Enterprise data processing addendum
Orange Tree Apps, LLC d/b/a L-Card
Version Date: September 13, 2026
This Enterprise Data Processing Addendum (“DPA”) forms part of the agreement between Orange Tree Apps, LLC, doing business as L-Card, an Indiana limited liability company (“Orange Tree Apps,” “L-Card,” “Company,” “Processor,” “Service Provider,” “Contractor,” “we,” “us,” or “our”), and the customer or organization that has entered into an agreement with Orange Tree Apps for use of the applicable L-Card Services (“Customer,” “Controller,” “Business,” “you,” or “your”).
This DPA governs Orange Tree Apps’ Processing of Customer Personal Data on behalf of Customer in connection with the Services.
This DPA is incorporated into and forms part of the applicable master services agreement, enterprise agreement, order form, statement of work, subscription agreement, online agreement, or other written agreement governing Customer’s use of the Services (collectively, the “Agreement”) where the Agreement references this DPA or where applicable Data Protection Law requires processor or service-provider terms.
If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA will control to the extent of that conflict.
This DPA does not replace the L-Card Privacy Policy, which describes Orange Tree Apps’ general privacy practices when Orange Tree Apps acts as an independent controller or business.
1. DEFINITIONS
For purposes of this DPA:
1.1 “Applicable Data Protection Law”
means any privacy, data-protection, or data-security law applicable to Orange Tree Apps’ Processing of Customer Personal Data under the Agreement, including, where applicable:
- the European Union General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”);
- the United Kingdom GDPR and Data Protection Act 2018 (“UK Data Protection Law”);
- the Swiss Federal Act on Data Protection, where applicable;
- the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”);
- the Indiana Consumer Data Protection Act;
- applicable comprehensive U.S. state privacy laws; and
- other privacy or data-protection laws applicable to the Processing covered by this DPA.
1.2 “Controller”
means the person or entity that determines the purposes and means of Processing Personal Data.
For purposes of U.S. state privacy laws, “Controller” includes a “Business” where that terminology applies.
1.3 “Customer Personal Data”
means Personal Data that Orange Tree Apps Processes on behalf of Customer in providing the Services under the Agreement.
Customer Personal Data does not include Personal Data for which Orange Tree Apps independently determines the purposes and means of Processing, including information processed for Orange Tree Apps’ own account administration, billing, fraud prevention, security, legal compliance, or other independent business purposes described in the L-Card Privacy Policy.
1.4 “Data Subject”
means an identified or identifiable natural person to whom Personal Data relates, including a “consumer” as defined by applicable U.S. state privacy laws.
1.5 “Personal Data”
means information defined as “personal data,” “personal information,” “personally identifiable information,” or a substantially similar term under Applicable Data Protection Law.
1.6 “Personal Data Breach”
means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Orange Tree Apps.
For purposes of U.S. law, this term also includes an applicable “security breach,” “breach of security,” or equivalent concept where required.
1.7 “Process,” “Processing,” or “Processed”
means any operation performed on Personal Data, whether by automated means or otherwise, including collection, recording, organization, storage, adaptation, retrieval, use, transmission, disclosure, restriction, deletion, or destruction.
1.8 “Processor”
means a person or entity that Processes Personal Data on behalf of a Controller.
For purposes of U.S. state privacy laws, “Processor” includes a “Service Provider” or “Contractor” where applicable.
1.9 “Services”
means the L-Card products and services provided to Customer under the Agreement, which may include, depending on the applicable order:
- L-Card Enterprise;
- L-Card Pro;
- digital business cards;
- digital portfolios;
- digital resumes;
- enterprise administration;
- contact management;
- QR-code functionality;
- NFC-enabled services;
- business-card scanning and OCR;
- analytics;
- contact collection;
- integrations;
- Lead Capture;
- Lead Marketing; and
- associated software, applications, support, and related services.
1.10 “Subprocessor”
means a third party engaged by Orange Tree Apps to Process Customer Personal Data on behalf of Customer in connection with the Services.
2. SCOPE AND ROLES
2.1 Customer as Controller
With respect to Customer Personal Data Processed by Orange Tree Apps on Customer’s behalf, Customer is the Controller or Business and Orange Tree Apps is the Processor, Service Provider, or Contractor, as applicable.
