Legal
Storm OS Data Processing Addendum
How we process personal data on your behalf. It forms part of the Terms and applies automatically, with no signature needed.
Effective date: August 12, 2026
Last updated: August 12, 2026
Version: 1.0
1. Parties and scope
This Data Processing Addendum ("DPA") forms part of the Storm OS Terms of Service at https://storm-os.app/terms (the "Agreement") between:
Processor / Service Provider: On-Call CMO LLC, a Pennsylvania limited liability company doing business as Storm OS, of 239 4th Ave, Ste 1401, Pittsburgh, PA 15222, USA ("Storm OS," "we," "us"); and
Controller / Business: the customer that has accepted the Agreement ("Customer," "you").
This DPA applies where Storm OS processes Personal Data on Customer's behalf in providing the Service, and it applies automatically, with no signature required, from the date Customer accepts the Agreement. Customer may also request a countersigned copy at legal@storm-os.com.
This DPA does not apply to Account Data, security telemetry, or diagnostic data for which Storm OS acts as a controller in its own right. That processing is governed by the Privacy Policy.
2. Definitions
| Term | Meaning |
|---|---|
| Customer Personal Data | Personal Data contained within Customer Data, as defined in the Agreement: the records, notes, tasks, files, custom fields, and configuration inside Customer's Workspace. |
| Data Protection Laws | All laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other US state privacy laws including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and Texas TDPSA. |
| Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Supervisory Authority | As defined in the GDPR. Where the CCPA applies, Business, Service Provider, Consumer, Personal Information, Sell, and Share carry their CCPA meanings, and the corresponding GDPR term is read to include it. |
| SCCs | The Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021. |
| UK Addendum | The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018, version B1.0. |
| Subprocessor | Any third party engaged by Storm OS to process Customer Personal Data. |
3. Roles of the parties
3.1 Customer is the Controller (and Business) of Customer Personal Data. Storm OS is the Processor (and Service Provider) and processes Customer Personal Data only on Customer's documented instructions.
3.2 Customer determines what Personal Data it puts into the Service, why, and who may access it. Customer is responsible for having a lawful basis for that processing, for providing any required notices to Data Subjects, and for the accuracy and legality of Customer Personal Data. This matters more than usual for a relationship management product: Customer Personal Data will typically include information about prospects, investors, partners, and their staff who have not interacted with Storm OS directly.
3.3 Where Customer is itself a processor for another controller, Customer warrants that it has authority to appoint Storm OS as a subprocessor on the terms of this DPA, and references to Customer's instructions include instructions from that controller as passed through by Customer.
3.4 For any processing outside the scope of §1, each party acts as an independent controller.
4. Instructions
4.1 Storm OS will process Customer Personal Data only:
(a) as necessary to provide, secure, and maintain the Service under the Agreement;
(b) in accordance with Customer's further documented instructions, where those instructions are consistent with the Agreement and technically feasible; and
(c) as required by applicable law, in which case Storm OS will inform Customer of that requirement before processing unless the law prohibits it on important grounds of public interest.
4.2 The Agreement, this DPA, Customer's configuration of the Service, and Customer's use of Service features constitute Customer's complete documented instructions.
4.3 Storm OS will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend that instruction until it is amended or confirmed. Storm OS may decline instructions that would require material changes to the Service or that it reasonably believes to be unlawful.
4.4 Prohibited uses. Storm OS will not:
(a) Sell or Share Customer Personal Data, as those terms are defined in the CCPA;
(b) retain, use, or disclose Customer Personal Data for any purpose other than performing the Service, including any commercial purpose of its own, except as permitted by Data Protection Laws;
(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Storm OS and Customer;
(d) combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from its own interactions with a Consumer, except as permitted for a Service Provider under the CCPA; or
(e) use Customer Personal Data to train, fine-tune, benchmark, or evaluate machine-learning or generative artificial intelligence models, whether Storm OS's own or a third party's.
