Ordnary

Technology

Data Processing Addendum

Last updated July 22, 2026

If your business uses our services, this sets out how Ordnary processes your customers' data on your behalf, and the safeguards we apply.

This Data Processing Addendum forms part of the Terms of Service and the Ordnary Web Services Terms (together, the "Agreement") between Ordnary ("processor") and the customer ("controller", "you"), to the extent Ordnary processes your customers' personal data on your behalf. This addendum gives effect to the requirements of Article 28 of the General Data Protection Regulation (GDPR) and the equivalent UK legislation. Need a signed copy? Contact notices@ordnary.com.

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meaning given to them by the GDPR.

Roles and scope

You are the controller (or processor on behalf of another controller) for your customers' personal data, and Ordnary is the processor (or subprocessor). Ordnary processes this personal data solely to deliver and support the services, and on the basis of your documented instructions, including instructions given through the services and the Agreement.

Subject matter and details of processing

Subject matter: the provision of Ordnary's services.

Duration: the term of the Agreement, supplemented by the limited retention period described below.

Nature and purpose: hosting, storage, transmission, processing, AI inference, support, and security.

Types of data: determined by you, typically account identifiers, content you submit, and usage and technical data.

Categories of data subjects: your users, customers, and contacts.

Ordnary's obligations

Ordnary will:

process your customers' personal data solely on the basis of your documented instructions, including for international transfers, unless required by law (in which case we'll inform you unless legally prohibited from doing so);

ensure that persons authorized to process data are bound by confidentiality;

implement appropriate technical and organizational measures (see Security below);

comply with the conditions for engaging subprocessors (see Subprocessors below);

assist you, taking into account the nature of the processing, in responding to data subject requests (see Data subject rights and AI below);

assist you with security, data breach notifications, data protection impact assessments, and consultations with supervisory authorities (Articles 32 through 36 GDPR);

at your choice, delete or return your customers' personal data at the end of the services, unless retention is required by law; and

make available information necessary to demonstrate compliance and enable audits as described under Audits below.

Your obligations

You're responsible for the lawfulness of your instructions and of the data you submit, including having a valid legal basis, providing required notices, and obtaining required consents. You may not submit special categories of personal data except to the extent the services allow it and with appropriate safeguards.

Subprocessors

You give general authorization for Ordnary to engage subprocessors to deliver the services. Current subprocessors are listed on our Subprocessors page. We impose data-protection obligations on subprocessors no less protective than this addendum, and we remain responsible for their performance. We'll notify you of new subprocessors and provide a reasonable period to object on reasonable data-protection grounds.

Data subject rights and AI

Taking into account the nature of the processing, Ordnary will assist you with appropriate technical and organizational measures to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). Where the services include AI features, Ordnary does not use your customers' personal data to train the models, unless you explicitly instruct us to do so, consistent with the AI Usage Policy.

Security

Ordnary implements technical and organizational measures appropriate to the risk, including: encryption in transit and at rest; access controls and the principle of least privilege; isolation between workspaces; network security; logging and monitoring; secure development practices; backup and recovery for managed services; and confidentiality and training for personnel. Further detail is in the Security Policy. We may update these measures, provided the overall level of protection isn't reduced.

Audits

Ordnary will make available information reasonably necessary to demonstrate compliance with this addendum, including relevant certifications or summaries of independent assessments, where available. Where this is insufficient, you may have an audit conducted no more than once per year (and after a material incident), on reasonable prior notice, during business hours, subject to confidentiality, and without disrupting operations.

Personal data breaches

Ordnary will notify you without undue delay after becoming aware of a personal data breach affecting your customers' personal data, with information reasonably available to help you meet your notification obligations, and will take reasonable steps to mitigate and remediate it.

International transfers

Your customers' personal data is processed primarily in the EU. Where Ordnary or a subprocessor transfers data outside the EEA/UK, this is done under an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference here, together with supplementary measures where needed.

Return and deletion

On termination or expiry of the services, Ordnary will, at your choice, delete or return your customers' personal data within a reasonable period, except for copies that must be retained by law; these remain subject to this addendum's confidentiality and security provisions until deleted.

Liability and precedence

Liability under this addendum is subject to the limitations in the Terms of Service. In the event of a conflict between this addendum and the rest of the Agreement regarding the processing of your customers' personal data, this addendum prevails.

Contact

Questions about data protection or this addendum? Contact privacy@ordnary.com or notices@ordnary.com.

For urgent requests, call +31 85 401 3197.