This Data Processing Addendum (“DPA”) forms part of the Agreement between Orchid AI Advisors LLC, a Georgia limited liability company (“Orchid”), and the customer identified in the applicable Order Form (“Customer”) for the Orchid AI Advisors platform (the “Service”). Capitalized terms not defined here have the meanings in the Terms of Service. If this DPA conflicts with the Terms on data-protection matters, this DPA controls.
1. Definitions
- “Personal Data” — information relating to an identified or identifiable natural person contained in Customer Data.
- “Data Protection Laws” — all laws applicable to the processing of Personal Data under the Agreement, including (where applicable) U.S. state privacy laws (e.g., the CCPA/CPRA) and the EU/UK GDPR.
- “Security Incident” — a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Orchid. Unsuccessful attempts (e.g., blocked probes, port scans) are not Security Incidents.
- “Subprocessor” — a third party engaged by Orchid to process Personal Data to provide the Service.
2. Roles and scope
2.1 For Personal Data submitted to the Service by or on behalf of Customer, Customer is the controller (or a processor acting for its own controller) and Orchid is the processor (or subprocessor).
2.2 For account administration, billing, website analytics, and security telemetry Orchid collects for its own purposes, Orchid is an independent controller, as described in its Privacy Policy; that processing is outside this DPA except where Data Protection Laws provide otherwise.
3. Customer instructions
Orchid will process Personal Data only: (a) to provide the Service; (b) as documented in the Agreement, this DPA, and the Service configuration chosen by Customer (together, Customer's complete instructions); and (c) as required by law, in which case Orchid will inform Customer unless legally prohibited. Orchid will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. CCPA service-provider terms
To the extent the CCPA/CPRA applies, Orchid acts as Customer's “service provider”: Orchid will not sell or share Personal Data; will not retain, use, or disclose it other than to perform the Service or as permitted by the CCPA; will not combine it with personal information from other sources except as permitted for service providers; certifies it understands these restrictions; and will notify Customer if it determines it can no longer meet its obligations under the CCPA. Orchid grants Customer the rights to take reasonable steps to remediate unauthorized use as the CCPA requires.
5. Confidentiality and personnel
Persons authorized to process Personal Data are bound by contractual or statutory confidentiality obligations. [Stated plainly for counsel and buyers: Orchid is presently a sole-operator business; production access is limited to that operator and the Subprocessors in Annex III.]
6. Security
6.1 Orchid will maintain appropriate technical and organizational measures to protect Personal Data, no less protective than those described in Annex II.
6.2 Orchid may update the measures from time to time, provided updates do not materially reduce the overall protection of Personal Data.
7. Security Incidents
7.1 Notice. Orchid will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer's Personal Data, by email to the Client Admin.
7.2 Content and cooperation. The notice will include the information reasonably available: nature of the incident, categories and approximate volumes of data and data subjects, likely consequences, and measures taken or proposed — supplemented as investigation proceeds. Orchid will take reasonable steps to contain and remediate and will reasonably cooperate with Customer's own notification obligations.
7.3 No admission. Notice of a Security Incident is not an admission of fault.
8. Subprocessors
8.1 Authorization and list. Customer generally authorizes the Subprocessors listed in Annex III (maintained at [URL — e.g., orchidaiadvisors.com/legal/subprocessors]).
8.2 Changes. Orchid will give at least thirty (30) days' notice (email to the Client Admin suffices) before adding or replacing a Subprocessor that processes Personal Data. Customer may object within that period on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees for the terminated portion.
8.3 Flow-down and responsibility. Orchid will impose data-protection obligations on Subprocessors no less protective than this DPA, and remains responsible for their performance.
8.4 AI model providers. Orchid's agreements with its AI model providers do not permit them to use Personal Data to train their foundation models. [VERIFY against the providers' commercial terms in force at signing.]
9. Data subject requests; assistance; learning
9.1 Taking into account the nature of the processing, Orchid will assist Customer with data-subject requests (access, correction, deletion, export) using the Service's built-in tools where possible, and otherwise within a reasonable time.
9.2 Orchid will forward to Customer any request received directly that concerns Customer's Personal Data and will not respond substantively except to redirect the requester.
9.3 Orchid will provide reasonable assistance with Customer's data-protection impact assessments and regulator consultations, to the extent required by Data Protection Laws and taking into account the information available to Orchid.
9.4 De-identified data. [IF the aggregated-learning clause is adopted in the Terms (§4.4):] Orchid may create and use de-identified, aggregated data as licensed there; Orchid will not attempt to re-identify it and will require the same of Subprocessors.
10. Government and law-enforcement requests
If a government or law-enforcement authority demands Personal Data, Orchid will: (a) redirect the authority to Customer where feasible; (b) notify Customer before disclosure unless legally prohibited; and (c) where a demand appears overbroad or unlawful, use commercially reasonable efforts to challenge or narrow it. Orchid will disclose only what it is legally compelled to disclose.