2.2 Customer Instructions
Orange Tree Apps will Process Customer Personal Data only:
- on Customer’s documented instructions;
- as necessary to provide, secure, support, and maintain the Services;
- as permitted by the Agreement and this DPA; or
- as required by applicable law.
The Agreement, this DPA, applicable order forms, Customer’s use and configuration of the Services, and other written instructions provided through authorized channels constitute Customer’s documented instructions.
2.3 Unlawful Instructions
If Orange Tree Apps reasonably believes a Customer instruction violates Applicable Data Protection Law, Orange Tree Apps may notify Customer and suspend the affected Processing until the parties resolve the issue.
Orange Tree Apps is not required to comply with an instruction that would require Orange Tree Apps to violate applicable law.
2.4 Independent Processing
This DPA does not apply to Processing for which Orange Tree Apps acts as an independent Controller or Business.
Such Processing is governed by the L-Card Privacy Policy and applicable law.
3. CUSTOMER RESPONSIBILITIES
Customer represents and warrants that:
- it has complied and will comply with Applicable Data Protection Law in connection with Customer Personal Data;
- it has all rights, permissions, notices, consents, and lawful bases necessary to provide or make Customer Personal Data available to Orange Tree Apps for Processing;
- its Processing instructions are lawful;
- its collection and use of Customer Personal Data through the Services complies with Applicable Data Protection Law;
- it will not instruct Orange Tree Apps to Process Personal Data in violation of applicable law;
- it is responsible for determining whether the Services are appropriate for its regulatory and compliance obligations; and
- it will configure and use the Services in a manner consistent with applicable privacy, security, marketing, employment, communications, and industry-specific requirements.
Customer is responsible for responding to Data Subjects concerning Customer’s own privacy practices and for providing legally required notices concerning Customer’s Processing.
4. DETAILS OF PROCESSING
The subject matter, nature, purpose, duration, categories of Data Subjects, and types of Personal Data covered by this DPA are described in Schedule 1.
Orange Tree Apps will Process Customer Personal Data for the duration of the Agreement and for such additional period as reasonably necessary to return, delete, secure, or lawfully retain information in accordance with this DPA and applicable law.
5. PROCESSING LIMITATIONS
Orange Tree Apps will not:
- Process Customer Personal Data for purposes materially unrelated to providing the Services except where permitted by this DPA or applicable law;
- sell Customer Personal Data;
- sell L-Card User or Customer account information;
- use Customer’s private contact lists as Lead Data for unrelated customers;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by Applicable Data Protection Law;
- use Customer Personal Data for unauthorized advertising to unrelated third parties; or
- attempt to re-identify data that is required by contract or law to remain de-identified, except as legally permitted to evaluate the effectiveness of de-identification.
Where the CCPA applies, Orange Tree Apps will not sell or share Customer Personal Data as those terms are defined by the CCPA except to the extent specifically authorized by Customer and permitted by law.
Orange Tree Apps will comply with applicable restrictions governing Service Providers and Contractors.
6. CONFIDENTIALITY
Orange Tree Apps will ensure that persons authorized to Process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive access only as reasonably necessary to perform their responsibilities; and
- are informed of applicable privacy and security responsibilities.
Orange Tree Apps will maintain reasonable access-control procedures designed to prevent unauthorized personnel from accessing Customer Personal Data.
7. INFORMATION SECURITY
Orange Tree Apps will implement and maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Customer Personal Data against:
- unauthorized access;
- unauthorized acquisition;
- unauthorized disclosure;
- loss;
- misuse;
- alteration;
- destruction; and
- other unauthorized Processing.
The general categories of security measures maintained by Orange Tree Apps are described in Schedule 2.
Security measures may be updated from time to time to reflect technological developments, evolving threats, operational changes, and industry practices, provided that Orange Tree Apps will not materially reduce the overall level of protection for Customer Personal Data during an applicable subscription term without reasonable justification.
Customer acknowledges that no information-security system can guarantee absolute security.
8. PERSONAL DATA BREACH
8.1 Notification
Orange Tree Apps will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer Personal Data where notification is required by Applicable Data Protection Law.
8.2 Information Provided
To the extent reasonably available and legally permissible, Orange Tree Apps’ notice will include information such as:
- the nature of the Personal Data Breach;
- categories of affected Customer Personal Data;
- categories or approximate number of affected Data Subjects, where reasonably ascertainable;
- likely consequences of the incident;
- measures taken or proposed to address the incident; and
- contact information for appropriate follow-up.
