Data Processing Addendum

Orren · Conquermental LLC · Last updated August 29, 2026

Draft pending legal review. A data processing addendum is a regulated document in several jurisdictions and this one has not been reviewed by counsel. It is written so that a customer who needs one has a factual starting point and so that a lawyer is reviewing what the software does rather than discovering it.

This Addendum forms part of the Terms of Service between Conquermental LLC ("Orren", "we", the processor) and the customer (the controller) and applies wherever data protection law makes the customer responsible for the personal data of other people that Orren processes on the customer's behalf.

1. Roles

2. What is processed

3. Our obligations

We will:

  1. Process personal data only on your instructions, unless the law requires otherwise, in which case we tell you first where we may.
  2. Ensure the people who run Orren are bound by confidentiality.
  3. Apply the security measures in section 6.
  4. Engage subprocessors only under section 5.
  5. Help you respond to requests from data subjects, and to your own security and impact assessments, to the extent the tooling in the app does not already let you do it yourself.
  6. Delete or return the personal data at the end of the service, under section 8.
  7. Make available the information needed to show compliance, and allow audits under section 9.
  8. Tell you without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting your data, with what we know and what we are doing.

4. Your obligations

You will have a lawful basis for the personal data you put into Orren, give the people concerned the notices the law requires, and use the controls Orren provides (hide, delete, export, disconnect) to honour their rights. You will not put into Orren personal data you are not entitled to hold.

5. Subprocessors

You authorise the subprocessors listed at Subprocessors, which says what each one holds and where. We will give you at least 30 days' notice before adding one, by updating that page and its date, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may end the service and receive a pro-rated refund of any prepaid term. Each subprocessor is bound by data-protection terms no less protective than these.

6. Security

7. International transfers

Our servers are in the United States. Where your data is subject to the law of the EEA, the United Kingdom or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), which are incorporated here by reference with you as data exporter and us as data importer, together with the UK Addendum and the Swiss amendments where they apply. [COUNSEL: attach the clauses and complete the annexes; sections 2, 5 and 6 above are written to serve as Annex I and II.]

8. Deletion and return

You can export all of your data from the app at any time. When the service ends, or when you ask, we delete your synchronised records, connector tokens and account from our systems within 30 days, and from backups on their normal cycle. Deleting a record or hiding a person in the app removes them from our systems on the next sync. We keep only what the law requires us to keep, and only for as long as it requires.

9. Audit

Once a year, on 30 days' notice, and at your cost, you may audit our compliance with this Addendum, in the first instance by written questions and by reviewing the documentation we provide, and, where that is not enough to meet a legal obligation you have, by an inspection at a time that does not disrupt the service.

10. Liability

Liability under this Addendum is subject to the limits in the Terms of Service, except where data protection law does not allow it.

11. Contact

Data protection questions: josh@conquermental.com. Conquermental LLC, [COMPANY ADDRESS].