Side Quest Energy LLC d/b/a optzi!
Data Processing Addendum
Last Updated: September 17, 2026 | Effective September 17, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Side Quest Energy LLC d/b/a optzi! ("Processor", "Optzi") and the customer ("Controller"). Where it conflicts with the Terms of Service on personal-data processing, this DPA controls. Optzi is the processor of Customer Personal Data and an independent controller for its own account, billing, diagnostic-telemetry, and ordinary support-correspondence data (governed by the Privacy Policy).
1. Roles and Scope
The Controller is the controller of Customer Personal Data, which includes end-user consent records, associated notice snapshots, customer-approved configuration, and scan results generated from the Controller's properties. Optzi is the processor, processing on the Controller's documented instructions (GDPR Art. 28). Optzi is an independent controller for its own account, billing, diagnostic-telemetry, and ordinary support-correspondence data, governed by the Privacy Policy. If the Controller voluntarily includes Customer Personal Data in a support message or attachment, Optzi processes that information as processor only to investigate and answer the support request. For the bounded DSB D2/D3 repair-evidence process, Customer Personal Data also includes minimized evidence derived from the Controller's configuration and scan results. Optzi processes that evidence only to plan, independently authorize, execute, reconcile, verify, or conditionally roll back an exact repair and to prove timely deletion. Optzi does not use DSB evidence for advertising, sale or sharing, profiling, product training, analytics enrichment, or any unrelated purpose.
2. Subject-Matter, Duration, Nature, and Purpose
Subject-matter: provision of the consent-management service. Duration: the term of the Agreement plus the retention window in section 6. Nature and purpose: collecting, storing, and making available end-user consent records and notice snapshots; scanning and configuration; generating advisory AI-assisted classifications for technical scan findings that the Controller must review before use; limited support requested by the Controller; and the bounded DSB repair-evidence process described below. Types of personal data: consent identifiers, consent and notice versions, visitor choices, timestamps, edge-derived country and region code, the visitor's Global Privacy Control signal where present, an impression identifier, customer configuration, scan results showing scripts found on the Controller's properties, and any Customer Personal Data the Controller voluntarily submits in a support message or attachment. For AI-assisted classification, the technical scan evidence is limited to a query-stripped host and path plus selected technical attributes for an external script or iframe, or the first 200 characters, total length, and type attribute of an inline script. Categories of data subjects: the Controller's website visitors. No special-category data, raw IP address, names, email addresses, precise geolocation, payment-card data, passwords, or credentials are intended to be sent through the automated product flow or submitted through support, although an inline-script excerpt could incidentally contain data embedded by the Controller. The Controller should not include such information in support content.
DSB repair evidence: solely for a bounded, operator-only repair, Optzi may process internal account, site, ScanFinding, SiteScript, and row identifiers; normalized fingerprints that contain the load-bearing hostname and path; state and evidence hashes; timestamps; configuration revisions; closed technical status and reason values; and technical audit-event identifiers and digests. The DSB evidence does not contain visitor consent events, visitor identifiers, IP addresses, cookie values, raw or full URLs, query strings, fragments, raw HTML or scripts, page content, names, email addresses, human actor identifiers, credentials, secrets, or free text. The relevant data subjects remain the Controller's website visitors to the extent the source scan/configuration is Customer Personal Data and, where an account or site identifier identifies a natural person such as a sole trader, that Controller or its personnel. DSB processing lasts only for the bounded periods in section 6.
3. Processor Obligations (Art. 28(3))
- (a) Process only on the Controller's documented instructions, including for international transfers, unless required by law (in which case Optzi will inform the Controller unless legally prohibited).
- (b) Ensure persons authorised to process are bound by confidentiality.
- (c) Apply Art. 32 security measures (see section 8).
- (d) Engage sub-processors only per section 4.
- (e) Assist the Controller, by appropriate technical and organisational measures, to respond to data-subject rights requests.
- (f) Assist the Controller with its Art. 32 to 36 obligations (security, breach notification, data-protection impact assessments), taking into account the nature of processing and the information available to Optzi.
- (g) At the Controller's choice, return and/or delete the Customer Personal Data at the end of provision (see section 6).
- (h) Make available the information necessary to demonstrate compliance and allow for and contribute to audits.
