Data Processing Addendum
Ordo offers this DPA on request when a Customer requires a written data-processing agreement for its own privacy compliance (enterprise procurement, EU/UK GDPR footprint, or PIPEDA-driven vendor management).
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between Ordo and Customer (the "Agreement"). It applies to Ordo's processing of Personal Information on behalf of Customer in the course of providing the Service.
Where this DPA and the Agreement conflict on a data-protection matter, this DPA controls. Where this DPA is silent, the Agreement applies.
#1. Definitions
Terms defined in the Agreement have the same meaning here. In addition:
- "Data Protection Laws" means all laws applicable to Customer's processing of Personal Information under the Agreement, including PIPEDA and provincial equivalents (Quebec Law 25, BC PIPA, Alberta PIPA), the EU General Data Protection Regulation (GDPR) 2016/679 and the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by CPRA, and any successor laws.
- "Personal Information" means any information that identifies, or can reasonably be used to identify, a natural person, processed by Ordo on Customer's behalf under the Agreement.
- "Data Subject" means the natural person to whom the Personal Information relates, including a Caller.
- "Processor", "Controller", "Processing", and "Data Subject Rights" have the meanings given in the applicable Data Protection Laws.
- "Sub-processor" means a third party engaged by Ordo to process Personal Information on Customer's behalf.
- "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information.
#2. Roles and scope
Customer is the Controller (or "controller-equivalent" in jurisdictions using different terminology) of the Personal Information processed under the Agreement. Ordo is the Processor acting on Customer's documented instructions.
Ordo's role and processing scope are described at Annex A. Customer represents that its instructions to Ordo (through the Agreement, the dashboard settings, and any supported configuration) comply with Data Protection Laws.
#3. Ordo's obligations as Processor
Ordo will:
- Process only on instructions. Process Personal Information only on Customer's documented instructions, including with regard to international transfers, unless required to do so by applicable law. If Ordo is legally compelled to process outside Customer's instructions, Ordo will notify Customer in advance where lawful.
- Confidentiality. Ensure that Ordo personnel with access to Personal Information are bound by confidentiality obligations at least as protective as those in the Agreement.
- Security. Implement and maintain the technical and organisational measures described in Annex B, designed to protect Personal Information against a Security Incident and appropriate to the risk.
- Sub-processor management. Engage Sub-processors only under a written contract that imposes data-protection obligations at least as protective as this DPA. Maintain the current Sub-processor list per useordo.org/legal/subprocessors/ and provide fourteen (14) days' prior notice of any material addition. Ordo remains liable to Customer for its Sub-processors' performance.
- Data Subject Rights. Assist Customer, at Customer's reasonable request and by appropriate technical and organisational measures, in fulfilling Customer's obligation to respond to Data Subject Rights requests (access, correction, deletion, portability, restriction, objection, or human-review under Quebec Law 25 or Article 22 GDPR). Where Ordo receives a Data Subject request directly, Ordo will forward it to Customer and will not respond on the merits unless instructed by Customer or required by law.
- Regulatory assistance. Assist Customer, taking into account the nature of the processing and the information available to Ordo, in meeting Customer's obligations under Articles 32-36 GDPR (security, notification, DPIA, prior consultation) and equivalent provisions of other Data Protection Laws.
- Return or delete. On termination of the Agreement, at Customer's choice, return or delete Personal Information as set out in Section 16 of the Agreement, subject to legal retention requirements.
- Audit. Make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and permit and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, no more than once per twelve (12)-month period (except in the case of a Security Incident or as required by a regulator), on at least thirty (30) days' prior written notice, subject to confidentiality obligations, and at Customer's expense.
#4. Security
Ordo maintains the security measures described in Annex B. Ordo will not materially reduce these measures during the term of the Agreement.
#5. Security Incident notification
Ordo will notify Customer of a Security Incident affecting Customer's Personal Information without undue delay and in any event within seventy-two (72) hours of Ordo's confirmation of the Incident. The notification will include, to the extent known and available: the nature of the Incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to mitigate the Incident. Ordo will provide updates as information becomes available.
