Data Processing Terms
Last updated 12 September 2026 (template pending legal review)
These terms form part of the agreement between the organization (“Controller”) and Orishare (“Processor”) and apply whenever the Service processes personal data on the Controller's behalf. A signed copy for Enterprise plans is available on request.
1. Subject matter and duration
Processing of end-customer identifiers, events and attributes to evaluate loyalty rules, keep balances and deliver notifications, for the duration of the agreement plus the export window.
2. Instructions
The Processor processes personal data only on documented instructions: the API calls, configuration and dashboard actions of the Controller's users. The Processor informs the Controller if an instruction appears to infringe applicable law.
3. Confidentiality and security
Personnel are bound by confidentiality. Technical and organisational measures include tenant isolation per environment, hashed credentials, encryption in transit and at rest, audited configuration changes, audited staff access with a stated reason, least-privilege service accounts, and tested backups. Details are on the security page.
4. Subprocessors
The Controller authorises the subprocessors listed on the subprocessors page. The Processor gives at least 30 days' notice of additions; the Controller may object on reasonable grounds, in which case the parties seek a solution or the Controller may terminate the affected part of the Service.
5. Data subject rights
The Processor provides the customer export and deletion endpoints so the Controller can answer access, portability and erasure requests directly, and assists with other requests where the Controller cannot act alone.
6. Personal data breaches
The Processor notifies the Controller without undue delay, and at the latest within 48 hours of becoming aware of a breach affecting the Controller's data, with the information available at that time.
7. Deletion and return
On termination the Controller has 30 days to export data; the Processor then deletes it, subject to legal retention obligations and backups that expire on their normal schedule.
8. Audits
The Processor makes available the information needed to demonstrate compliance and allows audits by the Controller or a mandated auditor, on reasonable notice, at most once a year unless required by a supervisory authority.
9. International transfers
Data is hosted in the United States (us-central1). Transfers from the EU/UK rely on the EU-US Data Privacy Framework where the subprocessor is certified, and on Standard Contractual Clauses otherwise.