Rotate Your Device

This site doesn't support landscape mode. Please rotate your phone to portrait.

Origami Data Processing Agreement

1. Introduction and effect

This Data Processing Agreement ("DPA") is between Airsplash Inc., doing business as Origami ("Origami"), and the customer identified in the Agreement ("Customer"). It governs Origami's Processing of Customer Personal Data on Customer's behalf and forms part of the Agreement.

This DPA takes effect when the parties sign or electronically accept it, or when Customer accepts Terms of Service that incorporate this version. For an existing Customer, incorporation through updated Terms of Service takes effect only through the applicable contractual change process. Publication of this DPA alone does not amend a separately negotiated agreement.

For Processing of Customer Personal Data, the order of precedence is: the applicable mandatory provisions of the UK Addendum for UK Restricted Transfers; the applicable SCCs; this DPA; and the Agreement, including the Terms of Service and Privacy Policy. This ordering is subject to the hierarchy provisions of the SCCs and UK Addendum. No service-improvement license, vendor disclaimer, dispute-resolution provision, or other term in the Agreement overrides Origami's obligations under this DPA.

This DPA does not govern Personal Data that Origami lawfully Processes as an independent Controller for its own account administration, billing, business communications, or legal obligations. That Processing is described in the Privacy Policy. This exception does not permit Origami to reclassify Customer content, prompts, outputs, lead data, or communications as independent-Controller data merely because it uses them for analytics, product improvement, security, or support.

2. Definitions

Agreement means the agreement governing Customer's use of Origami's Services, including the applicable order form and Terms of Service.

Customer Personal Data means Personal Data in Customer Data or Third-Party Data that Origami Processes on Customer's behalf through the Services, including Personal Data collected or generated at Customer's direction. Independent-Controller data described in Section 1 is excluded only to the extent Origami Processes it in that separate role.

Data Protection Laws means privacy and data-protection laws applicable to a party's Processing under this DPA, including, where applicable, Regulation (EU) 2016/679 ("GDPR"), the GDPR as incorporated into UK law and the UK Data Protection Act 2018 (together, "UK Data Protection Laws"), the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations ("CCPA").

Controller, Processor, Data Subject, Personal Data, and Processing have the meanings given by applicable Data Protection Laws. Customer may act as Controller or Processor; neither role is assigned merely by using a defined party name in this DPA.

Instructions means Customer's documented instructions, as described in Section 3.2.

Personal Data Breach means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Origami or its Sub-processors.

Services means the services Origami provides under the Agreement.

SCCs means the standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of June 4, 2021, incorporated under Schedule 1.

Sub-processor means a Processor engaged by Origami or another Sub-processor to Process Customer Personal Data on Customer's behalf. A provider's actual role depends on the relevant Processing, not its commercial label.

UK Addendum means the ICO International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, including its mandatory amendments, incorporated under Schedule 2.

Other capitalized terms have the meanings in the Agreement or applicable Data Protection Laws.

3. Processing and responsibilities

3.1 Roles and agency customers

Where Customer determines the purposes and means of Processing, Customer is Controller and Origami is Processor. Where Customer Processes Personal Data on behalf of a client or other Controller, Origami is Customer's Sub-processor. Customer shall obtain the authorization necessary to appoint Origami and its authorized Sub-processors, relay the relevant Controller's lawful Instructions and notices, and act as Origami's point of contact. Origami shall assist Customer in fulfilling the corresponding obligations to that Controller. This arrangement does not restrict rights conferred directly on that Controller by applicable law or the SCCs.

These role provisions support authorized client-service arrangements but do not themselves expand a license to the Services or Third-Party Data. Any exception to internal-use, redistribution, or third-party-access restrictions in the Agreement must be expressly agreed in writing.

3.2 Instructions

The Agreement, this DPA, Customer's authorized configuration and use of the Services, and additional written instructions agreed by the parties constitute Customer's Instructions. Customer may issue further lawful instructions concerning Customer Personal Data during the term. Instructions outside the agreed Services may require a separate scope and fee agreement, but this does not qualify Origami's mandatory duties under Data Protection Laws or the SCCs.

