Business Terms and Conditions
Effective date: 14 September 2026 · Last updated: 17 September 2026
Contents
- Scope of Services
- Cooperation, Delays, and Scope Changes
- Fees, Payment, and Billing
- Third-Party Costs
- Evaluation Period and Refunds
- Subscription Cancellation
- Accounts, Credentials, and Access
- Client Content and Permissions
- Restricted Data
- AI Limitations and Human Review
- Acceptable Use
- AI Transparency and Regulatory Cooperation
- Communications and Marketing
- Third-Party Services
- Security and Incidents
- Maintenance and Support
- Intellectual Property
- Confidentiality
- Data Protection
- Warranties
- Indemnification
- Limitation of Liability
- Suspension and Termination
- Effect of Termination and Transition
- Governing Law and Disputes
- Company and Notices
- General Terms
- Changes to Terms
Schedule 1: Data Processing Addendum
These Business Terms and Conditions (the "Terms") are entered into between OTRG Solutions LTD, a company incorporated in the Republic of Cyprus under registration number HE494719, trading as OTRG Solutions ("OTRG," "Company," "we," "us," or "our"), and the business customer accepting these Terms ("Client," "you," or "your").
These Terms govern Client’s access to and use of our website, professional services, software integrations, AI assistants, workflow automations, support, maintenance, and related services (collectively, the "Services").
By creating an account, ordering a Service, or otherwise using the Services, Client agrees to these Terms. Confirming an order in writing, including by email, is sufficient acceptance. No signed proposal, order form, contract, or other separate document is required for these Terms to bind Client. The individual ordering a Service or otherwise accepting these Terms represents that they have authority to bind Client.
The Services are offered solely for business and professional purposes and are not intended for consumers acting outside their trade, business, craft, or profession. If you are acting as a consumer, do not purchase or use the Services without first contacting us.
1. Scope of Services
OTRG provides custom AI assistants, workflow automations, integrations, and related implementation services, made available in the packages described on our website, which may include:
- AI Agent Setup (Setup Services): the build, configuration, testing, and deployment of one (1) AI agent/automation addressing the workflow agreed with Client, whether a common use case (e.g., lead response, customer support, proposal generation, or a repetitive administrative task) or one specific to Client's business. Scope is agreed with Client in writing (including by email) before work begins, and includes the technical implementation work required to put the agent into service. A single setup fee applies, as published on our website at the time of purchase. Additional agents are separate Setup Services, each with its own fee.
- Subscription Services: recurring hosting, licensing, monitoring, maintenance, or support for a previously deployed Setup Service.
Unless expressly stated otherwise on our website or agreed with Client in writing, the Services do not include legal, medical, financial, accounting, cybersecurity, compliance, or other regulated professional advice; guaranteed uptime or response times; manual review of every AI output; disaster recovery for Client systems; or new features after acceptance.
2. Cooperation, Delays, and Scope Changes
Client will timely provide the personnel, systems, accounts, documentation, content, test data, decisions, and approvals reasonably required to perform the Services. Client is responsible for the accuracy and completeness of materials and instructions it supplies.
Estimated delivery dates (including the typical three (3) business day turnaround for a Setup Service) are estimates, not binding deadlines, unless OTRG expressly states otherwise in writing. OTRG is not responsible for delays caused by Client, third-party providers, unavailable access, incomplete information, changes in scope, or events beyond OTRG’s reasonable control. If Client delays a project for more than thirty (30) days, OTRG may revise the schedule, reallocate personnel, invoice completed work, and charge reasonable restart costs disclosed in advance.
Requests that materially change the intended purpose, requirements, integrations, volume, workflows, or deliverables from what was purchased will be treated as a change request. OTRG need not begin such additional work until Client agrees to it in writing (including by email), together with any added fees and revised timing.
3. Fees, Payment, and Billing
The fees for the Setup Package and/or Subscription Services selected are as displayed on our website and confirmed to Client in writing at the time of purchase.
All fees are payable by credit card, or another card-based payment method OTRG makes available, charged through OTRG’s designated payment processor. OTRG does not invoice Clients and does not accept payment by bank transfer, cheque, or any other method, unless expressly agreed with Client in writing. No signed order form, proposal, or other document is required to create a binding payment obligation: Client’s written order confirmation, or OTRG’s written confirmation of a change request under Section 2, is sufficient.
