Draft for legal review. Bracketed text marks a decision or fact that counsel must confirm before this document is published.
This Data Processing Addendum (the DPA) forms part of the Terms of Service between [Legal Entity Name] (Orkka, we, us) and the customer that accepted those Terms (Customer, you). It applies where Orkka processes personal data on your behalf and where data protection law requires a written processor contract, including Article 28 of Regulation (EU) 2016/679 (GDPR) and the UK GDPR.
1. Scope & precedence
This DPA applies automatically, without signature, from the moment you accept the Terms, for as long as Orkka processes personal data on your behalf. If you need a signed copy or your own paper, contact [privacy@orkka.ai].
In the event of a conflict, the order of precedence is: (a) the Standard Contractual Clauses incorporated by Section 12; (b) this DPA; (c) the Terms of Service; (d) the Privacy Policy.
2. Definitions
- Customer Personal Data means personal data contained in Customer Content — repositories and code you connect, task descriptions, briefs, documents, messages to agents, and configuration.
- End-User Data means personal data relating to the users of a hosted app you build with Orkka, stored or processed in or through that hosted app — including its database, its email, its file uploads, and the AI features it calls.
- Protected Data means Customer Personal Data and End-User Data together.
- Controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the GDPR.
- Data Protection Law means all laws on the processing of personal data applicable to a party, including the GDPR, the UK GDPR, the Swiss FADP, and applicable US state privacy laws.
- SCCs means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.
3. Roles & instructions
You are the controller of Protected Data and Orkka is the processor. Where you act as a processor for another controller — for example where your hosted app serves your own business customers — Orkka is a sub-processor, you confirm you have the authority to enter into this DPA on that controller’s behalf, and the SCC module for processor-to-processor transfers applies.
Orkka processes Protected Data only on your documented instructions. Your instructions are: the Terms, this DPA, the configuration you choose in the product, the tasks you run, and the code your hosted app executes against the Orkka platform API. Orkka will not process Protected Data for its own purposes, will not sell it, and will not use it to train artificial-intelligence models. Orkka may process it as required by applicable law, and will inform you of that requirement first unless the law forbids it.
If Orkka considers an instruction to infringe Data Protection Law, it will tell you without undue delay and may suspend the affected processing until the instruction is withdrawn or amended.
Your responsibilities. You are responsible for the lawfulness of the Protected Data you place in the Service, for having a legal basis, for the notices and choices you give data subjects, for the accuracy of the data, and for the configuration you choose — including what your hosted app collects, retains, and displays. You must not place in the Service any special-category data, children’s data, or other restricted data prohibited by Section 8.3 of the Terms unless we have agreed otherwise in writing.
4. Confidentiality & personnel
Orkka ensures that persons authorised to process Protected Data are bound by an appropriate duty of confidentiality, receive training appropriate to their role, and have access only to the data they need.
5. Security
Orkka implements and maintains the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the risk to data subjects. Orkka may update those measures provided the level of protection is not materially reduced.
You are responsible for the security decisions inside your own hosted app and repositories: the authentication and authorisation logic your app implements, what your app exposes publicly, who you invite to your organization, and your review of AI-generated code before it is deployed. Orkka does not warrant that generated code is secure; see Section 6 of the Terms.
6. Subprocessors
You give Orkka general authorisation to engage subprocessors. The subprocessors engaged as at the effective date are listed in Annex III.
Orkka will give you at least [30] days notice before adding or replacing a subprocessor, by updating Annex III and notifying you by [email / in-product notice — confirm mechanism]. You may object on reasonable data-protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected part of the Service before the change takes effect and receive a pro-rata refund of prepaid, unused fees for it.
Orkka imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable to you for its subprocessors’ performance.
7. Data subject requests
Taking into account the nature of the processing, Orkka assists you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. Much of this is self-service: you can access, export, correct, and delete data through the product and, for a hosted app, directly in its database.
If Orkka receives a request from a data subject relating to Protected Data, it will not respond to it substantively, will tell the data subject to contact you where it can identify you, and will forward the request to you without undue delay.
8. Personal data breach
Orkka notifies you without undue delay, and in any event within [48] hours, after becoming aware of a personal data breach affecting Protected Data. The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point. Orkka will provide further information as it becomes available and will cooperate with you so that you can meet your own notification deadlines, which for controllers under the GDPR is 72 hours.
Notice will be sent to the [security contact] on your account. Keeping that contact current is your responsibility. Orkka notifying you is not an admission of fault or liability.
9. Impact assessments & prior consultation
Orkka provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to it. Assistance beyond providing existing documentation may be chargeable at our then-current rates.
10. Return & deletion
You may export Protected Data at any time during the term through the product, its API, your repository, or your hosted app database. On termination, Orkka deletes Protected Data in accordance with Section 14 of the Terms: unless prohibited or the termination is for cause, data remains available for export for at least [30] days, after which the hosted app deployment, repository, database, and stored files are deleted.
Residual copies may persist in backups, which age out on a rolling schedule of [period]; while they persist they remain subject to this DPA and are not actively processed. Orkka may retain data where required by law, for the period required.
11. Audits & information
Orkka makes available the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, as follows: first, by providing its security documentation and any third-party certifications or reports it holds [list any: SOC 2, ISO 27001, penetration test summary — none as at the effective date]; and second, where that is genuinely insufficient, by an audit at your expense, no more than once per twelve months (unless required by a supervisory authority or following a personal data breach), on at least [30] days notice, during business hours, without disrupting the Service, subject to confidentiality, and never including access to other customers’ data or to shared infrastructure that would expose it.