Information may be provided in phases as investigation progresses.
8.3 Cooperation
Orange Tree Apps will reasonably cooperate with Customer concerning Customer’s legally required investigation, risk assessment, notification, remediation, and regulatory obligations arising from a Personal Data Breach caused by Orange Tree Apps or its Subprocessors.
8.4 No Admission
Notification of a security incident or Personal Data Breach does not constitute an admission of fault, liability, or violation of law by Orange Tree Apps.
8.5 Customer Responsibility
Customer is responsible for fulfilling its own notification obligations to Data Subjects, regulators, customers, employees, or other persons unless applicable law or a separate written agreement expressly places a particular obligation on Orange Tree Apps.
9. DATA SUBJECT REQUESTS
Taking into account the nature of the Processing, Orange Tree Apps will provide reasonable assistance to Customer in responding to legally valid Data Subject requests involving Customer Personal Data.
Such requests may include requests for:
- access;
- correction;
- deletion;
- portability;
- restriction;
- objection;
- withdrawal of consent;
- opt-out rights; and
- other rights provided by Applicable Data Protection Law.
If Orange Tree Apps receives a request directly from a Data Subject concerning Customer Personal Data for which Customer is the Controller, Orange Tree Apps may:
- direct the Data Subject to Customer;
- notify Customer; or
- respond as Customer instructs or as required by law.
Orange Tree Apps will not independently respond on Customer’s behalf regarding Customer-controlled Personal Data unless required by law or authorized by Customer.
10. DATA PROTECTION IMPACT ASSESSMENTS AND REGULATORY CONSULTATION
Taking into account the nature of the Processing and information reasonably available to Orange Tree Apps, Orange Tree Apps will provide reasonable assistance to Customer with legally required:
- data protection impact assessments;
- privacy risk assessments;
- cybersecurity risk assessments;
- prior consultations with supervisory authorities; and
- similar regulatory assessments.
Customer remains responsible for determining whether such an assessment or consultation is legally required.
Additional work beyond reasonable standard assistance may be subject to mutually agreed fees where permitted by law.
11. SUBPROCESSORS
11.1 General Authorization
Customer provides general written authorization for Orange Tree Apps to engage Subprocessors as reasonably necessary to provide the Services.
11.2 Subprocessor Obligations
Orange Tree Apps will require each Subprocessor Processing Customer Personal Data to enter into contractual obligations that provide appropriate privacy and data-protection protections consistent with Orange Tree Apps’ obligations under this DPA, taking into account the nature of the services provided by the Subprocessor.
11.3 Responsibility
Orange Tree Apps remains responsible for the performance of its Subprocessors’ data-protection obligations to the extent required by Applicable Data Protection Law.
11.4 Changes to Subprocessors
Where Applicable Data Protection Law requires notice of new or replacement Subprocessors, Orange Tree Apps will provide a reasonable mechanism for Customer to receive such notice.
Customer may object to a new Subprocessor on reasonable and documented data-protection grounds within the period stated in the applicable notice.
The parties will work in good faith to resolve a valid objection.
If no commercially reasonable alternative is available, either party may terminate the affected portion of the Services in accordance with the Agreement, subject to applicable contractual rights and obligations.
11.5 Subprocessor Information
Orange Tree Apps may maintain a current list of material Subprocessors on its website, through an enterprise trust or security resource, or upon reasonable request.
12. U.S. STATE PRIVACY LAW REQUIREMENTS
Where Orange Tree Apps Processes Customer Personal Data as a Processor, Service Provider, or Contractor under applicable U.S. state privacy law, Orange Tree Apps will:
- Process Personal Data only for the limited and specified purposes set forth in the Agreement, this DPA, and Customer’s documented instructions;
- provide the level of privacy protection required of a Processor, Service Provider, or Contractor under applicable law;
- notify Customer if Orange Tree Apps determines it can no longer meet applicable statutory obligations;
- permit Customer to take reasonable and appropriate steps as legally required to ensure Processing is consistent with Customer’s obligations;
- permit Customer to take reasonable steps to stop and remediate unauthorized use of Customer Personal Data;
- require persons Processing Customer Personal Data to be subject to confidentiality obligations;
- assist Customer with applicable consumer requests as reasonably necessary;
- impose appropriate contractual privacy obligations on applicable Subprocessors;
- not sell Customer Personal Data;
- not retain, use, or disclose Customer Personal Data outside the purposes permitted by the Agreement, this DPA, and applicable law; and
- not combine Customer Personal Data with information received from another person or collected from Orange Tree Apps’ independent interaction with a Data Subject except where permitted under applicable law.
