Legal
Data processing agreement
Last updated: September 24, 2026
Version: 2026-09-24
This data processing agreement, including its schedules (the “DPA”), forms part of the agreement between Orquestr and the customer that uses the Services (the “Customer”) and governs Orquestr's processing of personal data on the Customer's behalf.
The DPA applies automatically when the Customer accepts the Terms of Service, signs an order or other agreement that incorporates it, or uses Services that involve processing personal data. It does not require a separate signature. If the parties sign it separately, it takes effect on the last signature date. The processor is Orquestr. Contact: legal@orquestr.com.
1. Definitions
“Affiliate” means an entity that controls, is controlled by, or is under common control with a party.
“Applicable Data Protection Law” means privacy, data-protection, and data-security law applicable to Orquestr's processing under the agreement, including, where applicable, the GDPR and U.S. state privacy laws.
“Controller,” “data subject,” “personal data,” “personal data breach,” “process,” and “processor” have the meanings in applicable law. “Controller” includes a “business,” and “processor” includes a “service provider” or “contractor,” where those state laws use those terms.
“Customer Data” means information the Customer, or someone for the Customer, submits to or processes through the Services. “Personal data” in this DPA means Customer Data that is regulated personal data. It does not include information Orquestr processes independently as a controller, such as business contacts, account, billing, and relationship information.
“GDPR” means Regulation (EU) 2016/679, the UK GDPR, and applicable implementing law, in each case where it applies.
“Restricted Transfer” means a transfer of personal data that requires a recognized mechanism under the GDPR or Swiss data-protection law.
“SCCs” means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
“Services” means the services covered by the agreement. “Subprocessor” means an affiliate or third party Orquestr engages to process personal data on the Customer's behalf. Capitalized terms not defined here have the meaning in the agreement that incorporates this DPA (the “Agreement”).
2. Scope, roles, and duration
The Customer is a controller or processor, as applicable. Orquestr is a processor or subprocessor acting on the Customer's behalf. Each party complies with the obligations of its role.
This DPA lasts for as long as Orquestr processes personal data on the Customer's behalf, including any post-termination period during which Orquestr retains it under the Agreement or the law. The subject matter, nature, purpose, categories of data and data subjects, and duration are in Schedule 1.
3. Instructions and Customer duties
Orquestr processes personal data only:
- to provide, secure, and maintain the Services;
- as configured or initiated by the Customer and its authorized users, including point-of-sale operations executed in the Customer's cloud;
- as the Agreement, this DPA, orders, and the Customer's other documented instructions describe; and
- as required by law, in which case Orquestr will notify the Customer before processing unless the law prohibits notice.
If, in Orquestr's reasonable opinion, an instruction violates applicable law, we will inform the Customer promptly and may suspend the affected processing until the parties resolve it.
The Customer is responsible for the lawfulness, accuracy, and quality of the data and of its instructions; for notices, consents, and lawful bases; for responding to data subjects and authorities as controller; for configuring services and permissions; for securing the systems, devices, credentials, API keys, and integrations it controls; and for ensuring its use complies with law and the Agreement. The Customer will not submit restricted data the Agreement prohibits without prior written approval and any required additional contract.
4. Confidentiality and personnel
Orquestr will ensure that personnel authorized to process personal data are bound by confidentiality and receive access only as necessary for their role. We take reasonable steps so that personnel understand privacy and security duties.
5. Security
Orquestr maintains technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are in Schedule 2.
We may update those measures for changes in technology, risk, law, or the Services, provided the update does not materially reduce the overall level of protection during a paid subscription term. The Customer acknowledges that security is shared and that the Services cannot remove every risk. The Customer has reviewed the measures Orquestr makes available and decides whether they are appropriate for its processing.
6. Personal data breaches
Orquestr will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data. The notice will include information reasonably available about the nature of the incident, likely consequences, affected data, and remediation. We may provide information in phases.
