Orquestr

Legal

Data processing agreement

Last updated: September 24, 2026

Version: 2026-09-24

This data processing agreement, including its schedules (the “DPA”), forms part of the agreement between Orquestr and the customer that uses the Services (the “Customer”) and governs Orquestr's processing of personal data on the Customer's behalf.

The DPA applies automatically when the Customer accepts the Terms of Service, signs an order or other agreement that incorporates it, or uses Services that involve processing personal data. It does not require a separate signature. If the parties sign it separately, it takes effect on the last signature date. The processor is Orquestr. Contact: legal@orquestr.com.

1. Definitions

“Affiliate” means an entity that controls, is controlled by, or is under common control with a party.

“Applicable Data Protection Law” means privacy, data-protection, and data-security law applicable to Orquestr's processing under the agreement, including, where applicable, the GDPR and U.S. state privacy laws.

“Controller,” “data subject,” “personal data,” “personal data breach,” “process,” and “processor” have the meanings in applicable law. “Controller” includes a “business,” and “processor” includes a “service provider” or “contractor,” where those state laws use those terms.

“Customer Data” means information the Customer, or someone for the Customer, submits to or processes through the Services. “Personal data” in this DPA means Customer Data that is regulated personal data. It does not include information Orquestr processes independently as a controller, such as business contacts, account, billing, and relationship information.

“GDPR” means Regulation (EU) 2016/679, the UK GDPR, and applicable implementing law, in each case where it applies.

“Restricted Transfer” means a transfer of personal data that requires a recognized mechanism under the GDPR or Swiss data-protection law.

“SCCs” means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914.

“Services” means the services covered by the agreement. “Subprocessor” means an affiliate or third party Orquestr engages to process personal data on the Customer's behalf. Capitalized terms not defined here have the meaning in the agreement that incorporates this DPA (the “Agreement”).

2. Scope, roles, and duration

The Customer is a controller or processor, as applicable. Orquestr is a processor or subprocessor acting on the Customer's behalf. Each party complies with the obligations of its role.

This DPA lasts for as long as Orquestr processes personal data on the Customer's behalf, including any post-termination period during which Orquestr retains it under the Agreement or the law. The subject matter, nature, purpose, categories of data and data subjects, and duration are in Schedule 1.

3. Instructions and Customer duties

Orquestr processes personal data only:

If, in Orquestr's reasonable opinion, an instruction violates applicable law, we will inform the Customer promptly and may suspend the affected processing until the parties resolve it.

The Customer is responsible for the lawfulness, accuracy, and quality of the data and of its instructions; for notices, consents, and lawful bases; for responding to data subjects and authorities as controller; for configuring services and permissions; for securing the systems, devices, credentials, API keys, and integrations it controls; and for ensuring its use complies with law and the Agreement. The Customer will not submit restricted data the Agreement prohibits without prior written approval and any required additional contract.

4. Confidentiality and personnel

Orquestr will ensure that personnel authorized to process personal data are bound by confidentiality and receive access only as necessary for their role. We take reasonable steps so that personnel understand privacy and security duties.

5. Security

Orquestr maintains technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are in Schedule 2.

We may update those measures for changes in technology, risk, law, or the Services, provided the update does not materially reduce the overall level of protection during a paid subscription term. The Customer acknowledges that security is shared and that the Services cannot remove every risk. The Customer has reviewed the measures Orquestr makes available and decides whether they are appropriate for its processing.

6. Personal data breaches

Orquestr will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data. The notice will include information reasonably available about the nature of the incident, likely consequences, affected data, and remediation. We may provide information in phases.

We will take commercially reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably cooperate with the response the law requires of the Customer. Notice is not an admission of fault. The Customer decides whether to notify data subjects, authorities, or others. Where the law allows, the Customer will consult Orquestr before a notice that identifies us and will consider reasonable corrections about our role.

Unsuccessful attempts or events that do not compromise personal data — such as scans, pings, failed logins, and blocked attacks — are not breaches under this DPA.

