This agreement governs how Orchard processes data on behalf of the Customer that deploys it, and the obligations each party accepts before any endpoint is enrolled or any data is captured.
Document: Orchard DPA · Version: 1.2 · Effective date: On acceptance (see Acceptance, below) · Applies to: Orchard customer deployments
In plain terms
The Customer instructs which devices and activity are monitored. Where it determines the purposes and means of that monitoring, it is the data controller and Orchard is its data processor. Where the Customer acts for another controller, Orchard acts as its sub-processor under the arrangements below.
- Controller — The Customer authorizes monitoring and instructs what is processed, for its own organization or authorized client environments.
- Processor — Orchard captures, transmits, isolates, and stores data only to deliver the service.
- Hard limits — Supported monitoring capture excludes screenshots, raw keystroke logging, and recognized password fields. Field values and clipboard content may be collected when full capture or work recording is enabled.
This Data Processing Agreement (the "DPA") is entered into by and between Enter the Orchard Syndicate, a Delaware corporation with its principal place of business in Minnesota, USA ("Orchard") and the customer that accepts it (the "Customer"). Their processing roles are set out in Section 2. It forms part of, and is subject to, the Master Services Agreement or Terms of Service between the parties (the "Agreement"). Where this DPA conflicts with the Agreement on the subject of data protection, this DPA controls.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement or in applicable data-protection law. "Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including, where applicable, the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended ("CCPA/CPRA"), and sector rules such as the Health Insurance Portability and Accountability Act ("HIPAA") or the Gramm-Leach-Bliley Act ("GLBA") that bind the Customer or its clients.
- Personal Data — any information relating to an identified or identifiable natural person processed by Orchard on the Customer's behalf under the Agreement.
- Processing — any operation performed on Personal Data, including capture, transmission, storage, structuring, retrieval, and deletion.
- Controller — the party that determines the purposes and means of Processing. The Customer is a Controller where it determines those purposes and means; a client may be the Controller where the Customer acts on its behalf.
- Processor — the party that Processes Personal Data on behalf of the Controller. Orchard acts as Processor or Sub-processor as described in Section 2.
- Sub-processor — any third party engaged by Orchard to Process Personal Data in delivering the service (see Annex C).
- Data Subject — the individual to whom Personal Data relates; here, principally the operators of monitored endpoints.
- Endpoint — a device on which the Orchard watcher (capture agent) is enrolled and running.
- Captured Activity — the semantic activity data the watcher records, as defined and bounded in Section 5.
2. Roles of the parties
- Where the Customer determines the purposes and means of monitoring, it is the Controller. It decides which endpoints, teams, and activity are included and the retention it requires. It is responsible for having a lawful basis and the necessary authority and notices in place for that monitoring.
- Orchard is the Processor where the Customer is Controller, and a Sub-processor where the Customer is a Processor for another Controller. It Processes Personal Data only to provide, secure, maintain, and support the service, and only on the Customer's documented instructions (this DPA and the Customer's configuration in the platform being such instructions).
- Service providers and client environments. A Customer, including an MSP, may act for client organizations. It is responsible for the necessary controller-to-controller or controller-to-processor arrangements with those clients and, where it acts as Processor, authorization to appoint Orchard as Sub-processor. The Customer must ensure its instructions to Orchard are consistent with the relevant Controller's instructions. The protections in this DPA apply to that processing.
- Orchard will not sell Personal Data and will not retain, use, or disclose it for any purpose other than performing the service, including not combining it with data from other sources except as needed to provide the service to the Customer. This is a "service provider" commitment for CCPA/CPRA purposes.
3. Scope, nature & purpose of processing
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A. In summary, Orchard Processes Captured Activity and related account and telemetry data to deliver always-on endpoint awareness, workforce and operational insights for the Customer, work recording, and scheduled automation, as configured by the Customer.
Orchard will Process Personal Data only for the duration of the Agreement and for the limited period afterward required for return or deletion under Section 12, unless retention is required by law.
4. Orchard's processing obligations
- Documented instructions. Orchard Processes Personal Data only on the Customer's documented instructions, including for international transfers, unless required to do otherwise by law — in which case Orchard will inform the Customer first, unless that law prohibits it.
- Confidentiality. Orchard ensures that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis.
- Security. Orchard implements and maintains the technical and organizational measures in Annex B, appropriate to the risk.
- Sub-processors. Orchard engages Sub-processors only under Section 7 and remains responsible for their performance.
