DATA PROCESSING AGREEMENT (DPA)
Omega MES – Standard GDPR Data Processing Agreement
Effective Date: 2026-06-01
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions (“Agreement”) between:
DDCS Szoftver Ltd.
1125 Budapest, Istenhegyi út 101/D, Hungary
Company Registration Number: 01-09-376037
VAT Number: HU28834553
(hereinafter referred to as the “Processor”)
and
the Customer using the Omega MES platform
(hereinafter referred to as the “Controller”).
1. Purpose of the Agreement
This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the Omega MES cloud-based Manufacturing Execution System platform and related services.
The Parties agree to comply with:
- Regulation (EU) 2016/679 (“GDPR”)
- applicable Hungarian and European Union data protection laws.
2. Subject Matter and Duration
The Processor shall process personal data solely for the purpose of providing the Omega MES services during the term of the Agreement.
Processing shall continue only for as long as necessary to provide the Service or fulfill legal obligations.
3. Nature and Purpose of Processing
Processing activities may include:
- storage of customer and employee data;
- user authentication and account management;
- production and operational data processing;
- support and ticket handling;
- system monitoring and security logging;
- billing and subscription management;
- communication and notification services.
The purpose of processing is to provide, maintain, secure, and improve the Omega MES platform.
4. Categories of Personal Data
The Processor may process the following categories of personal data:
- names;
- business contact information;
- email addresses;
- usernames;
- encrypted passwords;
- IP addresses;
- device and browser information;
- system activity logs;
- support communications;
- billing and subscription information.
The Processor does not intentionally process special categories of personal data under Article 9 GDPR unless explicitly instructed by the Controller.
5. Categories of Data Subjects
Data subjects may include:
- Customer employees;
- system administrators;
- operators and production staff;
- subcontractors;
- customer representatives;
- support contacts.
6. Obligations of the Controller
The Controller confirms that:
- it has a valid legal basis for processing personal data;
- it has informed data subjects as required by GDPR;
- it is responsible for the accuracy and legality of uploaded data;
- it shall not upload unlawful or prohibited personal data.
The Controller remains the Data Controller of all uploaded operational and personal data.
7. Obligations of the Processor
The Processor shall:
- process personal data only on documented instructions from the Controller;
- ensure confidentiality of authorized personnel;
- implement appropriate technical and organizational security measures;
- assist the Controller in fulfilling GDPR obligations where applicable;
- notify the Controller without undue delay in the event of a personal data breach.
The Processor shall not sell personal data to third parties.
8. Security Measures
The Processor implements commercially reasonable technical and organizational measures including:
- SSL/TLS encrypted communication;
- password encryption and authentication controls;
- role-based access management;
- firewall and hosting security protections;
- system logging and monitoring;
- regular software updates;
- backup and recovery procedures.
The Controller acknowledges that no internet-based service can guarantee absolute security.
9. Subprocessors
The Controller authorizes the Processor to engage subprocessors necessary for operating the Service.
Subprocessors may include:
- Heroku (Salesforce Inc.)
- Stripe
- HubSpot
- Sender.net
- Bluehost
- cloud hosting and infrastructure providers
- analytics and communication providers
The Processor shall ensure that subprocessors are subject to appropriate contractual and GDPR obligations.
10. International Data Transfers
Some subprocessors may process data outside the European Economic Area (EEA), including in the United States.
Where required, transfers shall be protected through:
- Standard Contractual Clauses (SCCs);
- GDPR-compliant contractual safeguards;
- adequacy decisions where applicable.
11. Assistance to the Controller
Taking into account the nature of processing, the Processor shall provide reasonable assistance regarding:
- data subject requests;
- security obligations;
- breach notifications;
- data protection impact assessments where applicable.
12. Personal Data Breach Notification
In the event of a personal data breach affecting Customer data, the Processor shall notify the Controller without undue delay after becoming aware of the breach.
Notifications may include:
- nature of the breach;
- likely consequences;
- measures taken or proposed;
- recommended mitigation steps.
13. Deletion and Return of Data
Upon termination of the Agreement, the Processor may delete or anonymize Customer personal data after a reasonable retention period unless retention is required by law.
The Controller is responsible for exporting necessary data before termination.
14. Audit Rights
Where legally required and reasonably justified, the Controller may request information regarding the Processor’s compliance with this DPA.
Any audit request must:
- be reasonable in scope;
- avoid disruption of operations;
- respect confidentiality and security obligations.
15. Limitation of Liability
Liability related to personal data processing shall be subject to the limitations defined in the General Terms and Conditions unless otherwise required by applicable law.
16. Governing Law
This DPA shall be governed by the laws of Hungary and applicable European Union legislation.
Any disputes arising from this DPA shall fall under the jurisdiction of the competent Hungarian courts.
17. Contact Information
DDCS Szoftver Ltd.
1125 Budapest, Istenhegyi út 101/D
Hungary
Email: info@omegames.co.uk
Website: https://omegames.co.uk