11. Deletion and return
11.1 Upon termination or expiry, and on Customer's written request made within thirty (30) days, Orchid will provide an export of Customer Data using the Service's organization-export capability.
11.2 Orchid will then delete Personal Data within [60/90 — DECIDE] days, except: (a) support-conversation records retained per the immutable [3-year] schedule; (b) backups, deleted on the backup rotation cycle [CONFIRM cycle length from the Supabase plan]; and (c) data Orchid must retain by law. On written request, Orchid will certify deletion in writing.
12. Audits
12.1 Orchid will make available information reasonably necessary to demonstrate compliance with this DPA — including its security-measures documentation, this DPA's annexes, and written responses to reasonable security questionnaires (response within a reasonable period not to exceed thirty (30) days).
12.2 Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied under 12.1, Customer may conduct an audit no more than once per twelve (12) months, on thirty (30) days' notice, at its own expense, during business hours, without disrupting the Service, and subject to Orchid's confidentiality and security requirements. [Note for buyers: Orchid does not currently hold a SOC 2 report; if one is obtained, it will satisfy audit requests under 12.1.]
13. International transfers
Data is hosted in [REGION — CONFIRM from the Supabase project settings]. To the extent Orchid processes Personal Data protected by EU/UK Data Protection Laws outside jurisdictions with adequacy, the parties incorporate the EU Standard Contractual Clauses, Module Two (controller → processor), with Orchid as data importer and Customer as data exporter, Annexes I and II of this DPA serving as the SCC appendices, and the UK Addendum / Swiss adaptations as applicable. [Dormant until EU/UK customers are onboarded; counsel to activate with the correct options (docking clause, governing member state, supervisory authority) at that time.]
14. Liability; term
Liability under this DPA is subject to the limitations of liability in the Terms (including the enhanced cap applicable to Orchid's breach of this DPA). This DPA remains in force as long as Orchid processes Personal Data under the Agreement.
Annex I — Description of processing
A. Parties. Data exporter/controller: the Customer identified on the Order Form (contact: its Client Admin). Data importer/processor: Orchid AI Advisors LLC, [ADDRESS], contact@orchidaiadvisors.com.
B. Processing description.
- Subject matter: operation of an AI-assisted discovery-interview platform.
- Duration: the subscription term plus the deletion period in §11.
- Nature and purpose: hosting, storage, transmission, AI-assisted analysis and generation, display to authorized users, notification delivery, support.
- Data subjects: Customer personnel invited to the platform; individuals mentioned in interview content or uploaded documents.
- Categories of Personal Data: names, business contact details, role information, opinions and workplace descriptions given in interviews, content of uploaded documents, support messages, voice audio (if voice features are used), usage and log data.
- Special categories: not intended; Customer agrees not to submit them absent a separate written agreement.
- Frequency: continuous during the term.
Annex II — Technical and organizational measures
Orchid maintains, at minimum:
- Tenant isolation — organization-scoped row-level security enforced in the database for every table and storage bucket, so one customer's users cannot read another customer's rows or files.
- Access control — invitation-only accounts; role separation (administrator / client-administrator / user); immediate disablement of users and whole organizations, enforced at multiple layers; a guard preventing removal of an organization's last administrator.
- AI-boundary safeguards — automated redaction intended to keep third-party personal names out of content sent to AI model providers; prompt-injection defenses on content entering the AI pipeline; per-interview monetary processing caps with organization-level allowances; service-wide kill switches for AI processing.
- Transport security — TLS for data in transit; an enforced browser content-security policy with violation reporting and monitoring.
- Auditability — activity audit logging of significant actions; error monitoring with administrator alerting; security-telemetry collection.
- Data lifecycle — organization-level export; document archive/purge tools with a bounded undo window; automated long-term retention purge (7 years for documents); user removal that revokes access while preserving organizational records, with a separate full-purge option.
- Backups — [CONFIRM: Supabase automated backup frequency and retention on the current plan; state what is true.]
- Vendor management — Subprocessors bound per §8.3; AI providers restricted from foundation-model training per §8.4.
[Counsel: this annex describes controls that actually exist in the platform; resist genericizing it — real, specific controls are easier to defend than boilerplate.]
Annex III — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage, server functions | [REGION] |
| Netlify | Web hosting, CDN, DNS | [CONFIRM] |
| Anthropic | AI language model processing (redacted content) | United States |
| ElevenLabs | Text-to-speech synthesis | [CONFIRM] |
| Resend | Transactional email | [CONFIRM] |
| CloudConvert | Document format conversion | [CONFIRM] |
| [Inbound email provider] | [Reply-by-email processing — CONFIRM identity] | [CONFIRM] |
This table is also published on its own at the Subprocessors page, kept in lockstep with this Annex and with the Privacy Policy's subprocessor table.
