Ollify LLC
Data Processing Agreement
Effective September 15, 2026 | Last Updated September 15, 2026 | Version 1.0
This Data Processing Agreement ("DPA") is entered into as of the DPA Effective Date by and between:
PROCESSOR Ollify LLC A Mississippi Limited Liability Company 901 N State St. STE N Jackson, MS 39202 support@ollify.app | CONTROLLER (CUSTOMER) The business entity that has agreed to Ollify's Terms of Service or executed a Master Service Agreement with Ollify (defined as "Customer," "you," or "your" in the Agreement), as the controller of personal data processed through the Service. |
This DPA is incorporated into and forms part of the Master Service Agreement or Terms of Service (collectively, the "Agreement") between Ollify and Customer governing Customer's use of the Ollify platform and related services (the "Service"). In the event of a conflict between this DPA and the Agreement on matters of data protection, this DPA controls.
ROLE CLARIFICATION — PROCESSOR vs. CONTROLLER
Ollify acts as a Processor of Customer Data submitted to the Service by Customer. Ollify acts as a Controller of its own operational data, including its marketing contact lists, employee data, and platform usage data collected for its own business purposes. This DPA governs only Ollify's processing as a Processor on Customer's behalf. Customer is the Controller of all Customer Data and is responsible for the lawfulness of its collection and processing instructions.
1. Definitions
Capitalized terms used in this DPA have the following meanings. Terms not defined here have the meanings given in the Agreement.
"Controller" means the entity that determines the purposes and means of Processing Personal Data. Customer is the Controller of Customer Data.
"Customer Data" means all Personal Data submitted by or on behalf of Customer to the Service, including data about Customer's employees, clients, contractors, and other individuals that Customer enters into or uploads to the platform.
"Data Subject" means an identified or identifiable natural person whose Personal Data is Processed under this DPA.
"Personal Data" means any information relating to an identified or identifiable natural person that Ollify Processes on behalf of Customer in connection with the Service, as further described in Annex B.
"Processing" (and "Process" or "Processed") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure, or destruction.
"Processor" means the entity that Processes Personal Data on behalf of the Controller. Ollify is the Processor.
"Security Incident" means a confirmed breach of Ollify's security measures that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Data Processed under this DPA.
"Subprocessor" means any third-party processor engaged by Ollify to Process Personal Data on behalf of Customer in connection with the Service, as listed in Annex C.
"Technical and Organizational Measures" or "TOMs" means the security measures described in Annex A.
"Terms of Service" or "Agreement" means the Master Service Agreement or Terms of Service governing Customer's use of the Service, into which this DPA is incorporated.
2. Roles and Relationship
2.1 Controller and Processor. The Parties acknowledge that with respect to Customer Data: Customer is the Controller, and Ollify is the Processor. Ollify Processes Customer Data only on behalf of Customer and pursuant to Customer's documented instructions, subject to applicable law. Each Party will comply with applicable data protection laws in the performance of their respective obligations under this DPA.
2.2 Customer Instructions. Customer's use of the Service and configuration of features constitutes Customer's documented instructions for Ollify's Processing of Customer Data. Customer may provide additional written instructions through:
- (a)
support requests submitted to Ollify;
- (b)
configuration changes made within the Service; or
- (c)
written notice to support@ollify.app.
Ollify will follow such instructions to the extent technically feasible and consistent with applicable law.
2.3 Conflicting Instructions. If Ollify believes any Customer instruction would require Ollify to violate applicable law, Ollify will promptly notify Customer and, unless prohibited by law, suspend Processing under the conflicting instruction until Customer provides a lawful alternative instruction. Ollify will not be liable for any failure to Process that results from Customer providing unlawful instructions.