Nothing in this section prohibits Orange Tree Apps from Processing information for legally permitted security, fraud prevention, debugging, internal operational, compliance, or other purposes permitted to Processors or Service Providers.
13. CALIFORNIA CCPA TERMS
To the extent the CCPA applies and Orange Tree Apps receives Personal Information from or on behalf of Customer as a Service Provider or Contractor:
13.1 Limited and Specified Purposes
Customer discloses Personal Information to Orange Tree Apps solely for the specific business purposes of providing, hosting, supporting, securing, maintaining, improving as permitted by law, and administering the Services identified in the Agreement and Schedule 1.
13.2 Prohibited Activities
Orange Tree Apps will not:
- sell the Personal Information;
- share the Personal Information for cross-context behavioral advertising except as lawfully authorized;
- retain, use, or disclose the Personal Information for purposes other than the specified business purposes except as permitted by the CCPA;
- retain, use, or disclose the Personal Information outside the direct business relationship with Customer except as permitted by the CCPA; or
- combine Personal Information received from Customer with Personal Information received from another source except where expressly permitted by the CCPA and applicable regulations.
13.3 CCPA Compliance
Orange Tree Apps will comply with applicable obligations imposed on Service Providers and Contractors under the CCPA and provide the same level of privacy protection required by applicable provisions of the CCPA with respect to Customer Personal Information Processed under this DPA.
13.4 Customer Monitoring
Customer may take reasonable and appropriate steps, consistent with applicable law and the audit provisions of this DPA, to confirm that Orange Tree Apps uses Customer Personal Information consistently with Customer’s obligations under the CCPA.
13.5 Remediation
Customer may notify Orange Tree Apps of suspected unauthorized use of Customer Personal Information. The parties will cooperate in good faith to investigate and remediate substantiated unauthorized Processing.
14. EUROPEAN ECONOMIC AREA AND GDPR
To the extent the GDPR applies to Customer Personal Data, the parties acknowledge and agree that:
- Customer is the Controller and Orange Tree Apps is the Processor unless otherwise stated in the applicable Agreement;
- Orange Tree Apps will Process Personal Data only on documented instructions from Customer unless required otherwise by applicable law;
- Orange Tree Apps will ensure persons authorized to Process Personal Data are subject to confidentiality obligations;
- Orange Tree Apps will implement appropriate technical and organizational security measures;
- Orange Tree Apps will comply with applicable requirements for engagement of Subprocessors;
- Orange Tree Apps will reasonably assist Customer with Data Subject rights;
- Orange Tree Apps will reasonably assist Customer with security, breach notification, impact assessments, and prior consultations where legally required;
- upon termination, Orange Tree Apps will delete or return Personal Data as described in this DPA unless retention is required by law;
- Orange Tree Apps will make available information reasonably necessary to demonstrate compliance with Article 28 of the GDPR; and
- Orange Tree Apps will permit audits consistent with Section 18 of this DPA.
15. UNITED KINGDOM AND SWITZERLAND
Where UK Data Protection Law applies, references in this DPA to the GDPR will be interpreted to include the UK GDPR as applicable.
Where Swiss data-protection law applies, the parties will interpret this DPA to provide substantially equivalent Processor protections as required by applicable Swiss law.
References to supervisory authorities, Data Subjects, international transfers, and similar concepts will be interpreted as necessary under the applicable jurisdiction.
16. INTERNATIONAL DATA TRANSFERS
Customer acknowledges that Orange Tree Apps is headquartered in the United States and that Customer Personal Data may be Processed in the United States and other countries in which Orange Tree Apps or its authorized Subprocessors operate.
Orange Tree Apps will use legally required transfer mechanisms where Applicable Data Protection Law restricts international transfers of Personal Data.
Where required, such mechanisms may include:
- adequacy decisions;
- applicable Standard Contractual Clauses;
- an applicable data-protection framework recognized by law;
- legally recognized certification mechanisms;
- binding corporate rules of an applicable provider;
- contractual safeguards; or
- another lawful transfer mechanism.
