Responsibility matrix
| Area | OneClient platform | Customer application |
|---|---|---|
| Notice and purpose transparency | Website privacy and cookie notices; customer-facing service documentation. | Give end users an application-specific notice describing purposes, data, recipients, and rights. |
| Consent | Optional marketing analytics remains off before choice; consent record is versioned. | Collect and record valid consent where the customer application relies on it, including email/analytics choices. |
| Data minimization | Scoped services, keys, policies, fields, logs, and plan retention controls. | Choose only necessary fields, events, recipients, model inputs, and retention periods. |
| Access control | Organization roles, environment isolation, scoped keys, trusted origins, and immutable audit events. | Maintain members, rotate secrets, use least privilege, and remove stale access. |
| End-user rights | Customer export/delete primitives plus OneClient account requests through support. | Authenticate and answer end-user requests; determine exceptions and notify OneClient when processor help is needed. |
| Deletion and retention | Plan-specific logs; 30-day funded export window after balance suspension; deletion workflows. | Configure retention, maintain backups, and delete project/end-user data according to the customer’s legal basis. |
| Security | Tenant isolation, encryption in transit, secrets management, outbound controls, rate/runtime limits, and auditability. | Secure customer code, policies, devices, integrations, content, and incident response. |
| International transfers | Provider/jurisdiction controls where available and contractual transfer mechanisms where required. | Select available jurisdiction guarantees, assess onward providers, and provide required transfer notices. |
| California rights | Request channel for know/access, correct, delete, opt-out/limit inquiries, and non-discrimination. | Determine business/service-provider roles and implement notices and request handling for the customer application. |
| Sale/sharing and ads | OneClient does not sell personal information for money; marketing analytics stays consent-controlled. | Disclose and honor opt-outs for the customer’s advertising, sharing, data brokers, or cross-context behavioral advertising. |
| AI | Scoped routing, catalog pricing, maximum-output reservations, BYOK separation, logs/limits. | Avoid unnecessary personal/sensitive data, select lawful providers/models, and provide notices or human review when required. |
Regulatory references
This matrix is informed by the EU General Data Protection Regulation, the European Commission data-protection framework, the California Privacy Protection Agency regulations, and the California Attorney General’s CCPA guidance. Requirements depend on role, location, data, purpose, scale, contract, and exemptions.
Use counsel for the actual product.OneClient supplies technical controls and documentation. Each customer decides its legal basis, notices, user experience, retention, regulated-data suitability, and whether a data protection impact assessment or other review is required.
Current boundary
EU or US jurisdiction controls are used where the underlying service supports a legal guarantee. APAC is presented as a performance placement hint, not a legal residency promise. Beta provider capabilities remain behind adapters and inherit provider availability and limits.