- Assistance. Taking into account the nature of the Processing, Orchard assists the Customer with data-subject requests (Section 9), security, breach notification, and data-protection impact assessments (Sections 10–11).
- Deletion or return. On termination, Orchard returns or deletes Personal Data per Section 12.
- Demonstrating compliance. Orchard makes available information reasonably necessary to demonstrate compliance with this DPA and supports audits per Section 11.
- Instruction conflicts. Orchard will notify the Customer if, in its opinion, an instruction infringes Data Protection Law.
5. What Orchard captures — and never captures
The capture boundary below is enforced in the watcher itself, not merely promised in policy. It is a core property of the product. Orchard will not weaken it for a given tenant without an explicit, documented instruction from the Customer and a corresponding amendment to this DPA.
Captured
- Foreground application — the app currently in focus.
- Window title — the title bar of the focused window.
- Idle time — active vs. idle intervals, not content.
- UIA control type & name — the kind and label of the control interacted with (e.g. "Button — Save").
- Field values & interactions — committed values and actions from supported desktop and browser controls, when full capture or work recording is enabled.
- Clipboard text — content in captured copy/paste actions when full capture or work recording is enabled; recognized password fields are excluded.
- Network flow metadata — the endpoint's outbound connections in aggregate: the owning application and OS account, protocol, remote address and port, reverse-DNS name where it resolves, and connection counts over a time window. Addresses, ports and volumes only — never payload contents.
- Voice transcripts — only on a workspace holding the Technician module, and only on that Customer's own internal endpoints (see 5.2): the text of a transcribed call, per channel, with timings. Off by default.
- Endpoint telemetry — hardware/OS facts, heartbeat, agent health.
- Account & tenancy data — user, role, client, and seat records the Customer creates.
Excluded from monitoring capture
- Screenshots or pixels — monitoring capture does not image the screen.
- Raw keystroke text — monitoring capture does not log printable keystrokes; committed field values may be captured as described above.
- Recognized password fields — controls identified as password fields by the application or browser are excluded from supported monitoring capture. Credential capture is not an available monitoring setting (see 5.1).
- Network payload contents — flow metadata records that a connection happened and its shape, never what travelled over it.
- Call audio — where transcription is enabled (5.2), audio is streamed for transcription and is not stored by Orchard. Only the resulting text is retained.
Orchard monitors application activity and, when enabled, field values, clipboard content, and interactions to understand and automate work. Full capture can collect that content outside a manually started recording. Scope and exclusions must be configured for the environments being monitored.
5.1 Password fields and connection credentials
Credential capture from monitored password fields is not a supported setting. Recognized password fields are excluded from supported monitoring capture. Sensitive information placed in ordinary fields, window titles, or clipboard content may still be included in enabled capture. The Customer is responsible for assessing its monitored environments and configuring scope and exclusions accordingly.
Credentials the Customer deliberately supplies to connect an integration are separate from monitoring capture. They are processed to provide the connection the Customer authorizes and protected under Section 6.
5.2 Live call transcription (optional feature)
Where live call transcription is in force for a workspace, the watcher can open a transcription session for a call on an enrolled endpoint — including automatically, on detecting a call in progress — and stream that call's audio to the speech-recognition Sub-processor named in Annex C, over a short-lived, per-session token minted by Orchard. Orchard never holds a standing credential on the endpoint for this, does not store the audio, and retains only the returned transcript text. The recognizer does not retain the audio for its own account and does not use it to train its models.
- Off by default. It rides with the Technician module, and only on the Customer's own endpoints. Two conditions must both hold before an endpoint will record. The workspace must hold the Technician module, which a Customer can add to its subscription itself; and the endpoint must belong to the Customer's Internal client — its own staff. An endpoint assigned to an end client never records, and neither does an endpoint whose client is unknown: not knowing whose desk it is reads as "do not record". An individual may decline unattended recording on their own machine, and that election can only subtract from what the workspace allows, never add to it.
- Orchard can force it off, and that is a real control. Independently of the module, Orchard can set the feature off for a named workspace, and that setting overrides the subscription. This is the control the Business Associate Agreement relies on to exclude transcription for a Customer handling Protected Health Information; it is not, and is no longer described as, an inability to reach the feature by configuration.
- Third parties to the call. A transcribed call routinely includes the voice of someone who is neither the Customer's personnel nor an Orchard user. The Customer is the controller for that processing.