Origami shall Process Customer Personal Data only on documented Instructions, including with respect to international transfers, unless applicable law requires otherwise. Where legally permitted, Origami shall notify Customer of such a legal requirement before Processing. Origami shall immediately inform Customer if it considers an Instruction unlawful or is unable to comply, and may suspend only the affected Processing while the parties resolve the issue. Customer configuration cannot authorize Processing prohibited by this DPA or an agreed customer-specific restriction.

3.3 Processing details and use restrictions

Annex 1 states the subject matter, purposes, nature, duration, data categories, and Data Subjects. Origami shall not use Customer Personal Data for its own marketing, cross-customer lead databases, or purposes incompatible with Customer's Instructions.

Origami shall not use, or authorize a Sub-processor to use, Customer Personal Data, including prompts and outputs, to train, fine-tune, or improve a general-purpose or shared AI model. Customer-specific model training requires a separate express written Instruction describing the purpose, data, providers, retention, and safeguards, and must remain within applicable law. Provider retention needed to deliver an authorized inference service or satisfy a legal obligation is distinct from model training and remains subject to this DPA and the disclosed provider arrangements.

Origami may Process the limited operational data necessary to diagnose errors, secure the Services, and improve the reliability of the Services supplied to Customer, within Annex 1 and applicable law. Processing Customer Personal Data into anonymous statistics remains subject to this DPA until the data is no longer Personal Data under applicable law. Origami may use such anonymous statistics only if it applies measures against reidentification, does not attempt to reidentify the data, and preserves applicable contractual confidentiality restrictions. Pseudonymization, removal of direct identifiers, or aggregation alone does not establish anonymity.

3.4 Customer responsibilities and data sourcing

Customer is responsible for its lawful Instructions, its permitted use of the Services, the notices and lawful bases required for Personal Data it supplies, and its outbound communications. Customer shall not submit sensitive or special-category data except where Origami has expressly agreed in writing and the parties have documented the necessary safeguards.

Each party remains responsible for obligations applicable to its own conduct and role. Customer's responsibilities do not excuse Origami's unlawful collection, sourcing, disclosure, or Processing. Where Origami engages a provider to perform Customer-directed research, enrichment, or verification, Origami shall assess and document the provider's role and the contractual basis for the intended Processing and supply Customer with information reasonably necessary to assess the use. A provider acting independently as Controller is not converted into a Sub-processor by this DPA; applicable controller-to-controller disclosures and transfer terms must be addressed before Customer Personal Data is disclosed to that provider.

4. Origami obligations

4.1 Confidentiality

Origami shall ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and may access it only as necessary for their authorized functions.

4.2 Security

Origami shall implement and maintain technical and organizational measures appropriate to the risks of Processing, including Annex 2. It shall consider the nature, scope, context, and purposes of Processing, the state of the art, and risks to individuals. Measures may evolve, but changes shall not materially reduce the protection of Customer Personal Data. Origami shall provide information reasonably necessary for Customer to assess those measures and any additional measures agreed in writing.

4.3 Sub-processing

Customer grants general written authorization for Sub-processors individually identified to Customer under Annex 3. A category of providers, a model catalogue, or a statement that providers vary is not a substitute for their identities. Before a provider receives Customer Personal Data, Origami shall disclose its identity, relevant Processing, and locations as required by Annex 3 and complete the authorization and transfer requirements applicable to that Processing.

Origami shall perform risk-based diligence and impose by written contract the same data-protection obligations required of it for the delegated Processing, including confidentiality, security, assistance, deletion, applicable transfer safeguards, and restrictions on data use. Origami remains responsible to Customer for each Sub-processor's performance of those obligations as required by Data Protection Laws and the SCCs.

Origami shall give Customer written notice of an intended addition or replacement at least 30 days before the new Sub-processor first Processes the affected Customer Personal Data, with sufficient information to assess and object on reasonable data-protection grounds. Notice shall be sent to Customer's designated contact or account administrator; updating a webpage alone is insufficient. This process also applies to relevant downstream providers and AI routing changes that introduce a new Sub-processor.

If Customer objects within the notice period, the parties shall seek a reasonable resolution. Origami shall not begin the disputed Processing while the objection is unresolved. If no resolution is available before the change is necessary, Origami may discontinue the affected feature and Customer may terminate the affected Services without a termination penalty. Accrued charges remain payable; treatment of prepaid fees is governed by the Agreement unless the parties agree otherwise. These provisions do not restrict stronger suspension or termination rights under the SCCs or applicable law.

