Opulentus Management Group

Data Processing Agreement

Effective and last updated: September 20, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Opulentus Management Group ("Opulentus," "we," "us") and the business client that engages us (the "Client"). It applies whenever we process personal data on the Client's behalf — bookkeeping records, payroll and HR files, employee documents, customer and tenant records, and the supporting appointment and invoice data held in the client portal. Where the Client's own privacy law applies, this DPA governs that processing; where we act for our own purposes (marketing our services, securing the platform, billing the Client), our Privacy Policy applies instead.

1. Roles of the parties

For personal data the Client uploads or instructs us to handle — employee records, HR documents, tenant and customer details, bookkeeping source data — the Client is the controller (under the LGPD, the controlador) and Opulentus is the processor (operador). For account registration, authentication, security telemetry, billing of our own fees and marketing of our own services, Opulentus is the controller. Each party complies with the data protection law applicable to it.

2. Subject matter, duration, nature and purpose

Subject matter: the back-office services described in the Client's signed proposal — bookkeeping, payroll and HR administration, appointment scheduling, invoicing and reporting. Duration: for as long as the engagement is in force, plus the retention periods in section 9. Nature and purpose: storing, organising, retrieving, correcting, transmitting and deleting the Client's records so that we can perform those services, and nothing else.

3. Categories of data subjects and personal data

Data subjects: the Client's authorised users, employees and contractors, customers, tenants and vendors. Categories of personal data: name, business and personal contact details, job title, department, start date, employment status, time-off records, uploaded employment documents, tenancy and property details, service requests, appointment records, invoice amounts and payment status, and free-text notes the Client or its users enter.

Special or sensitive categories are not requested by the platform. Where the Client chooses to upload documents that contain them (for example a benefits or medical form inside an HR file), the Client confirms it has a lawful basis to do so, and we handle them under the same access controls as all HR documents. We do not process personal data of children.

4. Client instructions and our obligations

We process personal data only on the Client's documented instructions — which include this DPA, the signed proposal, the configuration the Client chooses in the platform, and support requests — and never for our own purposes, and never to train machine-learning models. We will tell the Client if an instruction appears to conflict with applicable law, and we do not sell personal data or share it for cross-context behavioural advertising. Personnel with access are bound by confidentiality that survives the end of their engagement.

5. Security measures actually implemented

These are the measures in force today, not aspirations:

  • Authorisation in the database. Every table enforces row-level security, so a request can only return rows the signed-in account is entitled to. Roles are held in a dedicated roles table, never on the user record. Clients see only their own business; staff only the clients assigned to them; administrators everything. Application code applies the same filters again.
  • Authentication. Authenticator-app two-factor is mandatory and gated before access. Password reset links expire in 15 minutes, are single-use, invalidate any earlier link, and are capped at three requests per email address per hour, with only a hashed email address stored alongside the ticket. Sessions can be revoked everywhere at once.
  • Encryption. HTTPS only, with HTTP Strict Transport Security preloaded. Storage and backups are encrypted at rest by the managed infrastructure provider.
  • Egress control. All server-side outbound requests pass one hardened client with a fixed host allowlist, DNS resolution pinned away from private address ranges, a redirect cap and timeouts. Anything else fails closed.
  • Browser hardening. A Content-Security-Policy with per-route frame-ancestors, X-Frame-Options DENY on every response, nosniff, strict referrer policy, a restrictive permissions policy, and signed same-origin policy-violation reporting.
  • Accountability. An append-only audit log that application roles cannot write to directly records sign-ins, role and assignment changes, finance actions and security events with actor, action, entity and timestamp.
  • Abuse resistance. Sliding-window rate limits on sign-in, password reset, public forms, the portal assistant and the report intake endpoint, keyed by a hashed identifier rather than a stored IP address.
  • File handling. HR documents live in a private bucket; every download uses a short-lived signed link, and no file is publicly addressable.
  • Continuous monitoring. These controls are tested automatically against the live system and the results are recorded in a dated evidence log, which we can share with the Client on request.

6. Artificial intelligence features

The client-portal assistant answers questions using only the records the signed-in account is already entitled to see. The context we send to the model provider is filtered by role before it leaves our servers — the account's own appointments, invoice amounts and currency, and retainer scope — internal file links are never included, the request is sent with provider-side retention disabled, and the provider is contractually barred from using the content to train models. The assistant does not give tax or legal advice and does not take actions on the Client's records.

7. Sub-processors

The Client authorises the sub-processors below. Each is bound by written terms no less protective than this DPA. We will give the Client notice before adding or replacing a sub-processor that handles Client personal data, and the Client may object on reasonable data-protection grounds; if we cannot resolve the objection, the Client may terminate the affected service. Our servers can technically reach only these destinations.

