Data Processing Addendum.
Last updated: 5 August 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Vextria Atlas Group Limited, operating as Orderly (“Orderly,” “we,” “us”), and the customer identified in the applicable account or order (“Customer,” “you”). This DPA applies where and to the extent Orderly processes Personal Data on your behalf in the course of providing the Service.
1. Definitions
- “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 (“EU GDPR”), and applicable US privacy laws including the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
- “Personal Data” means any information relating to an identified or identifiable natural person contained in Customer Data that Orderly processes on your behalf.
- “Customer Data” means data you upload, sync, or transmit through the Service, as described in the Agreement.
- “Sub-processor” means a third party engaged by Orderly to process Personal Data on your behalf.
- “SCCs” means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” means the UK International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0).
- Terms such as “controller,” “processor,” “data subject,” “processing,” and “personal data breach” have the meanings given in the applicable Data Protection Laws.
2. Roles and Scope
2.1 Roles. For Personal Data processed to provide the Service on your behalf, you are the controller (or a processor acting for a third-party controller) and Orderly is your processor. Each party will comply with its obligations under Data Protection Laws.
2.2 Orderly as controller. Orderly acts as an independent controller for: (a) account, billing, and usage data relating to you and your authorized users; and (b) Network Data as described in Section 12 of this DPA and Section 5 of the Terms of Service. This DPA’s processor obligations do not apply to those activities.
2.3 Customer instructions. Orderly will process Personal Data only on your documented instructions, including as set out in the Agreement, this DPA, and your configuration of the Service (including Bridges, Operations, Dispatchers, Transformations, and AI Agent permissions), unless required otherwise by law, in which case Orderly will inform you of the legal requirement unless prohibited from doing so. Orderly will inform you if, in its opinion, an instruction infringes Data Protection Laws.
2.4 Customer warranties. You warrant that you have obtained all necessary rights, consents, and lawful bases to transfer Personal Data to Orderly and to instruct its processing as contemplated by the Agreement, and that you have provided all required notices to data subjects.
3. Details of Processing
- Subject matter: Provision of the Orderly platform and related services described in the Agreement.
- Duration: The term of the Agreement, plus the deletion period in Section 9.
- Nature and purpose: Ingesting, syncing, normalizing, storing, transforming, routing, and transmitting order, shipment, and fulfillment data between the Customer’s connected platforms; purchasing carrier services; generating predictions and AI Agent responses; providing support.
- Categories of data subjects: Customer’s end customers (order recipients); Customer’s authorized users and personnel; end users of Customer applications using the Embed system.
- Categories of Personal Data: Names; email addresses; phone numbers; billing and delivery addresses; order details and contents; shipment and tracking information; account identifiers; IP addresses and device information for authorized users.
- Special category data: Not intentionally processed. You agree not to submit special category data through the Service unless separately agreed in writing.
4. Confidentiality
Orderly ensures that persons authorized to process Personal Data are bound by contractual or statutory obligations of confidentiality and receive appropriate data protection training.
5. Security
5.1 Orderly implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures are described in Annex II.
5.2 Orderly may update the measures in Annex II from time to time, provided the updates do not materially reduce the overall level of protection.
6. Sub-processors
6.1 General authorization. You authorize Orderly to engage Sub-processors to process Personal Data. Orderly’s current Sub-processors are listed in Annex III (and/or at a URL Orderly maintains for this purpose).
6.2 Notice of changes. Orderly will provide at least 14 days’ notice (by email or through the Service) before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection in good faith, you may terminate the affected portion of the Service.
6.3 Flow-down. Orderly will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains liable for its Sub-processors’ performance.
6.4 Carriers. Shipping carriers to whom Personal Data is transmitted to perform delivery services (e.g., UPS, FedEx, USPS, DHL, Royal Mail) act as independent controllers of the data they receive, not as Sub-processors, and their processing is governed by their own terms and privacy policies.
7. Data Subject Rights
Taking into account the nature of the processing, Orderly will assist you, through appropriate technical and organizational measures and insofar as possible, in fulfilling your obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If Orderly receives a request directly from a data subject relating to Personal Data processed on your behalf, it will redirect the data subject to you and will not respond substantively except as required by law.
8. Personal Data Breach
Orderly will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Personal Data processed on your behalf. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. Orderly will cooperate with you and take reasonable steps to mitigate the breach. Orderly’s notification is not an acknowledgment of fault or liability.
9. Return and Deletion
Upon termination or expiry of the Agreement, Orderly will, at your choice, return Personal Data to you (via the Service’s export features) and/or delete it, within the 30-day export window described in the Agreement, except where retention is required by law. Backup copies are deleted in accordance with Orderly’s backup rotation schedule, not exceeding 90 days, and remain protected by this DPA until deleted.