7. Data subject requests and assistance

Taking into account the nature of the processing, Orquestr will provide tools and reasonable assistance available in the Services to help the Customer respond to data subjects. The Customer can access, export, correct, and delete much of Customer Data through the API and account controls, where they exist.

If we receive a request about personal data the Customer controls, we will, where appropriate, direct the requester to the Customer and notify the Customer, unless the law prohibits notice. We will not respond on the Customer's behalf unless the law requires it or the Customer authorizes it.

We will provide reasonable assistance with impact assessments, prior consultations, and security and breach duties the law requires of the Customer, given the information available to us. We may charge a reasonable fee for assistance that requires material work outside the ordinary Services, after advance notice and, on request, a good-faith estimate.

8. Subprocessors

The Customer authorizes the affiliates and subprocessors on the subprocessor list and gives general authorization to add or replace subprocessors under this section.

Orquestr will:

The Customer may object within 15 days after notice on reasonable, documented data-protection grounds. The parties will seek a good-faith solution. If they cannot find one, the Customer may stop using the affected feature or terminate the affected Services: that is its sole remedy for the objection. The Customer remains responsible for fees and usage incurred before termination.

We may use a subprocessor without prior notice where urgently necessary to maintain security or availability, and will give notice as soon as reasonably practical. Point-of-sale systems and other platforms the Customer connects are not subprocessors merely because of that connection.

9. International transfers

The Customer authorizes Orquestr and its subprocessors to process personal data in the United States and in the other countries where they operate, subject to the safeguards in this DPA.

For a Restricted Transfer from the EEA, the SCCs are incorporated as follows:

For a transfer subject to the UK GDPR, the SCCs as completed above apply as modified by the then-current UK International Data Transfer Addendum issued by the Information Commissioner's Office. The tables are deemed completed with the information in this DPA, with the Customer as exporter and Orquestr as importer, and the parties select the option that lets the importer end the addendum if an approved change creates a substantial and disproportionate increase in direct cost and the parties cannot agree an alternative.

For a transfer subject to Swiss law, the SCCs apply with references to the GDPR understood to include the Swiss Federal Act on Data Protection where necessary; the competent authority is the Federal Data Protection and Information Commissioner; and Swiss data subjects may bring proceedings in Switzerland where the law requires.

If a valid replacement transfer mechanism becomes available, Orquestr may update this section on notice, provided the replacement does not materially reduce the protection required.

10. Return, deletion, and retention

During the term, the Customer may access or export Customer Data using available functionality. The Customer should export before closing the account.

On the Customer's valid request or termination of the affected Services, Orquestr will delete or de-identify personal data within a commercially reasonable period, subject to:

Orquestr protects retained personal data and processes it only for that retention purpose. Further detail appears in the privacy notice and the Service documentation.

11. Automation and service improvement

The Customer instructs Orquestr to process personal data as needed to provide automated features the Customer selects, including transmission to providers on the subprocessor list, if any.

The Customer does not instruct Orquestr to use Customer Data to develop, test, train, or improve general-purpose models, except under a written agreement. Withholding that instruction does not prevent processing required to provide the Services, follow another instruction, maintain security, investigate abuse, comply with law, or create aggregated or de-identified analytics.

Orquestr will not authorize a model subprocessor to use personal data to train that subprocessor's general models except where disclosed to the Customer, required by a feature or provider the Customer selected, or separately authorized by the Customer. We will use commercially reasonable contractual options and settings intended to limit that training where they exist.

Orquestr does not make automated decisions on the Customer's behalf that produce legal or similarly significant effects, unless the documentation or an order identifies that function. The Customer is responsible for human review and for deciding whether that use is lawful.

12. Audits and information

On reasonable written request, Orquestr will provide information reasonably necessary to demonstrate compliance with this DPA. We may satisfy the request through then-current third-party audit reports, certifications, security documentation, questionnaires, or penetration-test summaries, subject to confidentiality. We do not claim that those reports exist today.

