Data Processing Addendum
Effective date: July 1, 2026
This Data Processing Addendum (the “DPA”) forms part of the Terms of Use, order form, master services agreement, or other written or electronic agreement governing a customer’s use of the Services (the “Agreement”) between the customer identified in the Agreement (“Customer”) and LAIW PTY LTD (ACN 667 737 251), trading as Odella (“Odella”).
This DPA applies when Odella processes Personal Data on Customer’s behalf in connection with the Services. Customer enters into this DPA for itself and, where applicable, for its authorized affiliates. By entering into the Agreement or continuing to use the Services to process Personal Data, each party agrees to this DPA. Capitalized terms not defined here have the meanings given in the Agreement.
If there is a conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA controls. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.
1. Definitions
“Applicable Data Protection Laws” means privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles; the EU General Data Protection Regulation 2016/679 (“EU GDPR”); the EU ePrivacy Directive and implementing laws; the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection (“Swiss FADP”); and United States state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
“Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processor,” and “Processing” have the meanings given in Applicable Data Protection Laws. “Personal Data” includes “personal information,” “personal data,” and similar terms defined by Applicable Data Protection Laws.
“Customer Personal Data” means Personal Data contained in Customer Data that Odella processes on Customer’s behalf under the Agreement.
“Standard Contractual Clauses” or “EU SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
“Subprocessor” means a third party appointed by or on behalf of Odella to process Customer Personal Data in connection with the Services. It does not include Customer personnel or a third party that Customer directly contracts with and instructs independently of Odella. A provider does not cease to be Odella’s Subprocessor merely because Customer selects or enables that provider through the Services if Odella contracts with the provider to process Customer Personal Data on Odella’s behalf.
2. Scope and roles
- Customer is the Controller of Customer Personal Data and Odella is the Processor, except where Customer is a Processor acting for another Controller, in which case Odella is Customer’s Subprocessor. Each party will comply with the obligations that apply to it under Applicable Data Protection Laws.
- Customer determines the purposes and means of processing Customer Personal Data. Customer instructs Odella to process Customer Personal Data only as necessary to provide, maintain, secure, support, and make account-specific improvements to the Services for Customer in accordance with the Agreement, Customer’s use and configuration of the Services, and Customer’s other documented instructions consistent with the Agreement.
- Annex I describes the subject matter, nature, purpose, and duration of processing, and the categories of Personal Data and Data Subjects.
- Odella acts as an independent Controller, and this DPA does not apply, when Odella processes Personal Data for its own independent purposes, such as account administration, direct billing, fraud prevention, legal compliance, direct customer relationship management, product-wide analytics, generalized Service improvement, or Large Language Model ("LLM") training, as described in the Privacy Policy and Agreement. Odella will identify and comply with an applicable legal basis for that independent processing. The LLM-training opt-in in the Agreement and Privacy Policy applies only to LLM training; it does not displace any non-waivable right to object to or restrict other independent-Controller processing.
- If Customer directs Odella to disclose Customer Personal Data to a Customer-selected third-party service, Customer authorizes that disclosure and is responsible for determining that the third party and transfer are lawful. Odella remains responsible for its own processing before the authorized disclosure.
3. Customer obligations
Customer will:
- process Customer Personal Data lawfully and provide all notices, obtain all consents, and establish all legal bases required for Odella’s processing under the Agreement and this DPA;
- ensure its instructions comply with Applicable Data Protection Laws and that it has the right to transfer Customer Personal Data to Odella;
- use the Services and configure access, integrations, retention, and security settings appropriately for the nature and sensitivity of Customer Personal Data;
- not instruct Odella to process Personal Data in violation of law, and not provide children’s Personal Data, special-category or sensitive Personal Data, criminal-offence data, protected health information, payment-card data, or government identifiers unless the Agreement expressly permits that processing and Customer has implemented appropriate safeguards; and
- act as the single point of contact for its Data Subjects and any Controller on whose behalf Customer acts; and
- reasonably cooperate with Odella where necessary for Odella to satisfy obligations that apply to its processing under Applicable Data Protection Laws.
Customer acknowledges that the Services depend on Customer’s configuration and instructions, including choices concerning retention periods, deletion, access, integrations, and data residency. Odella is not responsible for Customer’s failure to use available safeguards or for the acts of Customer-selected third-party services.