We will take commercially reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably cooperate with the response the law requires of the Customer. Notice is not an admission of fault. The Customer decides whether to notify data subjects, authorities, or others. Where the law allows, the Customer will consult Orquestr before a notice that identifies us and will consider reasonable corrections about our role.
Unsuccessful attempts or events that do not compromise personal data — such as scans, pings, failed logins, and blocked attacks — are not breaches under this DPA.
7. Data subject requests and assistance
Taking into account the nature of the processing, Orquestr will provide tools and reasonable assistance available in the Services to help the Customer respond to data subjects. The Customer can access, export, correct, and delete much of Customer Data through the API and account controls, where they exist.
If we receive a request about personal data the Customer controls, we will, where appropriate, direct the requester to the Customer and notify the Customer, unless the law prohibits notice. We will not respond on the Customer's behalf unless the law requires it or the Customer authorizes it.
We will provide reasonable assistance with impact assessments, prior consultations, and security and breach duties the law requires of the Customer, given the information available to us. We may charge a reasonable fee for assistance that requires material work outside the ordinary Services, after advance notice and, on request, a good-faith estimate.
8. Subprocessors
The Customer authorizes the affiliates and subprocessors on the subprocessor list and gives general authorization to add or replace subprocessors under this section.
Orquestr will:
- enter into a written agreement requiring each subprocessor to protect personal data in a manner appropriate to the service it performs;
- remain responsible for the data-protection obligations it delegates; and
- give at least 15 days' prior notice of a new subprocessor that will materially process personal data, by email, in-product notice, or the notice mechanism associated with the list.
The Customer may object within 15 days after notice on reasonable, documented data-protection grounds. The parties will seek a good-faith solution. If they cannot find one, the Customer may stop using the affected feature or terminate the affected Services: that is its sole remedy for the objection. The Customer remains responsible for fees and usage incurred before termination.
We may use a subprocessor without prior notice where urgently necessary to maintain security or availability, and will give notice as soon as reasonably practical. Point-of-sale systems and other platforms the Customer connects are not subprocessors merely because of that connection.
9. International transfers
The Customer authorizes Orquestr and its subprocessors to process personal data in the United States and in the other countries where they operate, subject to the safeguards in this DPA.
For a Restricted Transfer from the EEA, the SCCs are incorporated as follows:
- Module Two applies where the Customer is a controller and Orquestr is a processor.
- Module Three applies where the Customer is a processor and Orquestr is a subprocessor.
- The optional docking clause in Clause 7 applies.
- Option 2 in Clause 9 applies, with the notice period in section 8.
- The optional language in Clause 11 does not apply.
- The supervisory authority is determined under Clause 13 based on the exporter and the data subjects.
- The governing law for Clause 17 is the law of Ireland.
- The courts for Clause 18 are the courts of Ireland.
- Schedules 1 through 3 of this DPA complete the relevant annexes to the SCCs.
For a transfer subject to the UK GDPR, the SCCs as completed above apply as modified by the then-current UK International Data Transfer Addendum issued by the Information Commissioner's Office. The tables are deemed completed with the information in this DPA, with the Customer as exporter and Orquestr as importer, and the parties select the option that lets the importer end the addendum if an approved change creates a substantial and disproportionate increase in direct cost and the parties cannot agree an alternative.
For a transfer subject to Swiss law, the SCCs apply with references to the GDPR understood to include the Swiss Federal Act on Data Protection where necessary; the competent authority is the Federal Data Protection and Information Commissioner; and Swiss data subjects may bring proceedings in Switzerland where the law requires.
If a valid replacement transfer mechanism becomes available, Orquestr may update this section on notice, provided the replacement does not materially reduce the protection required.
10. Return, deletion, and retention
During the term, the Customer may access or export Customer Data using available functionality. The Customer should export before closing the account.
