are governed by the Privacy Policy and Terms of Service, not this DPA, unless separately agreed.
1. Parties and roles
“OnOffMyPC” / “Processor” means the Operator of the OnOffMyPC Service. “Customer” / “Controller” means the business entity that enters an MSA or other written B2B arrangement and determines the purposes of processing Personal Data submitted to the Service.
Where OnOffMyPC processes Personal Data on Customer’s documented instructions in providing the Service, OnOffMyPC acts as Processor (or sub-processor to Customer’s customers, if applicable). Where OnOffMyPC processes data for its own account administration, security, billing, or product improvement as described in the Privacy Policy, it acts as an independent controller for that limited processing.
2. Subject matter and nature of processing
- Subject matter: hosting and operation of remote PC power-control accounts, devices, commands, telemetry, and related support
- Duration: for the term of the MSA/Service plus deletion/return periods below
- Nature: collection, storage, transmission, display, deletion
- Purpose: providing the Service to Customer as agreed
- Types of Personal Data: account emails; authentication identifiers; device names and telemetry (power state, environmental sensors, Wi-Fi signal); command history; push tokens if enabled; billing identifiers if paid; IP addresses in security logs
- Data subjects: Customer’s authorized users and, if Customer permits, other individuals whose data Customer chooses to place in the Service
3. Instructions
Processor will process Personal Data only on Customer’s documented instructions (including configuration of the Service and this DPA/MSA), unless required by law. Customer is responsible for the lawfulness of its instructions and for notices/consents to data subjects.
4. Confidentiality and personnel
Processor ensures persons authorized to process Personal Data are bound by confidentiality and receive appropriate instructions.
5. Security measures
Processor implements technical and organizational measures appropriate to the risk, including:
- Transport encryption (TLS) for Service endpoints
- Hashed passwords for email/password accounts; session-based authentication
- Access controls for production systems and administrative interfaces
- Rate limiting and security audit logging for abuse/security events
- Hosted infrastructure on Cloudflare (Workers, D1, Durable Objects, Pages)
- Retention limits for telemetry, commands, and audit logs as described in the Privacy Policy
Customer acknowledges that the Service is not designed for special-category data or safety-critical control, and Customer must not submit such data unless expressly agreed in writing.
6. Subprocessors
Customer authorizes Processor to use the following categories/providers:
- Cloudflare — hosting, Workers, D1, Durable Objects, Pages, Email Routing
- Resend — transactional email
- Polar — payments/merchant of record when Customer purchases through Polar
- Google FCM / Apple APNs — push notifications when Customer’s users enable them
- Google / Apple / Microsoft — identity providers when users choose social sign-in
Processor will post material subprocessor changes on this page or notify Customer’s designated contact with reasonable advance notice where practicable. Customer may object on reasonable data-protection grounds; if unresolved, Customer may terminate the affected Service as its sole remedy for the objection.
7. International transfers
Processing may occur on globally distributed infrastructure. Processor will ensure transfers rely on appropriate mechanisms used by Processor and its subprocessors (for example standard contractual clauses where required).
8. Data subject rights
Taking into account the nature of processing, Processor will provide reasonable assistance to Customer in responding to data subject requests. End users of self-serve accounts may also contact [email protected] as described in the Privacy Policy.
9. Breach notification
Processor will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.
10. Deletion and return
Upon termination of the B2B Service, or upon Customer’s written request, Processor will delete or return Customer Personal Data from active systems within a commercially reasonable period, subject to retention required by law, security backups that roll off on their normal schedule, and Polar’s retention of transaction/tax records. Account self-delete flows include a grace period before purge, as described in the Privacy Policy.
11. Audits
Upon reasonable written notice, no more than once per twelve months (unless a regulator requires otherwise), Processor will make available information reasonably necessary to demonstrate compliance with this DPA (for example security summaries or questionnaire responses). On-site audits are not offered by default; any deeper review requires mutual written agreement, confidentiality, and Customer bearing reasonable costs unless a material non-compliance is found.
12. Liability
Liability under this DPA is subject to the limitations and exclusions in the governing MSA, or if none, the Terms of Service, except where prohibited by applicable data-protection law.
13. Contact
Privacy / DPA inquiries: [email protected]. Commercial / MSA: [email protected].