4.4 Rights requests

Taking into account the nature of Processing, Origami shall assist Customer through appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests. Origami shall promptly forward requests concerning Customer Personal Data to Customer and shall not respond on Customer's behalf except on Instructions or as required by law. Where legally permitted, it may identify Customer as the responsible contact. Customer shall supply the information necessary for Origami to act on applicable requests.

4.5 Personal Data Breaches

Origami shall notify Customer without undue delay after becoming aware of a Personal Data Breach. It shall provide available information on the nature of the breach, affected data and individuals, likely consequences, its contact point, and measures taken or proposed to contain and remedy the breach. Information may be provided in stages without further undue delay; lack of complete information shall not delay the initial notice.

Origami shall investigate and take appropriate containment and remediation steps, preserve relevant evidence as appropriate, and reasonably assist Customer with required notifications and other response duties. Customer remains responsible for its notifications to authorities and individuals unless the law provides otherwise. A notice is not an admission of fault.

4.6 Compliance assistance

Taking into account the nature of Processing and information available to it, Origami shall assist Customer with security obligations, impact and transfer assessments, required cybersecurity audits and privacy risk assessments, and prior consultation with competent authorities concerning the Processing. Reasonable scope and cost arrangements shall not prevent legally required assistance or access to information.

4.7 Return, deletion, and retention

During the term, Customer may use available export and deletion functions or request assistance at hello@origamiagents.com. Cancellation of a paid subscription alone does not constitute termination of all Services where Customer affirmatively continues to use a free account.

When Services involving the Processing end, Origami shall, at Customer's choice, return Customer Personal Data in a reasonably usable format and delete remaining copies, or delete the data. Origami shall obtain Customer's choice as part of offboarding; if Customer gives no different lawful instruction after being afforded a reasonable opportunity to export, deletion is the default. Retention for an agreed recovery period must be documented and limited to that purpose. Origami's ordinary soft-deletion flow includes an approximately 30-day recovery period; that workflow does not override a shorter deadline required by law or the SCCs.

Until deletion is complete, retained data remains protected by this DPA and shall not be used for ordinary service delivery or new purposes. Residual backups and disaster-recovery copies shall be isolated from ordinary use and removed through a documented, time-limited deletion or overwrite cycle disclosed to Customer. Restoration shall not reinstate data previously scheduled for deletion for ordinary use. Logs and fraud-prevention records are not blanket exceptions to Customer's deletion instructions.

Where applicable law requires retention, Origami shall limit retention and access to what that law requires and, where legally permitted, identify the basis and period to Customer. Origami shall cause authorized Sub-processors to meet corresponding obligations. On request, it shall confirm the completed deletion and identify any remaining legally required retention. Any stricter return, deletion, or certification requirement in the SCCs prevails.

4.8 Audit rights

Origami shall provide information reasonably necessary to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by Customer or an independent auditor it appoints. Relevant reports and questionnaires may satisfy a routine request where sufficient; they do not replace audit rights where further verification is reasonably necessary.

Routine audits may occur once in a 12-month period on reasonable notice, during normal business hours, subject to confidentiality and safeguards against disclosure of other customers' information and unreasonable disruption. Those limits do not apply where required by law or an authority, following a relevant Personal Data Breach, where there are reasonable indications of noncompliance, or where the SCCs otherwise permit an audit, including an audit requested under Module 3 on an underlying Controller's instructions. Reasonable urgent access shall be accommodated where needed.

Customer bears its audit costs and reasonable, agreed Origami support costs unless an audit identifies a material breach by Origami. Cost, confidentiality, scheduling, and information-security arrangements shall not prevent an effective audit or restrict mandatory rights. Origami shall promptly address material deficiencies and provide reasonable evidence of remediation.

5. International transfers

Origami shall make transfers requiring safeguards under Data Protection Laws only under a valid applicable transfer mechanism and shall comply with its conditions. Incorporating SCCs is not a substitute for assessing transfer risks or implementing necessary supplementary measures.