By providing payment details, Client authorizes OTRG and its payment processor to charge the designated payment method for the Setup Fee and, where selected, for recurring Subscription fees. Subscription Services renew automatically for successive periods equal to the initial subscription period unless cancelled in accordance with Section 6. OTRG may change recurring fees on at least thirty (30) days’ notice by email, effective at the next renewal.
Undisputed amounts that cannot be collected through the payment method on file may accrue interest at the lower of one percent (1%) per month or the maximum lawful rate, without limiting OTRG’s right to suspend the Services under Section 22. Fees exclude VAT, sales tax, withholding tax, and similar charges; Client is responsible for applicable taxes other than taxes based on OTRG’s net income. Client will not initiate an unjustified chargeback, without limiting its right to dispute a charge with OTRG in good faith.
4. Third-Party Costs
Unless expressly included in the price quoted to Client, OTRG’s fees exclude charges for model APIs, automation platforms, cloud hosting, telephony, messaging, email, CRM, scheduling, and other third-party services ("Third-Party Services"). Client is responsible for its own accounts with, and the charges of, any Third-Party Services its agents rely on.
OTRG will not materially increase a third-party usage commitment controlled by OTRG without Client’s approval. Usage estimates are not guarantees, and actual costs may vary with volume, pricing, exchange rates, provider policies, and Client usage.
5. Evaluation Period and Refunds
Client has fourteen (14) calendar days from OTRG’s written notice that a Setup Service deliverable is ready ("Evaluation Period") to test it.
The deliverable is measured against the scope agreed with Client in writing under Section 1 before work began, read together with the description of the Setup Service published on OTRG’s website at the time of purchase.
Client must report any reproducible material non-conformity with that description in writing during the Evaluation Period, with enough detail for OTRG to investigate. OTRG will have a reasonable opportunity to correct it and resubmit the affected deliverable.
A deliverable is accepted upon the earliest of: Client’s written acceptance; Client’s production use of it other than agreed testing; expiration of the Evaluation Period without a valid, timely rejection; or correction of all reported material non-conformities. Minor defects that do not materially impair the described purpose do not justify rejection.
If OTRG cannot correct a timely reported material non-conformity after a reasonable opportunity, Client may cancel the affected Setup Service and receive a refund, to the original payment method, of the fees paid directly to OTRG for the materially non-conforming and unusable deliverable.
Refunds are unavailable for change of mind, undocumented expectations, Client delay, Client-provided content or instructions, post-acceptance changes, change requests under Section 2, third-party charges, consumption fees, or failures of Third-Party Services outside OTRG’s reasonable control. After a refund, Client must stop using and delete the refunded deliverable and confirm deletion on request. Except as stated here or required by law, fees are non-refundable.
6. Subscription Cancellation
Either party may prevent renewal of a Subscription Service by giving at least thirty (30) days’ written notice (including by email) before the next renewal date. Cancellation takes effect at the end of the then-current paid period. No partial refund or credit is due for an unused portion unless required by law.
7. Accounts, Credentials, and Access
Client is responsible for its accounts, users, authentication methods, and access decisions. Client will provide only authorized access, use delegated or separate accounts where available, enable multi-factor authentication where supported, revoke former users, and promptly report suspected compromise.
OTRG will use credentials only to provide the Services, restrict them to personnel and contractors with a need to know, apply least privilege where reasonably practicable, and use reasonable safeguards. OTRG may request credential rotation after deployment or termination.
Client remains responsible for activity through Client-controlled accounts unless caused by OTRG’s breach of these Terms.
8. Client Content and Permissions
"Client Content" includes data, prompts, files, contact lists, recordings, branding, instructions, training materials, and other content supplied by or for Client.
Client represents that it has all rights, notices, lawful bases, permissions, and consents needed for OTRG and authorized subprocessors to process Client Content as contemplated. Client will not give unlawful instructions or content that violates third-party rights.
Client grants OTRG a limited, non-exclusive right to host, copy, transmit, modify, and process Client Content only as needed to provide, secure, support, and terminate the Services and comply with law. This does not permit use to train a general-purpose AI model.