For US Protected Health Information under a Business Associate Agreement, the applicable timeline is the HIPAA breach notification rule (45 CFR 164.410), which requires notification without unreasonable delay and no later than sixty (60) calendar days after discovery. That timeline governs PHI incidents.
#6. International transfers
Ordo processes Personal Information in Canada and the United States, and may transfer Personal Information to Sub-processors in those regions. Ordo relies on the following transfer mechanisms as applicable:
- PIPEDA: contractual and technical measures with Sub-processors, per Office of the Privacy Commissioner of Canada guidance on cross-border transfers.
- EU GDPR and UK GDPR: the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor and Module Three: Processor-to-Processor) as incorporated by reference into this DPA, plus the UK International Data Transfer Addendum (IDTA) where UK transfers are in scope.
- Quebec Law 25: the assessment described in Article 17 of Law 25, with contractual protections at Sub-processor level.
Where a new mechanism is required by law (for example, replacement of an invalidated adequacy decision), Ordo will implement it and notify Customer.
#7. Term
This DPA takes effect when signed and continues for as long as the Agreement is in force, or as long as Ordo processes Personal Information on Customer's behalf, whichever is later.
#8. Governing law
This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable there, consistent with the Agreement.
#Annex A · Processing details
- Subject matter: provision of the Ordo AI phone receptionist service.
- Duration: for the term of the Agreement.
- Nature and purpose: answering Customer's inbound phone line, understanding Callers' requests, generating spoken responses, recording call audio (where consented), transcribing calls, taking bookings and orders, passing messages, and integrating the result into Customer's own business systems where configured.
- Categories of Personal Information: Caller phone number and caller ID, Caller name (where volunteered), booking or order details, party sizes, dates, addresses, dietary and appointment preferences, and other information a Caller volunteers to complete the requested action; also standard log data associated with the Caller's interaction with the Service.
- Categories of Data Subjects: Callers to Customer's Ordo-connected phone line; Customer's own employees and administrators who use the dashboard.
- Special categories (Article 9 GDPR): Ordo does not knowingly collect health, financial, biometric, or other special categories of Personal Information. Where a Caller volunteers such information incidentally, Ordo escalates the call to Customer's staff and stops recording, as described in the Privacy Policy.
#Annex B · Technical and organisational security measures
Ordo maintains the following measures, appropriate to the risk represented by the processing:
Access control
- Unique, individually-attributable login credentials for every Ordo staff account with access to production systems.
- Multi-factor authentication required for all administrative access.
- Role-based access control; least-privilege access to Personal Information; access reviewed at least quarterly.
Encryption
- Personal Information encrypted in transit using industry-standard TLS.
- Personal Information encrypted at rest in production databases and object storage.
- Encryption keys managed by Ordo's cloud infrastructure provider under contractual key-management guarantees.
Logical isolation
- Multi-tenant isolation: each Customer's Personal Information is logically isolated. Cross-tenant queries are not possible through the application.
- Sub-processor traffic is scoped to the minimum data required for the specific service.
Audit logging
- Access to production systems is logged. Administrative actions on Personal Information are logged.
- Logs are retained for a period sufficient to meet audit and investigation needs (minimum twelve months).
Vulnerability management
- Dependencies scanned regularly for known vulnerabilities.
- Security-relevant patches applied on a risk-based schedule.
- Periodic review of application security posture.
Personnel
- Ordo personnel are bound by confidentiality obligations.
- Security awareness practices apply to anyone with access to Personal Information.
Business continuity
- Regular automated backups of production data.
- Documented recovery procedures.
Incident response
- Documented incident detection, response, and notification process aligned with Section 5 of this DPA.
Ordo reviews these measures at least annually and updates them as the risk and technical landscape evolve.
#Execution
Customer:
Name: ________________________ Title: ________________________ Signature: ____________________ Date: _______________________
Ordo:
Gregory Uku, operating as Ordo
Signature: ____________________ Date: _______________________