For transfers subject to the GDPR from Customer to Origami that require Article 46 safeguards, the SCCs apply as completed in Schedule 1: Module 2 where Customer is Controller and Module 3 where Customer is Processor. For corresponding UK Restricted Transfers, Schedule 2 applies. Swiss transfers are subject to the adaptations in Schedule 1.

Origami shall ensure that onward transfers, including remote access from another country where legally a transfer, satisfy applicable requirements. It shall assess relevant destination-country laws and practices, document required assessments, provide reasonable cooperation and information to Customer, and implement supplementary measures where necessary. Customer-specific location or provider restrictions must be agreed in writing and apply to primary, fallback, and indirect processing routes. A provider's headquarters does not establish its Processing location. If compliant Processing cannot continue, the affected transfers shall be suspended and the applicable termination and return or deletion provisions shall apply.

6. CCPA

This Section applies to Customer Personal Data governed by the CCPA. Origami acts as a service provider or contractor for the relevant Processing; Customer acts as the business or as its authorized service provider or contractor, according to the facts. Where Customer acts for another business, the corresponding requirements apply through the subcontracting chain.

Customer discloses the data only for the limited and specified business purposes in Annex 1. Origami shall:

  1. Not sell or share the data, as those terms are defined in the CCPA.
  2. Not retain, use, or disclose it for a purpose other than the specified business purposes, for a commercial purpose outside those purposes, or outside the direct business relationship, except as expressly permitted by the CCPA and consistently with any stricter obligations in this DPA.
  3. Not combine the data with Personal Data received from another person or collected from its own interactions with an individual except where the CCPA expressly permits it and Customer's lawful Instructions and this DPA permit the Processing. Customer-directed enrichment does not itself override this restriction.
  4. Comply with applicable CCPA requirements and provide the same level of privacy protection required by the CCPA for the relevant data, including reasonable security and assistance with consumer requests and applicable cybersecurity audits, privacy risk assessments, and automated-decisionmaking obligations.
  5. Permit Customer to take reasonable and appropriate steps to verify compliant use and, upon notice, stop and remediate unauthorized use, including obtaining documentation of deletion and exercising the audit rights in Section 4.8.
  6. Notify Customer without undue delay after determining that it can no longer meet its CCPA obligations and cooperate in stopping and remediating affected Processing.
  7. Impose corresponding CCPA requirements on subcontractors that Process this data and supply the information in its possession, custody, or control necessary for legally required assistance without misrepresenting material facts.

Origami certifies that it understands and will comply with these restrictions. Customer shall communicate applicable consumer requests and provide the information needed to fulfill them.

7. Other U.S. privacy laws

To the extent another U.S. state privacy law applies, Origami shall comply with the obligations applicable to its role as Processor, service provider, or contractor, including confidentiality, security, consumer-rights assistance, assessment assistance, deletion or return, and required sub-processing and audit provisions. This DPA does not designate Origami a Processor for Processing in which applicable law assigns it another role.

8. Liability

The Agreement's limitations of liability apply in the aggregate to the Agreement and this DPA. Nothing limits rights or liability under the SCCs, including their Clause 12, to the extent such rights or liability cannot be limited, or any liability that applicable law prohibits the parties from limiting. Origami may not rely on a general disclaimer of third-party conduct to avoid its Sub-processor responsibilities under this DPA.

9. Term

This DPA remains in effect while Origami or its Sub-processors Process Customer Personal Data, including any permitted retention after the Agreement ends. Termination does not extinguish confidentiality, security, assistance, or return and deletion obligations applicable to retained data.

10. Governing law and dispute resolution

The Agreement's governing-law and dispute-resolution provisions apply except where the SCCs, UK Addendum, or applicable law require otherwise. Those provisions do not restrict mandatory rights of Data Subjects, competent authorities, or parties under the applicable transfer terms.

11. General

Origami may update its standard DPA prospectively through the Agreement's applicable notice and acceptance process, without materially reducing the protection of Customer Personal Data except where required by law or a competent authority. Sub-processor changes remain subject to Section 4.3. A separately negotiated DPA may be modified only by written agreement of the parties. Changes cannot modify the SCCs or UK Addendum except as those instruments permit.

If a provision is unenforceable, the remainder remains effective to the extent permitted by law. The parties shall cooperate in adopting legally required changes. DPA notices to Origami may be sent to hello@origamiagents.com; notices to Customer shall use its designated privacy contact or account administrator. Each party shall keep those contact details current.

