Effective date: 10 September 2026
This Data Processing Addendum (DPA) forms part of the Orchard Terms of Service or other agreement between Synthetic Technology Ltd (Orchard, Processor) and the customer using Orchard for property management (Customer, Controller). It applies when Orchard processes Customer Personal Data on the Customer's behalf.
1. Definitions and priority
Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, EU GDPR where applicable, and binding amendments or replacement legislation. Other capitalised terms have the meaning in Data Protection Law or the main agreement. If this DPA conflicts with the main agreement about processing Customer Personal Data, this DPA controls.
2. Roles and compliance
The Customer is controller and Orchard is processor for Customer Personal Data. Each party will comply with obligations applicable to its role. The Customer determines the purposes and means of processing, is responsible for lawful instructions and notices, and confirms that it has a valid legal basis for the data supplied. Orchard is independently a controller for its account, security, billing, legal and business records as described in the Privacy Policy.
3. Documented instructions
Orchard will process Customer Personal Data only on documented Customer instructions, including the main agreement, configuration by authorised users, support requests and lawful written directions. Orchard will notify the Customer if it reasonably believes an instruction infringes Data Protection Law. If law requires processing outside instructions, Orchard will inform the Customer before processing unless prohibited by law.
4. Confidentiality and personnel
Orchard will limit access to personnel and contractors who need it for the Service, support, security or legal compliance. They are bound by confidentiality obligations and receive role-appropriate instructions. Orchard remains responsible for their permitted processing.
5. Security
Taking account of the state of the art, implementation cost, processing context and risks, Orchard will maintain measures designed to protect confidentiality, integrity, availability and resilience. Current measures include HTTPS encryption in transit, provider-encrypted backups, password hashing, secure and inactivity-limited sessions, CSRF protection, role-based access, email verification, file-type and size validation, security headers, audit logging, incident records, restoration arrangements and patch management. Details appear in the Security and Audit Statement. Customer remains responsible for authorised-user access, endpoint security, accurate permissions, exports and avoiding prohibited sensitive data.
6. Sub-processors
The Customer gives general written authorisation for the providers in the Sub-processor Register. Orchard will impose materially equivalent data-protection obligations on a sub-processor as required by law and remains responsible for its processor obligations. Orchard will give at least 30 days' notice of a new sub-processor that materially processes Customer Personal Data, normally by updating the register and notifying the account contact. The Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected Service without penalty for the unused prepaid period.
7. International transfers
Orchard will not make a restricted transfer except on documented instructions and with a lawful transfer mechanism. Where required, the parties incorporate the applicable UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, or the applicable EU Standard Contractual Clauses, completed using the processing details below. Orchard will carry out the required data-protection or transfer-risk assessment and apply supplementary measures where necessary. An applicable adequacy regulation or decision takes priority where available.
8. Individual rights
Taking account of the nature of processing, Orchard will provide reasonable technical and organisational assistance for access, correction, erasure, restriction, portability, objection and automated-decision rights. If Orchard receives a request relating primarily to Customer Personal Data, it will notify the Customer and will not substantively respond except on instruction or as legally required. Self-service correction, structured manager exports and the Orchard privacy-request workflow support this process.
9. Security incidents
Orchard will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide available information about its nature, affected categories and approximate volumes, likely consequences, mitigation and contact point. Information may be supplied in phases. Orchard will take reasonable containment and remediation steps and will not notify a regulator or individual on the Customer's behalf unless instructed or legally required. The Customer is responsible for controller notifications; Orchard will reasonably assist.
10. DPIAs and regulatory consultation
Taking account of available information and the nature of processing, Orchard will reasonably assist with data-protection impact assessments and prior consultation required for Customer use of the Service. Additional work outside ordinary product documentation may be subject to agreed reasonable charges.
11. Information and audits
Orchard will make available information reasonably necessary to demonstrate compliance, including this DPA, the security statement, sub-processor register and relevant audit evidence. No more than once per year, unless required by a regulator or following a material incident, the Customer may request a reasonable audit on at least 30 days' notice. Audits must protect other customers, security and confidentiality, occur during business hours, and avoid unnecessary disruption. Orchard may satisfy a request with recent independent reports where adequate and may charge reasonable costs for a Customer-specific onsite audit.
12. Return and deletion
During the Service, managers may export Customer Data using Orchard's structured export function. On termination or written instruction, Orchard will delete, anonymise or return Customer Personal Data within a commercially reasonable period, normally within 90 days, unless law requires retention. Data retained for law, security, accounting or dispute purposes is isolated and used only for that purpose. Backup copies are not restored to active use except for disaster recovery and are deleted on the scheduled backup cycle.
13. Liability and term
This DPA begins with the main agreement and continues while Orchard processes Customer Personal Data. Liability under this DPA is subject to the lawful exclusions and caps in the main agreement, without limiting rights or liabilities that Data Protection Law does not permit the parties to limit.
Annex 1: Processing details
- Subject matter: cloud property-management, tenant portal, rent recording, maintenance, document, reporting, manager-requested read-only Orchard AI assistance, communication, Orchard ID, support and security services.
- Duration: the Service term plus deletion, backup expiry and any lawful retention period.
- Nature and purpose: collection, recording, organisation, storage, retrieval, consultation, transmission to authorised users, read-only AI-assisted explanation of manager-scoped structured records, reporting, support, security, export, restriction and deletion as instructed.
- Data subjects: Customer personnel, property managers, landlords recorded by a manager, tenants, prospective tenants, contractors and other authorised contacts.
- Personal data: contact and account details; property and tenancy identifiers; lease and rent records; maintenance and communication records; uploaded business documents; Orchard AI questions, answers and compact structured source results; Orchard ID history; consent and disclosure records; support, device, session, IP and audit data.
- Excluded data: identity documents, special-category data, criminal-offence data, health data, bank credentials and full payment-card data are not intended for Customer Data fields unless separately agreed in writing.
- Frequency: continuous or as initiated by authorised users during the Service.
Annex 2: Technical and organisational measures
- unique accounts, password hashing, email verification, least-privilege role checks and session regeneration;
- HTTPS, secure cookie attributes, inactivity expiry, CSRF controls and browser security headers;
- provider-managed physical security, encrypted backups, database access controls and scheduled backup expiry;
- file extension, MIME and size validation; generated storage names; permission-checked downloads; prohibited-data declarations;
- audit events for security and material administrative actions, email-dispatch records and an incident register;
- change control, security patching, restoration procedures, provider review and data export controls; and
- documented incident assessment, containment, notification and post-incident review.