﻿# Osolix · Records of Processing Activities (RoPA) — v1

**Status:** Wave-B Foundation evidence · 2026-Q2
**Owner:** Chief Compliance Officer (Data Protection Officer)
**Article reference:** GDPR Art. 30 · UAE PDPL Art. 26 · KSA PDPL Art. 21
**Re-attestation:** Annually + on every new processing activity

This document is the canonical Records of Processing Activities (RoPA)
register that the Osolix Data Protection Officer maintains under GDPR
Article 30. It catalogues every processing activity Osolix carries out,
the lawful basis, the data categories, the recipients, and the retention.
It is shared with regulators on request and reviewed annually.

## 1 · Controller / Processor identity

| Role | Identity |
|---|---|
| Controller (Osolix as platform owner) | Osolix FZ-LLC, Dubai Internet City, UAE |
| Joint Controller (customer tenant) | The customer organisation hosting the tenant |
| Processor (sub-processor: cloud) | Microsoft Azure (UAE North + UK South regions) |
| Processor (sub-processor: AI) | Anthropic PBC (US) — tenant Atlas chat (AiMode = Online) AND the public marketing concierge Online path (anonymous, Decision 0071); the Offline default never sends to the LLM |
| Processor (sub-processor: billing) | Stripe Inc. (US, Ireland) |
| Processor (sub-processor: email) | Twilio SendGrid Inc. (US) |
| DPO contact | dpo@osolix.com |

## 2 · Processing activities

### Activity 1 — User authentication + access control
| Field | Value |
|---|---|
| Purpose | Authenticate users + enforce RBAC + audit access |
| Lawful basis | Contract (necessary to deliver the service) |
| Categories of subjects | Customer's employees, contractors |
| Categories of personal data | Email, hashed password, MFA secret, IP, user-agent, login-attempt log |
| Recipients | Internal Osolix support team (with customer consent) |
| Retention | Active + 90 days post-termination; audit log 7 years |
| Cross-border transfer | Azure UAE North primary; backups to UK South (adequacy decision applies) |
| Security measures | TLS 1.2+; bcrypt(12); MFA; account lockout; structured audit logging |

### Activity 2 — Custodian PII for asset accountability
| Field | Value |
|---|---|
| Purpose | Track who is responsible for each fixed asset |
| Lawful basis | Legitimate interest (asset stewardship) |
| Subjects | Customer's employees / contractors who custody assets |
| Data | Name, employee ID, photo (optional), national ID (optional), department, position |
| Recipients | Customer's tenant administrators + finance team |
| Retention | Per customer's policy; default 7 years (financial-record retention) |
| Cross-border transfer | None — stays in tenant's chosen region |
| Security measures | Tenant-isolated query filter; column-level access control via UserFarColumnAccess |

### Activity 3 — AI assistance (Atlas chat)
| Field | Value |
|---|---|
| Purpose | Provide conversational AI assistance to tenant users |
| Lawful basis | Contract |
| Subjects | Customer's employees who use Atlas |
| Data | Question text, anonymised tenant data summary, page context (route + label only) |
| Recipients | Anthropic (only when tenant.AiMode = Online); offline tenants never send to LLM |
| Retention | Question + answer cached 30 days for governance dashboard; Anthropic retains 30 days per their DPA |
| Cross-border transfer | Anthropic US — adequacy via SCCs |
| Security measures | TLS; no PII payload (only question + scrubbed summary); per-tenant API isolation |

### Activity 4 — Billing + subscription management
| Field | Value |
|---|---|
| Purpose | Charge for the subscription; deliver invoices |
| Lawful basis | Contract + legal obligation (tax) |
| Subjects | Customer's billing contact |
| Data | Name, billing email, billing address, VAT TRN, payment method (tokenised) |
| Recipients | Stripe (payment processor); customer's tax authority on regulator request |
| Retention | 7 years (financial-record retention) |
| Cross-border transfer | Stripe US/IE — adequacy via SCCs |
| Security measures | Stripe Tokenization; PCI-DSS Level 1 sub-processor; webhook signature validation |