3. Processing Details
The details of the Processing activities covered by this DPA are set forth in Annex B. The key details are summarized as follows:
Subject Matter | Provision of the Ollify business management platform and related services as described in the Agreement. |
Duration | For the term of the Agreement and until all Customer Data is returned or deleted per Section 9. |
Nature and Purpose | Hosting, storing, processing, and transmitting Customer Data to provide and operate the Service, fulfill Customer instructions, and support Customer's business operations. |
Types of Personal Data | As described in Annex B. Generally includes names, email addresses, phone numbers, business contact information, job and workflow data, documents, forms, location data (Mapbox), text messages (where Text Messaging Features are used), and communications. |
Categories of Data Subjects | Customer's employees, clients, customers, contractors, and other individuals whose data Customer submits to the Service. |
Special Categories | No special categories of personal data are intended to be processed. |
4. Customer Obligations
4.1 Lawfulness of Processing. Customer warrants that:
- (a)
it has a lawful basis for collecting and submitting Customer Data to the Service;
- (b)
it has provided all required notices and obtained all required consents from Data Subjects as required by applicable law;
- (c)
all Customer Data submitted to the Service is accurate and up to date to the best of Customer's knowledge; and
- (d)
Customer's instructions to Ollify are lawful and comply with applicable data protection law.
4.2 Instruction Authority. Customer is responsible for ensuring that individuals authorized to give instructions to Ollify on Customer's behalf have the authority to do so under applicable law and Customer's internal policies.
4.3 Prohibited Data. Customer shall not submit to the Service any:
- (a)
Protected Health Information ("PHI") as defined under HIPAA, under any circumstances. Ollify is not a Business Associate under HIPAA and will not enter into a Business Associate Agreement with any Customer;
- (b)
Controlled Unclassified Information ("CUI") or data subject to FAR/DFARS requirements;
- (c)
raw payment card numbers, card verification values (CVV), or financial account credentials, except where processed through a PCI-DSS compliant third-party payment processor integrated with the Service, in which case only a tokenized reference to such payment method — and not the underlying card number or credentials themselves — may be stored or transmitted through the Service;
- (d)
records of the identity, diagnosis, prognosis, or treatment of any patient maintained in connection with substance abuse programs governed by 42 CFR Part 2;
- (e)
mental health records subject to heightened state-specific confidentiality protections (including but not limited to California Welfare and Institutions Code § 5328 and New York Mental Hygiene Law);
- (f)
sensitive reproductive health information, including pregnancy status, abortion records, fertility treatment records, or contraception data;
- (g)
genetic information as defined under the Genetic Information Nondiscrimination Act (GINA); or
- (h)
Social Security Numbers or government identification numbers, under any circumstances.
Customer is solely responsible for any harm arising from submission of prohibited data categories.
4.4 Instructions in Writing. Customer's use of the Service constitutes Customer's instruction to Ollify to Process Customer Data as necessary to provide the Service. Additional specific instructions must be provided in writing. Ollify is not required to act on verbal instructions.
5. Ollify's Obligations as Processor
5.1 Compliance with Instructions. Ollify will Process Customer Data only:
- (a)
in accordance with Customer's documented instructions;
- (b)
as necessary to provide the Service and fulfill Ollify's obligations under the Agreement;
- (c)
as required by applicable law, in which case Ollify will notify Customer unless prohibited by law; and
- (d)
as set forth in this DPA.
Ollify will not Process Customer Data for its own purposes, including to train AI models, develop competing products, or for advertising, without Customer's prior written consent.
5.2 Confidentiality of Customer Data. Ollify will ensure that personnel authorized to Process Customer Data are subject to written confidentiality obligations and are permitted access only on a need-to-know basis. Ollify will limit access to Customer Data to personnel whose roles require access to provide the Service or fulfill Ollify's obligations under this DPA.
5.3 Security Measures. Ollify will implement and maintain the Technical and Organizational Measures ("TOMs") described in Annex A, designed to provide a level of security appropriate to the risk to the rights and freedoms of Data Subjects. Ollify may update the TOMs from time to time provided that any update does not materially reduce the overall security of the Service. Ollify's current security practices are described in Ollify's Security Documentation, available at ollify.app/legal/security.