9. Restricted Data
Unless expressly approved by OTRG in writing (including by email) with suitable safeguards, Client must not process through the Services protected health information; payment-card data outside an approved processor; government identification numbers; identification biometrics; precise geolocation; children’s data; passwords or private cryptographic keys other than approved integration credentials; or special-category and highly sensitive data unnecessary for the documented purpose.
Approval does not relieve Client of legal duties. OTRG may suspend unapproved Restricted Data processing.
10. AI Limitations and Human Review
Client acknowledges that AI systems are probabilistic and may generate inaccurate, incomplete, outdated, biased, inconsistent, unexpected, or inappropriate results ("AI Outputs"). Outputs may vary for the same input and may not be unique.
Unless expressly agreed otherwise, the Services are decision-support tools, not substitutes for qualified human judgment. Client is responsible for review, monitoring, escalation, and approval processes appropriate to the intended use.
OTRG does not warrant that AI Outputs are error-free, factually correct, legally compliant in every context, suitable for a particular decision, or free from third-party claims. OTRG will nevertheless configure the Services with reasonable skill and care according to the selected package, and address reproducible configuration defects under the evaluation or support process.
Client must review AI Outputs before relying on them where an error could materially affect a person, create legal exposure, transfer funds, enter a binding commitment, publish content, or affect health, safety, employment, housing, education, insurance, credit, legal services, or essential services.
11. Acceptable Use
Client must not use the Services to violate law or third-party rights; commit fraud, deception, impersonation, harassment, discrimination, unlawful surveillance, or manipulation; generate malware or unauthorized access; send unlawful spam, calls, or texts; hide an AI interaction where disclosure is required; make a solely automated decision with legal or similarly significant effects unless lawful and reviewed; unlawfully infer sensitive traits; conduct prohibited social scoring, emotion recognition, biometric categorization, or other prohibited AI practices; distribute unlawful exploitative content; bypass safety controls; or use the Services in an undisclosed regulated or high-risk context.
OTRG may investigate suspected misuse and suspend affected Services where reasonably necessary to prevent harm, comply with law, or protect systems. Where practicable, OTRG will give notice and limit suspension to the affected use.
12. AI Transparency and Regulatory Cooperation
The parties will identify their roles under applicable AI laws based on actual design, branding, intended purpose, deployment, and control. A contractual label does not override a role imposed by law.
Client is responsible for accurately describing the intended purpose and users; approving the use case before production; legally required notices and disclosures; appropriate human oversight and escalation; relevant personnel training and AI literacy; records and logs required for its use; deployer impact assessments; and notifying OTRG before materially changing the intended purpose or entering a regulated or high-risk context.
OTRG will implement agreed disclosure language, logging, escalation, and compliance configuration Client requests. Each party remains responsible for duties imposed directly on it.
13. Communications and Marketing
If the Services facilitate email, calls, texts, or outbound communications, Client is responsible for legality, required consent records, accurate sender identification, disclosures, do-not-call and suppression screening, effective opt-out mechanisms, prompt honoring of opt-outs, and prior approval of scripts, audiences, timing, frequency, and campaigns.
Client must comply with the TCPA, Telemarketing Sales Rule, CAN-SPAM Act, GDPR, ePrivacy rules, and equivalent laws. It must not use purchased, scraped, or unlawfully obtained lists. For AI-generated or artificial voice calls, Client must obtain consent required for artificial or prerecorded voice communications.
OTRG may refuse or suspend a campaign it reasonably believes is unlawful or materially risky.
14. Third-Party Services
Third-Party Services may change their availability, features, models, output, pricing, data practices, or APIs without notice. OTRG is not liable for failures caused solely by a Third-Party Service and outside OTRG’s control, but remains responsible for its own configuration work and express commitments.
If a provider materially changes or becomes unavailable, OTRG may modify the integration or propose a reasonable substitute. Material migration may require a change request under Section 2. OTRG will not substitute a provider in a way that materially reduces agreed data-protection safeguards without notice.
Client’s use of Third-Party Services is subject to their terms. OTRG does not grant their rights or make warranties for them.