4.5 Storm OS certifies that it understands the restrictions in §4.4 and will comply with them.
4.6 Aggregated and deidentified data. Storm OS may create and use aggregated or deidentified data derived from operating the Service (for example, volumetric and performance statistics) for capacity planning, security, and product improvement, provided such data cannot reasonably be used to identify any Data Subject or Customer, Storm OS commits to maintaining it in deidentified form, does not attempt to reidentify it, and contractually obligates any recipient to the same.
5. Confidentiality and personnel
5.1 Storm OS will treat Customer Personal Data as Customer's Confidential Information under the Agreement.
5.2 Storm OS will ensure that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations that survive termination of employment, are trained on their data protection responsibilities, and are granted access only on a least-privilege, need-to-know basis.
5.3 Personnel access to Workspace content. Storm OS does not routinely access Customer Personal Data. Personnel may access it only:
(a) at Customer's request, to provide support, via a support session that requires a stated reason, is capped at 60 minutes, displays a persistent in-app banner to the acting user, is recorded in Storm OS's platform audit log, and is written to Customer's own Workspace audit log so Customer's administrators can see who accessed what, when, and why;
(b) as strictly necessary to investigate or remediate a security incident, data corruption, abuse, or a serious availability failure, limited to what the investigation requires and audited on the same terms; or
(c) where compelled by law, subject to §7.3.
Support sessions cannot change a user's password or email address, and cannot export Customer Data, unless the acting operator holds an explicitly elevated support permission. Development and testing are performed against synthetic seed data.
6. Security
6.1 Storm OS will implement and maintain the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
6.2 Storm OS may update those measures over time provided the overall level of protection is not materially reduced.
6.3 Customer is responsible for the security decisions within its control: configuring Workspace access defaults, sharing rules and roles; enabling and enforcing multi-factor authentication; managing membership and promptly deactivating departed users; and securing the devices on which the Progressive Web App is installed.
7. Subprocessors
7.1 General authorization. Customer grants Storm OS general authorization to engage Subprocessors, subject to this §7. The Subprocessors engaged as at the effective date are listed in Annex III and maintained at https://storm-os.app/subprocessors.
7.2 Notice and objection. Storm OS will give Customer at least 30 days' notice before adding or replacing a Subprocessor that processes Customer Personal Data, by email to Workspace Admins and by updating the subprocessors page. Customer may object on reasonable data protection grounds within that period by written notice to privacy@storm-os.com. The parties will discuss the objection in good faith; if Storm OS cannot offer a reasonable alternative, Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid unused fees.
7.3 Flow-down and liability. Storm OS will impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Subprocessor's performance.
7.4 Where a Subprocessor is located outside the EEA, UK, or Switzerland, Storm OS will ensure an appropriate transfer mechanism is in place under §10.
8. Data subject rights and assistance
8.1 Self-service first. The Service gives Customer the tools to respond to most Data Subject requests directly: search, record edit and delete, soft delete with a 30-day Recycle Bin, merge, and full Workspace export in CSV/JSON. Customer will use those tools where they are sufficient.
8.2 Assistance. Taking into account the nature of the processing, Storm OS will provide reasonable assistance, by appropriate technical and organizational measures and insofar as possible, to help Customer fulfil its obligations to respond to requests for access, rectification, erasure, restriction, portability, and objection.
8.3 Requests received by Storm OS. If Storm OS receives a request from a Data Subject relating to Customer Personal Data, it will not respond substantively other than to acknowledge and redirect, and will notify Customer without undue delay (and in any event within 10 business days) so Customer can respond as Controller. Storm OS will not alter or delete Customer's records in response to such a request without Customer's instruction.
8.4 Further assistance. Storm OS will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities under GDPR Articles 35 and 36, and with Customer's obligations under Articles 32 to 36 generally, taking into account the information available to Storm OS.