Annex 1. Details of Processing

Subject matter. Provision of Customer-directed prospecting, research, enrichment, table and document workflows, AI inference, integrations, and communications features, together with associated support, service security, and maintenance.

Duration. The duration of the relevant Services followed by only the return, deletion, recovery, and legally required retention permitted under Section 4.7. Customer may give earlier lawful deletion instructions.

Nature and specified purposes. Collection, recording, organization, storage, retrieval, verification, analysis, inference and generation, transmission to authorized recipients and providers, restriction, export, and deletion for these purposes, according to enabled features:

  • Store and manage Customer's tables, documents, uploaded lists, and workflow configuration.
  • Retrieve and verify professional contact and company information and conduct research at Customer's direction, subject to provider permissions and applicable law.
  • Process Customer's prompts and relevant context to produce requested research, classifications, scores, summaries, or communication drafts.
  • Authenticate authorized users and connect Customer-approved mailboxes, CRM systems, and other integrations.
  • Send, receive, synchronize, and report on communications initiated or configured by Customer.
  • Resolve Customer support requests, diagnose errors, protect account access, detect abuse affecting the Services, and maintain the reliability of the Services supplied to Customer.

Data Subjects. Customer's and its authorized clients' personnel, contractors, users, prospects, customers, business contacts, partners, communication senders and recipients, and individuals in Customer-connected systems or Customer-directed research.

Data types. Names; professional profiles; employers and job titles; business and other contact details submitted or lawfully retrieved; Customer-provided files, lists, table values, documents, prompts, code, messages, and outputs; communication recipients, subjects, bodies, and replies; authorized-user and organization identifiers; integration credentials and tokens; IP addresses, device/browser information, and operational diagnostic data to the extent Processed on Customer's behalf. Data is limited to what the relevant feature and Instructions require.

Sensitive data. The Services do not require special-category or other legally sensitive Personal Data. Customer shall not submit it without express written agreement describing categories, strict purpose and access restrictions, and additional safeguards appropriate to the risk. Ordinary integration credentials remain subject to the specific security measures in Annex 2.

Frequency. On Customer's instructions, including continuous storage and Customer-configured recurring workflows during the term.

Annex 2. Security measures

Origami shall maintain the following measures in accordance with Section 4.2. References to a technical mechanism describe its stated scope and do not warrant that it applies to every data field, endpoint, log, or provider.

Access and confidentiality. Authentication through the identity provider; role-based and need-to-know access controls; organization-scoped application authorization for Customer data access; controls over privileged administration and service credentials; personnel confidentiality and access provisioning and revocation. Authorized organization administrators and management-account permissions may span configured child organizations. Customer-directed public sharing is a separate access mode that Customer controls; it is not a promise of isolation from parties Customer authorizes.

Encryption and credentials. TLS protection for HTTPS access to the Services. Application-layer AES-256-GCM encryption with a random 96-bit initialization vector and authenticated decryption is used for designated sensitive credential fields, including applicable integration credentials and webhook signing secrets. Encryption keys are supplied separately from the encrypted database values through the runtime environment. This mechanism is not a representation of application-layer encryption of all lead data, messages, tables, prompts, or logs. Protection of other stored data relies on the relevant managed infrastructure controls; Origami shall provide Customer the applicable storage and key-management information needed to assess those controls.

Application and operational controls. Source control and controlled deployment practices; security-relevant testing and dependency management; organization-aware access controls; monitoring and incident handling; minimization and redaction controls for logs, with restricted access to diagnostic data. Diagnostic records that retain Personal Data remain subject to the same purpose, security, and retention obligations. Origami shall assess controls for effectiveness and address material deficiencies.

Resilience and lifecycle. Managed infrastructure for hosting, database, storage, and recovery, with backup and restoration arrangements appropriate to Processing risk. Retention, recovery, and deletion shall follow Section 4.7 and the applicable documented retention schedule. Production and non-production access and data use shall be controlled according to their risks; this is not a claim that all environments use physically separate infrastructure.

Organization and vendors. Personnel guidance appropriate to roles, provider diligence, written data-protection obligations, incident escalation and response responsibilities, and periodic review of relevant measures. Third-party facility, physical-access, and infrastructure controls are supplied by the applicable managed infrastructure providers. No particular certification, audit result, uptime, recovery target, or security-testing frequency is warranted unless expressly agreed in writing.

