Data Processing Agreement

Last updated: August 20, 2026 · OkLau Technologies Inc.

1. Scope & Parties

This Data Processing Agreement ("DPA") governs the processing of business and personal data by OkLau Technologies Inc. ("Processor") on behalf of tenant organizations ("Controller") using the OkLau Enterprise Cloud platform.

2. Data Processing Purpose

We process enterprise data solely to provide, operate, maintain, and support the modular ERP and SaaS services as described in our Terms of Service. Data is processed exclusively on documented instructions from the Controller.

3. Technical & Organizational Security

OkLau implements state-of-the-art security measures including: TLS 1.3 encryption in transit, AES-256 encryption at rest, tenant database schema isolation, granular RBAC access enforcement, field-level encryption for PHI/PII, and automated snapshot backup routines.

4. Sub-Processors

We engage vetted sub-processors for cloud hosting infrastructure (AWS, Google Cloud) and payment processing (Stripe). An up-to-date registry of sub-processors is available upon request.

5. Data Subject Rights & DSAR

We provide automated tools within the platform's Data Privacy module enabling Controllers to fulfill Data Subject Access Requests (DSAR), rectifications, and cryptographic erasure requests in compliance with GDPR and CCPA.

6. Breach Notification

We commit to notifying affected Controllers without undue delay and within 72 hours of becoming aware of any confirmed personal data breach, providing full forensic context and remediation steps.

7. Data Return & Deletion

Upon contract termination, all customer tenant data may be exported in open structured formats (JSON / CSV / SQL Archive) and will be irreversibly deleted within 30 days.

8. Contact

For DPA inquiries or custom data protection addenda, contact dpo@oklau.com.

← OkLau Home Privacy Policy Terms of Service Security & Trust Cookie Policy