← All legal documents

Data Processing Agreement

Ormy · Version 1.2 · Effective 16 September 2026

Changed in 1.2: Annex I(D) and Annex III described AI conversation, which the app no longer has.

Read this first — most people do not need this document

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between:

Note on the contracting entity. The consumer Ormy app is sold on the App Store by Kyle Ormesher, a sole trader established in the Isle of Man. Business agreements are entered into by Turbolt LLC, which is the entity named below and in the accompanying Master Services Agreement. Both are operated by the same person, and the same technical and organisational measures apply.

(1) Turbolt LLC, a limited liability company registered in the State of Wyoming, United States, trading as Ormy, of [REGISTERED ADDRESS] ("Processor", "we", "us"); and

(2) the organisation identified in the Order Form or Master Services Agreement that it accompanies ("Controller", "you").

This DPA forms part of, and is subject to, the Master Services Agreement or other written agreement between the parties (the "Agreement"). Where this DPA conflicts with the Agreement on a data protection matter, this DPA prevails.

2. Definitions

"Data Protection Law" means all law applicable to the processing of Personal Data under this DPA, including the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 (the EU GDPR) and its national implementing laws, the Data Protection (Application of GDPR) Order 2018 (Isle of Man), and any successor to any of them.

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Data" and "Supervisory Authority" have the meanings given in Data Protection Law.

"Customer Personal Data" means Personal Data that we process on your behalf under the Agreement, as described in Annex I.

"Sub-processor" means any third party engaged by us to process Customer Personal Data.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner.

3. Roles of the parties

3.1 In respect of Customer Personal Data, you are the Controller and we are the Processor.

3.2 You warrant that you have a lawful basis for the Processing you instruct, that you have given Data Subjects all required transparency information, and that where the Processing involves Special Category Data you have a valid condition under Article 9 for it.

3.3 We act as an independent Controller only in respect of data we process for our own administrative purposes — billing your organisation, maintaining our business records, and securing our platform. That processing is governed by our Privacy Policy and not by this DPA.

4. Our obligations as Processor

4.1 Instructions

We will process Customer Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law to which we are subject — in which case we will inform you of that legal requirement before processing, unless the law forbids us from doing so on important grounds of public interest. The Agreement, this DPA and your use of the configuration options within Ormy together constitute your complete documented instructions.

We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law. We may suspend the affected Processing until the instruction is amended or confirmed.

4.2 Confidentiality

We ensure that every person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality, is trained in their obligations, and has access only to what their role requires.

4.3 Security

We implement and maintain the technical and organisational measures set out in Annex II, which are appropriate to the risk, taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing. We may update those measures provided the level of protection is not reduced.

4.4 Sub-processors

(a) You give general written authorisation for us to engage Sub-processors. The Sub-processors authorised at the date of this DPA are listed in Annex III and maintained at our sub-processor page.

(b) We will give you at least 30 days' written notice before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Agreement without penalty and receive a pro-rata refund of prepaid fees for the unused term.

(c) We impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA. We remain fully liable to you for each Sub-processor's performance of its obligations.

4.5 Assistance with Data Subject rights

Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR.

Where a Data Subject contacts us directly about Customer Personal Data, we will not respond substantively but will refer them to you and notify you without undue delay, unless you have instructed us otherwise.

Ormy provides self-service deletion within the app, which allows a Data Subject to erase their own data immediately without needing either party to act.

4.6 Assistance with your wider obligations

Taking into account the nature of the Processing and the information available to us, we will assist you in complying with your obligations under Articles 32 to 36 of the GDPR — security of processing, breach notification to the Supervisory Authority and to Data Subjects, data protection impact assessments, and prior consultation.

4.7 Deletion or return

On termination or expiry of the Agreement, we will, at your choice, delete or return all Customer Personal Data, and delete existing copies, unless law requires us to retain it. Unless you tell us otherwise within 30 days of termination, we will delete it.

Data held in encrypted routine backups is deleted on the ordinary backup expiry cycle, and remains subject to this DPA until it is.

4.8 Records, information and audit

We maintain records of Processing carried out on your behalf, and will make available to you all information necessary to demonstrate compliance with Article 28.

