Last updated: July 09, 2026. This agreement outlines GDPR-compliant data processor obligations.
This Data Processing Agreement ("DPA") governs the processing of personal data by OptiDrive on behalf of the customer ("Controller") in connection with the image optimization and content delivery services defined in the Terms of Service. This DPA forms an integral part of the service agreement between both parties and is designed to ensure compliance with Article 28 of the GDPR, CCPA, and equivalent global privacy laws.
• Categories of Data Subjects: Users, customers, website visitors, and employees of the Controller whose media assets are processed or delivered via OptiDrive. • Types of Personal Data: Uploaded media assets containing human likenesses, user profiles, image metadata, request IP addresses, geolocations, and referring URLs. • Nature and Purpose: Automated real-time image compression, resizing, transformation, caching, and CDN asset delivery. • Duration: The duration of processing corresponds to the lifespan of the Controller's workspace registration.
OptiDrive hereby covenants and agrees to: • Process Personal Data only on documented instructions from the Controller, including with respect to transfers of personal data to a third country. • Ensure that personnel authorized to process the personal data have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality. • Implement and maintain appropriate technical and organizational security measures (defined in Section 4) to ensure a level of security appropriate to the risk.
OptiDrive has implemented and will maintain the following security infrastructure: • Encryption in Transit: All API payloads and dashboard traffic are protected using TLS 1.3 encryption. • Encryption at Rest: Workspace BYOS bucket keys and configuration credentials are encrypted using AES-256 keys. • Network Isolation: Databases reside in secure virtual private clouds (VPCs) with restricted external access. • Access Audits: Every system administration action is logged inside secure audit databases.
The Controller grants a general authorization to OptiDrive to engage third-party sub-processors (such as Stripe for payments, AWS/Vercel for CDN, and Neon for database hosting). We will maintain an up-to-date list of sub-processors on our website and notify the Controller of any intended changes at least 14 days in advance, giving the Controller the opportunity to object to such changes.
In the event of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data processed by us, OptiDrive will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach.
OptiDrive will assist the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights under GDPR Chapter III. Furthermore, OptiDrive will make available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Upon termination of the service agreement, or upon manual deletion of assets by the Controller via the API/Dashboard, OptiDrive will permanently delete all master files and cached duplicates within 30 days, unless EU or member state law requires retention of the personal data.