On the Customer's valid request or termination of the affected Services, Orquestr will delete or de-identify personal data within a commercially reasonable period, subject to:
- the Customer's instructions and product controls;
- normal backup rotation and technical limits;
- retention required or permitted by law;
- security, fraud-prevention, dispute, financial, and audit needs; and
- data that has been aggregated or de-identified so that it is no longer personal data.
Orquestr protects retained personal data and processes it only for that retention purpose. Further detail appears in the privacy notice and the Service documentation.
11. Automation and service improvement
The Customer instructs Orquestr to process personal data as needed to provide automated features the Customer selects, including transmission to providers on the subprocessor list, if any.
The Customer does not instruct Orquestr to use Customer Data to develop, test, train, or improve general-purpose models, except under a written agreement. Withholding that instruction does not prevent processing required to provide the Services, follow another instruction, maintain security, investigate abuse, comply with law, or create aggregated or de-identified analytics.
Orquestr will not authorize a model subprocessor to use personal data to train that subprocessor's general models except where disclosed to the Customer, required by a feature or provider the Customer selected, or separately authorized by the Customer. We will use commercially reasonable contractual options and settings intended to limit that training where they exist.
Orquestr does not make automated decisions on the Customer's behalf that produce legal or similarly significant effects, unless the documentation or an order identifies that function. The Customer is responsible for human review and for deciding whether that use is lawful.
12. Audits and information
On reasonable written request, Orquestr will provide information reasonably necessary to demonstrate compliance with this DPA. We may satisfy the request through then-current third-party audit reports, certifications, security documentation, questionnaires, or penetration-test summaries, subject to confidentiality. We do not claim that those reports exist today.
The Customer may audit compliance no more than once in any 12-month period, unless an additional audit is required by law, a competent authority, or a confirmed breach. Before an audit, the Customer must:
- give at least 30 days' notice where practical;
- propose a scope limited to processing that concerns the Customer;
- use an independent, qualified auditor that does not compete with Orquestr;
- sign reasonable confidentiality terms; and
- avoid unreasonable interference with operations or with the security and confidentiality of other customers.
Audits will ordinarily be remote and document-based. On-site access is available only where the law requires it and the information cannot reasonably be provided another way. The Customer bears its audit costs and will reimburse Orquestr for reasonable costs of assistance beyond ordinary compliance materials, unless the audit finds a material breach by Orquestr.
13. U.S. state privacy laws
Where state privacy laws apply, Orquestr acts as the Customer's service provider or contractor for personal data. Orquestr will not:
- sell or share personal data for cross-context behavioral advertising;
- retain, use, or disclose personal data outside the direct business relationship with the Customer or for a commercial purpose other than the purposes the Agreement and this DPA describe, except as those laws permit;
- combine personal data received from the Customer with personal information received from another person or from Orquestr's own interactions with a consumer, except as those laws permit; or
- attempt to re-identify de-identified data except to test whether de-identification complies with law.
Orquestr certifies that it understands these restrictions and will comply with them. The Customer may take reasonable steps to check that use is consistent with its obligations, including the audits in section 12.
14. Government requests
Unless prohibited by law, Orquestr will notify the Customer of a legally binding government request for personal data and will direct the authority to the Customer where appropriate. We will review the request for legal validity, disclose only what is legally required, and challenge it where there are reasonable grounds to do so.
15. Liability and order of precedence
Each party's liability under this DPA is subject to the exclusions and limits in the Agreement, except to the extent applicable law or the SCCs prohibit that limitation.
If there is a conflict about processing of personal data, this order applies: the applicable SCCs or mandatory transfer terms; this DPA; the Agreement; and other incorporated documents. The rest of the Agreement continues.
16. Changes and termination
Orquestr may update this DPA where reasonably necessary to comply with law, update transfer mechanisms, or reflect changes to the Services, provided the update does not materially reduce protection. We will give reasonable notice of material changes. The governing law and dispute terms of the Agreement apply to this DPA, except where mandatory transfer terms require otherwise.
Schedule 1. Processing details
Parties
Importer / provider: Orquestr. Privacy contact: legal@orquestr.com. Role: processor or subprocessor.
