Skip to content
OffsightAI
Sign In

Legal

Data Processing Addendum

When Offsight processes personal data on your behalf, the DPA is the document that says how. This page is the summary — what it covers and what it commits us to.

Last updated: August 7, 2026. This page summarizes the Offsight AI Data Processing Addendum. The executed DPA is the operative document and governs wherever this summary differs from it. Published for information; it is not legal advice.

1. When the DPA applies

The DPA applies where Offsight Inc. (“Offsight”) processes personal data on a customer’s behalf in the course of providing the Service. It is entered into alongside the Terms of Service and the customer’s Order Form, and forms part of that agreement.

It does not apply to data Offsight handles for its own purposes — a demo request, a sales enquiry, a support message from a visitor. For that, Offsight is the controller and the Privacy Policy is the full description.

2. Roles

  • Customer is the controller. You decide what goes into your tenant, who has access to it, and how long it stays.
  • Offsight is the processor. We process it on your documented instructions — which, in practice, are the configuration of your tenant and the actions your users take in the product — and for no other purpose.
  • Sub-processors are engaged under Offsight’s responsibility. Offsight uses sub-processors to deliver the Service, on terms no less protective than those we owe you, and we remain answerable to you for their performance. The categories are in section 7.

3. Processing particulars

ItemDescription
Subject matterProvision of the Offsight AI manufacturing execution system — the console, the iOS and Android apps, the Offsight APIs and the AI features.
DurationFor the term of the agreement, plus the period needed to export and then delete Customer Data after termination.
Nature and purposeHosting, storage, retrieval, display, transmission, analysis and AI-assisted processing of records the customer puts into its tenant, in order to deliver the Service.
Types of personal dataNames, work email addresses and phone numbers, job titles and roles, user IDs and permission assignments, authentication and access logs, labor and timesheet records, sign-offs and attributions on quality and inspection records, photographs taken on the floor that may include people, and anything a user chooses to type into a free-text field or an AI request.
Categories of data subjectsThe customer’s employees, contractors and temporary workers; the customer’s administrators and managers; and third parties given access by the customer, such as inspectors, general contractors and project stakeholders.
Special categoriesNone. The Service is not configured to process special categories of personal data, and customers are asked not to submit them.

4. AI processing under the DPA

This is the part that is new relative to a conventional MES, so the DPA addresses it explicitly.

  • Model providers are sub-processors. Model inference is performed on Offsight’s behalf by third-party providers engaged as sub-processors under section 7, under commercial API terms.
  • Scoped transmission. An AI request transmits the content of the request and the records, documents or images retrieved to answer it — not the tenant.
  • No foundation-model training. Offsight does not use Customer Data to train, fine-tune or develop general-purpose AI models, and inference requests are made under commercial API terms under which customer content is not used to train the provider’s models.
  • Permissions and attribution. An AI request executes in the context of the user who made it, bounded by that user’s per-module and per-user-group permissions, and the resulting actions are recorded in the audit trail against that user.
  • Session records are Customer Data. Requests, actions and output are stored in your tenant, are subject to your retention decisions, and are exported and deleted with everything else.
  • Human review. AI output is decision support and requires review by a qualified person before it is relied on. The requirement is set out in the Terms of Service, and is a controller obligation you retain.

5. Confidentiality and personnel

Offsight personnel who can access Customer Data are subject to confidentiality obligations, are granted access on a need-to-perform basis, and that access is logged. Support access to a tenant is auditable.

6. Security measures

The technical and organizational measures set out in the DPA include:

  • encryption in transit (TLS) and encryption at rest;
  • two-factor authentication;
  • per-module and per-user-group permissions administered by customer admins;
  • tenant isolation and per-tenant data separation;
  • audited access, including administrative and support access;
  • API keys with rotation, live usage metering and enforceable limits; and
  • managed cloud infrastructure in the United States — containerized services, a managed relational database with a read replica, and a caching tier.

Offsight will respond to reasonable written security questionnaires from a customer and its assessors, subject to confidentiality, and will describe the architecture and the parties involved in delivering it under that cover.

7. Sub-processors and notice

Offsight engages sub-processors to deliver the Service. They fall into a small number of categories: cloud hosting and storage, AI model inference, design-file processing, transactional and notification email, subscription billing and payment processing, and DNS and edge delivery for our public website.

Each is engaged under a written contract imposing data-protection obligations no less protective than those in the DPA, is permitted to use the information only to provide its service to Offsight, and is bound to confidentiality. Offsight remains responsible to the customer for their performance.

The identified list of sub-processors, with the data categories each one receives, is provided to customers and their assessors under the executed DPA. Request it — and email notice of additions or replacements — at support@offsight.com. The DPA sets out the mechanism for objecting to a new sub-processor on reasonable data-protection grounds.

8. International transfers

Offsight is based in the United States and the Service is operated on infrastructure in the United States. Where personal data is transferred out of a jurisdiction that restricts such transfers, the DPA incorporates the applicable transfer mechanism and the associated commitments.

9. Data subject requests

As controller, you handle requests from your own people. Offsight will provide reasonable assistance — and the product itself does much of the work, since an administrator can search, export and delete records directly. Where a data subject contacts Offsight instead, we will direct them to you rather than act on your data.

10. Incident notification

Offsight will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to it so that the customer can meet its own notification obligations, together with reasonable cooperation in investigation and remediation.

11. Return and deletion

On termination, the customer can export Customer Data using the export functions of the Service, with assistance available. Once the export window has passed, Customer Data is deleted in accordance with the agreement. Note that Customer Data may be irretrievably deleted if an account is ninety (90) days or more delinquent.

12. Contact

Questions about this policy: support@offsight.com. Contract questions: sales@offsight.com.

Offsight Inc.
650 California St
San Francisco, California 94108

Send us the questionnaire before the call.

We will have the DPA and the architecture answers ready, and your IT lead can ask about them while the product is on screen.