4. Odella’s processing obligations
Odella will:
- process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement and this DPA, unless applicable law requires other processing;
- if legally permitted, inform Customer before processing Customer Personal Data to comply with a legal requirement;
- promptly inform Customer if Odella believes an instruction violates Applicable Data Protection Laws, and may suspend the affected processing until Customer confirms or modifies the instruction;
- ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive security and privacy training appropriate to their roles;
- implement and maintain the technical and organizational measures described in Annex II;
- not disclose Customer Personal Data to a third party except as permitted by the Agreement, this DPA, Customer’s instructions, or applicable law; and
- to the extent legally permitted, promptly inform Customer if Odella receives a legally binding demand from a law enforcement or government authority for disclosure of Customer Personal Data. Odella will review the demand for validity and scope and disclose only the Customer Personal Data it is legally required to disclose.
5. Assistance and Data Subject requests
- Taking into account the nature of the processing, Odella will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to requests from Data Subjects to exercise their rights.
- If Odella receives a request from a Data Subject concerning Customer Personal Data, Odella will, where legally permitted, direct the requester to Customer or notify Customer. Odella will not respond on Customer’s behalf unless Customer instructs it to do so or applicable law requires it.
- Taking into account the nature of processing and information available to Odella, Odella will provide reasonable assistance with Customer’s obligations concerning security, Personal Data Breach notifications, data protection impact assessments, and prior consultation with supervisory authorities.
- Odella may charge reasonable fees for assistance that is unusually burdensome or outside the ordinary functionality of the Services, unless the assistance is required because Odella breached this DPA.
6. Security and Personal Data Breaches
- Odella will maintain security measures appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. The current measures are summarized in Annex II.
- Odella may update its security measures as technology and risks evolve, provided the updates do not materially reduce the overall protection of Customer Personal Data.
- Odella will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Customer Personal Data and, where feasible, within 48 hours after becoming aware of it.
- As information becomes available, the notice will describe the nature of the breach, the categories and approximate number of affected Data Subjects and records, likely consequences, relevant mitigation or remediation, and a contact for follow-up. Odella may provide this information in phases and will not delay an initial notice solely because all details are not yet available.
- Odella will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably cooperate with Customer. Odella’s notice is not an admission of fault or liability.
- Customer is responsible for notifying regulators, Data Subjects, or others unless Applicable Data Protection Laws require Odella to notify them directly.
7. Subprocessors
- Customer gives Odella general written authorization to engage Subprocessors. The current Subprocessor list, including processing functions and locations where available, is maintained in the Odella Trust Center and is incorporated into this DPA.
- Odella will impose written data protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to Odella under this DPA, to the extent relevant to the Subprocessor’s services. Odella remains responsible for each Subprocessor’s performance of those obligations as required by Applicable Data Protection Laws.
- Odella will post an intended addition or replacement to the Subprocessor list at least 15 days before the Subprocessor begins processing Customer Personal Data, except where an emergency threatens the security or availability of the Services. Customers may request direct Subprocessor change notices by contacting legal@odella.ai.
- Customer may object to a new Subprocessor on reasonable data protection grounds by emailing legal@odella.ai within 15 days after notice and explaining the grounds. The parties will work in good faith to address the concern and offer commercially reasonable alternatives where available. If the parties do not resolve the objection within 30 days after Odella receives it and Odella cannot provide the affected Services without the new Subprocessor, either party may terminate the affected Services. Customer will receive a pro rata refund of prepaid fees covering the period after termination, if any.
8. International transfers
- Customer authorizes Odella and its Subprocessors to process Customer Personal Data in Australia, the United States, and other countries identified in the Subprocessor list, subject to this section and any data residency commitment in the Agreement.
- Data residency settings do not prevent transfers or remote access reasonably required for support, security, incident response, billing, abuse prevention, legal compliance, or Customer-selected third-party services, as described in the Agreement and Privacy Policy.
- For a restricted transfer of Customer Personal Data from the EEA to a country not recognized as providing adequate protection, the EU SCCs are incorporated into this DPA as described in Annex III.
- For a restricted transfer from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, version B1.0 in force March 21, 2022 (“UK Addendum”), is incorporated as described in Annex III.
- For a restricted transfer from Switzerland, the EU SCCs apply with the Swiss modifications in Annex III.
- Where Australian Privacy Principle 8 applies, Odella will take reasonable steps to ensure an overseas recipient handles Personal Data consistently with the Australian Privacy Principles, unless an exception applies.
- The parties will reasonably cooperate regarding supplementary transfer measures and transfer impact information required by Applicable Data Protection Laws.
