Legal
Data Processing Addendum
Last updated 15 August 2026. Forms part of the Terms of Service.
This is the Article 28 agreement a buyer's legal or procurement team asks for. It applies automatically to every customer, with no signature needed. If your process requires a signed copy on your own paper, write to olha@ordelume.com and we will sign it.
1. Parties and roles
The customer is the controller of the personal data in its workspace. Ordelume, operated by Olha Horobets, individual entrepreneur registered in Ukraine (registration number to be added), is the processor. Where the customer is itself a processor for its own client, Ordelume is a subprocessor and the same obligations apply.
2. Subject matter and duration
We process personal data to provide the Ordelume service described in the Terms, for as long as the customer has an account, plus the deletion window in section 9.
3. Nature and purpose
Storage, organisation, retrieval, analysis, and transmission of workspace records so the customer can run its sales, delivery, hiring, finance, and internal communication, including AI-generated drafts and analysis produced on the customer's request.
4. Categories of data subjects and data
| Data subjects | Personal data |
|---|---|
| The customer's own staff and workspace members | Name, business email, role, title, department, capacity and workload records, and where the customer chooses to record them, payroll and bonus amounts |
| The customer's leads, contacts, and clients | Name, business contact details, employer, job title, public profile information including LinkedIn profile data, message and email history, meeting notes, deal and invoice values, and where the customer uploads a call recording, the speech in that recording and the transcript made from it. Obtaining consent to record a call is the customer's responsibility as controller; the recording itself is never uploaded to or stored by Ordelume |
| Candidates, where the customer uses recruiting features | Name, contact details, CV content the customer uploads, interview stage and notes |
Ordelume is not designed for special category data under Article 9 or for criminal conviction data. Do not put it in.
5. Our obligations
- We process personal data only on the customer's documented instructions. Using the product is an instruction; so is a written request to us. If we believe an instruction breaks data protection law, we say so.
- Everyone with access is bound by confidentiality.
- We keep the technical and organisational measures in section 6.
- We help the customer answer data subject requests, carry out impact assessments, and consult regulators, to the extent the customer needs our help and only we can give it.
- We do not use workspace data for our own purposes, do not sell it, and do not train models on it.
6. Security measures
Current measures, described plainly so they can be verified rather than believed:
- In transit: HTTPS everywhere, HSTS, secure and HttpOnly session cookies.
- Credentials: passwords stored as PBKDF2-SHA256 with 240,000 iterations and a per-password salt. Provider API keys and OAuth tokens encrypted at rest and never exposed to the browser.
- Tenant isolation: every request resolves the workspace from the authenticated session against actual membership; a request naming another company's workspace is refused, and the same check is repeated inside the AI layer.
- Access control inside a workspace: role-based visibility per module, an approvals queue for sensitive actions, and an audit log.
- Sessions: 12-hour lifetime; a password reset ends every existing session.
- Hosting: managed EU infrastructure in Frankfurt with provider-managed backups and encrypted storage.
- Change control: version-controlled deployments with the ability to roll back.
We hold no SOC 2 or ISO 27001 certification today and do not claim one.
7. Subprocessors
The customer authorises the subprocessors listed at ordelume.com/subprocessors. We stay responsible for their performance and bind each to obligations no weaker than these. Before adding or replacing one, we give at least 30 days' notice by email; if the customer reasonably objects on data protection grounds within that period, it may terminate without penalty.
8. Personal data breach
We notify the customer without undue delay, and in any event within 72 hours of becoming aware of a breach affecting its data, with what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. We do not wait until the picture is complete to tell you it happened.
9. Deletion and return
Customers can export any module to CSV at any time during the term. On termination, or on written request, we delete workspace data within 30 days, backups included, unless the law requires us to keep something. We confirm deletion in writing when asked.
10. Audit
We answer reasonable written security questionnaires and provide the information needed to demonstrate compliance with this addendum. An on-site audit can be arranged once per year, with 30 days' notice, at the customer's cost, subject to confidentiality and to not disturbing other customers' data.
11. International transfers
Data is stored in the EU (Frankfurt). Our operations are in Ukraine, and some subprocessors are in the United States. Where a transfer outside the EEA requires safeguards, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this addendum by reference, together with any supplementary measures required by the transfer risk assessment. The details in sections 1, 2, 3, 4, 6, and 7 populate the annexes of those clauses.
12. Precedence
If this addendum conflicts with the Terms of Service on the processing of personal data, this addendum wins.
Need it signed, or on your own template? Write to olha@ordelume.com with the document and we will turn it around.