8.5 Assistance beyond what is reasonably required by Data Protection Laws, or that is disproportionate in scope or frequency, may be chargeable at Storm OS's then-current professional services rates, on prior notice.
9. Personal Data Breach
9.1 Storm OS will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it, by email to Workspace Admins and the security contact on file.
9.2 The notification will include, to the extent known and as it becomes known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a contact point for further information. Where information is not available at the time of notification, Storm OS will provide it in phases without further undue delay.
9.3 Storm OS will take reasonable steps to contain, investigate, and remediate the breach, and will preserve relevant logs and evidence.
9.4 Storm OS's notification is not an acknowledgment of fault or liability. Customer is responsible for determining whether the breach requires notification to Supervisory Authorities or Data Subjects and for making those notifications. Storm OS will not notify any Supervisory Authority or Data Subject on Customer's behalf without Customer's prior consent, except where independently required to do so by law.
9.5 Customer will keep an accurate security contact email current in the Workspace Admin console.
10. International transfers
10.1 Customer acknowledges that Storm OS is established in the United States and that provision of the Service involves transfer of Customer Personal Data to the United States and, where applicable, to Subprocessor locations identified in Annex III.
10.2 EEA transfers. Where Customer Personal Data is transferred from the EEA to a country that is not the subject of an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (Controller to Processor) applies where Customer is a Controller;
- Module Three (Processor to Processor) applies where Customer is a Processor acting on behalf of a third-party controller;
- Clause 7 (docking clause) applies;
- Clause 9, Option 2 (general written authorization) applies, with the notice period specified in §7.2 of this DPA;
- Clause 11(a) optional language (independent dispute resolution) does not apply;
- Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;
- Clause 18(b): disputes will be resolved before the courts of Ireland;
- Annex I to the SCCs is populated by Annexes I(A), I(B), and I(C) of this DPA;
- Annex II to the SCCs is populated by Annex II of this DPA;
- Annex III to the SCCs (where used) is populated by Annex III of this DPA.
10.3 UK transfers. The UK Addendum is incorporated and applies to transfers from the UK, completed as set out in Annex IV.
10.4 Swiss transfers. For transfers subject to the FADP, the SCCs apply with these amendments: references to the GDPR are read as references to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; the term "Member State" does not limit Data Subjects in Switzerland from bringing proceedings in their place of habitual residence; and the SCCs also protect the data of legal entities until the FADP no longer extends to them.
10.5 Supplementary measures. In addition to the SCCs, Storm OS applies the measures in Annex II, including encryption in transit and at rest, tenant isolation enforced in the database layer, least-privilege and audited personnel access, and the government-request handling in §10.6, as supplementary measures supporting the transfer.
10.6 Government access requests. If Storm OS receives a legally binding request from a public authority for Customer Personal Data, it will: (a) review the request for lawfulness and challenge it where there are reasonable grounds to consider it unlawful, overbroad, or defective, seeking interim relief where appropriate; (b) disclose only the minimum data legally required; and (c) notify Customer of the request before disclosure where legally permitted, or, if prohibited, seek a waiver of the prohibition and provide such information as it is lawfully able, as promptly as possible. Storm OS will document such requests and provide the information required by Clause 15 of the SCCs.
10.7 Alternative mechanisms. If a transfer mechanism relied on here is invalidated, amended, or superseded, the parties will work in good faith to implement a valid alternative (including any successor clauses) without undue delay, and Storm OS may update this DPA accordingly on notice.
11. Audit and information rights
11.1 Storm OS will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. In the first instance this will be satisfied by: this DPA and its Annexes, the Privacy Policy, the subprocessors page, and a completed standard security questionnaire (Storm OS will use commercially reasonable efforts to complete Customer's own questionnaire once per twelve-month period).