10. Audits and Assistance
10.1 Orderly will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and certifications where available, and will allow for and contribute to audits conducted by you or your appointed auditor, subject to: reasonable prior notice (at least 30 days); at most one audit per 12-month period except following a personal data breach or where required by a supervisory authority; confidentiality undertakings; no access to other customers’ data; and your responsibility for audit costs.
10.2 Taking into account the nature of processing and information available, Orderly will provide reasonable assistance with your data protection impact assessments and prior consultations with supervisory authorities where they relate to the Service.
11. International Transfers
11.1 Orderly may process Personal Data in the United Kingdom, the European Economic Area, the United States, and other countries where Orderly or its Sub-processors operate.
11.2 Where Personal Data protected by the EU GDPR is transferred to a country without an adequacy decision, the SCCs (Module Two: controller to processor, or Module Three: processor to processor, as applicable) are incorporated into this DPA, with: Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 14 days’ notice); Clause 11 optional language excluded; Clause 17 governed by the law of Ireland; Clause 18 courts of Ireland; and Annexes I–III of this DPA serving as the SCC Annexes.
11.3 Where Personal Data protected by the UK GDPR is transferred outside the UK without adequacy regulations, the UK Addendum is incorporated and amends the SCCs as set out in the Addendum, with Table 1–3 information taken from this DPA and its Annexes, and either party able to end the Addendum as set out in Section 19 of the Addendum.
11.4 Where a Sub-processor is certified under the EU–US Data Privacy Framework, the UK Extension, or the Swiss–US DPF, Orderly may rely on that certification as the transfer mechanism for transfers to that Sub-processor.
12. Network Data
As described in Section 5 of the Terms of Service, Orderly derives Network Data from shipments processed through the Service using data minimization at the point of ingestion: personal identifiers (names, email addresses, phone numbers, street addresses, order contents) are never ingested into the Orderly Intelligence system. Orderly processes Network Data as an independent controller, considers it effectively anonymized, and commits not to attempt to re-identify any individual from it. To the extent Network Data is deemed Personal Data under applicable law, Orderly processes it on the basis of its legitimate interests in improving the accuracy, reliability, and security of the Service.
13. CCPA Service Provider Terms
To the extent the CCPA applies, Orderly acts as your “service provider.” Orderly will not: sell or share Personal Data; retain, use, or disclose Personal Data for any purpose other than performing the Service and as permitted for service providers under the CCPA (including the internal-use and security purposes permitted by CCPA regulations); or combine Personal Data with personal information from other sources except as permitted for service providers. Orderly certifies that it understands and will comply with these restrictions, will notify you if it can no longer meet its CCPA obligations, and grants you the right to take reasonable steps to stop and remediate unauthorized use.
14. Liability and Order of Precedence
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent prohibited by Data Protection Laws. In case of conflict, the order of precedence is: (1) the SCCs and UK Addendum; (2) this DPA; (3) the Agreement.
Annex I — Details of Processing
A. List of parties
- Data exporter: the Customer (controller or processor). Contact: as set out in the Customer’s account.
- Data importer: Vextria Atlas Group Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: legal@vextria.tech. Activities: provision of the Orderly platform.
B. Description of transfer: As set out in Section 3 of this DPA. Frequency: continuous, for the duration of the Agreement.
C. Competent supervisory authority: For EU GDPR transfers, the supervisory authority of the exporter’s establishment or, where Clause 13 SCCs applies, the Irish Data Protection Commission. For UK transfers, the Information Commissioner’s Office.
Annex II — Technical and Organizational Measures
- Encryption of Personal Data in transit (TLS 1.2+) and at rest
- Multi-tenant logical isolation of customer data
- Role-based access control, least-privilege access, and MFA for personnel access to production systems
- Audit logging of access to production systems and administrative actions
- Network security controls including firewalls and segmentation
- Vulnerability management and patching processes; penetration testing at least annually
- Secure software development lifecycle including code review
- Backup and disaster recovery procedures with defined RPO/RTO
- Personnel confidentiality obligations and data protection training
- Vendor/Sub-processor security assessment procedures
- Incident response plan with defined escalation and notification procedures
- Data minimization at ingestion for Orderly Intelligence (personal identifier fields discarded at the API boundary)
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting, storage, and AI model infrastructure | United States / Europe |
| Stripe, Inc. | Payment processing | United States |
| Metronome, Inc. | Usage metering and billing | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and service reliability | United States |
Note: shipping carriers receive data as independent controllers and are not Sub-processors (see Section 6.4).