Legal

Data Processing Addendum.

Last updated: 5 August 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Vextria Atlas Group Limited, operating as Orderly (“Orderly,” “we,” “us”), and the customer identified in the applicable account or order (“Customer,” “you”). This DPA applies where and to the extent Orderly processes Personal Data on your behalf in the course of providing the Service.

1. Definitions

2. Roles and Scope

2.1 Roles. For Personal Data processed to provide the Service on your behalf, you are the controller (or a processor acting for a third-party controller) and Orderly is your processor. Each party will comply with its obligations under Data Protection Laws.

2.2 Orderly as controller. Orderly acts as an independent controller for: (a) account, billing, and usage data relating to you and your authorized users; and (b) Network Data as described in Section 12 of this DPA and Section 5 of the Terms of Service. This DPA’s processor obligations do not apply to those activities.

2.3 Customer instructions. Orderly will process Personal Data only on your documented instructions, including as set out in the Agreement, this DPA, and your configuration of the Service (including Bridges, Operations, Dispatchers, Transformations, and AI Agent permissions), unless required otherwise by law, in which case Orderly will inform you of the legal requirement unless prohibited from doing so. Orderly will inform you if, in its opinion, an instruction infringes Data Protection Laws.

2.4 Customer warranties. You warrant that you have obtained all necessary rights, consents, and lawful bases to transfer Personal Data to Orderly and to instruct its processing as contemplated by the Agreement, and that you have provided all required notices to data subjects.

3. Details of Processing

4. Confidentiality

Orderly ensures that persons authorized to process Personal Data are bound by contractual or statutory obligations of confidentiality and receive appropriate data protection training.

5. Security

5.1 Orderly implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures are described in Annex II.

5.2 Orderly may update the measures in Annex II from time to time, provided the updates do not materially reduce the overall level of protection.

6. Sub-processors

6.1 General authorization. You authorize Orderly to engage Sub-processors to process Personal Data. Orderly’s current Sub-processors are listed in Annex III (and/or at a URL Orderly maintains for this purpose).

6.2 Notice of changes. Orderly will provide at least 14 days’ notice (by email or through the Service) before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection in good faith, you may terminate the affected portion of the Service.

6.3 Flow-down. Orderly will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains liable for its Sub-processors’ performance.

6.4 Carriers. Shipping carriers to whom Personal Data is transmitted to perform delivery services (e.g., UPS, FedEx, USPS, DHL, Royal Mail) act as independent controllers of the data they receive, not as Sub-processors, and their processing is governed by their own terms and privacy policies.

7. Data Subject Rights

Taking into account the nature of the processing, Orderly will assist you, through appropriate technical and organizational measures and insofar as possible, in fulfilling your obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If Orderly receives a request directly from a data subject relating to Personal Data processed on your behalf, it will redirect the data subject to you and will not respond substantively except as required by law.

8. Personal Data Breach

Orderly will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Personal Data processed on your behalf. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. Orderly will cooperate with you and take reasonable steps to mitigate the breach. Orderly’s notification is not an acknowledgment of fault or liability.

9. Return and Deletion

Upon termination or expiry of the Agreement, Orderly will, at your choice, return Personal Data to you (via the Service’s export features) and/or delete it, within the 30-day export window described in the Agreement, except where retention is required by law. Backup copies are deleted in accordance with Orderly’s backup rotation schedule, not exceeding 90 days, and remain protected by this DPA until deleted.

10. Audits and Assistance

10.1 Orderly will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and certifications where available, and will allow for and contribute to audits conducted by you or your appointed auditor, subject to: reasonable prior notice (at least 30 days); at most one audit per 12-month period except following a personal data breach or where required by a supervisory authority; confidentiality undertakings; no access to other customers’ data; and your responsibility for audit costs.

10.2 Taking into account the nature of processing and information available, Orderly will provide reasonable assistance with your data protection impact assessments and prior consultations with supervisory authorities where they relate to the Service.

11. International Transfers

11.1 Orderly may process Personal Data in the United Kingdom, the European Economic Area, the United States, and other countries where Orderly or its Sub-processors operate.

11.2 Where Personal Data protected by the EU GDPR is transferred to a country without an adequacy decision, the SCCs (Module Two: controller to processor, or Module Three: processor to processor, as applicable) are incorporated into this DPA, with: Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 14 days’ notice); Clause 11 optional language excluded; Clause 17 governed by the law of Ireland; Clause 18 courts of Ireland; and Annexes I–III of this DPA serving as the SCC Annexes.

11.3 Where Personal Data protected by the UK GDPR is transferred outside the UK without adequacy regulations, the UK Addendum is incorporated and amends the SCCs as set out in the Addendum, with Table 1–3 information taken from this DPA and its Annexes, and either party able to end the Addendum as set out in Section 19 of the Addendum.

11.4 Where a Sub-processor is certified under the EU–US Data Privacy Framework, the UK Extension, or the Swiss–US DPF, Orderly may rely on that certification as the transfer mechanism for transfers to that Sub-processor.

12. Network Data

As described in Section 5 of the Terms of Service, Orderly derives Network Data from shipments processed through the Service using data minimization at the point of ingestion: personal identifiers (names, email addresses, phone numbers, street addresses, order contents) are never ingested into the Orderly Intelligence system. Orderly processes Network Data as an independent controller, considers it effectively anonymized, and commits not to attempt to re-identify any individual from it. To the extent Network Data is deemed Personal Data under applicable law, Orderly processes it on the basis of its legitimate interests in improving the accuracy, reliability, and security of the Service.

13. CCPA Service Provider Terms

To the extent the CCPA applies, Orderly acts as your “service provider.” Orderly will not: sell or share Personal Data; retain, use, or disclose Personal Data for any purpose other than performing the Service and as permitted for service providers under the CCPA (including the internal-use and security purposes permitted by CCPA regulations); or combine Personal Data with personal information from other sources except as permitted for service providers. Orderly certifies that it understands and will comply with these restrictions, will notify you if it can no longer meet its CCPA obligations, and grants you the right to take reasonable steps to stop and remediate unauthorized use.

14. Liability and Order of Precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent prohibited by Data Protection Laws. In case of conflict, the order of precedence is: (1) the SCCs and UK Addendum; (2) this DPA; (3) the Agreement.


Annex I — Details of Processing

A. List of parties

B. Description of transfer: As set out in Section 3 of this DPA. Frequency: continuous, for the duration of the Agreement.

C. Competent supervisory authority: For EU GDPR transfers, the supervisory authority of the exporter’s establishment or, where Clause 13 SCCs applies, the Irish Data Protection Commission. For UK transfers, the Information Commissioner’s Office.

Annex II — Technical and Organizational Measures

Annex III — Sub-processors

Sub-processorPurposeLocation
Google Cloud Platform (Google LLC)Cloud hosting, storage, and AI model infrastructureUnited States / Europe
Stripe, Inc.Payment processingUnited States
Metronome, Inc.Usage metering and billingUnited States
Functional Software, Inc. (Sentry)Error monitoring and service reliabilityUnited States

Note: shipping carriers receive data as independent controllers and are not Sub-processors (see Section 6.4).