4. Sub-Processors
The Controller authorises Optzi to engage the following sub-processors to process Customer Personal Data on its behalf: Supabase (database hosting in the EU), Vercel (application hosting), Cloudflare (edge content delivery network and key-value storage), Trigger.dev (background job processing for site scans), Anthropic (AI-assisted classification of the limited technical scan evidence described in section 2), Featurebase (in-app support messaging, limited to Customer Personal Data the Controller voluntarily submits while requesting support), and Amazon Web Services, Inc. (Amazon S3 object storage and AWS CloudTrail security-audit delivery, with customer-derived DSB objects placed in eu-central-1 (Frankfurt), solely for the bounded DSB repair-evidence purpose described in sections 1 and 2). AWS does not receive visitor consent events through DSB. Clerk (authentication services) and Stripe (billing and payment processing) are engaged solely for Optzi's own account, identity, and billing data as Optzi's service providers and do not process Customer Personal Data.
Optzi will provide the Controller with at least thirty (30) days' prior written notice (by email to the account contact and/or dashboard notification) of any intended addition or replacement of a sub-processor that will process Customer Personal Data. The Controller may object in writing within fifteen (15) days of receipt of such notice on reasonable data-protection grounds. If the parties cannot resolve the objection, Optzi may terminate the affected portion of the Service or the Controller may terminate the Agreement without penalty. Optzi shall impose written data-protection obligations on each sub-processor that are no less protective, in substance, than the obligations imposed on Optzi under this DPA for the relevant processing, and Optzi remains responsible to the Controller for each sub-processor's performance of those obligations.
5. Continuity of Processing During Suspension or Non-Payment
Where Optzi suspends access to paid or self-service features for non-payment or other breach, Optzi shall nevertheless, while the Agreement is not terminated: (a) continue to operate the deployed consent notice so end-users keep being presented with a consent mechanism and consent interactions keep being recorded; and (b) retain all Customer Personal Data without deletion, alteration, or degradation. Suspension affects only the Controller's ability to administer, edit, deploy changes to, and self-export; it does not authorise Optzi to cease processing necessary to maintain the Controller's compliance posture, nor to erase or render inaccessible the data.
6. Access During Suspension; Return and Deletion on Termination (Art. 28(3)(e), (g))
Notwithstanding any suspension, Optzi shall continue to assist with data-subject requests and shall make available, on request and within a reasonable period, a complete copy of the Customer Personal Data, not conditioned on payment of suspended or disputed amounts, and promptly in recognition of the Controller's own statutory deadlines (including the Art. 12(3) one-month period); Optzi may provide such a copy out-of-band where self-service export is suspended. On termination, at the Controller's choice, Optzi shall return and/or delete all Customer Personal Data and initiate deletion of active copies within thirty (30) days of the later of termination and the Controller's instruction, unless law requires storage (in which case Optzi will inform the Controller and retain only as required). For support content processed through Featurebase, Optzi will use Featurebase's supported tools to remove applicable active-workspace content within that same period. Featurebase's published DPA states that active-system deletion after termination may take up to ninety (90) days and encrypted backups are overwritten within three hundred sixty-five (365) days after source deletion. Absent an instruction within thirty (30) days, Optzi may delete after at least fourteen (14) days' prior written notice. Optzi may retain its own minimised, no-PII business records (billing-state, administrative-action, webhook-idempotency, and proof-of-erasure logs) for up to seven (7) years for tax/accounting and legal claims (Art. 17(3)(b)/(e)). The Optzi-controlled retention windows are enforced in Optzi's code; provider-held support data follows the documented operational deletion process.
Detailed DSB repair evidence is permanently deleted by exact stored-object version no later than the earliest of (a) ninety (90) days after the source ScanFinding was created, (b) ninety (90) days after the DSB object was stored, or (c) an earlier deadline resulting from the Controller's valid instruction or an applicable erasure obligation. A Controller instruction or account/site erasure invokes the same thirty (30)-day completion limit in this section and includes every matched DSB copy; an ordinary technical retention lock does not extend that limit. Subject to a documented purpose and legal-basis assessment, minimized DSB security logs, integrity digests, key-revocation evidence, and proof-of-erasure records may be retained for no more than three hundred sixty-five (365) days. They do not contain visitor consent events and must be deleted earlier or redesigned if they remain reasonably linkable to the Controller after detailed DSB evidence is erased. No DSB record is added to the seven-year business-ledger category. A deletion deadline may be paused only to the extent a documented legal obligation or claims hold requires it, and Optzi will inform the Controller unless legally prohibited.
7. Suspension Is Not Termination
Suspension does not terminate the Agreement; on cure (including reactivation of a lapsed subscription), Optzi restores access and the retained data is available to the Controller in full, without loss.