9. Return and deletion
- During the term, Customer may access, export, or delete Customer Data using available Service functionality, subject to the Agreement.
- On termination or Customer’s valid written request, Odella will delete or return Customer Personal Data from active systems within 30 days, unless applicable law requires retention. Unless access is restricted for fraud, unlawful conduct, an urgent security risk, or a material breach that makes continued access unsafe, Odella will make available existing export functionality during that period where reasonably practicable.
- Customer Personal Data in backups will be isolated from ordinary use and deleted through Odella’s standard backup expiry cycle, except that Odella may retain information as required by law or reasonably necessary for security, fraud prevention, dispute resolution, or backup integrity. Any retained Customer Personal Data remains protected by this DPA and will not be processed for another purpose.
- On written request, Odella will confirm completion of deletion, subject to the limitations above.
10. Information and audits
- Odella will make available information reasonably necessary to demonstrate compliance with this DPA. Odella may satisfy an audit request by providing relevant third-party audit reports, certifications, summaries, questionnaires, or Trust Center materials, subject to confidentiality restrictions.
- If that information is reasonably insufficient, Customer may conduct one audit in any 12-month period through an independent, qualified auditor that is not Odella’s competitor. Additional audits are permitted following a confirmed Personal Data Breach affecting Customer Personal Data or where a supervisory authority requires one.
- Customer must provide at least 30 days’ written notice, limit the audit to systems and records relevant to Customer Personal Data, conduct it during normal business hours, avoid disrupting operations, and ensure the auditor signs appropriate confidentiality terms. Audits may not expose another customer’s information, security-sensitive information, or information that Odella is prohibited from disclosing. Audit reports, supporting materials, and findings are Odella’s Confidential Information.
- Customer will bear its audit costs and reimburse Odella’s reasonable costs for an on-site or unusually burdensome audit, unless the audit identifies a material breach of this DPA by Odella.
- Odella will promptly address material issues identified by a valid audit to the extent required by Applicable Data Protection Laws.
11. United States state privacy terms
To the extent CCPA or another U.S. state privacy law applies to Odella’s processing of Customer Personal Data, Odella acts as a service provider or processor and will:
- process Customer Personal Data only for the limited and specified business purposes described in the Agreement, this DPA, and Customer’s documented instructions;
- not provide monetary or other valuable consideration to Customer in exchange for Customer Personal Data, and the parties acknowledge that Customer has not sold Customer Personal Data to Odella;
- not sell or share Customer Personal Data, including for cross-context behavioral advertising, or process it for targeted advertising;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the permitted purposes;
- not use Customer Personal Data governed by this section for independent LLM training unless Customer has affirmatively authorized that processing or Applicable Data Protection Laws otherwise permit it without impairing Odella’s status as a service provider or Processor;
- not combine Customer Personal Data with Personal Data received from another person or collected from Odella’s own interaction with a consumer, except as directed by Customer or otherwise permitted by applicable law;
- where Customer instructs or permits Odella to process Customer Personal Data in de-identified form, take reasonable measures to prevent the data from being associated with a natural person or household, publicly commit to maintain and use the data in de-identified form and not attempt to re-identify it except as permitted by law, and contractually require any recipient to observe equivalent restrictions;
- provide the same level of privacy protection required of Customer for the relevant processing;
- notify Customer without undue delay if Odella determines it can no longer meet an applicable obligation; and
- allow Customer to take reasonable and appropriate steps to verify compliance and, following reasonable notice of suspected non-compliance, work with Customer in good faith to stop and remediate unauthorized use of Customer Personal Data. If an issue cannot reasonably be remedied, Odella will stop the affected processing upon Customer’s written instruction, subject to the Agreement and applicable law.
Customer will not instruct or permit processing that would cause its disclosure of Customer Personal Data to Odella to constitute a sale or share under U.S. state privacy law or cause Odella not to qualify as Customer’s service provider or processor.
Each party certifies that it understands and will comply with the restrictions in this section.
12. Liability, termination, and general terms
- Each party’s liability arising out of this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent those limitations are prohibited by Applicable Data Protection Laws or the Standard Contractual Clauses.
- This DPA remains in effect while Odella processes Customer Personal Data. Obligations that by their nature should survive, including confidentiality, deletion, and transfer protections, survive termination.
- The governing law and dispute provisions in the Agreement apply to this DPA, except where Applicable Data Protection Laws or the Standard Contractual Clauses require otherwise.