5.4 Data Subject Rights Assistance. Ollify will provide reasonable assistance to Customer in fulfilling Data Subject rights requests, including:
- (a)
providing self-service tools within the Service for data access, export, and deletion where technically feasible;
- (b)
responding to Customer's written requests for assistance within a reasonable time; and
- (c)
providing the technical means to enable Customer to identify and locate Customer Data.
Ollify will not respond directly to Data Subject requests relating to Customer Data without Customer's authorization, and will refer any Data Subjects who contact Ollify directly regarding their rights to Customer.
5.5 Security Incident Notification. In the event Ollify discovers or becomes aware of a confirmed Security Incident affecting Customer Data, Ollify will:
- (a)
notify Customer without undue delay and in any event within seventy-two (72) hours of confirming the Security Incident;
- (b)
provide, to the extent then known, a description of the nature of the Security Incident, the categories and approximate number of Data Subjects affected, the categories and approximate volume of Customer Data affected, and the likely consequences of the Security Incident; and
- (c)
describe the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.
5.6 Records of Processing. Ollify will maintain records of its Processing activities as required by applicable law, including records of the categories of Processing performed on behalf of Customer, security measures implemented, subprocessors engaged, and any Security Incidents. Ollify will make these records available to Customer upon written request, subject to any confidentiality restrictions.
5.7 Data Protection Impact Assessments. Where required by applicable law, Ollify will provide reasonable assistance to Customer in conducting data protection impact assessments (DPIAs) relating to the Service, to the extent Customer does not have access to the relevant information independently.
5.8 Cooperation with Regulators. Ollify will cooperate with Customer and, where required by applicable law, with data protection authorities in connection with any investigation or inquiry relating to the Processing of Customer Data under this DPA, to the extent permitted by law.
6. Subprocessors
6.1 Authorization. Customer hereby grants Ollify general authorization to engage Subprocessors to perform Processing activities on Customer's behalf in connection with the Service. The current list of authorized Subprocessors is available at ollify.app/legal/subprocessors and is incorporated into this DPA by reference as Annex C. By entering into this DPA, Customer confirms it has reviewed and accepted the current Subprocessor list.
6.2 Notification of Changes. Ollify will provide Customer with at least thirty (30) days' advance notice before adding a new Subprocessor or replacing an existing Subprocessor that may have a material impact on the Processing of Customer Data. Notice will be provided by:
- (a)
updating the Subprocessor list at ollify.app/legal/subprocessors; and
- (b)
sending an email to Customer's designated privacy contact.
The notice period commences on the date the Subprocessor list is updated.
6.3 Customer Right to Object. Customer may object to the addition of a new Subprocessor by providing written notice to support@ollify.app or privacy@ollify.app within thirty (30) days of receiving notification under Section 6.2, specifying the reasonable grounds for the objection. The thirty (30) day objection window opens on the date Ollify updates the Subprocessor list pursuant to Section 6.2 and closes thirty (30) days thereafter. Upon receiving a timely objection, the Parties will negotiate in good faith for up to thirty (30) days to find a mutually acceptable resolution. If no resolution is reached within thirty (30) days, Customer may terminate the Agreement on thirty (30) days' written notice. Ollify will provide Customer a pro-rata refund of any prepaid fees for the unused portion of Customer's then-current subscription term. Continued use of the Service after the objection period constitutes acceptance of the new Subprocessor.
6.4 Subprocessor Obligations. Ollify will impose data protection obligations on each Subprocessor that are at least as protective as those set forth in this DPA, by entering into a written agreement with each Subprocessor. Ollify remains liable to Customer for the performance and compliance of each Subprocessor to the same extent as if Ollify performed the activities itself.
7. International Data Transfers
7.1 US Processing. All Processing of Customer Data under this DPA takes place within the United States, specifically in Ollify's AWS us-east-1 region. Ollify does not transfer Customer Data outside of the United States as of the DPA Effective Date.
