Data processing addendum
The standard terms for personal data that customers put into OrhanAI. Offered as a signed document on request; this page is the same text, published so it can be read before asking.
Before you rely on this
This is a template, not legal advice, and it has not been reviewed by counsel for your jurisdiction. Read it, and have your own adviser read it, before treating it as sufficient for a regulated workload. A signed copy is available at links@orhanai.com.
1. Roles
For personal data that a customer or their visitors put into the service, the customer is the controller and OrhanAI is the processor. OrhanAI processes that data only on the customer's documented instructions, which the subscription agreement and the customer's use of the product constitute.
For a customer's own account data — the name and email of the people who sign in, and billing records — OrhanAI is the controller, and the Privacy Policy applies.
2. What is processed
- Categories of data subject: the customer's workspace users, and visitors who use an embedded agent.
- Categories of personal data: name, email address, phone number where a visitor supplies one, message content, uploaded images and documents, and coarse visitor context — country, region, city, device, browser, language, timezone and referring page.
- Raw IP addresses are not stored. Where an IP is needed to enforce a rate limit or to record an audit entry, it is hashed with a server-side secret first.
- Special category data is not requested by the service and should not be put into it.
- Duration: for as long as the customer's account is active, subject to any retention window the customer sets and to section 6.
3. Sub-processors
The customer authorises the sub-processors listed on the sub-processors page, which distinguishes those every workspace uses from those that receive data only when the customer connects the integration.
OrhanAI will give notice before a new sub-processor begins processing customer personal data, and the customer may object on reasonable data protection grounds. Each sub-processor is bound by terms no less protective than these.
4. Security
OrhanAI maintains the technical and organisational measures described on the security page, which is written against what the software actually does rather than against a control framework. In summary: every tenant-owned query is scoped to a workspace, credentials for connected services are encrypted at rest, public widget access is refused unless the embedding domain is allowed, and administrative access is separated from customer access.
Personnel with access to customer data are bound by confidentiality obligations.
5. Incidents
OrhanAI will notify the customer without undue delay, and in any case within 72 hours of confirming a personal data breach affecting their data, with what is known at the time. The process is published at incident response.
6. Data subject requests, return and deletion
- Visitors can request an export or a deletion of their own data through the widget, and the customer can act on such a request from the dashboard.
- A workspace owner can export the whole workspace at any time, in a form that deliberately contains no credentials, API key hashes, webhook secrets or certificates.
- A workspace can set retention windows for conversations and audit records. Floors apply — seven days for conversations, ninety for audit records — so a policy cannot be set short enough to delete live data or to make the audit log useless for the incident it exists to explain.
- On termination, customer data is deleted on request, and otherwise within a reasonable period. Deleting a workspace also deletes its uploaded files from object storage and its embeddings from vector search.
- Where OrhanAI is required by law to retain something, it says so rather than deleting it quietly.
7. Audit
OrhanAI will provide the information reasonably necessary to demonstrate compliance with this addendum, and will accommodate an audit by the customer or an auditor they mandate, on reasonable notice and no more than once a year unless a regulator requires otherwise.
OrhanAI does not currently hold a SOC 2 or ISO 27001 report. Saying so is more useful than implying otherwise.
8. International transfers
Sub-processors listed on the sub-processors page may process data outside the customer's country. Where required, transfers rely on the European Commission's standard contractual clauses or an equivalent mechanism, which the signed addendum incorporates.