15. Security and Incidents
OTRG will maintain reasonable technical and organizational measures appropriate to the Services and processing risks, including as applicable access controls, least privilege, credential protection, secure transmission, personnel confidentiality, patch management, and incident response.
No system is completely secure. OTRG does not guarantee that incidents will never occur.
OTRG will notify Client without undue delay after becoming aware of a confirmed incident materially affecting Client systems, credentials held by OTRG, or Client Personal Data ("Security Incident"). Notice will include reasonably available information and be supplemented as needed. Unsuccessful scans or attempts that do not compromise confidentiality, integrity, or availability are not notifiable Security Incidents.
The parties will reasonably cooperate in investigation and mitigation. OTRG will not notify regulators or individuals for Client unless required by law or agreed in writing.
16. Maintenance and Support
Subscription Services include only the support and maintenance described on OTRG’s website for the selected plan. Unless otherwise stated, support is provided during OTRG’s Cyprus business hours excluding public holidays; response times are targets; maintenance covers reproducible defects in OTRG’s configuration, not new features, changed requirements, Client modifications, increased volume, or material redevelopment caused by third-party changes; and OTRG may perform planned or emergency maintenance.
OTRG may update the Services for security, reliability, or compatibility, provided it does not materially remove contracted core functionality without a reasonable substitute.
17. Intellectual Property
Client retains its Client Content, trademarks, and pre-existing materials ("Client Materials").
After full payment, Client owns the final workflows, prompts, and configurations created specifically and exclusively for Client as part of a paid Setup Package ("Custom Deliverables"), excluding Company Technology and Third-Party Materials.
OTRG retains its pre-existing and independently developed software, connectors, templates, libraries, methods, know-how, architectures, tools, generic prompts, reusable logic, monitoring systems, documentation formats, improvements, and skills ("Company Technology").
Where Company Technology is embedded in a paid Custom Deliverable, OTRG grants Client a perpetual, worldwide, non-exclusive, royalty-free license to use, copy, and modify it only as needed to use the Custom Deliverable internally. Client may not resell, sublicense, extract, or commercialize Company Technology as a standalone product. Subscription-only Company Technology is licensed solely during an active subscription.
Third-party software, open-source components, AI models, and platform configurations ("Third-Party Materials") remain subject to their licenses. Ownership and use of AI Outputs may depend on law and provider terms. OTRG assigns only rights it owns and does not guarantee that outputs are unique or protectable.
OTRG may use generalized feedback that does not identify Client or disclose Confidential Information. It may not use Client’s name, logo, testimonial, or project details publicly without prior written consent.
18. Confidentiality
"Confidential Information" means non-public information marked confidential or reasonably understood to be confidential, including business plans, pricing, credentials, security information, customer data, software, prompts, workflows, and Client Content.
The receiving party will use it only for the agreement; protect it with at least reasonable care; disclose it only to personnel, advisers, contractors, and subprocessors who need it and are bound by confidentiality; and remain responsible for breaches by its recipients, except independent advisers under professional duties.
Confidential Information excludes information demonstrably known lawfully without restriction, public without breach, lawfully received without duty, or independently developed without its use.
If legally compelled, the receiving party will, where permitted, give prompt notice and assistance and disclose only what is required.
These duties continue for five (5) years after disclosure. Trade secrets, credentials, and personal data remain protected while they retain that character or law requires.
19. Data Protection
Each party will comply with data-protection laws applicable to its activities.
For personal data in Client Content processed on Client’s behalf ("Client Personal Data"), Client acts as controller or business and OTRG as processor or service provider, unless Schedule 1 provides otherwise. Schedule 1 applies automatically and is not dependent on a request.
OTRG is an independent controller for business-contact, account, billing, security, support, website, legal-compliance, and relationship-management data processed for its own purposes, subject to its Privacy Policy.
OTRG will not sell or share Client Personal Data for cross-context behavioral advertising or use it to train a general-purpose or shared AI model without Client’s prior express written authorization.
20. Warranties
Each party represents it has authority to enter the agreement.
OTRG warrants it will perform with reasonable skill and care, materially according to the selected package, and comply with laws directly applicable to its provision. Client’s remedy is correction or re-performance and, if unavailable within a reasonable period, termination and a pro-rata refund of prepaid fees for materially affected unused Services.