7.2 Future International Transfers. If Ollify intends to transfer Customer Data outside of the United States in the future, Ollify will:
- (a)
provide Customer with at least sixty (60) days' advance written notice;
- (b)
implement an appropriate transfer mechanism as required by applicable law, which may include Standard Contractual Clauses (SCCs), adequacy decisions, or other valid legal mechanisms; and
- (c)
update this DPA or execute a transfer addendum as appropriate.
Ollify will not transfer Customer Data internationally without a valid legal transfer mechanism in place.
NOTE ON GDPR
This DPA does not include GDPR-specific language because Ollify is currently a US-focused product and does not specifically target or serve customers in the European Economic Area, United Kingdom, or Switzerland. If Customer is subject to GDPR or if Ollify expands internationally, the Parties will execute a GDPR-compliant DPA addendum incorporating Standard Contractual Clauses (SCCs) or another valid transfer mechanism. Contact support@ollify.app to discuss GDPR requirements.
8. Audit Rights
8.1 Customer Audit Rights. Subject to the terms of this Section, Customer has the right to audit Ollify's compliance with this DPA no more than once per calendar year, upon at least thirty (30) days' prior written notice to support@ollify.app, during normal business hours, at Customer's own expense. Audits must be conducted in a manner that minimizes disruption to Ollify's operations and does not compromise the security or privacy of other customers' data. Customer may engage a qualified independent third-party auditor to conduct the audit, provided the auditor is subject to reasonable confidentiality obligations.
8.2 SOC 2 Report as Audit Substitute. Ollify may satisfy its audit obligations under Section 8.1 by providing Customer with a then-current SOC 2 Type 2 report or equivalent third-party security audit report, subject to a mutual non-disclosure agreement. Customer agrees to treat any such report as Confidential Information and to limit access to individuals who have a need to review the report for compliance purposes.
8.3 Audit Costs. Customer bears all costs of any audit conducted under this Section. If an audit reveals a material breach of this DPA by Ollify, Ollify will bear the reasonable direct costs of the audit attributable to the investigation of the breach.
8.4 Regulator Access. Ollify will cooperate with data protection authorities as required by applicable law and will notify Customer promptly upon receiving any request or inquiry from a data protection authority relating to the Processing of Customer Data, to the extent permitted by law.
9. Data Return and Deletion
9.1 Data Export upon Termination. Upon termination or expiration of the Agreement for any reason, Customer may export all Customer Data from the Service using Ollify's standard export tools for a period of sixty (60) days following the effective date of termination (the "Export Window"). Ollify will maintain Customer Data in a retrievable state during the Export Window.
9.2 Deletion Following Export Window. After the Export Window closes, Ollify will remove Customer Data from active production systems, and remaining copies will thereafter cycle out of backup and archive systems in accordance with Ollify's published data retention schedules. Certain records are retained beyond this process where required by law or as described in this DPA and the Agreement, including messaging opt-out records (retained permanently so that opt-outs are honored). Upon Customer's written request, Ollify will provide written confirmation describing the state of Customer Data: what has been removed from active systems, what remains in time-limited backup or archive layers and the schedule on which it will cycle out, and what is retained under a legal or regulatory requirement and why.
9.3 Backup Retention. Backup copies of Customer Data may be retained for up to thirty-five (35) days following deletion from production systems as part of Ollify's standard backup and disaster recovery procedures. Backup data is used solely for disaster recovery and is not accessible for individual data requests. All backup copies will be purged within thirty-five (35) days of production deletion.
9.4 Legal Hold. If Customer Data is subject to a legal hold, litigation hold, or regulatory preservation requirement, Ollify will suspend deletion of the applicable Customer Data upon Customer's written notice specifying the scope of the hold. Customer is responsible for notifying Ollify of any legal hold requirements and for releasing the hold in writing when the requirement has ended.