The Customer may audit compliance no more than once in any 12-month period, unless an additional audit is required by law, a competent authority, or a confirmed breach. Before an audit, the Customer must:

Audits will ordinarily be remote and document-based. On-site access is available only where the law requires it and the information cannot reasonably be provided another way. The Customer bears its audit costs and will reimburse Orquestr for reasonable costs of assistance beyond ordinary compliance materials, unless the audit finds a material breach by Orquestr.

13. U.S. state privacy laws

Where state privacy laws apply, Orquestr acts as the Customer's service provider or contractor for personal data. Orquestr will not:

Orquestr certifies that it understands these restrictions and will comply with them. The Customer may take reasonable steps to check that use is consistent with its obligations, including the audits in section 12.

14. Government requests

Unless prohibited by law, Orquestr will notify the Customer of a legally binding government request for personal data and will direct the authority to the Customer where appropriate. We will review the request for legal validity, disclose only what is legally required, and challenge it where there are reasonable grounds to do so.

15. Liability and order of precedence

Each party's liability under this DPA is subject to the exclusions and limits in the Agreement, except to the extent applicable law or the SCCs prohibit that limitation.

If there is a conflict about processing of personal data, this order applies: the applicable SCCs or mandatory transfer terms; this DPA; the Agreement; and other incorporated documents. The rest of the Agreement continues.

16. Changes and termination

Orquestr may update this DPA where reasonably necessary to comply with law, update transfer mechanisms, or reflect changes to the Services, provided the update does not materially reduce protection. We will give reasonable notice of material changes. The governing law and dispute terms of the Agreement apply to this DPA, except where mandatory transfer terms require otherwise.

Schedule 1. Processing details

Parties

Importer / provider: Orquestr. Privacy contact: legal@orquestr.com. Role: processor or subprocessor.

Exporter / Customer: the customer identified in the Agreement. Role: controller or processor, as applicable. Contact: the account owner, an administrator, or another contact the Customer designates.

Subject matter and purpose

Processing Customer Data to provide, secure, and maintain the Services described in the Agreement, including point-of-sale connectivity, the API, integrations, and sales, inventory, price, customer, and catalog operations the Customer initiates and that run in the Customer's cloud, plus related billing support.

Duration and frequency

Ongoing for the duration of the Agreement and any limited post-termination retention period. Transfers occur continuously or as initiated by the Customer and its users.

Categories of data subjects

Categories of personal data

Sensitive or restricted data

The Customer decides which categories it submits and must have a lawful basis. Restricted data identified in the Agreement remains prohibited unless agreed in writing and any required additional contract is in place.

Processing operations

Collection, receipt, access, organization, hosting, storage, consultation, use, transmission, disclosure to authorized subprocessors and to integrations the Customer enables, restriction, export, deletion, and de-identification, as necessary to provide the Services.

Subprocessors

The current list, as updated under section 8.

Schedule 2. Technical and organizational measures

Orquestr maintains a risk-based security program proportionate to the size and nature of the Services. Measures include, where applicable:

Access and identity

Data and infrastructure

Application and change security

Logging, monitoring, and incidents

Availability, personnel, and data lifecycle

Point-of-sale operations run in the Customer's cloud. The Customer sets the measures for that environment. Orquestr infrastructure that does not yet have a confirmed provider is not described in this schedule as if it were already under contract.

Schedule 3. SCC annex information

For Annex I.A of the SCCs, the parties and roles are in Schedule 1. By entering into the Agreement, each party is deemed to sign the SCCs as of the effective date of this DPA.

For Annex I.B, the transfer and processing details are in Schedule 1. For Annex I.C, the competent supervisory authority is determined under Clause 13 of the SCCs and section 9 of this DPA. For Annex II, the measures are in Schedule 2. For Annex III, the authorized subprocessors are those on the subprocessor list.