- Amendments to this DPA are governed by the amendment provisions of the Agreement. Odella may update this DPA to reflect changes in law or the Services, provided an update does not materially reduce Customer’s data protection rights during a current subscription term. Odella will provide notice of materially adverse changes as required by the Agreement or law.
- Notices concerning this DPA may be sent to legal@odella.ai. Privacy and Data Subject requests may be sent to dsar@odella.ai.
Annex I — Details of processing
A. Parties
Data exporter: Customer and, where applicable, its authorized affiliates, as identified in the Agreement. The exporter’s contact details and activities are described in the Agreement. The exporter is a Controller or Processor, as applicable.
Data importer: LAIW PTY LTD (ACN 667 737 251), trading as Odella, 70 Acanthus Avenue, Burleigh Waters, QLD 4220, Australia; legal@odella.ai. Odella’s activities are the provision of the Services described in the Agreement. Odella is a Processor or Subprocessor for Customer Personal Data.
By entering into the Agreement, each party is deemed to have signed this Annex and the applicable Standard Contractual Clauses.
B. Description of processing
Subject matter and purpose: Providing, maintaining, securing, supporting, and making account-specific improvements to the Services for Customer in accordance with the Agreement and Customer’s documented instructions. This may include enabling Customer to hire, onboard, train, and manage AI Employees that complete Customer-configured tasks and workflows across connected workplace tools.
Nature of processing: Collection, receipt, recording, organization, storage, retrieval, consultation, analysis, transformation, generation of Customer-requested output, transmission to Customer-authorized recipients and integrations, troubleshooting, security monitoring, backup, deletion, and other processing necessary to provide the Services.
Duration: For the term of the Agreement and the limited deletion and backup period described in Section 9.
Frequency: Continuous or as initiated and configured by Customer during the term.
Categories of Data Subjects:
- Customer’s authorized users, administrators, employees, contractors, and representatives;
- Customer’s customers, prospects, suppliers, partners, and business contacts;
- individuals whose information Customer submits, imports, or makes accessible through a connected service; and
- other Data Subjects identified by Customer’s use of the Services.
Categories of Personal Data:
- identity and contact information, such as name, business email, phone number, organization, title, role, and user identifiers;
- account, authentication, authorization, and organization-membership information;
- Customer workspace data, including prompts, instructions, messages, files, documents, images, records, datasets, templates, workflows, process descriptions, and Customer-requested output;
- communications data, which may include email, SMS, MMS, voice, delivery, consent, and opt-out records where Customer enables those features;
- integration data and business records made available through Customer-connected services; and
- technical and operational information that constitutes Customer Personal Data, such as IP address, device data, usage events, workflow records, logs, support content, and security events.
Sensitive Personal Data: The Services are not designed to require special-category or sensitive Personal Data. Customer may submit such data only where permitted by the Agreement and law. The categories depend entirely on Customer’s instructions and may include sensitive data contained in Customer-provided content.
Processing operations for sensitive data: The same operations described above, with access restrictions, encryption, logging, and other measures appropriate to risk.
Retention: As configured by Customer, for the Agreement term, and afterward as described in Section 9 and the Agreement.
Transfers to Subprocessors: The subject matter, nature, and duration are limited to the functions described in the current Subprocessor list.
Competent supervisory authority: Determined under Clause 13 of the EU SCCs. Where the exporter is not established in the EEA but is subject to the EU GDPR and has appointed an EU representative, the authority for the representative’s member state will be competent. Otherwise, it will be the authority for the member state where affected Data Subjects are located, as applicable.
Annex II — Technical and organizational measures
Odella maintains a risk-based security program designed to protect the confidentiality, integrity, availability, and resilience of Customer Personal Data. Measures include, as appropriate to the Services and processing:
1. Governance and personnel
- Documented information security, privacy, incident response, access control, vendor management, business continuity, and data handling policies.
- Assigned security and privacy responsibility, periodic risk and control reviews, and corrective-action tracking.
- Confidentiality obligations and security awareness requirements for personnel with access to protected information.
- Data classification and handling requirements for public, internal, confidential, and restricted information.
2. Identity and access management
- Role-based and least-privilege access to production systems and Customer Personal Data.
- Unique user identities, approval processes for privileged access, and multi-factor authentication for privileged access and critical production systems.
- Access logging and periodic review of access rights.
- Prompt revocation or modification of access following termination or role changes.
- Controlled emergency access limited in scope and duration and reviewed after use.