9.5 Deletion During Term. During the term of the Agreement, Customer may delete Customer Data from the Service using available in-app tools. Deleted Customer Data is removed from ordinary views immediately, processed through Ollify's deletion pipeline (which includes a thirty (30) day recovery grace period), and cycled out of backup systems within thirty-five (35) days. After the recovery grace period, the underlying record is anonymized; ordinary Customer Data is then purged within one (1) year, while signed documents and their audit trail are retained as legal evidence for seven (7) years before purge. Ollify's deletion of Customer Data at Customer's instruction does not relieve Customer of its own obligations to retain data as required by applicable law.
10. Limitation of Liability
The limitations of liability set forth in the Agreement (including any Master Service Agreement or Terms of Service) apply to this DPA and to all claims arising out of or related to the Processing of Customer Data. Specifically:
The aggregate cap on Ollify's liability under this DPA shall not exceed the amounts set forth in the Agreement's limitation of liability provision.
Excluding damages arising from Ollify's breach of confidentiality obligations (which are subject to a separate cap as specified in the Agreement), neither Party will be liable for indirect, consequential, incidental, special, or exemplary damages arising out of or related to this DPA.
Ollify's liability for Security Incidents is limited to direct damages caused by Ollify's failure to comply with the security obligations in this DPA and is subject to the aggregate cap in the Agreement.
Nothing in this Section limits liability that cannot be limited under applicable law, including liability for gross negligence or willful misconduct.
11. Term
This DPA is effective as of the DPA Effective Date and remains in force for the duration of the Agreement. This DPA terminates automatically upon the expiration or termination of the Agreement. The obligations in Sections 5.2 (Confidentiality), 9 (Data Return and Deletion), and 10 (Limitation of Liability) survive termination of this DPA.
12. General Provisions
Entire Agreement. This DPA, together with the Agreement and all Annexes, constitutes the entire agreement between the Parties regarding the Processing of Customer Data and supersedes all prior agreements and understandings on this subject.
Precedence. In the event of a conflict between this DPA and the Agreement on matters of data protection and privacy, this DPA controls. In all other matters, the Agreement controls.
Amendment. This DPA may be amended only by a written instrument signed by authorized representatives of both Parties. Ollify may update the Subprocessor list in Annex C in accordance with Section 6.2 without a formal DPA amendment.
Governing Law. This DPA is governed by the law specified in the Agreement's governing law provision.
Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions continue in full force and effect.
No Third-Party Beneficiaries. This DPA does not confer any rights on Data Subjects as third-party beneficiaries. Data Subjects must direct any rights requests to Customer as the Controller.
Counterparts. This DPA may be executed in counterparts. Electronic signatures are valid and binding.
13. Execution and Acceptance
13.1 Self-Service Customers. For Customers who subscribe to the Service on a self-service basis through Ollify's online sign-up flow, this DPA does not require a separate signature. This DPA is incorporated into and forms part of the Agreement by reference, and Customer accepts the terms of this DPA in full by clicking to accept the Terms of Service (or equivalent click-through acceptance) at sign-up, or by otherwise accessing or using the Service. The DPA Effective Date for self-service Customers is the date Customer accepts the Terms of Service.
13.2 Enterprise Customers. For Customers who enter into a separately negotiated Master Service Agreement or enterprise order form with Ollify, this DPA may instead be executed by the Parties' authorized representatives, in which case the DPA Effective Date is the date of last signature. Electronic signatures are valid and binding.
13.3 No Effect on Validity. The method of acceptance under Section 13.1 or 13.2 does not affect the validity, binding effect, or enforceability of this DPA, which is effective and binding on both Parties as of the applicable DPA Effective Date.
14. Annex A — Technical and Organizational Measures (TOMs)
The following Technical and Organizational Measures ("TOMs") describe the security controls Ollify maintains to protect Customer Data. These measures are subject to ongoing improvement and may be updated by Ollify provided that any update does not materially reduce overall security.