Client warrants that its intended use, Client Content, instructions, marketing, and deployment comply with law and third-party rights.
Except for express warranties and to the maximum lawful extent, the Services, AI Outputs, and Third-Party Services are provided "as is" and "as available." OTRG disclaims implied warranties of merchantability, fitness, non-infringement, uninterrupted availability, and error-free operation.
21. Indemnification
Client will defend and indemnify OTRG and its officers, directors, employees, and contractors from third-party claims, damages, fines, penalties, judgments, and reasonable legal fees arising from Client’s unlawful use; Client Content or instructions infringing rights; failure to obtain consent, give notice, or honor opt-outs; Client’s campaigns, products, services, or final decisions; or material breach of Sections 8 through 13.
OTRG will defend and indemnify Client from a third-party claim that a paid Custom Deliverable created solely by OTRG infringes copyright or trade-secret rights. This excludes claims arising from Client Materials or instructions, AI Outputs, Third-Party Materials, non-OTRG modifications, use outside the agreement, or unapproved combinations. OTRG may obtain continued rights, modify or replace the item, or terminate it and refund its fee depreciated over twelve (12) months from acceptance.
The indemnified party must promptly notify the other, reasonably cooperate at the indemnifying party’s expense, and allow it to control defense and settlement. Delay reduces the duty only to the extent of material prejudice. A settlement may not admit fault by, impose non-monetary duties on, or fail to release the indemnified party without its reasonable consent.
22. Limitation of Liability
To the maximum lawful extent, neither party is liable for indirect, incidental, special, exemplary, punitive, or consequential damages, or loss of profits, revenue, anticipated savings, goodwill, opportunity, or data.
Except for Excluded Claims, each party’s total aggregate liability relating to a Setup Package or Subscription will not exceed the greater of: (a) amounts paid or payable for it during the twelve (12) months before the event; or (b) the total Setup Services fees paid for it.
"Excluded Claims" are fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence, indemnification duties, Client’s payment duties, infringement or misappropriation of the other party’s intellectual property, breach of confidentiality, and liability that cannot lawfully be limited.
For Schedule 1, data-protection, or security-incident claims not otherwise excluded by mandatory law, aggregate liability will not exceed two (2) times the general cap, and such claims are governed exclusively by this sub-cap and not treated as an uncapped confidentiality claim under the preceding paragraph. Limits apply under any legal theory and in aggregate across related events.
23. Suspension and Termination
OTRG may suspend affected Services if Client fails to pay an undisputed amount and does not cure within ten (10) business days after notice; creates material security risk; uses the Services unlawfully or abusively; materially breaches Sections 7 through 13 or Schedule 1; or exceeds an agreed limit without reducing usage or approving added fees.
Where practicable, OTRG will provide notice and an opportunity to cure, limit suspension to the affected Service, and restore it after resolution.
Either party may terminate an affected Setup Service or Subscription for material breach not cured within thirty (30) days after notice. A payment breach has ten (10) business days. Either party may terminate immediately on insolvency or cessation of business. OTRG may terminate immediately if continued performance would violate law or create material imminent risk that suspension cannot reasonably mitigate.
Termination does not affect accrued rights or payment duties.
24. Effect of Termination and Transition
Upon termination, Subscription-only licenses end; each party stops using the other’s Confidential Information except as legally required; Client pays accrued undisputed fees; OTRG revokes its access to Client systems; and Client may export Client-owned data and Custom Deliverables in a reasonably available standard format during the subscription and for thirty (30) days afterward.
After the retrieval period, OTRG may delete Client Content from active systems subject to Schedule 1, law, and backup cycles. Reasonable transition or migration assistance is available at OTRG’s then-current rates unless included. OTRG is not responsible for third-party technical restrictions or for reconstructing data Client failed to retain.
Provisions intended by nature to survive do so, including payment, IP, confidentiality, applicable data-protection duties, indemnification, liability limits, and disputes.
25. Governing Law and Disputes
The agreement is governed by the laws of the Republic of Cyprus, excluding conflict rules.
Before proceedings, the parties will attempt good-faith resolution for thirty (30) days through representatives authorized to settle. This does not prevent urgent interim relief, protection of IP or Confidential Information, or action needed to preserve a limitation period.