### Activity 5 — Transactional email
| Field | Value |
|---|---|
| Purpose | Email-verification, approval requests, maintenance reminders, lease renewals |
| Lawful basis | Contract + legitimate interest |
| Subjects | Customer's employees |
| Data | Recipient email, name, tenant + entity name, approval / event payload |
| Recipients | SendGrid (email transit); recipients themselves |
| Retention | 30 days log retention |
| Cross-border transfer | SendGrid US — adequacy via SCCs |
| Security measures | TLS; SPF/DKIM/DMARC aligned; one-click unsubscribe on non-essential mail |

### Activity 6 — Audit trail
| Field | Value |
|---|---|
| Purpose | Demonstrate platform integrity + comply with SOX 404 / IFRS audit requirements |
| Lawful basis | Legal obligation + legitimate interest |
| Subjects | Every signed-in user |
| Data | User ID, IP, user-agent, action, before/after value, timestamp |
| Recipients | Customer's tenant administrators + auditors |
| Retention | 7 years (regulatory minimum) |
| Cross-border transfer | None — same region as tenant data |
| Security measures | Append-only via AuditInterceptor; row-version concurrency; tenant isolation |

### Activity 7 — Public marketing concierge chat + sandbox/lead intake
| Field | Value |
|---|---|
| Purpose | Answer anonymous website visitors' product/pricing questions; capture sales leads + sandbox-demo requests (Decision 0071) |
| Lawful basis | Legitimate interest (responding to an inbound sales enquiry); LLM forwarding is minimised + disclosed (EU AI Act Art. 50) |
| Subjects | Anonymous public website visitors (prospects; not yet customers) |
| Data | Visitor-typed question (free text); optional work email + message on the lead form; client IP + user-agent on the lead row only. No special-category data solicited (input notice) |
| Recipients | Anthropic PBC (US) — ONLY on the Online path, and only the PII-scrubbed question + the deterministic grounded answer. The default Offline path transmits nothing |
| Retention | Lead rows: PII scrubbed 180 days after submission (DataRetentionService) → anonymised funnel row. Chat transcripts not persisted server-side (only a PII-safe SHA-256 hash logged) |
| Cross-border transfer | US transfer to Anthropic on the Online path only — SCCs under an executed Anthropic DPA (OUTSTANDING; until executed, the prod Anthropic key stays unset → Offline-only → no transfer) |
| Security measures | [AllowAnonymous] + dedicated rate-limit + daily spend circuit-breaker; engine has no OsolixDbContext (cannot reach tenant data); user text isolated from the system prompt (OWASP LLM01); inbound PII scrubber; non-enumerable lead tracking id; PII-safe hashed logging |

## 3 · Data subject rights — implementation map

| Right | Endpoint / surface | Charter ref |
|---|---|---|
| Access | `GET /api/me/export` | P1.6 |
| Rectification | Profile page; email-change verification | P1.7 |
| Erasure | `POST /api/me/erase` (30-day cool-off + permanent purge) | P1.10 |
| Erasure (anonymous marketing lead) | `POST /api/sandbox-requests/{trackingId}/erase` (token-proof) + `/welcome/Company/privacy/request` | P1.10 |
| Restriction | TenantAdmin can suspend without delete | P1.5 |
| Portability | `GET /api/me/export` returns portable JSON | P1.6 |
| Objection | `NotificationPreferences` page | P1.5 |
| Avoid automated decisions | Every AI suggestion is advisory; every workflow approval is human | P1.5 |

## 4 · Cross-border transfer mechanism
* EU customers: Standard Contractual Clauses (Module 3 — Processor → Sub-processor) + supplementary measures (encryption + TLS).
* UK customers: UK International Data Transfer Addendum to the SCCs.
* UAE customers: Adequacy decision pending; UAE PDPL Art. 23 cross-border mechanism applied.
* KSA customers: Adequate-protection assessment per KSA PDPL Art. 27.

## 5 · Open items
* Run the annual RoPA review with the DPO + every department head.
* Add an automated DSR (Data Subject Request) intake portal at `/welcome/Company/privacy/request`.
* Execute the Anthropic DPA/SCC covering anonymous marketing-site (public concierge) traffic before enabling the Online path in production (Decision 0071); until then the prod Anthropic key stays unset → Offline-only → no transfer.