14.1 Encryption.
Encryption in Transit — All Customer Data transmitted between Customer's systems and Ollify's servers is encrypted using TLS 1.2 or higher (Transport Layer Security).
Encryption at Rest — Customer Data stored on Ollify's servers is encrypted at rest using AES-256 or equivalent industry-standard encryption.
Backup Encryption — Backup copies of Customer Data are encrypted using the same standards as production data.
14.2 Access Controls.
Role-Based Access Control (RBAC) — Access to Customer Data is restricted based on personnel roles and responsibilities. Personnel are granted the minimum access necessary to perform their duties (principle of least privilege).
Authentication — Ollify personnel with access to production systems are required to use strong passwords and multi-factor authentication (MFA).
Access Review — Ollify conducts periodic reviews of access rights to production systems and Customer Data. Access is revoked promptly upon personnel departure.
Customer Access Controls — Ollify provides Customer with role-based user management tools to control which of Customer's users can access Customer Data within the Service.
14.3 Audit Logging.
System audit logs are maintained for all access to and modifications of Customer Data in production systems.
Application and system logs are retained for a minimum of ninety (90) days, and platform audit logs for seven hundred thirty (730) days; logs are used for security monitoring and incident investigation.
Log access is restricted to authorized security and operations personnel.
14.4 Security Incident Response.
Ollify maintains a written security incident response plan covering detection, containment, investigation, notification, and remediation.
Security incidents are escalated immediately to Ollify's designated security team upon discovery.
Confirmed Security Incidents affecting Customer Data are reported to Customer within 72 hours of confirmation, per Section 5.5.
14.5 Backup and Recovery.
Customer Data is backed up on a regular schedule. Backups are encrypted and stored across physically separate data centers (availability zones) within Ollify's production AWS region. Cross-region backup replication is part of Ollify's infrastructure roadmap and has not yet been implemented as of the DPA Effective Date.
Backup retention: automated daily backups. Customer Data is retained in backups for up to thirty-five (35) days following deletion from production systems, per Section 9.3. Backups are used solely for disaster recovery.
Formal, scheduled backup restoration testing is being implemented as part of Ollify's infrastructure roadmap and has not yet been performed as of the DPA Effective Date.
14.6 Personnel Security.
All Ollify personnel with access to Customer Data are subject to written confidentiality obligations.
Ollify provides security awareness training to personnel with access to production systems.
Personnel access is revoked the same business day, or the next business day if the separation occurs after normal business hours.
14.7 Vulnerability Management.
Security vulnerabilities are tracked, prioritized, and remediated according to severity. Critical vulnerabilities are prioritized for immediate remediation.
Dependency and library updates are reviewed and applied on a regular schedule.
14.8 Physical Security.
Customer Data is hosted on Amazon Web Services (AWS) infrastructure in the us-east-1 region. AWS maintains SOC 2 Type 2, ISO 27001, and other certifications covering physical security of its data centers.
Ollify personnel do not have physical access to AWS data center hardware.
15. Annex B — Details of Processing
This Annex B describes the details of Processing activities covered by this DPA.