We will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are subject to reasonable conditions: no more than once in any 12-month period unless a Personal Data Breach or a Supervisory Authority requires otherwise; at least 30 days' written notice; during business hours; subject to confidentiality; conducted so as not to disrupt the service or compromise other customers' data; and at your cost save where the audit reveals a material breach by us.

We may satisfy an audit request by providing current third-party certifications, penetration test summaries, or a completed security questionnaire, where these reasonably address your enquiry.

5. Personal Data Breach

5.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

5.2 That notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. Where the full picture is not available at once, we will provide it in phases without further undue delay.

5.3 We will take reasonable steps to contain and remediate the breach, cooperate with you, and not make any public statement identifying you without your prior written consent unless legally compelled.

5.4 Notification under this clause is not an acknowledgement of fault or liability.

6. International transfers

6.1 You authorise us to transfer Customer Personal Data to the countries identified in Annex III, using the safeguards stated there.

6.2 Where a transfer is made from the UK or the EEA to a country without an adequacy decision, the parties agree that:

6.3 We will notify you if we become subject to a law that prevents us from complying with the SCCs, and you may suspend transfers or terminate the affected Processing.

7. Liability

7.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, save that nothing limits either party's liability to a Data Subject or a Supervisory Authority under Data Protection Law.

7.2 Where both parties are found responsible for damage caused by Processing, each bears the share corresponding to its part of the responsibility.

8. Term and general

8.1 This DPA takes effect on the effective date of the Agreement and continues until all Customer Personal Data has been deleted or returned under clause 4.7.

8.2 Clauses 4.7, 5, 7 and this clause 8 survive termination.

8.3 We may update this DPA where necessary to reflect a change in Data Protection Law, a Supervisory Authority decision, or a new approved transfer mechanism, provided the change does not reduce your protection. We will give 30 days' notice of any such change.

8.4 This DPA is governed by the law stated in the Agreement, subject to clause 6.2.

Annex I — Description of the processing

A. Categories of Data Subject

Individuals to whom you provide access to Ormy — typically your employees, staff, clients, service users or the people you support.

B. Categories of Personal Data

C. Special Category Data

Ormy is not designed to collect Special Category Data, and we do not require it. However, a Data Subject may voluntarily enter information revealing health — for example a medication reminder or a therapy appointment.

Where you deploy Ormy in a context where this is likely — a healthcare, social care, disability or mental health setting — you must ensure you have a valid Article 9 condition, and you should say so before signing. Additional restrictions apply, agreed in writing.

D. Nature and purpose of the Processing

Storing reminders and preferences; using AI to word a question in a heads-up, a suggested next step and a suggested reminder, from a reminder’s title; scheduling and delivering push notifications; producing in-app activity summaries and periodic recaps; providing support; maintaining security and service availability.

E. Duration

For the term of the Agreement, plus the deletion period in clause 4.7. Activity log entries are automatically deleted after 90 days.

F. Frequency

Continuous, for the duration of the Agreement.

Annex II — Technical and organisational measures

Access control

Encryption

Availability and resilience

Data minimisation and pseudonymisation

Deletion

Governance

Annex III — Authorised Sub-processors

Sub-processorPurposeLocationSafeguard
ConvexDatabase and server functionsUnited StatesSCCs + UK Addendum
ClerkAuthenticationUnited StatesSCCs + UK Addendum
AnthropicWording heads-up questions, next steps and suggested reminders, from a reminder’s titleUnited StatesSCCs + UK Addendum
ExpoPush delivery and app updatesUnited StatesSCCs + UK Addendum
AppleDistribution, push, paymentsUnited States / globalApple transfer framework
RevenueCatSubscription stateUnited StatesSCCs + UK Addendum

The authoritative, maintained version of this list is at our sub-processor page.

Execution

This DPA is offered pre-signed by us and is accepted by you when you enter into the Agreement, or by countersignature below.

For and on behalf of Turbolt LLC (Processor)

Name: Kyle Ormesher · Title: Founder · Date: 6 August 2026

For and on behalf of the Controller

Name: ______________________ · Title: ______________________

Signature: ______________________ · Date: ______________