16.1 EU Standard Contractual Clauses
If Customer Personal Data protected by the GDPR is transferred from the European Economic Area to Orange Tree Apps in a country not recognized as providing adequate protection and no other lawful transfer mechanism applies, the parties agree that the then-applicable European Commission Standard Contractual Clauses may be incorporated into this DPA by reference.
Unless otherwise agreed in writing:
- Module Two, Controller to Processor, will apply where Customer is Controller and Orange Tree Apps is Processor;
- Module Three may apply where Customer is Processor and Orange Tree Apps is Subprocessor;
- the information required by the applicable annexes will be deemed supplied by this DPA, the Agreement, Schedules 1 and 2, and applicable order documentation; and
- the parties will complete additional information reasonably necessary to give effect to the applicable clauses.
Nothing in this DPA modifies mandatory provisions of legally required Standard Contractual Clauses.
16.2 UK Transfers
Where UK restricted-transfer rules apply, the parties will use the applicable UK International Data Transfer Addendum, International Data Transfer Agreement, or other lawful mechanism as required.
16.3 Transfer Assessments
The parties will reasonably cooperate regarding transfer-impact assessments where legally required.
17. GOVERNMENT AND LAW-ENFORCEMENT REQUESTS
If Orange Tree Apps receives a legally binding demand from a government or law-enforcement authority for Customer Personal Data, Orange Tree Apps will, to the extent legally permitted:
- review the demand for validity;
- disclose only information reasonably required to comply;
- notify Customer before disclosure when legally permitted and commercially reasonable; and
- consider reasonable lawful objections or challenges where appropriate.
Orange Tree Apps is not required to pursue litigation or incur disproportionate expense to challenge a legally valid government demand.
18. AUDITS AND COMPLIANCE INFORMATION
18.1 Compliance Information
Upon reasonable written request, Orange Tree Apps will make available information reasonably necessary to demonstrate compliance with this DPA.
Such information may include, where available and appropriate:
- security documentation;
- policy summaries;
- certification information;
- questionnaires; or
- other relevant materials.
Orange Tree Apps may redact information reasonably necessary to protect security, confidentiality, other customers, trade secrets, or privileged information.
18.2 Audit Rights
Where Applicable Data Protection Law grants Customer an audit right, Customer may request an audit no more than once during any twelve-month period unless:
- required by a competent regulator;
- reasonably necessary following a material Personal Data Breach; or
- additional audits are otherwise required by Applicable Data Protection Law.
Customer must provide reasonable advance written notice.
The parties will attempt to satisfy audit requirements first through existing documentation, certifications, reports, and questionnaires.
If an on-site or additional audit is legally necessary, the audit must:
- occur during normal business hours;
- minimize disruption;
- be subject to appropriate confidentiality obligations;
- avoid access to information belonging to other customers;
- avoid unreasonable security risks; and
- be conducted by Customer or an independent auditor that is not a competitor of Orange Tree Apps.
Customer will bear its audit costs unless Applicable Data Protection Law requires otherwise or the audit identifies a material violation of this DPA attributable to Orange Tree Apps.
19. DATA RETURN AND DELETION
Upon termination or expiration of the Services, and subject to Customer’s applicable account functionality and written instructions, Orange Tree Apps will delete or return Customer Personal Data within a commercially reasonable period unless:
- applicable law requires retention;
- the Agreement authorizes continued retention;
- the information is maintained in secure backup systems and deletion is not immediately practical;
- the information has been lawfully de-identified or aggregated; or
- Orange Tree Apps independently requires certain information for billing, fraud prevention, security, legal compliance, dispute resolution, or enforcement of legal rights.
Customer Personal Data remaining in backups will remain protected under this DPA until deleted in accordance with Orange Tree Apps’ normal backup-retention processes.
20. DE-IDENTIFIED AND AGGREGATED DATA
Orange Tree Apps may create aggregated, statistical, anonymous, or de-identified information from Customer Personal Data where permitted by applicable law.
Where information is required by law to remain de-identified, Orange Tree Apps will:
- maintain it in de-identified form;
- take reasonable measures designed to prevent re-identification; and
- not attempt to re-identify the information except where permitted by applicable law, such as to test the effectiveness of de-identification measures.
Properly de-identified or aggregated information that no longer constitutes Personal Data under Applicable Data Protection Law is not Customer Personal Data for purposes of this DPA.