Categories of Data Subjects | Customer's employees and contractors who use the Service; Customer's clients, customers, and business contacts whose information Customer enters into the Service; and other individuals whose Personal Data Customer submits to the Service in the course of operating its business. |
Categories of Personal Data | Identifiers and contact information (names, email addresses, phone numbers, physical addresses); Professional information (company name, job title, business role); Job and workflow data (job records, schedules, notes, assignments); Document and form content (documents uploaded or created in the Service, form submissions, digital signatures); Communications (support messages, text message content and delivery status where Text Messaging Features are used, and AI feature interactions if and when AI features become available); Location data (delivery addresses and routing data from Mapbox features); Account and authentication data (usernames, account settings, access logs). |
Special Categories of Personal Data | No special categories of personal data are intended to be processed. Customer warrants that it will not submit any special categories of personal data (including health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, or financial account numbers) to the Service without a separately executed addendum. |
Processing Operations | Storage and hosting of Customer Data; authentication and access control; execution of Customer instructions via the platform interface; transmission to Subprocessors as necessary for service delivery; backup and disaster recovery; security monitoring and logging; export and deletion upon Customer request; and, if and when AI features become available, processing of prompts and related context by AI features when enabled by Customer. |
Retention Periods | See Section 9 and the Agreement's retention terms. Generally: Customer Data retained for subscription term plus 60-day export window; audit logs 730 days; backups retained for up to thirty-five (35) days following deletion from production systems for disaster recovery, per Section 9.3. |
Processing Location | United States (AWS us-east-1). No international transfers at DPA Effective Date. See Section 7 for international transfer procedures. |
16. Annex C — Subprocessor List
This Annex C lists the Subprocessors that Process Customer Data (as defined in Section 1(b)) on Ollify's behalf, consistent with the definition of "Subprocessor" in Section 1(h). Vendors Ollify uses solely for internal operations (e.g., source control, internal chat, credential management) that do not Process Customer Data are not "Subprocessors" under this DPA and are therefore not listed below. The current authoritative list of Subprocessors under this DPA is maintained at ollify.app/legal/subprocessors, or upon written request to support@ollify.app. The table below reflects the Subprocessors approved as of the DPA Effective Date. Ollify will update the online list and notify Customer of changes in accordance with Section 6.2.
Subprocessor | Purpose | Data Location | Status | Security Certification |
Amazon Web Services (AWS) | Cloud infrastructure, hosting, storage, and compute, including Amazon SES for transactional email delivery; stores all Customer Data, account information, logs, and backups. | United States (us-east-1) | Active | SOC 2 Type 2, ISO 27001, FedRAMP |
Mapbox, Inc. | Mapping, routing, and geolocation features. Processes location data (addresses, coordinates, routing queries) submitted via mapping features. Does not receive account information or general Customer Data. | United States | Active | SOC 2 Type 2 |
AWS End User Messaging (Amazon Web Services) | Text message (SMS) delivery. Powers the Text Messaging Feature within the Service, through which Customer sends text messages to its own clients, drivers, contractors, or other contacts. Processes recipient phone numbers, message content, delivery status, and opt-out ("STOP") replies. | United States | Active | Covered under AWS certifications (SOC 2 Type 2, ISO 27001) |
Expo (Expo, Inc.) | Mobile application build, distribution, and over-the-air update delivery. Also processes device push-notification tokens. | United States | Active | SOC 2 Type 2 |
Stripe, Inc. | Payment processing. Handles subscription billing, payment card processing, and invoicing. Ollify LLC is the merchant of record for Customer's subscription charges; Stripe processes the payment. Will not receive general Customer Data. | United States | Active | SOC 2 Type 2, PCI DSS Level 1 |
National Highway Traffic Safety Administration (NHTSA) | VIN decoding. NHTSA's vPIC service decodes Vehicle Identification Numbers (VINs) entered by Customer to return vehicle specifications, powering the Auto Glass Pack add-on. Only the VIN itself is transmitted; no personal or customer-identifying information is sent. | United States | Active | N/A (U.S. government agency; does not offer security certifications or a data processing agreement in the commercial sense) |
Planned Subprocessor — Not Yet Active One integration is built but not yet active: Anthropic, PBC, the AI provider for the AI Agent add-on, which is not available in production as of the DPA Effective Date. When AI features launch, using them will transmit to Anthropic: the Customer's business name; an overview of the Customer's configured data structure; the name and role of the user interacting with the AI; the user's prompts; and the records returned by tools in answer to the request — under a single Ollify API credential shared across all customers. Customer Data is not used to train Anthropic's models. This integration will be activated with Customer notice per Section 6.2. |
Current list maintained at: ollify.app/legal/subprocessors, or upon written request to support@ollify.app
Questions about subprocessors: support@ollify.app