- Notice and consent are the Customer's. The Customer is responsible for the notice, consent and, where required, recording-warning that call recording and transcription demand in every jurisdiction in which any party to the call is located — including all-party (commonly "two-party") consent jurisdictions. Orchard does not determine and cannot verify where the far end of a call is.
- Retention. Voice sessions and their transcript segments are deleted 30 days after creation (Annex A).
Customer responsibility. The Customer must ensure that monitored individuals are notified of monitoring as required by applicable law and employment rules, and that an appropriate lawful basis exists before an endpoint is enrolled.
6. Security & tenant isolation
- Multi-tenant isolation. Every record is tenant-scoped. Tenant separation is enforced at the database layer using PostgreSQL Row-Level Security (RLS), which is fail-closed: with no tenant context set, a query returns zero rows rather than leaking across tenants. Tenant context is bound from the authenticated identity before any data is read.
- Enrollment & agent identity. Enrollment and agent tokens embed the tenant identifier so tenant context is established before any database read, keeping the watcher's writes confined to its own tenant.
- Encryption in transit. Data transmitted between endpoints, the API, and the consoles is protected with current TLS, terminating on Orchard's own Google Cloud load balancer. No third-party edge or reverse proxy stands in front of it, so no vendor outside Annex C sees a request body in the clear.
- Tenant access control. Customer console roles are least-privilege — owner / admin / member, where member is read-only.
- Internal access is the one deliberate, audited exception to RLS. Orchard's support / platform console is separate from the tenant API: its own credentials, its own authentication secret, and mandatory TOTP multi-factor authentication. It connects to the database under a role that is SELECT-only on tenant tables — even sales-assisted tenant provisioning routes its writes through a constrained path, not the elevated platform role — and every read it performs is written to an immutable platform audit log (which staff member, which action, which tenant, when). RLS is bypassed here by design, for support and operations; that bypass is constrained and fully accountable, not silent.
- Encryption at rest & key management. Managed database storage is encrypted at rest by the cloud provider (Google Cloud SQL, AES-256, with provider-managed keys). Selected sensitive fields — for example window titles, control names, stored integration secrets, and MFA seeds — are additionally encrypted at the application layer (AES-GCM) before they reach the database.
- Logging & monitoring. Operator actions and every cross-tenant platform read are written to append-only audit logs; application logs are structured and centrally collected, and production access is limited to authorized staff on a need-to-know basis.
The full set of measures is set out in Annex B. Orchard may update measures provided the level of protection is not materially reduced.
7. Sub-processors
- The Customer provides general authorization for Orchard to engage the Sub-processors listed in Annex C, each bound by data-protection terms no less protective than this DPA.
- Orchard will give the Customer prior notice of any intended addition or replacement of a Sub-processor, with at least 30 days to object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected service.
- Customer-initiated integrations. Where the Customer connects a third-party system it controls — for example a ConnectWise or other PSA connection, which Orchard ingests on a read-only basis — that third party is the Customer's own processor/integration, not an Orchard Sub-processor, and the Customer is responsible for its terms.
8. International transfers & residency
Orchard hosts the platform on cloud infrastructure as described in Annex C. The primary processing region is the United States (Google Cloud region us-central1). Where live call transcription is in force (5.2), the call audio stream and the transcript returned are processed by the recognizer named in Annex C on its United States endpoints. Where Processing involves a transfer of Personal Data subject to GDPR/UK GDPR outside the EEA/UK to a country without an adequacy decision, the transfer is governed by the Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA on the terms set out in Annex D — including the modules selected, the optional clauses elected, and the mapping from this DPA's annexes to the annexes those clauses require. Where this DPA conflicts with those clauses, those clauses prevail on the subject matter they govern.
9. Assistance with data-subject rights
Taking into account the nature of the Processing, Orchard provides reasonable assistance — through appropriate technical and organizational measures, insofar as possible — to help the Customer respond to requests from Data Subjects exercising rights of access, rectification, erasure, restriction, portability, and objection. If Orchard receives such a request directly, it will not respond except on the Customer's instruction and will promptly forward the request to the Customer.
10. Personal-data breach notification
- Orchard notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Customer's data.
- The notice will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it.
- Orchard reasonably assists the Customer with the Customer's own breach-notification obligations to regulators and Data Subjects. Notification is not, by itself, an acknowledgment of fault.
11. Audits & demonstrating compliance
Orchard makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (or following a breach, or where required by a supervisory authority), allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to confidentiality and to not compromising other customers' security or data. Where available, Orchard may satisfy this obligation by providing current third-party reports or certifications (for example, a SOC 2 report).