The courts of the Republic of Cyprus have exclusive jurisdiction. OTRG may bring a claim solely to collect undisputed overdue fees in any court having jurisdiction over Client.
26. Company and Notices
- Legal company name
- OTRG Solutions LTD
- Trading name
- OTRG Solutions
- Cyprus registration number
- HE494719
- Registered address
- 45, Taxiarchon BL.4, Apt.001, 8036 Paphos
- VAT number
- 60373602T
- Support email
- support@otrgsol.com
- Legal-notice email
- legal@otrgsol.com
Formal notices must be written and sent to the designated email and any physical address stated on OTRG’s website. Email is received the next business day unless a delivery failure is received. Notice of legal proceedings must also use a method permitted by procedural law.
27. General Terms
These Terms are the entire agreement and supersede prior understandings. Client purchase-order terms do not apply unless expressly accepted by OTRG in writing.
The parties are independent contractors and neither may bind the other.
Neither party may assign these Terms without the other’s consent, not unreasonably withheld. Either may assign to an affiliate or with a merger, reorganization, relevant asset sale, or change of control if the assignee assumes the duties and is not a direct competitor of the other party.
OTRG may use qualified subcontractors and remains responsible for their performance. Subprocessors are governed by Schedule 1.
Neither party is liable for delay caused by events beyond reasonable control if it mitigates the impact. This does not excuse payment for Services already provided.
If a provision is unenforceable, it will be modified minimally and the remainder remains effective. Failure to enforce is not a waiver. Except for indemnified persons, no third party has beneficiary rights. Electronic acceptance is valid. "Including" means "including without limitation."
28. Changes to Terms
OTRG may update these Terms for future purchases. For active subscriptions, OTRG may update them on at least thirty (30) days’ notice for legal, security, operational, or product reasons.
An update will not retroactively reduce ownership, materially expand OTRG’s use of Client Content, or materially reduce confidentiality or data-protection duties during a paid term without express agreement. If an update materially and adversely affects an active subscription, Client may reject it by cancelling before it takes effect and receive a pro-rata refund for the unused prepaid period. Continued use after the effective date constitutes acceptance where lawful.
Schedule 1: Data Processing Addendum
This DPA forms part of the agreement whenever OTRG processes Client Personal Data on Client’s behalf.
1. Definitions and Roles
"Data Protection Laws" means the GDPR, Cyprus data-protection law, and other privacy laws applicable to the processing. GDPR terms including "controller," "processor," "personal data," "processing," and "personal data breach" retain their statutory meanings. "Subprocessor" means a third party engaged by OTRG to process Client Personal Data.
Client is controller and OTRG is processor. If Client is a processor for another controller, OTRG is Client’s subprocessor.
2. Instructions
OTRG will process Client Personal Data only on documented instructions in these Terms, as necessary to provide, secure, support, and terminate the Services, or as required by law. Where lawful, OTRG will notify Client before legally required processing.
OTRG will promptly inform Client if an instruction reasonably appears to infringe Data Protection Laws and may suspend the affected processing while the parties resolve it.
Client is responsible for the lawfulness of instructions, data accuracy, notices, lawful bases, and data-subject responses except for OTRG assistance described below.
3. Processing Details
- Subject matter
- AI assistants, automations, integrations, support, monitoring, and related Services Client has purchased.
- Duration
- The applicable Setup Package or Subscription, plus deletion and backup periods.
- Nature and purpose
- Hosting, transmitting, retrieving, structuring, analyzing, generating responses, automating workflows, troubleshooting, securing, and deleting data.
- Data subjects
- Client personnel, contractors, customers, prospects, leads, website users, suppliers, and others whose data Client submits.
- Data categories
- Contact details, business communications, account identifiers, interaction records, prompts, AI inputs and outputs, appointment or CRM data, and technical usage data.
- Sensitive data
- Not permitted unless expressly approved with safeguards under Section 9 of these Terms.
- Frequency
- Continuous or occasional, according to Client use.
4. Confidentiality and Security
OTRG will ensure authorized persons are bound by confidentiality, receive suitable guidance, and access data only as needed.
