Skip to main content
Draft — pending legal counsel review

Data Processing Agreement (DPA)

DRAFT — not legally binding

DRAFT — pending legal counsel review. Do not rely on this as legal advice.

Last updated: June 2026 · Effective: pending counsel sign-off

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Controller" or "Customer") and Orqelo (the "Processor"). It governs the processing of personal data by Orqelo on your behalf in connection with the Orqelo Service. Enterprise customers requiring a signed DPA should contact legal@orqelo.com.

1. Definitions

Terms used in this DPA and not defined herein have the meanings given in the GDPR (Regulation (EU) 2016/679) or equivalent applicable data protection legislation.

  • Controller: the Customer (you), who determines the purposes and means of processing personal data.
  • Processor: Orqelo, which processes personal data on behalf of the Controller.
  • Data Subjects: individuals whose personal data is processed — typically your end users, chatbot visitors, and team members.
  • Personal Data: any information relating to an identified or identifiable natural person processed via the Service.

2. Roles and responsibilities

You (the Customer) are the Controller of personal data submitted to the Service by or on behalf of your organisation, including conversation data submitted by your end users. Orqelo is the Processor for that data.

For Orqelo's own operational data (e.g. account registration data, billing data of your team members), Orqelo acts as an independent Controller, as described in the Privacy Policy.

3. Processing purposes and legal basis

Orqelo will process personal data solely for the following purposes ("Permitted Purposes"):

  • Providing and operating the Service as described in the Terms of Service;
  • Complying with legal obligations;
  • Carrying out your documented instructions (including DSAR responses and data deletion requests);
  • Protecting the security and integrity of the Service.

Orqelo will not process personal data for any other purpose, including training AI models, unless you have given explicit prior consent or unless you have enabled AI improvement participation in workspace settings.

4. Categories of data and data subjects

  • Categories of personal data: Names, email addresses, conversation content, device and session metadata, usage data, and any other personal data submitted by you or your end users via the Service.
  • Special categories: We advise against submitting special category data (health, financial, biometric) unless you have an Enterprise agreement with specific controls in place. We do not seek to collect special category data.
  • Data subjects: Your end users (chatbot visitors), your team members, and any individuals whose personal data you submit as part of knowledge base documents.

5. Data isolation and security measures

Orqelo implements the following technical and organisational measures ("TOMs") to protect personal data:

5.1 Multi-tenant isolation

All tenant data tables are protected by Postgres Row-Level Security (RLS). A per-request database-level guardrail ensures that no query from one tenant can access another tenant's data. This is enforced at the database engine, not the application layer, and is CI-gated on every code merge.

5.2 Encryption at rest

All data is encrypted at rest using AES-256. Each tenant is assigned a unique Data Encryption Key (DEK). DEKs are managed by AWS Key Management Service (KMS). Enterprise customers may provide their own Customer Managed Key (BYOK) via AWS KMS.

5.3 Encryption in transit

All data in transit is encrypted using TLS 1.3. Internal service-to-service communication is encrypted within the VPC.

5.4 Access controls

Authentication uses JWT tokens stored in HttpOnly, SameSite=Strict cookies. MFA (TOTP) is available and required for administrative actions. Role-based access controls (RBAC) restrict team member permissions within a workspace.

5.5 Audit log

All security-sensitive operations are recorded in a cryptographic, tamper-evident audit log. Each entry is chained to its predecessor via a cryptographic hash. Audit logs can be exported by you at any time from the dashboard.

6. Sub-processors

You authorise Orqelo to engage the sub-processors listed at /legal/subprocessors. Orqelo will inform you of any intended addition or replacement of sub-processors with at least 30 days' notice, giving you the opportunity to object. If you object and no resolution is reached, you may terminate the Service without penalty within 30 days.

Orqelo ensures that sub-processors are bound by data processing terms no less protective than this DPA.

7. International data transfers

Data is processed primarily in the EEA (AWS eu-west-1). A disaster-recovery replica resides in AWS us-east-1. Transfers from the EEA to third countries (including the US) are conducted subject to Standard Contractual Clauses (SCCs, 2021/914). Enterprise customers may elect a single-region eu-west-1 configuration with no cross-region replication outside the EEA.

8. Data subject rights

Orqelo will assist you in responding to data subject requests within commercially reasonable timelines. Automated DSAR tooling is available in the tenant dashboard (Settings → Privacy) allowing self-service data export and deletion for your end users. Where manual processing is required, Orqelo will respond within 5 business days of a written request.

9. Data breach notification

In the event of a personal data breach affecting your data, Orqelo will notify you without undue delay and, in any case, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

10. Deletion and return of data

Upon your request or upon termination of the Terms of Service, Orqelo will delete or return all personal data (as you choose) within 90 days, unless retention is required by applicable law. Deletion is cryptographic where technically feasible (DEK destruction renders data unrecoverable).

11. Audit rights

You have the right to audit Orqelo's compliance with this DPA no more than once per year, upon 30 days' written notice. In lieu of an on-site audit, Orqelo may provide relevant certifications, third-party audit reports, or security questionnaire responses to satisfy audit obligations.

12. Governing law

This DPA is governed by the same law as the Terms of Service, as specified in your executed Master Service Agreement with Orqelo.

13. Contact

For DPA enquiries, signed copies, or Enterprise customisation: legal@orqelo.com