Customer Data Processing Addendum
- Legal entity
- Orion AI Solutions Inc.
- Effective
- July 29, 2026
- Integrity
- f0925c0f454f625efa78082cf475838b935bd797046b16deffa53a8e28b47980
Customer Data Processing Addendum
This Customer Data Processing Addendum ("DPA") forms part of the Agreement between Orion AI Solutions Inc., a Delaware corporation located at 2810 N Church St #607813, Wilmington, DE 19802 ("Orion"), and Customer. It applies when Orion processes Customer Personal Data on Customer's behalf.
1. Definitions
"Applicable Data Protection Law" means privacy, data-protection, and breach-notification law applicable to the processing.
"Customer Personal Data" means personal data, personal information, or similar regulated information submitted to or generated by the Services and processed by Orion on Customer's behalf.
"Controller," "Processor," "Business," "Service Provider," "Consumer," "Data Subject," "Sell," and "Share" have the meanings in Applicable Data Protection Law.
"Security Incident" means confirmed unauthorized acquisition of, access to, or disclosure of Customer Personal Data in Orion's control, excluding unsuccessful attempts and events caused by Customer or its users unless Orion contributed to them.
"Subprocessor" means a third party engaged by Orion to process Customer Personal Data for the Services.
2. Roles and scope
Customer is the Controller or Business and Orion is the Processor or Service Provider for Customer Personal Data, except where the parties' actual activities require a different role. Customer determines the purposes and essential means of processing and is responsible for lawful instructions, notices, consent, rights, data accuracy, and minimization.
Orion will process Customer Personal Data only to provide, secure, support, and improve the contracted Services; on Customer's documented instructions; as described in the Agreement; or as required by law. If law requires other processing, Orion will notify Customer before processing unless prohibited.
If Orion believes an instruction violates Applicable Data Protection Law, Orion may suspend the affected processing and notify Customer. Orion does not provide legal advice.
3. U.S. service-provider restrictions
Where U.S. state privacy law applies, Orion will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or permitted business purposes; or combine it with personal information received from another person except as permitted by law to provide the Services.
Orion will provide the same level of privacy protection required of a Processor or Service Provider, notify Customer if Orion determines it can no longer meet its obligations, and permit Customer to take reasonable steps to stop and remediate unauthorized use.
4. Confidentiality and personnel
Orion will limit access to personnel and contractors who need Customer Personal Data to perform their duties and will require them to protect its confidentiality. Orion will provide appropriate privacy and security training based on role.
5. Security
Orion will maintain administrative, technical, and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and access. Measures will address, as appropriate:
- access control, authentication, least privilege, and account lifecycle;
- encryption in transit and at rest where supported and appropriate;
- secure software development, change control, vulnerability management, and testing;
- logging, monitoring, incident detection, response, and recovery;
- availability, backup, restoration, and business continuity;
- tenant separation and production access restrictions;
- vendor risk and subprocessor oversight; and
- workforce confidentiality and security training.
Customer is responsible for its endpoints, credentials, user permissions, integrations, configurations, and lawful instructions.
6. Subprocessors
Customer generally authorizes Orion to use the Subprocessors listed in Orion's current Subprocessor List. Orion will impose written data-protection obligations appropriate to each Subprocessor's services and remains responsible for its obligations under this DPA to the extent required by law and contract.
Orion will post a new Subprocessor to its published list at least thirty days before authorizing that Subprocessor to process Customer Personal Data, except when an emergency replacement is reasonably necessary to maintain security, availability, or legal compliance. Customer may object on reasonable data-protection grounds within fifteen days after notice. The parties will work in good faith on a reasonable alternative; if none is commercially reasonable, Customer may terminate only the affected Service without penalty for the unused prepaid period.
7. Individual requests
Taking into account the nature of processing, Orion will provide reasonable assistance for Customer to respond to requests under Applicable Data Protection Law. If Orion receives a request concerning Customer Personal Data, Orion may direct the requester to Customer and will not independently respond except on Customer's instruction or as required by law.
Customer is responsible for verifying the requester and deciding the response. Orion may charge reasonable fees for unusually burdensome assistance not included in the Services, after notice.
8. Security Incidents
Orion will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will include information reasonably available about the nature of the incident, affected data and individuals, likely consequences, mitigation, and a contact, and may be provided in phases.
Notification is not an admission of fault or liability. Customer is responsible for notices to individuals, regulators, and others unless law assigns that duty to Orion. The parties will cooperate reasonably on investigation, mitigation, preservation, and required notices.
9. Return, deletion, and retention
On termination or Customer's authenticated instruction, Orion will return or delete Customer Personal Data as required by Applicable Data Protection Law and the Agreement, except information retained for law, security, fraud prevention, dispute, backup, or legal-hold purposes. Retained information remains protected and will not be used for another purpose.
Deletion may follow documented production, backup, log, object-store, queue, and Subprocessor cycles. Orion will describe applicable limitations and provide reasonable confirmation when the verified deletion workflow is available.
10. Compliance information and audits
Upon reasonable request, Orion will provide information necessary to demonstrate compliance with this DPA, which may include current third-party reports, certifications, questionnaires, or summaries. If those materials are insufficient and law requires more, Customer may conduct one audit per year through an independent qualified auditor under confidentiality, during business hours, without accessing other customers' data or disrupting the Services.
Customer bears audit costs unless an audit identifies Orion's material breach. Additional audits may occur after a material Security Incident or regulator requirement. Orion may satisfy overlapping requests through a common audit or report.
11. Regulatory assistance
Taking into account the nature of processing and information available, Orion will reasonably assist Customer with legally required data-protection impact assessments, regulator consultations, and records of processing. Customer remains responsible for determining whether they are required.
12. International transfers
If Customer Personal Data subject to transfer restrictions is transferred to a country without an applicable adequacy determination, the parties will use a valid transfer mechanism. This DPA does not by itself complete the party-specific selections required for the European Commission Standard Contractual Clauses or UK Addendum. Customer must execute Orion's then-current transfer addendum before directing a restricted EEA, UK, or Swiss transfer that requires those clauses.
13. Processing details
Subject matter: providing Orion's CRM, communications, automation, AI-assisted, analytics, integration, billing-support, and related Services.
Duration: the Agreement term plus permitted retention and deletion periods.
Nature and purpose: hosting, organizing, enriching at Customer's direction, transmitting, recording where configured, analyzing, securing, supporting, and deleting Customer Personal Data to provide the Services.
Data subjects may include Customer personnel, agents, contractors, leads, prospects, customers, policyholders, communication recipients, website visitors, and persons contained in Customer Data.
Data may include identifiers; contact and account data; professional, commercial, insurance-related, communication, appointment, consent, source, device, usage, location inferred from number or supplied address, call and message content, recordings, transcripts, and support data. Customer must not submit sensitive data unless the feature and Agreement expressly permit it and Customer has a lawful basis.
Frequency: continuous or as initiated and configured by Customer.
14. Liability, precedence, and contact
The Agreement's liability, indemnity, dispute, and governing-law provisions apply to this DPA unless Applicable Data Protection Law prohibits them. This DPA controls over conflicting Agreement terms for Customer Personal Data processing.
Privacy requests: privacy@orionaisolutions.ai. Legal notices: legal@orionaisolutions.ai. Mail: Orion AI Solutions Inc., 2810 N Church St #607813, Wilmington, DE 19802. Delaware law applies as stated in the Terms, without displacing mandatory Applicable Data Protection Law.