3. Encryption and data protection
- Encryption of sensitive data in transit using TLS 1.2 or higher and encryption at rest using AES-256 or equivalent provider-managed encryption, as appropriate.
- Managed key and secret storage, access restrictions, and rotation practices.
- Logical separation controls designed to prevent one customer’s Customer Data from being made available to another customer except as instructed or permitted by the Agreement.
- Data minimization, masking, and avoidance of unnecessary production data in non-production environments where feasible.
4. Infrastructure, application, and network security
- Provider-managed data center physical and environmental controls.
- Firewalls, restricted administrative access, secure configuration, and minimized public exposure.
- Separation of development and production environments.
- Change review through source control and pull requests, testing, deployment records, and rollback or recovery practices appropriate to the change.
- Vulnerability, dependency, and cloud security monitoring, with risk-based remediation.
- Endpoint safeguards, device encryption, screen locks, and secure remote-work practices for personnel devices that access protected systems.
5. Logging, monitoring, and incident response
- Logging of relevant authentication, administrative, cloud, application, and security events for systems that process Customer Personal Data.
- Access controls and retention protections for audit logs.
- Monitoring and escalation processes for suspicious events and security violations.
- A documented incident response process covering preparation, identification, containment, eradication, recovery, notification analysis, and post-incident review.
- Personal Data Breach assessment and notification procedures.
6. Availability, backup, and recovery
- Backups, point-in-time recovery, snapshots, version control, or equivalent recovery mechanisms for critical production systems.
- Access protection for backups and recovery configuration.
- Documented business continuity and disaster recovery responsibilities and procedures.
- Periodic recovery testing or documented recovery walkthroughs proportionate to system risk.
7. Vendor and Subprocessor management
- Risk-based security and privacy review before onboarding material vendors where practical.
- Written confidentiality, security, and data protection terms appropriate to vendor risk and access.
- Periodic review of critical and high-risk vendors and assessment of relevant incidents or material changes.
- Removal of vendor access when no longer required.
8. Deletion and disposal
- Customer-accessible deletion and export functionality where provided by the Services.
- Documented deletion procedures covering active systems, vendors, logs, and backup expiry.
- Secure disposal or sanitization of data and media consistent with risk and provider capabilities.
Annex III — International transfer terms
1. EU Standard Contractual Clauses
For a restricted transfer subject to the EU GDPR, the EU SCCs are incorporated by reference and completed as follows:
- Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor.
- Clause 7 (Docking Clause) applies.
- In Clause 9(a), Option 2 (general written authorization) applies, with the notice period in Section 7 of this DPA.
- In Clause 11(a), the optional independent dispute-resolution language does not apply.
- In Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland.
- In Clause 18(b), disputes will be resolved by the courts of Ireland.
- Annex I of the EU SCCs is completed with Annex I of this DPA; Annex II with Annex II of this DPA; and Annex III with the Subprocessor list referenced in Section 7.
- If Customer is a Processor, Customer confirms that its instructions and actions concerning Customer Personal Data, including its appointment of Odella as a Subprocessor, are authorized by the relevant Controller.
2. United Kingdom
For a restricted transfer subject to UK data protection law, the UK Addendum is incorporated and completed as follows:
- Table 1 is completed with Annex I(A) of this DPA.
- Table 2 selects the version of the EU SCCs and modules described above.
- Table 3 is completed with Annexes I and II of this DPA and the Subprocessor list.
- In Table 4, both the importer and exporter may end the UK Addendum as permitted by its terms.
- By entering into the Agreement, the parties are deemed to have signed the UK Addendum.
3. Switzerland
For a restricted transfer subject to the Swiss FADP, the EU SCCs apply with these changes:
- references to the EU GDPR include the Swiss FADP to the extent applicable;
- references to “member state” will not prevent Swiss Data Subjects from exercising their rights in Switzerland;
- the competent authority is the Swiss Federal Data Protection and Information Commissioner;
- the governing law and forum provisions in the EU SCCs extend to Switzerland where required by the Swiss FADP; and
- Personal Data includes personal data protected under the Swiss FADP.
4. Precedence and alternative mechanisms
If an approved successor to the EU SCCs or UK Addendum becomes available, it will apply as required by law. If Odella adopts another valid transfer mechanism, including an adequacy decision or certification recognized by the relevant authority, that mechanism may apply instead. The Standard Contractual Clauses prevail over inconsistent terms of this DPA for a restricted transfer.
Changelog
- 2026-07-01: Initial release, including global transfer, Subprocessor, de-identification, government-request, and U.S. state privacy terms.