Annex 3. Sub-processor information and AI routing

A. Required named register

Origami shall provide Customer a complete, dated register of Sub-processors relevant to the purchased and enabled Services before they Process Customer Personal Data. It may supply commercially sensitive identities and supporting documents under reasonable confidentiality terms, but confidentiality shall not prevent Customer from evaluating authorization, complying with law, providing legally required information to its Controller, or responding to competent authorities.

For each provider the register shall identify its contracting legal entity, service or Processing function, data categories disclosed, relevant Processing and access countries, applicable transfer mechanism, and whether it is engaged directly or through a named Sub-processor. Optional features and their applicable providers shall be identified. The register supplied to Customer is incorporated into this Annex, subject to Section 4.3; undisclosed providers are not authorized by a generic category description.

B. Existing provider inventory to be reconciled with the register

The following service names are retained from the October 1 inventory to identify its coverage. They do not establish a provider's legal entity, live feature status, contractual role, or Processing location. The customer-specific register in Part A must resolve those details before authorization.

Service name Function identified in the inventory
Anthropic AI model services
OpenAI AI model and transcription services
Vercel AI Gateway and related infrastructure
Supabase Database, storage, and related infrastructure
Render Application hosting, cache, and queues
Cloudflare Edge, proxy, security, and delivery infrastructure
Clerk Authentication and identity
PostHog Analytics, feature flags, error tracking, and replay
Datadog Performance monitoring and telemetry
Intercom Support and in-product communications
Resend Transactional email
Composio Email and other integration connectivity
Google Customer-authorized integrations
Slack Alerts and Customer-authorized integrations
Sendblue Text-message alerts
Unipile LinkedIn connectivity and messaging
Porkbun Domain registration and management
name.com Domain registration and management

Stripe's payment and billing processing, and each provider's other independent-Controller activities, must be classified by the actual data flow and contractual role. A provider is covered as a Sub-processor only to the extent it Processes Customer Personal Data on Customer's behalf. Payment administration outside that scope is addressed under Section 1.

Data sourcing, enrichment, verification, search, research, browser automation, and additional model-provider identities must be individually included in the register where those providers Process Customer Personal Data. Independently operated data suppliers must be identified and treated according to their actual role under Section 3.4. A provider supplying data without receiving Customer Personal Data is not a Sub-processor solely because it supplies that data.

C. AI restrictions and customer destinations

AI inference may use direct model-provider connections or an intermediary gateway. Origami shall ensure that the actual contracting and processing chain is reflected in the register; a gateway's model catalogue does not establish that every listed model provider is the gateway's Sub-processor or is authorized for Customer's data.

The restrictions in Section 3.3 apply to every authorized AI route, including fallback, image, transcription, tool, and other indirect processing routes. Any customer-specific provider, retention, or location restriction agreed in writing takes precedence over default routing. Origami shall not use an unavailable compliant route as grounds to fall back to a provider or configuration that violates those restrictions; it shall instead stop the affected operation. Restrictions and responsibilities for a Customer-supplied provider account or API key shall be expressly documented before that route is used; supplying a key alone does not waive this DPA's data-use restrictions.

A Customer-directed destination, such as its own CRM, webhook, or connected application, is not Origami's Sub-processor merely because it receives data on Customer's Instructions. Intermediaries selected by Origami to provide that connection remain subject to the applicable Sub-processor requirements.

Schedule 1. EU SCCs and Swiss adaptations

A. Incorporation and selections

The parties incorporate the official SCC text in the Annex to Commission Implementing Decision (EU) 2021/914, rather than restating or modifying its mandatory text. Module 2 applies to Controller-to-Processor transfers; Module 3 applies to Processor-to-Processor transfers. Only the module applicable to the relevant transfer is activated.

  • Clause 7, the optional docking clause, is not used.
  • Clause 9(a), Option 2, general written authorization applies, with at least 30 days' advance notice of intended Sub-processor additions or replacements.
  • The optional independent dispute-resolution language in Clause 11(a) is not used.
  • Clause 13 applies with the competent authority identified under Part D below.
  • Clause 17, Option 1, selects the law of Ireland.
  • Clause 18(b) selects the courts of Ireland, without restricting Clause 18(c).

