Legal & Trust / Documents

Data Processing Agreement

Proposed controller/processor terms and a schedule to complete for each client engagement.

Review draft — not yet effective. Prepared 2026-09-28. This document must be checked against actual practices and applicable law before use.

Parties, scope, and instructions

This proposed DPA is between the client identified in a signed services agreement (Controller) and Jacob Reid doing business as Orikware (Processor), to the extent Orikware processes personal data on that client’s behalf. It takes effect only when incorporated into or executed with that agreement and completed schedules. If the client is itself a processor, its authority and the corresponding subprocessing obligations must be recorded.

Processing is limited to documented lawful instructions for the agreed services, including instructions about transfers. The Processor must notify the Controller if it considers an instruction contrary to applicable data protection law and, where lawful, before processing required by law outside those instructions.

Schedule A — processing particulars

Before production processing, the parties must attach a completed schedule identifying the service, subject matter, duration, processing purposes and operations, data types, categories of people, relevant locations, and Controller rights and obligations.

Potential operations include receiving inquiries, authenticating users, storing records, generating voice interactions or summaries, synchronizing approved appointments, and providing support. Potential data subjects include client staff, callers, leads, and customers. Only the categories and operations expressly selected in the schedule are authorized. Sensitive or specially regulated data is excluded unless separately assessed and expressly agreed.

Confidentiality and security

The Processor must restrict processing to authorized personnel subject to confidentiality duties and implement technical and organizational measures appropriate to the processing risk. Schedule B must record the measures agreed for the deployment, including access controls, tenant separation, secure transport, credential handling, retention, incident response, and any backup or recovery arrangements.

Security descriptions must reflect implemented controls. No audit certification, specific recovery time, or blanket compliance status is created by this draft. The parties must review material changes to the processing risk or agreed safeguards.

Subprocessors and transfers

Schedule C must identify the authorized subprocessors, functions, processing locations, and applicable transfer arrangements. Possible providers include Vercel, Supabase, Vapi and configured voice/model providers, Make.com, and client-authorized business systems; this list is not authorization to use every provider.

Engaging or replacing a subprocessor requires the Controller’s prior specific written authorization or an agreed general authorization with advance notice and a meaningful opportunity to object on data protection grounds. The Processor must impose equivalent relevant obligations by contract and remains responsible for its subprocessor obligations under applicable law.

Restricted international transfers must not start until the parties document a valid mechanism and required assessments or supplementary measures. This draft does not itself constitute standard contractual clauses or establish a transfer certification.

Requests, assessments, and incidents

Taking account of the processing and available information, the Processor must provide reasonable assistance with data subject requests, security obligations, impact assessments, and regulator consultations required by applicable law. Requests received directly must be forwarded to the Controller unless law requires another response.

The Processor must notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, provide available relevant information, and cooperate with containment and remediation. Further information may follow in phases. The Controller determines required notices to regulators and individuals, unless law assigns a separate obligation to the Processor.

Evidence and audit

The Processor must make information reasonably necessary to demonstrate compliance available to the Controller and allow appropriate audits, including inspections, by the Controller or an authorized independent auditor. Procedures should protect confidentiality and other clients’ data without obstructing legally required oversight. Any reasonable scheduling or cost arrangements must be agreed and must not defeat these obligations.

Return, deletion, and end of service

At the Controller’s choice, the Processor must return or delete personal data and delete existing copies when processing ends, unless applicable law requires retention. Schedule D must define the retention period, return format, deletion timetable, and treatment of backups and downstream providers. Data retained under a legal obligation must remain protected and restricted to that purpose.

The DPA governs conflicting service terms about processing personal data. General fees and liability arrangements remain subject to the signed agreement and rights that cannot lawfully be limited. Complete and sign all schedules before relying on this document.

← All legal documents