OTRG will maintain measures appropriate to risk, state of the art, cost, scope, and context, including as applicable role-based least-privilege access; multi-factor authentication for privileged systems where supported; encryption in transit; protection of credentials; logging and monitoring; secure change management; patch management; applicable backups; access revocation; and incident response.
Measures may evolve if overall protection is not materially reduced.
5. Subprocessors
Client generally authorizes necessary Subprocessors. OTRG will maintain a current list and provide it to Client on request; impose written obligations substantially equivalent to this DPA; remain responsible for their performance; and provide at least fifteen (15) days’ notice before adding or replacing a material Subprocessor where practicable.
Client may object during that period on reasonable documented data-protection grounds. The parties will seek a solution. If none is commercially reasonable, either may terminate only the affected Service and OTRG will refund prepaid fees for its unused period.
6. International Transfers
OTRG will not transfer Client Personal Data from the EEA to a country without applicable adequacy unless a valid Chapter V GDPR mechanism exists.
Where required, the parties incorporate the then-current European Commission Standard Contractual Clauses applicable to their roles. Modules, optional clauses, authority, law, forum, measures, Subprocessors, and transfer details will be completed in a transfer annex on request.
OTRG may rely on a valid adequacy framework, including the EU-U.S. Data Privacy Framework, for an eligible recipient. It will use another lawful mechanism if the relied-upon mechanism ceases to be valid.
7. Data-Subject Requests and Assistance
Taking account of processing nature, OTRG will reasonably assist Client with data-subject requests. If OTRG receives one concerning Client data, it will promptly forward it and not respond substantively unless instructed or legally required. Client verifies the requester and determines the response.
Taking account of available information, OTRG will reasonably assist with security duties, breach notifications, impact assessments, and supervisory consultations. Non-standard assistance may be charged at agreed rates where lawful, except where required by OTRG’s breach.
8. Compliance Information and Audits
OTRG will provide information reasonably necessary to demonstrate Article 28 GDPR compliance. No more than annually, unless required by an authority or after a material breach, Client may request relevant reports, certifications, or a reasonable questionnaire.
If insufficient, Client may audit through an independent auditor bound by confidentiality, with thirty (30) days’ notice, during business hours, without accessing other clients’ data or unreasonably disrupting operations. Client pays audit costs unless it identifies OTRG’s material breach.
9. Personal Data Breach
OTRG will notify Client without undue delay after becoming aware of a Personal Data Breach involving Client Personal Data and, where reasonably practicable, within forty-eight (48) hours.
Notice will provide known details about the nature, affected data and people, likely consequences, remediation, and contact. Information may be provided in phases. Notice is not an admission of fault. Client handles regulator and individual notices unless law requires OTRG or the parties agree otherwise.
10. Return and Deletion
During the term and for thirty (30) days after termination, OTRG will provide a reasonable means to retrieve Client Personal Data in OTRG-controlled systems.
Afterward, OTRG will delete or anonymize it from active systems unless law requires retention. OTRG does not maintain routine backups of Client Personal Data, which is held in systems Client controls. Where a backup copy nevertheless exists, it will remain protected, will not be used in the ordinary course, and will be deleted when overwritten through ordinary cycles.
On reasonable request, OTRG will confirm deletion. It may retain minimal records for compliance, disputes, enforcement, and legal duties.
11. U.S. State Privacy Terms
Where OTRG acts as a "service provider," "contractor," or equivalent, it will process personal information only for specified business purposes; not sell or share it for cross-context behavioral advertising; not retain, use, or disclose it outside the direct relationship except as legally permitted; not combine it with other data except as permitted; provide the required level of protection; notify Client if it can no longer comply; and permit reasonable steps to stop and remediate unauthorized use.
12. AI Model Training
OTRG will not use Client Personal Data to train, fine-tune, or improve a general-purpose or shared AI model. It will configure third-party providers not to train on Client Personal Data where the applicable enterprise or API service offers and contractually supports that control.
Any Client-specific training or fine-tuning using personal data will be described to Client in writing, including model, purpose, data, retention, access, and deletion.
13. Conflict and Survival
This DPA controls conflicts concerning Client Personal Data and survives while OTRG retains such data.