21. LEAD CAPTURE AND LEAD MARKETING
Where Customer purchases L-Card Lead Capture or Lead Marketing Services, the parties acknowledge that different data roles may apply to different Processing activities.
21.1 Customer-Provided Campaign Data
To the extent Customer provides Personal Data, suppression lists, campaign instructions, CRM information, contact information, or other Personal Data to Orange Tree Apps for Processing solely on Customer’s behalf, Orange Tree Apps will Process that information as Processor or Service Provider as described in this DPA.
21.2 Lead Data
Lead Data provided through L-Card Lead Capture may originate from licensed data providers, public sources, intent-signal providers, business information, data partners, or other lawful sources.
Whether Orange Tree Apps acts as Controller, Processor, or another legally recognized role with respect to particular Lead Data depends upon the applicable data source, Processing activity, contractual arrangement, and Applicable Data Protection Law.
Nothing in this DPA represents that L-Card User account information or private L-Card contact lists are sold or repurposed as Lead Data.
21.3 Customer Marketing Obligations
Customer remains responsible for determining whether and how it may lawfully use Lead Data or other information for marketing and communications.
Customer is responsible for compliance with applicable:
- email marketing laws;
- telemarketing laws;
- text-messaging laws;
- privacy laws;
- suppression requirements;
- opt-out requests;
- consent requirements;
- advertising laws; and
- industry-specific rules.
22. NO SALE OF L-CARD CUSTOMER DATA
Orange Tree Apps does not sell L-Card User or Customer Personal Data.
Orange Tree Apps does not sell:
- enterprise employee account information;
- L-Card account registration data;
- Customer’s private contact lists;
- contacts collected through Customer’s L-Card accounts;
- Customer billing information;
- private Customer account information; or
- private Customer Personal Data merely because it is stored in the L-Card platform.
L-Card may display an actual User or Customer digital card, portfolio, resume, or similar material as an example or reference when authorized by the applicable User, Customer, or organization or where another appropriate legal right exists.
Such authorized reference use does not constitute a sale of Customer Personal Data.
23. SPECIAL CATEGORIES AND SENSITIVE PERSONAL DATA
Customer will not provide or instruct Orange Tree Apps to Process highly sensitive or specially regulated Personal Data unless:
- the functionality is expressly designed for such Processing;
- the parties have agreed in writing to the Processing where appropriate; and
- Customer has satisfied applicable legal requirements.
Examples may include:
- health information regulated by HIPAA;
- financial account credentials;
- government identification numbers;
- biometric identifiers used for identification;
- precise geolocation;
- information concerning children;
- highly sensitive employment information; or
- other legally protected sensitive data.
Unless Orange Tree Apps has entered into a specific written agreement stating otherwise, the Services are not intended to function as a repository for regulated health information subject to HIPAA.
24. CUSTOMER CONFIGURATION AND ACCESS CONTROL
Customer is responsible for:
- selecting authorized administrators and Users;
- maintaining appropriate permissions;
- promptly disabling accounts for personnel who no longer require access;
- maintaining secure authentication credentials;
- controlling information Users choose to make public on digital cards;
- managing Customer-configured integrations;
- securing exported Customer data;
- maintaining appropriate endpoint security; and
- establishing internal policies concerning use of the Services.
Orange Tree Apps is not responsible for unauthorized Processing resulting from Customer’s failure to appropriately administer its own Users, permissions, credentials, exports, or connected applications, except to the extent caused by Orange Tree Apps’ breach of this DPA.
25. THIRD-PARTY INTEGRATIONS
The Services may permit Customer to enable integrations with third-party applications and platforms.
Where Customer independently directs Customer Personal Data to a third-party integration not acting as Orange Tree Apps’ Subprocessor, that third party’s Processing is governed by Customer’s agreement with that provider.
Orange Tree Apps is not responsible for privacy or security practices of third parties selected and independently authorized by Customer.
26. RECORDS OF PROCESSING
Orange Tree Apps will maintain records relating to Processing activities as required by Applicable Data Protection Law.
Customer will provide information reasonably necessary for Orange Tree Apps to satisfy applicable Processor recordkeeping obligations.
27. COOPERATION WITH REGULATORS
Where legally required and applicable to Orange Tree Apps’ Processing of Customer Personal Data, Orange Tree Apps will reasonably cooperate with competent data-protection authorities.