11.2 Where the documentation in §11.1 is genuinely insufficient to demonstrate compliance, Customer may conduct an audit, itself or through an independent auditor bound by confidentiality that does not compete with Storm OS, subject to: at least 30 days' prior written notice; no more than once per twelve-month period except following a Personal Data Breach affecting Customer or where required by a Supervisory Authority; conduct during normal business hours; a scope limited to Storm OS's processing of Customer Personal Data; and no access to other customers' data, to Storm OS's own confidential commercial information, or to production Personal Data of any kind.
11.3 Customer bears its own audit costs and will reimburse Storm OS's reasonable costs for audits beyond the first in any twelve-month period.
11.4 Where the SCCs apply, this §11 is the parties' agreed means of exercising the audit rights in Clause 8.9, without limiting those rights where they cannot be limited by law.
12. Return and deletion
12.1 On termination or expiry of the Agreement, Customer may export Customer Personal Data in full, as a documented CSV/JSON bundle covering all objects, custom fields, and relationships, for 30 days, using the Workspace export in the Admin console.
12.2 After the export period, Storm OS will delete Customer Personal Data from active systems within 30 days, and it will age out of backups within Storm OS's rolling backup expiry cycle (currently 35 days). Storm OS will certify deletion in writing on request.
12.3 Storm OS may retain Customer Personal Data to the extent required by applicable law, and will continue to protect it under this DPA for as long as it is retained.
13. General
13.1 Order of precedence. In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the rest of the Agreement, in each case only as to the subject matter of the conflict.
13.2 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent Data Protection Laws prohibit that limitation. Nothing in this §13.2 limits any Data Subject's rights under the SCCs.
13.3 Term. This DPA takes effect with the Agreement and continues until Storm OS ceases to process Customer Personal Data, at which point the obligations that by their nature should survive will do so.
13.4 Changes. Storm OS may update this DPA where required by changes in Data Protection Laws, changes to the Service, or the introduction of new transfer mechanisms, on at least 30 days' notice to Workspace Admins, provided no update materially reduces the protections afforded to Customer Personal Data.
13.5 Governing law. Except where the SCCs, UK Addendum, or Data Protection Laws require otherwise, this DPA is governed by the law and venue specified in the Agreement.
13.6 Contact. Data protection matters: privacy@storm-os.com. Security matters and incident reports: security@storm-os.com. Contractual matters: legal@storm-os.com.
Annex I(A): Parties
Data exporter (Controller / Processor): the Customer identified in the Agreement.
Contact: the Workspace Admin email address and any privacy contact designated by Customer in the Workspace Admin console.
Activities relevant to the transfer: use of the Storm OS relationship and pipeline management service.
Role: Controller (or Processor where §3.3 applies).
Signature and date: deemed executed on Customer's acceptance of the Agreement.
Data importer (Processor): On-Call CMO d/b/a Storm OS, 239 4th Ave, Ste 1401, Pittsburgh, PA 15222, USA.
Contact: privacy@storm-os.com.
Activities relevant to the transfer: hosting and operating the Storm OS application, database, file storage, transactional email, and support.
Role: Processor.
Signature and date: deemed executed on Customer's acceptance of the Agreement.
Annex I(B): Description of processing
Categories of Data Subjects
- Customer's Authorized Users: founders, employees, contractors, advisors, and observers with Workspace access
- Customer's prospects, leads, and customers, and their employees and representatives
- Current and prospective investors, and the employees and representatives of funds and syndicates
- Partners, resellers, referrers, and their employees and representatives
- Any other individual whose details Customer chooses to record in its Workspace
Categories of Personal Data
- Identity and contact: name, job title, employer, email address, telephone number, postal or business address, social profile URLs, website and domain
- Account and authentication (Authorized Users): password hash, Google identity provider subject identifier, MFA enrolment status, session and device metadata, IP address at sign-in
- Relationship and workflow: relationship role and sub-type, engagement level, ownership, introductions and associations, pipeline and stage, opportunity value and line items, tasks, next steps, loss reasons, tags, relationship fit and activity scores
- Interaction records: notes, logged activities, meeting and call records entered by users, timeline events
- Content: attachments and documents uploaded by Authorized Users, which may contain Personal Data determined solely by Customer
- Custom fields: additional fields defined by Customer, the content of which is determined solely by Customer
- Audit: actor, timestamp, device summary, and before/after values for audited actions
Sensitive data. The Service is not designed for and Customer is contractually prohibited from submitting special category data under GDPR Article 9, criminal offence data under Article 10, government identifiers, payment card numbers, health records, precise biometric data, or precise geolocation. If Customer nonetheless submits such data through free-text fields, custom fields, or attachments, Customer does so as Controller and at its own risk, and the restrictions in the Agreement apply.