8. Security (Art. 32)
Tenant isolation is enforced in application code through account-scoped queries; encrypted transport; least-privilege database access over a pooled service connection, with PostgreSQL row-level security enabled as defense-in-depth on the core account tables. Optzi does not load a third-party analytics or error-tracking SDK through the consent widget on the Controller's properties; Featurebase is limited to authenticated in-app support requested by the customer or team member. Confidentiality (Art. 28(3)(b)) and security obligations apply at all times, including during any suspension and any post-termination retention period.
9. Breach Notification (Art. 28(3)(f))
Optzi shall notify the affected Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, including DSB repair evidence. Optzi will not delay that processor-to-controller notice while completing a United States state-law analysis or while waiting for complete facts. The initial notice will provide the information then reasonably available, including the nature and approximate time of the incident; the affected processing, data categories, and approximate scope; likely consequences; containment and remediation taken or proposed; relevant sub-processor involvement; and a contact for follow-up. Optzi will provide material updates as facts become available, take reasonable steps to contain and mitigate the incident, preserve available integrity and audit evidence consistent with containment and lawful deletion duties, and reasonably assist the Controller with its applicable regulator and data-subject assessments. The Controller remains responsible for its regulator and data-subject notifications unless Optzi is legally required or expressly instructed to act. If the incident affects personal data for which Optzi is controller, including operator-security data, Optzi will separately assess and perform its own applicable duties.
10. International Transfers
Where Customer Personal Data is transferred outside the European Economic Area, United Kingdom, or Switzerland, including where limited technical scan evidence is processed by Anthropic or support content is processed by Featurebase, we rely on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Modules 2 and/or 3 as applicable to processor-to-processor transfers), the UK International Data Transfer Addendum, and any Swiss addendum, as completed for Optzi's processing activities and sub-processor arrangements. Our primary database is hosted in the European Union. The applicable completed modules and addenda are available upon request from support@useoptzi.com.
For DSB, customer-derived S3 objects are intended to be placed in AWS eu-central-1 (Frankfurt). Region selection does not by itself resolve every transfer or government-access question. Before DSB processing begins, Optzi will document the applicable AWS contracting entity, AWS Data Processing Addendum, processor-to-processor transfer mechanism, UK and Swiss terms, relevant AWS sub-processor chain, regional controls, and supplementary safeguards, and will reassess a material AWS sub-processor or transfer change before resuming affected processing.
11. Audit (Art. 28(3)(h))
Optzi shall, upon the Controller's reasonable written request with at least thirty (30) days' prior notice, make available such information as is reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, by the Controller or an independent auditor mandated by the Controller (subject to appropriate confidentiality obligations). Such audits shall be limited to once in any twelve (12) month period unless (a) required by a competent supervisory authority, (b) there is reasonable suspicion of material non-compliance with this DPA, or (c) the Controller has identified a specific compliance concern. The Controller shall bear its own costs of any audit unless the audit reveals material non-compliance by Optzi, in which case Optzi shall bear the reasonable costs of the audit. Optzi may satisfy its obligations under this section by providing the Controller with copies of relevant third-party audit reports (such as SOC 2 Type II) or other equivalent documentation, redacted as necessary for confidentiality. Audits shall be conducted during normal business hours, without undue disruption to Optzi's operations, and subject to Optzi's reasonable security and confidentiality requirements.
12. CCPA/CPRA Service-Provider Terms
To the extent Optzi processes personal information on behalf of a customer that is a "business" under the CCPA/CPRA, Optzi acts as a service provider or contractor for the limited and specified business purposes of providing the consent-management service, recording and returning consent evidence, scanning the customer's site for scripts, operating customer-approved configuration, security, debugging, and assisting with consumer requests. Optzi shall not sell or share Customer Personal Data; shall not retain, use, or disclose Customer Personal Data outside the direct business relationship with the Controller except as permitted by the CCPA/CPRA; shall not retain, use, or disclose Customer Personal Data for any purpose other than the specified business purposes or as otherwise permitted by law; shall not combine Customer Personal Data with personal information received from or collected on behalf of another person except as permitted by the CCPA/CPRA; shall provide at least the same level of privacy protection required of businesses by the CCPA/CPRA; shall notify the Controller if Optzi determines it can no longer meet those obligations; shall enable the Controller to respond to consumer requests; and shall require equivalent terms from subcontractors that process Customer Personal Data.
13. Liability
Liability under this DPA is subject to the limitation of liability in the Terms of Service.
Side Quest Energy LLC d/b/a optzi! • Virginia, USA • support@useoptzi.com