Data Processing Addendum outline (DRAFT for legal review)
Applies when Othermile processes personal information on a Customer's behalf.
- Roles: Customer controls the information; Othermile processes it only on Customer's documented instructions (these terms, the settings Customer chooses, and API calls Customer makes).
- Categories of data: order details Customer or its connected services send (order numbers, products, destination region, prices and costs), approver identities and decisions, and agent action details where Customer uses agent approvals.
- Purpose: checking orders against border rules and Customer limits, comparing routes, routing approvals, recording signed decisions, notifications, support.
- Confidentiality: staff access limited to need to know, under confidentiality obligations.
- Security measures: as described in the security documentation (encryption in transit, row level security, hashed keys, signed receipts, backups, access logging).
- Subprocessors: listed publicly; 30 days' notice of additions with a right to object.
- Location and transfers: primary storage in Canada; transfers only with comparable protection.
- Breach notice: without undue delay, and within [72] hours of confirming a breach affecting Customer data.
- Assistance: help with access, correction and deletion requests and with privacy impact assessments.
- Deletion: readable details deleted per retention setting and on termination after the export window; signed receipts contain digests only and are deleted with the workspace.
- Audit: reasonable information on request; independent audit reports (for example SOC 2) once available.