12. Return & deletion on termination
- On termination or expiry of the Agreement, and at the Customer's choice, Orchard returns the Personal Data in a commonly used format and/or deletes it, together with existing copies, within 30 days, unless retention is required by law.
- Backups containing Personal Data are deleted or expire within their ordinary rotation cycle, after which they are no longer restored to active use.
- On request, Orchard certifies completion of deletion in writing.
13. Liability, governing law & miscellaneous
- Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
- Governing law & venue. This DPA is governed by the law and subject to the venue stated in the Agreement, or, if none, the State of Delaware, USA.
- Order of precedence. In the event of conflict on data-protection matters: this DPA, then the Agreement, then Orchard's documentation.
- Changes. Orchard may update this DPA to reflect changes in law or the service, provided the level of protection is not materially reduced; material changes will be notified to the Customer.
- Severability & survival. If any provision is held unenforceable, the remainder stays in effect. Obligations that by their nature should survive termination do so.
14. Derived data & aggregated learning
Orchard improves the service by learning from the structure of work — never from its contents. This section defines exactly what may be derived from Captured Activity, and what may never leave a tenant boundary.
- Structural fingerprints. Orchard may derive anonymized, aggregated structural data from Captured Activity: workflow shapes (the ordered sequence of application, action, and control identity), frequency and duration statistics, and automation-outcome statistics. Derivation strips captured field values, window titles, URL paths, and record identifiers at the moment of derivation — the boundary is enforced in the derivation code, not merely promised in policy.
- Never included. Derived data that crosses a tenant boundary never includes captured field values, window titles, personnel identities, client or end-user names, or any content that could identify the Customer or its clients. Only the structural fingerprint and its aggregate statistics cross tenants.
- Permitted uses. Orchard may use derived data to improve its products — including cross-customer workflow recognition, industry benchmarks, and the training of automation models. Derived data is never sold and never attributed to a Customer or its clients.
- Capture scope unchanged. Nothing in this section expands what the watcher captures. Capture scope remains governed by Section 5 and by the monitoring-authorization statement each client affirms.
- Client portability. Each end client's automation history and measured-savings ledger belong with that client, and are exportable to the client or a successor service provider on request.
- Exclusion on request. The Customer may instruct Orchard in writing to exclude its tenant from the derivation described in this section, in whole. Orchard applies the exclusion within 30 days of the instruction and confirms in writing when it is in force, after which no structural fingerprint or aggregate statistic derived from that tenant's Captured Activity crosses its tenant boundary. It is applied by Orchard on request rather than by a switch in the console, so ask before enrolling if the answer needs to be in place from the first endpoint. This is the same election offered at Section 10 of the Business Associate Agreement; exercising it under either agreement exercises it under both.
- Raw data rights unchanged. The Customer may export or request deletion of its raw Captured Activity at any time (Section 12). Previously derived anonymized aggregates persist, as they contain no Personal Data.
Annex A — Details of processing
| Subject matter | Provision of the Orchard endpoint-capture, awareness/insights, recording, and scheduling/automation service to the Customer. |
| Duration | The term of the Agreement, plus the return/deletion period in Section 12. |
| Nature & purpose | Capture, transmission, isolation, storage, structuring, retrieval, analysis, and deletion of Captured Activity and related data to deliver workforce monitoring, operational insights, work recording, and scheduled automation. |
| Categories of Data Subjects | Operators of monitored endpoints in the Customer's organization or authorized client environments; Customer console users. |
| Types of Personal Data | Foreground application and window titles; idle/active intervals; desktop/browser control type, name, and committed field values and interactions when full capture or recording is enabled (excluding recognized password fields); clipboard content in captured copy/paste actions; network flow metadata (owning application and OS account, protocol, remote address, port, resolved hostname, connection counts — never payload contents); endpoint hardware/OS telemetry and agent health; account, role, client, and seat records. |
Only if the Customer enables live call transcription (5.2): the transcript text of a transcribed call, including the speech of third parties to that call. Call audio is streamed for transcription and is not stored.
Excluded from supported monitoring capture: screenshots/pixels, raw keystroke logging, and recognized password fields. See Section 5.
Special-category data: Not intentionally processed. Window titles, field values, or clipboard content could incidentally reveal sensitive information in some workflows; the Customer is responsible for assessing this risk for its monitored environments and configuring scope accordingly.
