Data Processing Addendum
This Addendum forms part of the Terms of Service between Conquermental LLC ("Orren", "we", the processor) and the customer (the controller) and applies wherever data protection law makes the customer responsible for the personal data of other people that Orren processes on the customer's behalf.
1. Roles
- You are the controller of the personal data in your records: your leads, clients, correspondents, invitees and the people who appear in your captures and recordings. You decide why it is collected and what is done with it.
- We are the processor. We process it only to provide the service to you and on your documented instructions, which are the Terms of Service, this Addendum, and what you do in the app.
- For your own account data (your email, licence, payments, diagnostics) we are the controller, and the Privacy Policy applies.
2. What is processed
- Subject matter. Operating Orren for you: storing and synchronising your records, answering your questions about them, and running the automations you configure.
- Duration. The life of your account, plus the retention periods in section 8.
- Nature and purpose. Storage, retrieval, indexing, embedding for search, generation of answers and drafts by AI models, sending messages on your instructions, and matching payments and bookings to people.
- Categories of data subjects. Your leads and prospects, customers and clients, people who message or comment on your connected accounts, people invited to your calendar bookings, and people who appear in your recordings and notes.
- Categories of personal data. Names, usernames, platform identifiers, profile pictures, message and comment content, booking details, payment amounts and dates with the email the payment carried, notes and transcripts you make about people, and the relationships Orren infers between these.
- Special categories. Orren is not designed for them. If your notes contain health, financial-hardship or similar information about people, you are responsible for having a lawful basis for it.
3. Our obligations
We will:
- Process personal data only on your instructions, unless the law requires otherwise, in which case we tell you first where we may.
- Ensure the people who run Orren are bound by confidentiality.
- Apply the security measures in section 6.
- Engage subprocessors only under section 5.
- Help you respond to requests from data subjects, and to your own security and impact assessments, to the extent the tooling in the app does not already let you do it yourself.
- Delete or return the personal data at the end of the service, under section 8.
- Make available the information needed to show compliance, and allow audits under section 9.
- Tell you without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting your data, with what we know and what we are doing.
4. Your obligations
You will have a lawful basis for the personal data you put into Orren, give the people concerned the notices the law requires, and use the controls Orren provides (hide, delete, export, disconnect) to honour their rights. You will not put into Orren personal data you are not entitled to hold.
5. Subprocessors
You authorise the subprocessors listed at Subprocessors, which says what each one holds and where. We will give you at least 30 days' notice before adding one, by updating that page and its date, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may end the service and receive a pro-rated refund of any prepaid term. Each subprocessor is bound by data-protection terms no less protective than these.
6. Security
- Data in transit is encrypted with TLS. Data at rest is encrypted by Google Cloud.
- Each customer's records are separated by database-level row-level security enforced for every role, including administrative ones.
- Connector tokens are never returned to the app or shown in any interface.
- The app is signed and notarised; releases are built from a gate that refuses undeclared network paths.
- Production access is limited to the people who run Orren, with individual credentials.
- Details and vulnerability reporting are in the Security Policy.
7. International transfers
Our servers are in the United States. Where your data is subject to the law of the EEA, the United Kingdom or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), which are incorporated here by reference with you as data exporter and us as data importer, together with the UK Addendum and the Swiss amendments where they apply. [COUNSEL: attach the clauses and complete the annexes; sections 2, 5 and 6 above are written to serve as Annex I and II.]
8. Deletion and return
You can export all of your data from the app at any time. When the service ends, or when you ask, we delete your synchronised records, connector tokens and account from our systems within 30 days, and from backups on their normal cycle. Deleting a record or hiding a person in the app removes them from our systems on the next sync. We keep only what the law requires us to keep, and only for as long as it requires.
9. Audit
Once a year, on 30 days' notice, and at your cost, you may audit our compliance with this Addendum, in the first instance by written questions and by reviewing the documentation we provide, and, where that is not enough to meet a legal obligation you have, by an inspection at a time that does not disrupt the service.
10. Liability
Liability under this Addendum is subject to the limits in the Terms of Service, except where data protection law does not allow it.
11. Contact
Data protection questions: josh@conquermental.com. Conquermental LLC, [COMPANY ADDRESS].