DATA PROCESSING ยท EFFECTIVE 29 AUGUST 2026
Data Processing Addendum
This Data Processing Addendum ("DPA") applies where a business customer accepts these terms in an order, account or written agreement ("Controller") and instructs Daniel Rossi Marinho - Unipessoal Lda, VAT/NIPC PT519202120 / 519202120, operating as CONSELA ("Processor"), to process personal data through the Service. Acceptance of the Service Terms incorporates this DPA for the customer's use of the Service. Full legal information is available on our Legal Information page. Contact: [email protected].
1. Parties and scope
The customer identified in the applicable order or account ("Controller") appoints Daniel Rossi Marinho - Unipessoal Lda, VAT/NIPC PT519202120 / 519202120, operating as CONSELA ("Processor"), to process personal data in order to provide the Service. CONSELA acts as an independent controller for its own account, billing, security, support and legal-compliance processing.
Processing details
- Subject matter: hosting, organizing, researching and generating output from customer workspace data.
- Duration: for the customer's use of the Service and the deletion periods in this DPA and the Privacy Policy.
- Data subjects: customer users, organization members, invitees and people described in customer-submitted content.
- Data categories: identifiers, contact details, account and permission data, prompts, documents, reports, transcripts, communications and technical metadata.
- Special categories: the Controller must not submit special-category data unless it has a lawful basis and the parties have agreed appropriate safeguards.
2. Instructions and confidentiality
CONSELA processes personal data only on documented instructions, including providing the Service, security, support, deletion and other instructions in the agreement. Personnel with access are bound by confidentiality.
3. Security
CONSELA maintains risk-appropriate technical and organizational measures including signed-in access controls, organization and project authorization, tenant-scoped database queries, role-based permissions, encrypted transport, hashed share tokens, anti-forgery protection, upload validation, rate limiting, security logging, encrypted backups, provider access controls, incident response procedures and deletion workflows. AI agents are restricted to approved web-research tools and are not granted application file or shell tools. No measure eliminates all risk, and the controls may evolve as risks and infrastructure change.
4. Subprocessors
The Controller authorizes the subprocessors listed at /subprocessors, including OpenRouter's downstream model endpoints used for the selected route. CONSELA will impose written data-protection obligations and remain responsible for subprocessors as required by law. CONSELA will provide at least 30 days' notice of a material subprocessor change where required; the Controller may object on reasonable data-protection grounds and may terminate the affected Service if the objection cannot be reasonably resolved.
5. Assistance
Taking account of the processing, CONSELA will provide reasonable assistance with data-subject requests, security obligations, breach assessment, DPIAs and consultations. The parties must agree how extraordinary assistance is charged.
6. Incidents
CONSELA will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Data and will provide available information about scope, impact, mitigation and remediation. Notifications will be sent to the customer's designated account or security contact, or to the account email if no security contact has been recorded.
7. Transfers
For transfers restricted by applicable data-protection law, the parties will use the appropriate adequacy decision, Standard Contractual Clauses, UK addendum or other lawful mechanism, with the required supplementary measures and transfer-impact assessment.
8. Return and deletion
At the end of the Service, or after a verified deletion request, CONSELA will provide an export and apply the applicable account, project or organization deletion workflow. Member-account deletion is scheduled for processing after a 14-day grace period, during which the member may cancel; eligible processing removes the member's access and anonymizes the member while preserving Controller Data belonging to the organization. Project deletion is scheduled for 14 days, hides the project immediately, and may be cancelled by restoring the project during the grace period. At the end of that period, project meetings, reports, files and related content are permanently purged unless a documented legal or security hold applies. Organization deletion is scheduled for 14 days, disables organization changes and invitations immediately, and may be cancelled during the grace period. After that period, the organization is quarantined while applicable export, security and retention processes are completed. Encrypted production backups are retained on a rolling 14-day schedule; security logs, legal-acceptance records, accounting duties and security investigations may require limited retention. Normal OpenCode/LLM sessions and traces are not retained after processing unless an administrator explicitly enables a debug trace, which expires after 14 days. The customer may request an export through Your Data Rights or by contacting CONSELA.
9. Audit and precedence
CONSELA will provide information reasonably needed to demonstrate compliance and support audits subject to confidentiality, security and proportionality. This DPA supplements the Terms of Service; if there is a conflict about processing of Controller Data, this DPA prevails.
Questions about this DPA: [email protected]. CONSELA handles DPA communications by email and does not offer telephone support.