Exporter / Customer: the customer identified in the Agreement. Role: controller or processor, as applicable. Contact: the account owner, an administrator, or another contact the Customer designates.
Subject matter and purpose
Processing Customer Data to provide, secure, and maintain the Services described in the Agreement, including point-of-sale connectivity, the API, integrations, and sales, inventory, price, customer, and catalog operations the Customer initiates and that run in the Customer's cloud, plus related billing support.
Duration and frequency
Ongoing for the duration of the Agreement and any limited post-termination retention period. Transfers occur continuously or as initiated by the Customer and its users.
Categories of data subjects
- the Customer's users, personnel, contractors, representatives, and business contacts;
- the Customer's customers, prospects, and end users;
- people who appear in point-of-sale sales, inventory, customer records, or catalogs; and
- other data subjects whose data the Customer instructs Orquestr to process.
Categories of personal data
- names, identifiers, contact details, and profile information;
- sales, inventory, price, customer, supplier, and catalog records, and their metadata;
- point-of-sale connection credentials, tokens, and identifiers;
- IP addresses, device, browser, authentication, API, webhook, usage, log, and security data;
- organization, role, permissions, and configuration; and
- support communications and subscription, balance, and transaction metadata, excluding full card data processed directly by the payment processor.
Sensitive or restricted data
The Customer decides which categories it submits and must have a lawful basis. Restricted data identified in the Agreement remains prohibited unless agreed in writing and any required additional contract is in place.
Processing operations
Collection, receipt, access, organization, hosting, storage, consultation, use, transmission, disclosure to authorized subprocessors and to integrations the Customer enables, restriction, export, deletion, and de-identification, as necessary to provide the Services.
Subprocessors
The current list, as updated under section 8.
Schedule 2. Technical and organizational measures
Orquestr maintains a risk-based security program proportionate to the size and nature of the Services. Measures include, where applicable:
Access and identity
- individual personnel accounts and role-based access;
- least privilege on production and customer systems;
- multi-factor authentication on critical systems, where the system supports it;
- documented onboarding, role changes, and offboarding; and
- periodic review of access to critical systems.
Data and infrastructure
- encryption in transit using common protocols, where the channel supports it;
- encryption at rest through infrastructure-provider controls, where a provider exists and supports it;
- managed secret storage and restrictions on disclosure;
- account or project authorization controls; and
- separation of production access from ordinary end-user access.
Application and change security
- version control and review of production changes;
- automated tests and security checks proportionate to the change;
- dependency and vulnerability monitoring; and
- API authentication and authorization controls, input handling, webhooks, and rate limits.
Logging, monitoring, and incidents
- operational and security logs with access and retention controls;
- monitoring and alerting for material availability and security events;
- a response process covering triage, containment, investigation, recovery, communication, and follow-up; and
- preservation of relevant evidence during material incidents.
Availability, personnel, and data lifecycle
- infrastructure and database backups proportionate to critical services, where the provider offers them;
- monitoring of provider status and production health;
- confidentiality duties for authorized personnel and written data-protection terms with subprocessors;
- product functions for access, export, and deletion, as published; and
- deletion or de-identification from active systems after a valid request or termination, subject to backup rotation and lawful retention.
Point-of-sale operations run in the Customer's cloud. The Customer sets the measures for that environment. Orquestr infrastructure that does not yet have a confirmed provider is not described in this schedule as if it were already under contract.
Schedule 3. SCC annex information
For Annex I.A of the SCCs, the parties and roles are in Schedule 1. By entering into the Agreement, each party is deemed to sign the SCCs as of the effective date of this DPA.
For Annex I.B, the transfer and processing details are in Schedule 1. For Annex I.C, the competent supervisory authority is determined under Clause 13 of the SCCs and section 9 of this DPA. For Annex II, the measures are in Schedule 2. For Annex III, the authorized subprocessors are those on the subprocessor list.
