1. Scope and roles
These Data Processing Terms form part of the Oveloa Terms of Service. They apply only to the extent that Chakker Digital (Mohamed Chakker) processes personal data in customer content on behalf of a business customer.
The customer is the controller, or a processor authorized by its controller, and Oveloa is the processor or subprocessor. Oveloa remains a controller for its own account, security, support, legal-compliance and billing records as described in the Privacy Notice.
2. Processing details
- Subject and purpose: hosting, arranging, generating, reviewing, revising, delivering, securing and supporting property-media projects.
- Duration: for the customer's use of the service and the documented retention or deletion periods stated in the Privacy Notice.
- Operations: collection, upload, storage, organization, transmission to generation providers, transformation, retrieval, display, export and deletion.
- People: customers, team members, property owners, occupants, agents, photographers, reviewers and people incidentally depicted in submitted media.
- Data: account identifiers, project details, property photographs and plans, prompts, review comments, timestamps, delivery records and technical metadata.
Customers should avoid special-category data and unnecessary identifying material. Oveloa is not intended for medical, biometric, criminal-offence or other highly sensitive records.
3. Customer instructions and responsibilities
The agreement, product settings and the customer's lawful use of Oveloa are the documented instructions. The customer must have a lawful basis, provide required notices, obtain any necessary permissions and ensure its instructions comply with applicable law.
Oveloa will notify the customer if, in its reasonable view, an instruction infringes applicable data-protection law, unless law prohibits that notice. Additional or materially different instructions require written agreement and may involve reasonable costs.
4. Confidentiality and security
Oveloa restricts personal-data access to authorized people and processors bound by confidentiality. It applies proportionate technical and organizational safeguards, including authenticated access, role checks, scoped storage access, transport encryption, server-side credentials, file validation, rate limits, event idempotency, operational monitoring and retention controls.
No online service can promise absolute security. The customer remains responsible for account security, member access and the material it chooses to submit.
5. Rights, compliance and incidents
Taking account of the processing and information available, Oveloa will reasonably assist the customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments and regulator consultations. Oveloa may ask the customer to reimburse reasonable costs for unusually extensive assistance not caused by Oveloa's breach.
Oveloa will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer content and provide information reasonably available for the customer's response.
6. Authorized subprocessors
The customer gives general written authorization for Oveloa to use the following subprocessors where needed:
- Cloudflare — application delivery, computing, storage, security and operational infrastructure.
- Supabase — authentication and identity services.
- Resend — transactional email delivery.
- Stripe — checkout, subscription, payment, tax and billing services.
- BytePlus / ModelArk — AI video generation from submitted references and instructions.
Oveloa will impose data-protection obligations appropriate to the service on subprocessors. Material changes to this list will be posted here or otherwise communicated where required, giving the customer a reasonable opportunity to object on substantiated data-protection grounds.
7. International transfers
Processing may occur outside Norway or the EEA. Where an adequacy decision does not apply, Oveloa relies on an approved transfer mechanism such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. Customers may request information about the applicable safeguards through the privacy contact below.
8. Return, deletion and audit information
During the service, customers may retrieve available project outputs through Oveloa. At the end of processing, Oveloa deletes or renders customer personal data inaccessible according to the documented retention periods, unless law requires continued storage.
Oveloa will make information reasonably necessary to demonstrate compliance with these terms available to the customer and permit a proportionate audit where legally required. Audits must protect other customers, security and confidential information, use existing independent reports first where suitable, and be arranged with reasonable notice.
9. Contact and precedence
Privacy contact: privacy@oveloa.com. Operator address: Grønnegata 78-88, 9008 Tromsø, Norway.
If these terms conflict with the general Terms of Service on processing customer personal data, these Data Processing Terms control. They remain subject to the liability and governing-law provisions of the Terms to the extent permitted by applicable data-protection law.