Frequency: Continuous / always-on while endpoints are enrolled and active.
Retention: Each class of data is swept automatically on its own schedule. The periods below are the current defaults. They are set per Orchard deployment, not per customer — a shorter period is available by agreement for a dedicated deployment, and none of them is a floor the Customer must wait out: raw Captured Activity can be exported or deleted on request at any time (Section 12).
| Data | Retained for |
|---|---|
| Captured Activity in the primary database — foreground and action samples | 7 days |
| Network flow metadata in the primary database — application, remote address and port, connection counts per hour; never payloads | 7 days |
| The same activity in Orchard's analytics store (Annex C). It carries application, window title, control name, OS account, machine, and derived keys. It never carries field values, clipboard text, pixels or keystrokes. | Up to 730 days |
| Captured Activity with no analytics copy — clipboard content in captured copy/paste actions | 90 days |
| Voice sessions and transcript segments (5.2) | 30 days |
| Endpoint telemetry — metric samples and measured network routes | 90 days |
| Derived work records — the entity/work spine and hourly activity counters. Machine, OS account, kind of work, hour and counts; no window titles and no field values. | 400 days |
| In-product UI events | 180 days |
| Account, client, seat, credential and audit records | Life of the account, then returned or deleted on termination (Section 12) |
Deletion in the primary database is clamped to the analytics copy: a row is never swept before it has been copied, so a stalled copy delays deletion rather than losing the record.
Annex B — Technical & organizational measures
| Area | Measure |
|---|---|
| Tenant isolation | PostgreSQL Row-Level Security, fail-closed (no tenant context → zero rows). Tenant context bound from authenticated identity before any read; transaction-local and re-bound after commit. The only path that bypasses RLS is the audited internal platform console (see Identity & access). |
| Capture minimization | Monitoring capture includes activity and, when enabled, committed field values, clipboard content, and interactions. It excludes screenshots, raw keystroke logging, and recognized password fields. Credential capture is not a supported monitoring setting (see 5.1). Network flow metadata is aggregated on the endpoint to counts per connection window and never carries payload contents. Call audio, where transcription is enabled, is streamed for transcription and never stored. |
| Feature gating | Live call transcription (5.2) is off unless the workspace holds the Technician module, and then runs only on endpoints belonging to the Customer's Internal client; an end client's endpoint, or one whose client is unknown, never records. Orchard can force the feature off for a named workspace, overriding the subscription — the control the BAA relies on. |
| Identity & access | Least-privilege Customer console roles (owner / admin / read-only member). The internal platform console is separate, with its own credentials and authentication secret, a SELECT-only database role on tenant tables, mandatory TOTP MFA, and an immutable audit-log entry for every read. |
| Authentication | Per-user credentials with password-strength enforcement; agent/enrollment tokens scoped to a single tenant; login rate-limited with uniform timing to resist account enumeration. App-based TOTP multi-factor authentication, with single-use recovery codes, is available to every Customer operator, and a workspace owner can require it for all users in the workspace. MFA is mandatory for Orchard's internal platform administrators. |
| Encryption in transit | Current TLS for endpoint↔API and console↔API traffic, terminating on Orchard's own Google Cloud load balancer. No third-party edge proxy sits in front of it; the hostnames that carry captured content resolve straight to that load balancer. |
| Encryption at rest | Managed database storage encrypted at rest by the cloud provider (Google Cloud SQL, AES-256). Selected sensitive fields are additionally application-encrypted before storage. |
| Resilience & backup | Managed Google Cloud SQL automated backups with point-in-time recovery (PITR) enabled. |
| Change management | Contract-first API with a checked-in OpenAPI specification; database migrations versioned and applied on deploy. |
| Vulnerability management | Application dependencies are pinned via lockfiles; the managed platform (Cloud Run, Cloud SQL) receives the provider's security patching. An independent third-party penetration test is planned as the platform matures. |
| Personnel | Confidentiality obligations and need-to-know access for staff handling Personal Data. |
Annex C — Approved sub-processors
Current as of the effective date, subject to the update mechanism in Section 7.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Google Cloud Platform (GCP) | Cloud infrastructure (compute, storage), the managed PostgreSQL database, the analytics store, and the load balancer that terminates TLS for every endpoint, console and API request. Hosted in the United States (us-central1). | All platform data, in transit and at rest. |
