﻿# Osolix · PDPL Data Protection Impact Assessment (DPIA) — v1

**Status:** Wave-B Foundation evidence · 2026-Q2
**Jurisdictions:** UAE Federal Decree-Law 45/2021 (PDPL), KSA PDPL, EU GDPR, UK GDPR
**Owner:** Chief Compliance Officer
**Audit dimensions:** #13 Compliance · #19 Data integrity & migration

## 1 · Purpose of processing

Osolix is a B2B fixed-asset platform. Personal data is processed only to the extent required to operate the customer's account: authentication, authorisation, audit trail, and notifications. There is no marketing-data sale, no profile resale, no cross-customer data pooling.

## 2 · Data categories

| Category | Examples | Subjects | Retention |
|---|---|---|---|
| Account | Email, name, hashed password, MFA secret | Customer's employees | Active + 90 days post-termination |
| Custodian PII | Phone, national ID (optional), photo | Customer's employees / contractors | Per customer's retention policy; default 7 years |
| Audit trail | User ID, IP, user-agent, timestamp, action, before/after value | Every signed-in user | 7 years (financial-reg minimum) |
| Telemetry | Page load time, error events (no PII payload) | Customer's employees | 90 days |
| Support session | Operator user ID, reason, expiry | Customer + Osolix support staff | 1 year |

## 3 · Lawful basis

* **Contract** — processing is necessary to deliver the customer's subscribed service.
* **Legitimate interest** — security logging, fraud detection, audit trail.
* **Consent** — marketing emails (separate opt-in via NotificationPreferences), product analytics (cookie banner).
* **Legal obligation** — retention of financial records.

## 4 · Data flows

| Flow | Source | Destination | Encryption |
|---|---|---|---|
| Browser → API | Customer browser | Azure App Service | TLS 1.2+ |
| API → DB | App Service | Azure SQL | TLS in transit, TDE at rest |
| API → Anthropic | App Service | api.anthropic.com | TLS; only the anonymised question + tenant-scoped data summary; no PII payload |
| API → Stripe | App Service | api.stripe.com | TLS; tokenised payment data only |
| API → SendGrid | App Service | api.sendgrid.com | TLS; recipient email only |
| API → ERP (outbox) | App Service | Customer's allow-listed endpoint | HTTPS to customer's URL; payload signed |

## 5 · Sub-processors

| Sub-processor | Purpose | DPA on file | SOC 2 |
|---|---|---|---|
| Microsoft Azure | Hosting (compute, DB, storage, Key Vault) | ✅ | ✅ |
| Anthropic | LLM-powered AI chat polishing | ✅ | ✅ |
| Stripe | Subscription billing | ✅ | ✅ |
| SendGrid | Transactional email | ✅ | ✅ |

## 6 · Data subject rights — implementation

| Right | Endpoint / surface |
|---|---|
| Access | `GET /api/me/export` returns a JSON archive of the user's account + custodian records |
| Rectification | `Profile` page; email change uses verification flow |
| Erasure | `DELETE /api/me` triggers `DataRetentionService` workflow (immediate logical delete + 30-day purge) |
| Restriction of processing | TenantAdmin can suspend a user without deleting |
| Portability | Same `GET /api/me/export` endpoint returns a portable JSON archive |
| Objection | `NotificationPreferences` page lets the user opt out of every non-essential email |
| Avoid automated decisions | AI chat answers are advisory; every workflow approval requires a human |

## 7 · Risk assessment

| Risk | Likelihood | Impact | Mitigation | Residual |
|---|---|---|---|---|
| Cross-tenant data leak | Low | Critical | Tenant query filter + RBAC tests + cross-tenant probe suite | Low |
| Credential stuffing | Medium | High | Lockout after 5 failures + MFA + WebAuthn passkey roadmap | Low |
| LLM prompt-leak via Anthropic | Low | Medium | No PII payload in prompts; tenant data summarised before send | Low |
| Backup tape loss | Low | Critical | Geo-redundant copy + Key-Vault-managed encryption | Low |
| Insider abuse (Osolix staff) | Low | High | Support session step-up requires customer consent + time-boxed + fully audited | Low |
| Public concierge — visitor pastes PII/special-category into free text | Medium | Medium | "No sensitive data" input notice; inbound PII scrubber before LLM + before logging; transcripts not persisted | Low |
| Public concierge — cross-border transfer to US LLM without safeguard | Medium | High | Online path disabled until the executed Anthropic DPA/SCC (prod key unset → Offline-only); scrubbed payload only | High until DPA executed |
| Public concierge — hallucination / wrong public advice | Medium | Medium | Deterministic grounding + mandatory citations; cite-or-escalate; LLM only rephrases the grounded answer; RAI-ENG-02 eval gate in CI | Low |

## 8 · Open items
* Cookie consent banner + analytics opt-out toggle (P1.2).
* Right-to-erasure automation finish (`DataRetentionService` v1).
* DSR (Data Subject Request) intake portal at `/welcome/Company/privacy/request`.
* Execute the Anthropic DPA/SCC for anonymous public-concierge traffic before enabling the Online path in production (Decision 0071).

## 9 · Sign-off
* CCO: pending Q2 review
* CISO: pending Q2 review