The official SCCs control over any inconsistency in this DPA. No provision qualifies the parties' mandatory obligations concerning lawful Instructions, confidentiality, security, transparency, audits, onward transfers, authority access, data-subject rights, liability, suspension, or return and deletion. The parties shall complete any additional transfer-specific information required by the SCCs before the relevant transfer.

B. Annex I.A: parties

Exporter: Customer, using the legal name, address, and designated contact stated in the Agreement or verified contracting account record. Its relevant activities are use of the Services and the Customer-directed Processing in Annex 1. Its role is Controller or Processor as applicable to the transfer. Customer's acceptance of this DPA constitutes its signature and date for the SCCs.

Importer: Airsplash Inc., doing business as Origami, 1 Sutter Street, Suite 1000, San Francisco, CA 94104, United States. Contact: hello@origamiagents.com. Relevant activities: providing the Services and Processing described in Annex 1. Role: Processor or Sub-processor. Origami's entry into the Agreement incorporating this DPA constitutes its signature as of this DPA's effective date.

For Module 3 transfers, Customer shall identify the relevant underlying Controller and furnish information and Instructions needed for Origami to comply with that module. The parties' operational contact arrangements do not restrict duties owed to that Controller under the SCCs.

C. Annex I.B: transfers

The categories of Data Subjects and Personal Data, sensitive-data restrictions, frequency, purposes, nature, and retention are those in Annex 1 and Section 4.7. Sub-processor Processing is limited to the functions, data, locations, and duration identified in the named register under Annex 3. Annex 2 supplies SCC Annex II. The named register supplies SCC Annex III and relevant further-processing information.

D. Annex I.C: competent authority

For transfers governed by GDPR, the competent authority is determined by SCC Clause 13: the authority responsible for the exporter where it is established in an EU Member State; the authority of the Member State of its appointed representative where that branch of Clause 13 applies; or the competent authority of a Member State where affected Data Subjects are located as provided by the remaining branch of Clause 13. The exporter shall identify the actual applicable authority in its contracting information or written transfer record before transfer. Where Customer is a Processor, the exporter for this purpose is Customer, not automatically its underlying Controller.

E. Switzerland

For transfers subject to the FADP, the SCCs apply with references to GDPR understood to include the FADP to the extent required for the Swiss transfer; the Federal Data Protection and Information Commissioner is the competent authority for FADP matters; and Member State references shall not prevent Swiss Data Subjects from exercising applicable rights in Switzerland. For transfers subject to both GDPR and FADP, these adaptations do not displace GDPR rights or the competent EU authority. The selected governing law and forum remain those above without limiting mandatory Swiss-law rights.

Schedule 2. UK Addendum

The ICO International Data Transfer Addendum, version B1.0, including its Part 2 Mandatory Clauses as revised under Section 18, is incorporated for UK Restricted Transfers. Its Part 1 tables are completed as follows:

Table 1: The start date is this DPA's effective date. Exporter and importer are the parties and contacts identified in Schedule 1.B. Customer's verified contracting details supply its legal name, main address, and any applicable trading name and registration number. Acceptance of this DPA constitutes execution of the Addendum by the parties.

Table 2: The selected SCCs are the official 2021 SCCs incorporated in Schedule 1. Module 2 applies where Customer is Controller; Module 3 where Customer is Processor. Clause 7 and the optional Clause 11 language are not used. Clause 9(a) uses general authorization with a 30-day notice period. Modules 1 and 4 are not used; the Table 2 combination-of-data entry relevant to Module 4 is not applicable.

Table 3: Annex I.A is Schedule 1.B; Annex I.B is Schedule 1.C and Annex 1; Annex II is Annex 2; Annex III is the named register required by Annex 3. The parties shall supply any further Appendix Information required for the relevant transfer before it occurs.

Table 4: Neither party may end the Addendum solely under its Section 19 when the approved Addendum changes. This does not limit other suspension or termination rights under the Addendum, SCCs, this DPA, or applicable law.

The Addendum's mandatory hierarchy and UK adaptations apply. The EU SCCs alone do not substitute for the UK Addendum for a UK Restricted Transfer relying on these terms.

← Back to home