| Cloudflare | DNS for entertheorchard.ai, the marketing website, and public distribution of the watcher installer and browser-extension updates from object storage (dl. and updates.entertheorchard.ai). Not in the data path: since 2026-09-16 the hostnames that carry Captured Activity — the API, the console and the admin console — resolve directly to Orchard's Google Cloud load balancer, so Cloudflare no longer terminates TLS for them and no longer sees a request body. | Standard request metadata (IP address, user-agent, requested path) for the website and for installer downloads. No Captured Activity, no console or API traffic, no account records. |
| Resend | Transactional email delivery (e.g. password reset, account email). | Recipient email address and message contents. |
| Soniox | Live call transcription (5.2), on its United States endpoints. Audio is streamed from the endpoint to Soniox under a short-lived, per-session key minted by Orchard; Orchard stores only the text returned. Soniox does not retain the audio for its own account and does not use submitted audio or transcripts to train its models. Added by the notice at Section 7 given 2026-09-18; effective 2026-10-18. | Call audio, in transit only and stored by neither party, and the returned transcript text. |
| Deepgram | The recognizer Soniox replaces, on the same terms. In service until 2026-10-18 only, so that no workspace loses transcription while the Section 7 notice period runs; removed from this Annex once the replacement is in force in every environment. | As above. |
Cloudflare's row is kept, rather than deleted, because Cloudflare remains a vendor of Orchard's: it resolves the names and serves the public downloads. What changed on 2026-09-16 is the traffic it carries, and the change is stated here so a reviewer holding version 1.1 can see it.
Customer-initiated integrations (e.g. a ConnectWise/PSA connection the Customer configures and Orchard ingests read-only) are the Customer's own integrations and are not listed here as Orchard Sub-processors. See Section 7.
Annex D — Standard Contractual Clauses
The clauses referenced at Section 8, and how this DPA populates the annexes they require. They take effect on the same date as this DPA and apply only to a transfer that Section 8 covers.
EEA transfers. The Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"), incorporated in full, in the module matching the parties' roles: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to sub-processor) where the Customer is itself a processor for its end client. The elections are:
| Clause | Election |
|---|---|
| Clause 7 — docking | Applies. A further party may accede. |
| Clause 9 — sub-processors | Option 2, general written authorisation, with the notice period and objection right at Section 7 of this DPA. |
| Clause 11 — redress | The optional independent-dispute-resolution paragraph does not apply. |
| Clause 13 — supervision | The authority identified at Annex I.C below. |
| Clause 17 — governing law | The law of Ireland. |
| Clause 18(b) — forum | The courts of Ireland. |
UK transfers. The UK International Data Transfer Addendum to the EU SCCs (version B1.0) issued under s.119A DPA 2018, incorporated in full. Its Table 1 (parties) and Table 3 (appendix information) are completed by the mapping below; Table 2 selects the EU SCCs and modules named above; Table 4 is set to neither party — neither may end the Addendum under its Section 19.
Swiss transfers. The EU SCCs as adapted per the FDPIC: references to the GDPR are read as references to the FADP, the competent authority is the FDPIC, and nothing in the clauses prevents a data subject from bringing proceedings in Switzerland.
Mapping to the SCC annexes
| SCC annex | Populated by |
|---|---|
| Annex I.A — Parties | The parties named in the preamble of this DPA, with the contact details in the acceptance record. Exporter: the Customer, as controller or as processor. Importer: Orchard, as processor or as sub-processor. |
| Annex I.B — Description of transfer | Annex A of this DPA: categories of data subjects, types of Personal Data, sensitive-data note, frequency, nature and purpose, and retention. |
| Annex I.C — Competent supervisory authority | The authority of the EEA member state in which the Customer is established, or, where the Customer is not established in the EEA, of the member state in which the data subjects whose data is transferred are located. |
| Annex II — Technical and organisational measures | Annex B of this DPA. |
| Annex III — List of sub-processors | Annex C of this DPA, under the general authorisation at Section 7. |
Acceptance
This DPA takes effect on the earlier of (a) the date of the last signature below, and (b) the date the Customer first enrolls an endpoint, or otherwise uses the service, after this DPA has been made available to it. Signature is not a condition of it binding either party — a signed counterpart is available on request where the Customer's procurement requires one, and the signature block below is provided for that purpose.
Orchard maintains the version of this DPA in force from time to time and the date each version took effect; material changes are notified under Section 13.
Orchard (Processor) — Signature / Name / Title / Date
Customer (Controller or Processor, as applicable) — Signature / Name / Title / Date