Last Updated: February 14, 2023
This Data Processing Addendum, including all schedules and exhibits attached hereto (“ DPA ”) is entered into between the company accessing or using Olo’s products or services (“ Company ”) and Olo Inc. (“ Processor ”) in connection with Processor’s provision of services to Company under any existing, written, and currently valid agreements (collectively, “ Agreement ”). It applies where Processor’s Processing of Personal Data on behalf of Company is subject to Applicable Data Protection Law. Notwithstanding the foregoing, this DPA does not apply to any Personal Data processed by Processor in connection with Borderless Olo Pay, with respect to which Processor acts as a Controller (as defined below) and with respect to which the parties acknowledge and agree that they are independent Controllers. This DPA is hereby incorporated by reference into the Agreement.
We reserve the right to modify this DPA at any time. If we make material changes to this DPA, we will notify you by updating the date of this DPA. The current version of this DPA will always be posted at this page. All capitalized terms not otherwise defined in this DPA will have the meaning given to them in the Agreement. In the event of any inconsistency or conflict between this DPA and the Agreement, this DPA will govern. This DPA will survive termination of the Agreement. Company and Processor agree as follows:
Processor will Process Personal Data on Company’s behalf, as described in more detail in Schedule 1 . As between Company and Processor, Company will be the Controller and Processor will be the Processor. Processor is fully responsible for any authorized or unauthorized Processing of Personal Data. Processor agrees to:
Company will inform Processor of any Data Subject request with which the parties must comply including, but not limited to, requests to access, update, correct, delete, or transfer Personal Data, restrict or stop certain Processing, or obtain additional details about how Personal Data is Processed. Company will provide the information necessary for Processor to comply with such requests, and Processor will cooperate, and follow any instructions Company issues, in responding to such requests in a timely and lawful manner. Processor will provide confirmation and supporting documentation that verifies its compliance with this section, upon request.
If Processor wishes to subcontract any Processing of Personal Data to a third party, Processor shall notify Company at least ten (10) business days prior to engaging a subprocessor. Company shall have the opportunity to object to the use of a subprocessor to the extent such opportunity is required by Applicable Data Protection Law. If the objection cannot be resolved, either Company or Processor may terminate Processor’s services and the associated Agreement.
Processor will implement appropriate administrative, technical, and organizational safeguards to ensure the confidentiality, integrity, and availability of Personal Data and prevent any unauthorized or unlawful Processing of such data. The safeguards will be appropriate to the nature of the Personal Data, meet or exceed prevailing industry standards, and comply with Applicable Data Protection Law.
Upon Company’s request, or immediately upon termination of the Agreement, Processor will cease all Processing of Personal Data and, at Company’s direction, either (a) return such data to Company or (b) destroy such data and certify such destruction to Company in writing. Processor is permitted to retain Personal Data where it has a legal requirement to do so.
The parties agree that Company’s subsidiaries and affiliates are intended third-party beneficiaries of this DPA.
If Processor determines that it can no longer meet its obligations under this DPA, it will promptly notify Company. Processor will cooperate with Company’s reasonable requests regarding any unauthorized Processing of Personal Data.
The Processing is in relation to Processor’s provision of services under the Agreement.
The Processing will begin after the Effective Date and will end upon expiration or termination of the Agreement.
The nature and purposes of Processing include processing and fulfilling online order and delivery transactions; verifying customer information; processing payments; creating and maintaining guest profiles; providing software to enable Company to manage consumer marketing campaigns; and conducting analytics.
Contact information; location information; and transaction information.
Processor will retain the Personal Data until the date that is ninety (90) days following termination of the Agreement, unless otherwise agreed to by the parties.
The technical and organizational measures implemented by the Processor (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the Processing, and the risks for the rights and freedoms of natural persons are: (a) secure business facilities, data centers, servers, and back-up systems and disaster recovery; (b) network, device application, database and platform security; (c) secure transmission, storage and disposal; (d) encryption of Personal Data placed on any electronic notebook, portable hard drive or removable electronic media with information storage capability, such as compact discs, USB drives, flash drives, tapes; (e) encryption of Personal Data in transit over public networks; (f) segregating Personal Data from information of other clients of Olo; and (g) personnel security and integrity including, but not limited to, background checks consistent with applicable law.
For transfers to (sub)processors, the specific technical and organization measures to be taken by the (sub)processor to be able to provide assistance to the controller and, for transfers from a processor to a subprocessor, to the data exporter, are described in the DPA.
The specific technical and organizational measures Processor will take to assist Company in fulfilling its obligations to respond to Data Subjects’ requests to exercise their rights under Applicable Data Protection Law are described in the DPA.