Frequency of transfer: continuous, for the duration of the Agreement.
Nature of the processing: collection, recording, organization, structuring, storage, retrieval, consultation, use, indexing, deduplication and merging, scoring, synchronization to Authorized Users' devices for offline use, backup, disclosure to Authorized Users and authorized Integrations, erasure, and destruction.
Purpose of the processing: providing the Storm OS relationship and pipeline management service to Customer under the Agreement, including hosting, synchronization, notification, reporting, support, and security.
Duration: for the term of the Agreement, plus the retention and deletion periods in §12 of this DPA.
Subprocessor processing: as described in Annex III, for the duration of the Agreement or until the Subprocessor is replaced.
Annex I(C): Competent Supervisory Authority
Where the data exporter is established in an EEA Member State, that Member State's Supervisory Authority.
Where the data exporter is not established in the EEA but falls within the territorial scope of the GDPR under Article 3(2) and has appointed a representative under Article 27, the Supervisory Authority of the Member State in which that representative is established.
Where the data exporter is not established in the EEA and has not appointed a representative, the Supervisory Authority of Ireland, consistent with the choice of law in §10.2. Storm OS has not appointed an Article 27 representative, on the basis that it markets the Service in the United States only, quotes prices solely in US dollars, and offers the Service solely in English. It will appoint one and update this Annex before actively marketing to the EU or UK.
Annex II: Technical and organizational measures
Storm OS maintains the following measures. Detail is current as at the effective date and may be updated under §6.2.
Pseudonymization and encryption
- TLS 1.2 or higher for all data in transit, with HSTS enforced on
storm-os.appandstorm-os.com - Encryption at rest at the storage layer for the Postgres database, blob storage, and backups
- Passwords hashed with Argon2id and a minimum strength requirement; passwords never stored or logged in recoverable form
- Attachments and export bundles stored privately and served only through short-lived signed URLs; no publicly addressable object storage
Confidentiality and access control
- Multi-tenant isolation: every tenant row carries a workspace identifier; Postgres row-level security is applied as defense in depth; cross-tenant access is covered by a fail-closed test in continuous integration
- A single server-side authorization module resolves access on every read and write, and the same module trims list, search, report, and offline-sync results, so clients never receive records they are not entitled to
- Capability roles (Admin, Manager, Member, Read-Only) combined with per-object access defaults, admin sharing rules, and per-record shares, all configurable by Customer
- Short-lived access tokens plus rotating refresh tokens stored in
httpOnly,Secure,SameSite=Laxcookies, never readable by client-side script; refresh-token reuse detection invalidates the entire session family - Optional TOTP multi-factor authentication per user; Workspace-wide MFA enforcement available to Customer administrators
- Per-device session listing with individual and global sign-out; deactivating a member immediately revokes sessions and API access
- Least-privilege personnel access; support access to Workspace content only under the reason-gated, time-capped, dual-audited process in §5.3
- Brute-force protection with per-account and per-IP throttling and progressive delays
Integrity
- Append-only audit logging of authentication, membership, role, permission and sharing changes, schema changes, merges, deletions, purges and restores, imports and undo, exports, branding changes, and support sessions, retained 400 days and exportable by Customer administrators
- Idempotency keys on unsafe endpoints and per-mutation identifiers on offline sync, preventing duplicate application of retried writes
- Field-level conflict detection with explicit user resolution for concurrent offline edits
- Soft deletion with a 30-day Recycle Bin; merges reversible for 7 days; imports fully undoable for 7 days