12. International transfers
Orkka and its subprocessors process Protected Data in [list of regions — confirm against Annex III], which may include the United States. Where a transfer of Protected Data from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision takes place, the parties incorporate the SCCs by reference, as follows:
- Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) where you are a processor;
- the optional docking clause in Clause 7 [applies / does not apply]; in Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 6;
- in Clause 11, the optional independent dispute-resolution language [does not apply]; in Clause 17 the governing law is [Member State]; in Clause 18(b) the forum is [Member State];
- Annexes I, II, and III of the SCCs are populated by Annex I, Annex II, and Annex III of this DPA; and
- for UK transfers, the UK International Data Transfer Addendum applies to the SCCs, and for Swiss transfers, references are read as including the FADP and the Swiss Federal Data Protection and Information Commissioner.
13. US state privacy law
Where the California Consumer Privacy Act as amended (CCPA) applies, Orkka acts as a service provider. Orkka does not sell or share Protected Data, does not retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA, does not combine it with personal information from other sources except as the CCPA permits, and certifies that it understands and will comply with these restrictions. Equivalent commitments apply under other US state privacy laws that impose them.
14. Liability, term & general
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, to the extent permitted by law. Nothing in this DPA limits a data subject’s rights under Data Protection Law or a party’s liability to a supervisory authority.
This DPA continues for as long as Orkka processes Protected Data. Orkka may update it to reflect changes in law, in the Service, or in its subprocessors, on notice; if an update materially reduces your protections you may terminate the affected Service before it takes effect. Questions and requests under this DPA go to [privacy@orkka.ai].
Annex I — Description of the processing
A. Parties
Data exporter (controller): the Customer identified in the Orkka account, at the address on the account. Contact: the account owner and any privacy contact set on the account.
Data importer (processor): [Legal Entity Name, Registered Address], provider of the Orkka platform. Contact: [privacy@orkka.ai].
B. Description of the processing
- Categories of data subjects: your personnel and members of your organization; individuals whose personal data appears in the repositories, tasks, documents, or files you submit; and, for hosted apps, the end users of those apps and anyone whose data your end users submit to them.
- Categories of personal data: identification and contact data (name, email, profile); account, organization, and permission data; authentication data such as credentials created by a hosted app’s sign-in system; usage, log, device, and IP data; billing contact and payment metadata; free-text content submitted to agents or to a hosted app; files and uploads; and any other personal data you choose to store in a hosted app.
- Special categories: none. Special-category data is prohibited by Section 8.3 of the Terms unless separately agreed in writing.
- Frequency: continuous, for as long as the Service is used.
- Nature and purpose: hosting, storage, transmission, and analysis of the data in order to operate the Orkka platform; to run AI agents that plan, write, test, review, and deploy software at your direction; and to provision and operate hosted apps, including their database, authentication, email, file storage, payment session creation, and AI features.
- Retention: for the duration of the account, then as described in Section 10 of this DPA and the retention section of the Privacy Policy.
- Subprocessor processing: as described in Annex III, for the duration of the underlying service.
C. Competent supervisory authority
[To be determined by counsel — the authority of the Member State of the exporter’s establishment or of its Article 27 representative.]
Annex II — Technical & organisational measures
| Measure | Description |
|---|---|
| Encryption | TLS for data in transit. Encryption at rest for platform storage and databases, provided by the underlying cloud services. Secrets and access tokens are held in a managed key vault and encrypted at rest. |
| Tenant isolation | Every record is scoped to an organization and the scope is enforced at the data layer. Each hosted app receives its own database and a dedicated database role with least privilege; credentials are not shared between projects. |
| Access control | Role-based access within the product, configured by the organization owner. Administrative access to production is limited to personnel who need it, authenticated through the identity provider, and logged. |
| Repository access | Repositories are accessed with short-lived, scoped installation tokens rather than long-lived credentials. Tokens are issued per operation and are not persisted. |
| Agent execution isolation | Agent runs execute in isolated workspaces with a restricted tool surface and guardrails that block dangerous or out-of-scope operations. |
| Logging & monitoring | Application, execution, and access logs with retention of [period]. Alerting on error and abuse signals. |
| Resilience | Managed database backups as provided by the underlying platform, with a recovery objective of [RPO/RTO to be confirmed by counsel and engineering — see Section 8.7 of the Terms]. |
| Vulnerability management | Dependency scanning, patching of managed platform components, and code review of changes before release. |
| Personnel | Confidentiality obligations for everyone with access to personal data, and background checks where permitted by law. |
| Deletion | Documented deletion paths for accounts, projects, and hosted apps, with backups ageing out on a rolling schedule. |
Measures must be verified against the platform as deployed before this annex is published, and reviewed whenever the architecture changes.
Annex III — Subprocessors
| Subprocessor | Purpose | Data involved | Processing location |
|---|---|---|---|
| Microsoft Azure | Platform compute, storage & PostgreSQL | Customer Personal Data; platform records | [Region] |
| Neon | Managed PostgreSQL for hosted apps (one database per project) | End-User Data stored by the hosted app | [Region] |
| Vercel | Deployment hosting for hosted apps | Hosted app code, configuration & request logs | [Region] |
| Anthropic | AI model provider for agent execution and hosted-app AI features | Content submitted for processing; prompts sent by hosted apps | United States |
| Resend | Transactional email delivery | Recipient addresses, message content & delivery events | [Region] |
| Stripe | Payment processing & invoicing | Billing contact and payment metadata | United States / Ireland |
| Clerk | Authentication for the Orkka platform | Account name, email, profile & credentials | United States |
| GitHub | Repository hosting & access via the Orkka GitHub App | Repository content and metadata | United States |
This addendum supplements the Terms of Service and the Privacy Policy.