Data Processing Agreement
Version 2.0 · Last updated 22 September 2026
This Data Processing Agreement ("DPA") forms part of the service agreement between Orin Technologies BV ("Processor") and the customer organisation ("Controller") for the provision of Orin and everything served with it: the web application, the driver app, the customer and partner portal and the partner API ("Service"). It applies from the moment an account exists and does not have to be signed separately to be in force.
How to read this
Section 2 says what we process and for whom, and includes the documents your customers send you and what our AI reads out of them. Section 4 says who else touches it and how you hear about a change. Section 6 says what is actually in place, and section 7 says plainly which audit reports exist. Section 8 says what happens when you leave.
Need a signed copy for your own file? Write to legal@orin.software with the entity name and address to put on it and we send one back signed, normally the same week. A countersigned copy is not a precondition for this DPA to apply.
1. Definitions
- "Controller" means the customer who determines the purposes and means of processing personal data through the Service.
- "Processor" means Orin Technologies BV, a company registered in the Netherlands, which processes personal data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person as defined by Article 4(1) of the GDPR.
- "Processing" means any operation performed on personal data, as defined by Article 4(2) of the GDPR.
- "Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
2. Scope and Purpose
The Processor processes personal data solely for the purpose of providing the Service to the Controller, as described in the service agreement. The nature of processing includes storage, retrieval, transmission, and deletion of personal data as necessary to operate the Service.
Categories of personal data processed:
- Account information: Names, email addresses, phone numbers, login credentials
- Operational data: Shipment details, delivery addresses, order references, proof of delivery photos and signatures
- GPS and location data: Coordinates and addresses used for route planning, geocoding, and delivery tracking
- Financial data: Billing information, invoice details, payment method identifiers (processed via Stripe)
- Inbound documents and their content: Order e-mails and their attachments, transport documents, carrier and supplier invoices and signed proofs of delivery that the Controller or its trading partners send into the Service, together with the values read out of them and the corrections a user makes when reviewing that reading.
Reading those documents involves the AI sub-processors listed in section 4 and is covered by this DPA in the same way as any other processing. By default a person reviews and confirms a reading before it becomes an operational record; automatic confirmation is a setting the Controller may enable, at a threshold the Controller sets.
Categories of data subjects:
- Employees and staff of the Controller (planners, administrators)
- Drivers engaged by the Controller
- Contacts of the Controller's customers (recipients, consignees)
- Contacts at the Controller's subcontractors and suppliers, including their drivers where the Controller records them
- Users the Controller's own customers invite into the portal
3. Processor Obligations
The Processor shall:
- Process on documented instructions only: Process personal data solely in accordance with the Controller's documented instructions, unless required to do so by applicable law.
- Confidentiality: Ensure that all persons authorized to process personal data are bound by appropriate confidentiality obligations.
- Security measures: Implement and maintain appropriate technical and organizational measures to protect personal data, including:
- Encryption of data at rest and in transit
- Role-based access controls with least-privilege principles
- Comprehensive audit logging of data access and modifications
- Regular penetration testing and vulnerability assessments
- Data subject requests: Assist the Controller in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, portability, restriction, objection) in a timely manner.
- Breach notification: Notify the Controller of any Data Breach without undue delay after becoming aware of it, and in any event within 48 hours. The 48 hours is an outer limit, not a window to work in: the Controller has its own 72-hour clock towards its supervisory authority, which only starts when we tell it, so we notify as soon as we know there is something to notify and follow up with detail as it becomes available rather than waiting to have all of it. The notification states the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed.
- Data deletion/return: Upon termination of the service agreement, at the Controller's choice, delete or return all personal data and delete existing copies, unless applicable law requires storage of the personal data.
4. Sub-processors
The Controller grants the Processor general written authorization to engage sub-processors for the provision of the Service. The current list of sub-processors is available at /sub-processors.
The Processor shall notify the Controller at least 30 days in advance of any intended changes to the list of sub-processors, giving the Controller the opportunity to object to such changes. If the Controller objects on reasonable grounds, the Processor shall make reasonable efforts to provide an alternative solution. If no alternative is available, either party may terminate the affected portion of the Service.
The Processor shall impose on each sub-processor, by way of a written agreement, data protection obligations no less protective than those set out in this DPA.
5. International Transfers
The Processor's primary data processing infrastructure is located in the European Union (Microsoft Azure, West Europe region, Netherlands).
Where personal data is transferred to sub-processors located outside the European Economic Area, the Processor shall ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- EU-US Data Privacy Framework certification, where applicable
- Transfers to countries recognized by the European Commission as providing an adequate level of data protection
6. Data Security Measures
The Processor implements and maintains the following technical and organizational security measures:
- Encryption in transit: All data transmitted between clients and servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: All stored data, including database records and file storage, is encrypted using AES-256.
- Access control: Role-based access control (RBAC) enforced at the application and infrastructure level, following the principle of least privilege.
- Multi-tenant isolation: Strict tenant-level data isolation ensures that each Controller's data is logically separated and inaccessible to other tenants.
- Automated backups: Regular automated backups with encryption, stored in geographically redundant locations within the EU.
- Network isolation: The production database is reachable only over a private network endpoint inside our own virtual network, with public access disabled.
- Credential handling: Passwords and driver PINs are stored hashed; application secrets are held in a managed key vault rather than in configuration.
- Logging and alerting: Application and infrastructure logging with alerting on failures.
This list is what is in place, and it matches the measures published on our Privacy Policy. We do not currently run scheduled third-party penetration testing, and this DPA no longer claims that we do. Where a Controller requires a test, we will cooperate with one it commissions on reasonable notice.
7. Audit Rights
The Controller may audit the Processor's compliance with this DPA once per calendar year, subject to the following conditions:
- The Controller shall provide at least 30 days' written notice prior to the audit.
- Audits shall be conducted during normal business hours and shall not unreasonably interfere with the Processor's operations.
- The Controller shall bear the costs of the audit, unless the audit reveals a material breach by the Processor.
- The Processor shall make available all information reasonably necessary to demonstrate compliance with this DPA.
The Processor holds no SOC 2 Type II report and no ISO 27001 certificate. Saying so plainly is more useful than a clause promising them "where available". What we can provide on request is a written description of the technical and organisational measures, answers to a security questionnaire, and the architecture of the tenant separation described in section 6. If your procurement process requires a certified report, tell us early: it is a real gap and we would rather you heard it from us than discovered it at the end.
8. Term and Termination
This DPA shall become effective upon the Controller's acceptance of the service agreement and shall remain in effect for the duration of the service agreement.
Upon termination of the service agreement, the Processor shall:
- Cease all processing of personal data on behalf of the Controller.
- At the Controller's request, return all personal data in a commonly used, machine-readable format.
- Delete all personal data within 90 days of termination, unless retention is required by applicable law (for example tax and accounting records, which are kept for the statutory period and for nothing else).
- Provide written confirmation of deletion upon request.
Export the data yourself before access ends: it is available from inside the Service at any time and does not require a request. The 90 days is the outer limit for what we still hold afterwards, not a period you have to wait through. Backups fall out of rotation on their own schedule within the same window.
An individual user deleting their own account is a different thing from a Controller terminating the service agreement: see Delete my account for which is which. Cancellation and access are governed by section 12 of the Terms and Conditions.
9. Contact
For questions or requests related to this Data Processing Agreement:
Orin Technologies BV, registered in the Netherlands.
Email: legal@orin.software
Related: the sub-processor list (the authoritative version of section 4), the Privacy Policy and the Terms and Conditions.
To request a signed copy of this DPA or to discuss specific data processing requirements, please contact us at the email address above.