Incorporated where and to the extent required by applicable data protection law
OMIS Master Subscription Agreement, incorporated where and to the extent required by applicable data protection law
1.1 This Data Processing Addendum ("DPA") is incorporated into the OMIS Master Subscription Agreement (the "Agreement") under Section 12.12 of the Agreement. It applies only where, and only to the extent that, applicable data protection law ("Data Protection Law") requires contractual terms between a controller and a processor, or between parties in analogous roles however denominated, including a "business" and a "service provider" or "contractor" under California law, for Provider's processing of Personal Data on Customer's behalf under the Agreement. Where no Data Protection Law imposes such a requirement, this DPA does not apply and Section 12 of the Agreement alone governs.¶
1.2 Where this DPA applies, it controls over Section 12 of the Agreement to the minimum extent required by the applicable Data Protection Law. In all other respects the Agreement controls, and nothing in this DPA enlarges Provider's obligations, or Customer's rights, beyond what that law requires. Capitalized terms not defined in this DPA have the meanings given in the Agreement.¶
1.3 This DPA remains in effect for so long as Provider processes or retains Personal Data on Customer's behalf, including during any post-termination period of export, legally required retention, or backup rotation under Sections 6.12, 6.13, and 12.9 of the Agreement and Schedule Z, and terminates when that processing and retention cease. It terminates earlier only if Data Protection Law ceases to apply to the processing.¶
2.1 Customer is the controller and Provider is the processor of the Personal Data, and where Data Protection Law uses other terms, Customer acts in the analogous role of "business" and Provider in the analogous role of "service provider" or "contractor," including under California law, in each case with respect to the Personal Data processed under the Agreement. Each Party will comply with the Data Protection Law applicable to it in that role.¶
| Item | Description |
|---|---|
| Subject matter and duration | Provision of the Services for the term of the Agreement, and thereafter for so long as Provider processes or retains Personal Data during any period of post-termination export, legally required retention, or backup rotation, as provided in Section 1.3 |
| Nature and purpose | Hosting, storage, display, organization, support, and backup of Customer Data as necessary to provide, secure, and support the Services |
| Categories of data subjects | Customer's Authorized Users; property buyers; closing attorneys; builder, subdivision, and billing contacts |
| Categories of Personal Data | Names; business contact details; user account identifiers; content of the categories above as recorded by Customer in the Services |
| Special or regulated categories | None. Section 12.2(d) of the Agreement prohibits their submission without Provider's prior written agreement. |
| Processing instructions | The Agreement, each Order Form, this DPA, and Customer's configuration and use of the Services constitute Customer's complete and documented instructions. Additional instructions require Provider's written agreement and may be billable. |
4.1 Customer generally authorizes Provider to engage subprocessors, including hosting and infrastructure suppliers, to process Personal Data in connection with the Services. Provider will engage each subprocessor under a written contract, which may consist of the subprocessor's standard written terms, that imposes data protection obligations substantially equivalent in effect to those in this DPA and that complies with the requirements Data Protection Law places on downstream contracts, and Provider remains responsible for the subprocessor's performance.¶
4.2 Where Data Protection Law grants Customer a right to be informed of, or to object to, a new subprocessor, Provider will, on Customer's written request, make available a then-current description of its subprocessor categories or, where Data Protection Law requires more, the disclosure that law requires. Where Data Protection Law grants Customer a right to notice of a new subprocessor, Provider will give that notice automatically, before engaging the new subprocessor for Customer's Personal Data, through the location identified on the Order Form and, where that law requires direct notice, by email to Customer's Authorized Representatives. Customer may object in writing, within fifteen (15) days after that notice, on reasonable, documented data protection grounds. The Parties will confer in good faith; Provider may resolve the objection by not using the new subprocessor for Customer's Personal Data or by other reasonable means. If the objection cannot be resolved within thirty (30) days, Customer may, as its sole and exclusive remedy, terminate the affected Order Form on written notice with a refund of Fees prepaid for the period after termination, and no Early Termination Fee applies to that termination. Absent a right under Data Protection Law, Section 12.4 of the Agreement governs and this Section 4.2 does not apply.¶
5.1 Where Data Protection Law grants Customer a right to verify or audit Provider's compliance with this DPA, Provider will, on written request not more than once in any twelve (12) month period, make available the information reasonably necessary to demonstrate that compliance, which Provider may satisfy, where Data Protection Law permits, by providing the security overview described in Section 12.11 of the Agreement, a summary report or attestation prepared by or for Provider, or written responses, each Provider Confidential Information.¶
5.2 Where, and only where, the applicable Data Protection Law expressly grants an audit or inspection right that cannot be satisfied under Section 5.1, Provider will permit an audit limited to the processing of Customer's Personal Data, conducted on reasonable notice during business hours, no more than once in any twelve (12) month period, by Customer or an independent auditor that is not a competitor of Provider and that is bound by confidentiality obligations satisfactory to Provider. No audit may access the data of any other customer, Provider's source code, or Provider's trade secrets, and no penetration, vulnerability, or technical testing is permitted. Provider may instead elect to engage a qualified independent auditor itself and provide the resulting report, where Data Protection Law permits that alternative, with Customer's consent where that law requires it and at Provider's expense where that law so allocates the cost. Except where Data Protection Law requires Provider to bear a cost, Customer bears all costs of audits and verification, including Provider's time at the rates in Schedule Z.¶
5.3 Where Data Protection Law grants Customer the right, Customer may take reasonable and appropriate steps, through the verification mechanisms in Sections 5.1 and 5.2, to help ensure that Provider uses Personal Data consistently with Customer's obligations under that law, and, on Customer's documented written notice of unauthorized use of Personal Data, Provider will take reasonable and appropriate steps to stop and remediate the unauthorized use identified.¶
6.1 To the maximum extent permitted by applicable Data Protection Law, liability under this DPA is subject to Section 11 of the Agreement, including the aggregate cap and the sublimit in Section 11.3(d).¶
6.2 To the maximum extent permitted by applicable Data Protection Law, remedies under this DPA are limited to those stated in it and in the Agreement. Nothing in this DPA creates third-party rights in any data subject.¶
6.3 This DPA may be updated in accordance with Section 14.13 of the Agreement, including to reflect changes in Data Protection Law, by publication of a new version at its own address; this version is not edited.¶
Data Processing Addendum | Version 5 | Effective September 1, 2026
Permanent address: /legal/omis-dpa-v5.html
The Plug Group · Data Processing Addendum · Version 5