Data Processing Agreement
Our commitments as processor of the personal data our customers store in OmniDesk.
Last updated: 9 October 2026
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer (controller / "database owner") and OmniPrime Development ([Full legal name of the business — to be completed], [Company number / Licensed Dealer (Osek Murshe) number — to be completed], [Registered business address in Israel — to be completed]) (processor / "holder") and applies to personal data contained in Customer Data ("Customer Personal Data").
It is intended to satisfy the requirements of the Israeli Protection of Privacy Law and the Protection of Privacy Regulations (Data Security), 5777-2017 (including Regulation 15 on outsourcing), and Article 28 of the GDPR where the GDPR applies.
2. Details of processing
- Subject matter and duration: provision of the Service for the Subscription term and the post-termination deletion period.
- Nature and purpose: hosting, storage, retrieval, display, analysis and transmission of Customer Data as instructed through the Service.
- Data subjects: the Customer's employees, users, customers, leads, suppliers and other contacts.
- Categories of data: identification and contact details, business and transaction details, communications history and any other data the Customer chooses to enter. The Customer should not enter special categories of data unless necessary and lawful.
3. OmniPrime's obligations
- Process Customer Personal Data only on the Customer's documented instructions (these Terms and the Customer's use of the Service), unless required otherwise by law.
- Ensure that personnel with access are bound by confidentiality and are trained in data protection.
- Implement and maintain the security measures described in the Privacy Policy and appropriate to the Data Security Regulations, and review them periodically.
- Notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a security incident affecting Customer Personal Data, and provide the information reasonably required for the Customer's own notifications.
- Assist the Customer, taking into account the nature of the processing, in responding to data-subject requests and in data-protection impact assessments and consultations with authorities.
- At the end of the Service, make Customer Data available for export for 30 days and then delete it within a further 60 days, unless retention is required by law.
- Make available information necessary to demonstrate compliance and allow reasonable audits, no more than once a year on 30 days' notice, subject to confidentiality, or by providing relevant third-party certifications of our infrastructure providers.
4. Sub-processors
The Customer authorises the following sub-processors. We will give at least 30 days' notice of any new sub-processor, during which the Customer may object on reasonable grounds and, if no solution is found, terminate the affected service with a pro-rata refund.
- Microsoft Corporation and its affiliates (Microsoft Azure) — hosting, databases, caching, monitoring and email delivery; Israel Central and EU regions.
- PayMe — payment processing for subscription billing (Customer billing data only; not Customer Data).
5. International transfers
Customer Personal Data is hosted in Israel. Any transfer outside Israel complies with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001 and, where applicable, Chapter V of the GDPR.
6. Customer obligations
The Customer warrants that it has a lawful basis and has given all required notices for the processing, that its instructions are lawful, and that it will configure user roles and department access appropriately.
OmniPrime Development
[Full legal name of the business — to be completed] · [Company number / Licensed Dealer (Osek Murshe) number — to be completed]
[Registered business address in Israel — to be completed]
info@primels.co.il · +972 55 502 7988 · primels.co.il