Sub-processorPurposeData receivedLocation
Lovable (application hosting and transactional email)Runs the application and its server functions and delivers account and invoice email from notify.opulentusmanagementgroup.com.Account identifiers, email addresses and message bodies.United States
Lovable AI GatewayClient portal assistant — AI request routing.Client name/company, appointment titles and times, invoice amounts, currency and status, and retainer plan. Requests are sent with storage disabled.United States
OpenAIClient portal assistant — AI model inference.Client name/company, appointment titles and times, invoice amounts, currency and status, and retainer plan. Requests are sent with storage disabled.United States
Supabase (managed Postgres database, authentication, file storage)Stores every application record, authentication credentials and second-factor enrolment, and the hr-documents file bucket.All categories listed in the privacy policy, including identity, appointment, invoice, HR/employment and property/tenancy records.United States
StripeHosted checkout, subscription billing and payment webhooks.Name, email, billing amount and currency, payment method details collected directly by Stripe. Opulentus stores only payment intent / session references and payment status.United States
Google (Google Workspace / Gmail)Email processor: sends new-lead and booking-request notifications to the company inbox and the enquiry auto-reply to visitors, from info@opulentusmanagementgroup.com.Name, email address, phone, company and the message a visitor typed into the contact or booking form.United States
Google Analytics 4Only when enabledAggregate website measurement. Loads only after affirmative consent.Device and browser type, pages viewed, approximate location from IP address.United States
ShopifyOnly when enabledReads shop name, currency and order totals for clients who connect their own store.Store identifier and aggregate order figures. No shopper personal data.Client's Shopify region
Cloudflare DNS over HTTPSResolves and pins hostnames before any outbound server request, to prevent server-side request forgery.Hostnames only. No personal data.Global

8. International transfers

Our infrastructure and sub-processors are located in the United States. Where the Client transfers personal data subject to the GDPR or UK GDPR, the parties incorporate the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914), Module Two (controller to processor), with the Client as data exporter and Opulentus as data importer, together with the UK International Data Transfer Addendum where the UK GDPR applies. The governing law is the law of Ireland for the EU Clauses; the docking clause applies; and the security measures in section 5 form Annex II. Where the LGPD applies, transfers rely on the contractual guarantees in this DPA under Article 33 of Lei nº 13.709/2018.

9. Retention and deletion

We keep Client personal data for the life of the engagement and then as required by U.S. law and professional standards: seven years for accounting and tax engagement records, at least four years for payroll tax records. Short-lived operational data expires sooner and automatically — abuse counters after 24 hours, password reset tickets after seven days, browser policy-violation reports after 90 days, privacy choices after six months. On written request at the end of the engagement we will return the Client's data in a machine-readable export and then delete or anonymise it, except where a legal retention duty applies; in that case the data remains protected by the measures in section 5 until the period expires.

10. Data subject requests

If a data subject contacts us directly about data we hold for the Client, we will not respond substantively — we will forward the request to the Client without undue delay and assist the Client in answering it, including by producing exports, correcting records or deleting data on instruction. Requests reach us at info@opulentusmanagementgroup.com or +1 (770) 750-4802. Our own response times when we are the controller are 45 days for U.S. state privacy requests, one month under the GDPR and UK GDPR, and 15 days under the LGPD.

11. Personal data breach

We will notify the Client without undue delay, and in any event within 48 hours of confirming a personal data breach affecting Client personal data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed, drawing on the audit log to establish scope. We will assist the Client with its own notification duties — including the 72-hour GDPR deadline, ANPD notification, and U.S. state breach statutes such as Georgia's — and will not make public statements about a breach affecting the Client without consulting the Client, unless legally compelled.

12. Audits and information rights

On reasonable written request, not more than once a year unless required by a supervisory authority, we will provide the current control register and dated evidence log, answer a security questionnaire, and give the information the Client reasonably needs to demonstrate compliance. We do not yet hold a SOC 2 report or ISO 27001 certificate; we will share one when we obtain it. On-site audits of shared infrastructure are satisfied by the relevant sub-processor's own certifications.

13. Liability, order of precedence and changes

Each party's liability under this DPA is subject to the limitations and exclusions in our Terms of Service and the signed proposal. If this DPA conflicts with those documents on the processing of personal data, this DPA controls. Where the Standard Contractual Clauses conflict with this DPA, the Clauses control. We will post revisions here with an updated effective date and give notice of material changes. Questions or a countersigned copy request: info@opulentusmanagementgroup.com or +1 (770) 750-4802.

This DPA is drafted from Opulentus's actual systems and data flows. It is a contractual document, not legal advice, and is under review by counsel; a Client whose own regulator requires specific wording should raise it with us before signing.

Privacy PolicyTerms of ServiceCookie PolicyData Processing AgreementBack to home