New: US import bans on some Canadian products start September 29. See what it means for your orders. Check a product

Data Processing Addendum outline (DRAFT for legal review)

Applies when Othermile processes personal information on a Customer's behalf.

  • Roles: Customer controls the information; Othermile processes it only on Customer's documented instructions (these terms, the settings Customer chooses, and API calls Customer makes).
  • Categories of data: order details Customer or its connected services send (order numbers, products, destination region, prices and costs), approver identities and decisions, and agent action details where Customer uses agent approvals.
  • Purpose: checking orders against border rules and Customer limits, comparing routes, routing approvals, recording signed decisions, notifications, support.
  • Confidentiality: staff access limited to need to know, under confidentiality obligations.
  • Security measures: as described in the security documentation (encryption in transit, row level security, hashed keys, signed receipts, backups, access logging).
  • Subprocessors: listed publicly; 30 days' notice of additions with a right to object.
  • Location and transfers: primary storage in Canada; transfers only with comparable protection.
  • Breach notice: without undue delay, and within [72] hours of confirming a breach affecting Customer data.
  • Assistance: help with access, correction and deletion requests and with privacy impact assessments.
  • Deletion: readable details deleted per retention setting and on termination after the export window; signed receipts contain digests only and are deleted with the workspace.
  • Audit: reasonable information on request; independent audit reports (for example SOC 2) once available.