OpenAI Data Processing Addendum

OpenAI Data Processing Addendum

Parties: Pacific Apps, Inc. and OpenAI
Executed: July 9, 2023
Status: Executed agreement; public redacted copy available
Original: Executed record retained internally
Contact: support@idialogue.app

Why we publish it

Pacific Apps makes a redacted copy of its executed OpenAI Data Processing Addendum publicly available so customers can review the contractual data-protection terms governing this important processing relationship.

The public copy removes signatures, electronic execution metadata, and the OpenAI organization ID. The original executed agreement is retained internally and can be validated through a controlled review when required for procurement or security due diligence.

What the DPA covers

The agreement supplements the applicable OpenAI services agreement and establishes contractual safeguards for the processing of personal data.

At a high level, the agreement addresses:

  • processor and controller responsibilities;
  • documented processing instructions;
  • confidentiality and security obligations;
  • subprocessors;
  • assistance with individual rights and data-protection obligations;
  • security incidents;
  • return or deletion of personal data;
  • audits and compliance information; and
  • international-transfer safeguards where applicable.

The executed agreement controls. This summary is provided for convenience and is not a replacement, amendment, or legal interpretation of its terms.

What should be evaluated separately

The DPA establishes contractual data-protection obligations between Pacific Apps and OpenAI. Current product behavior and operational controls should be evaluated separately, including:

  • the request-level store setting used by a particular workflow;
  • the data supplied to OpenAI by a particular agent or file-processing workflow;
  • current endpoint-specific storage and retention behavior;
  • optional provider data-sharing or service-improvement settings;
  • iDialogue transcripts, artifacts, memory, logs, and billing records; and
  • security certifications or attestations applicable to Pacific Apps or OpenAI.

These controls can vary by endpoint, provider configuration, iDialogue workflow, and customer deployment.

Current OpenAI controls

Model training

OpenAI states that API data is not used to train or improve its models unless the API customer explicitly opts in. Optional feedback, evaluation, fine-tuning, and service-improvement sharing programs are separate controls that should be reviewed for the applicable OpenAI organization and project.

Responses application state

Current reviewed iDialogue Responses API workflows use store=true where stored application state is required to support threaded conversations, background continuation, and file-processing workflows.

Retention

OpenAI currently documents stored Responses application state as retained for at least 30 days. Other OpenAI endpoints and data classes, including uploaded files, conversations, abuse-monitoring logs, and optional sharing programs, may have different storage and retention behavior.

Provider capabilities, approved data controls, and contractual terms may also affect the applicable behavior for a particular deployment.

See:

Customer-provided OpenAI keys

Approved deployments can use a customer-provided OpenAI API key, placing provider-level administration, billing, usage visibility, rate limits, and applicable account settings within the customer's OpenAI organization.

A customer-provided key does not automatically change iDialogue workflow settings, transcript handling, request storage configuration, or all OpenAI retention behavior.

Review the OpenAI Connection guide for additional information about this control boundary.

Need the DPA for a security or procurement review?

For questions about the agreement, validation of the executed record, or additional procurement documentation, contact support@idialogue.app.

Generated 2026-08-11T02:58:43.351982Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.