- Schema-level input validation on every API payload
Availability and resilience
- Serverless architecture with automatic scaling and no single points of manual intervention
- Managed database with point-in-time recovery and automated backups
- Documented disaster recovery procedure with restore drills and recorded RTO/RPO targets
- Error monitoring, function error-rate dashboards, dead-letter queue with retry for background jobs
Testing and assurance
- Automated unit, integration, and end-to-end test suites gating every deployment, including negative authorization tests on every endpoint
- Dependency vulnerability scanning
- Automated unit, integration, and end-to-end test suites gating every deployment, including denied-path authorization tests on every endpoint, with severity-1 and severity-2 findings remediated before release. Storm OS has not yet commissioned an independent third-party penetration test; it will update this Annex and notify Customers when one is completed
Device and endpoint measures (Progressive Web App)
- Offline data scoped to the signed-in user and Workspace, and wiped on sign-out
- Authentication never stored in JavaScript-readable browser storage
- Optional app lock requiring re-authentication after inactivity
- Remote session revocation honored on the device's next connection
- Attachment binaries not stored offline
Organizational measures
- Written confidentiality obligations for all personnel with access
- Data protection and security awareness training
- Documented incident response procedure with defined notification timelines
- Subprocessor due diligence and contractual flow-down of these obligations
- Development and testing against synthetic seed data
Measures for transfers
- The government-request handling process in §10.6
- Storm OS does not currently publish a periodic transparency report. It will notify affected Customers of compelled disclosures directly, as set out in §10.6
Annex III: Subprocessors
| Subprocessor | Legal entity and location | Processing activity | Personal Data processed | Location of processing |
|---|---|---|---|---|
| Netlify | Netlify, Inc., USA | Application hosting, serverless functions, CDN, blob storage for attachments and export bundles, error and performance monitoring | All Customer Personal Data in transit; attachments and files at rest; diagnostic data | USA |
| Neon | Neon, Inc., USA | Managed Postgres database | All Customer Personal Data at rest | United States and Germany |
| Resend | Resend, Inc., USA | Transactional email (verification, invitations, notifications) | Recipient name and email address, message content | USA |
| Google LLC | Google LLC, USA | Identity provider, where an Authorized User signs in with Google | Sign-in identity only | USA |
| Stripe | Stripe, Inc., USA | Subscription billing and payment processing | Billing contact name, email, address, tax ID | USA |
The current list is maintained at https://storm-os.app/subprocessors.
Annex IV: UK International Data Transfer Addendum
Completed in accordance with the UK Addendum (version B1.0).
Table 1: Parties. As set out in Annex I(A). Start date: the date Customer accepted the Agreement.
Table 2: Selected SCCs, Modules and Selected Clauses. The SCCs as incorporated by §10.2 of this DPA, including the modules and optional clauses selected there, and Annexes I to III as populated by this DPA.
Table 3: Appendix Information.
- Annex 1A (List of Parties): Annex I(A) of this DPA
- Annex 1B (Description of Transfer): Annex I(B) of this DPA
- Annex II (Technical and organisational measures): Annex II of this DPA
- Annex III (List of Sub processors): Annex III of this DPA
Table 4: Ending the Addendum when the Approved Addendum Changes. Neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.
Acceptance
This DPA is accepted by Customer on acceptance of the Agreement and requires no signature. A countersigned PDF is available on request at legal@storm-os.com.
On-Call CMO d/b/a Storm OS
239 4th Ave, Ste 1401, Pittsburgh, PA 15222, USA
privacy@storm-os.com · security@storm-os.com · legal@storm-os.com
Questions about any of this go to legal@storm-os.com. Privacy requests go to privacy@storm-os.com, and anything security related to security@storm-os.com.