Customer remains responsible for communications with regulators concerning Customer’s own Processing unless otherwise required by law.
28. LIABILITY
The liability of each party arising from this DPA is subject to the exclusions, limitations, and liability provisions contained in the Agreement unless:
- Applicable Data Protection Law prohibits application of a particular limitation; or
- the parties expressly agree otherwise in a signed written agreement.
Nothing in this DPA expands either party’s liability beyond what is required by applicable law or the Agreement.
29. INDEMNIFICATION
Any indemnification obligations concerning privacy, data protection, Customer Personal Data, or security are governed by the Agreement unless the parties expressly agree otherwise in writing.
This DPA does not independently create unlimited indemnification liability.
30. TERM AND TERMINATION
This DPA becomes effective when:
- Customer and Orange Tree Apps execute an Agreement incorporating this DPA;
- an applicable order form incorporates this DPA by reference;
- Customer accepts an online agreement that expressly incorporates this DPA; or
- the parties otherwise agree in writing that this DPA applies.
This DPA continues for as long as Orange Tree Apps Processes Customer Personal Data on Customer’s behalf.
Obligations that by their nature should continue after termination, including confidentiality, security, deletion, regulatory cooperation, liability, and international-transfer requirements, will survive for as long as applicable Customer Personal Data remains in Orange Tree Apps’ possession or control.
31. CHANGES TO THIS DPA
Orange Tree Apps may update this DPA to:
- reflect changes in Applicable Data Protection Law;
- address regulatory guidance;
- reflect changes to the Services;
- improve data-protection protections;
- address technological developments; or
- update administrative information.
Orange Tree Apps will not materially reduce Customer’s data-protection rights under this DPA during an active contractual term without a legally or operationally reasonable basis.
Where required, material changes will be communicated through reasonable means.
If Customer and Orange Tree Apps have executed a separately negotiated DPA, amendments to that signed DPA will be governed by its terms rather than this website version unless the parties agree otherwise.
32. ORDER OF PRECEDENCE
In the event of a conflict among documents concerning Processing of Customer Personal Data, the following order will generally apply:
- mandatory provisions of Applicable Data Protection Law;
- legally required Standard Contractual Clauses or other mandatory transfer mechanism;
- a separately negotiated and signed DPA between Customer and Orange Tree Apps;
- this DPA;
- the Agreement; and
- the L-Card Privacy Policy.
The Privacy Policy continues to govern Processing for which Orange Tree Apps acts independently as a Controller or Business.
33. GOVERNING LAW
Except where Applicable Data Protection Law or legally required international transfer terms require otherwise, this DPA will be governed by the governing-law provisions of the Agreement.
If the Agreement does not specify governing law, this DPA will be governed by the laws of the State of Indiana, without regard to its conflict-of-law principles.
34. ELECTRONIC INCORPORATION
This DPA may be incorporated into an Agreement electronically.
A reference in an Agreement, order form, subscription, or other binding contract to the Orange Tree Apps / L-Card Data Processing Addendum or to the webpage where this DPA is published will incorporate the then-applicable version as stated in the applicable Agreement.
Electronic acceptance and incorporation will have the same effect as execution of a paper agreement to the extent permitted by applicable law.
35. CONTACT INFORMATION
Questions concerning this DPA, privacy, data protection, or enterprise processing may be directed to:
Orange Tree Apps, LLC
d/b/a L-Card
Attn: Privacy / Data Protection
501 Miles Ridge Road
Madison, Indiana 47250
United States
Email: support@orangetreeapps.com
Telephone: (812) 920-6397
SCHEDULE 1
DETAILS OF PROCESSING
1. Subject Matter
Processing of Customer Personal Data as necessary to provide the L-Card Services purchased or authorized by Customer.
2. Duration
For the duration of the Agreement and any limited post-termination period during which Customer Personal Data is lawfully retained, returned, deleted, or maintained in secure backup systems.
3. Nature of Processing
Processing may include:
- collection;
- receipt;
- hosting;
- storage;
- organization;
- structuring;
- display;
- transmission;
- retrieval;
- consultation;
- use;
- contact management;
- OCR processing;
- analytics;
- sharing at Customer’s direction;
- integration with authorized applications;
- support;
- backup;
- security monitoring;
- export;
- deletion; and
- other Processing necessary to provide the Services.
4. Purposes of Processing
Purposes may include:
- creating and maintaining L-Card accounts;
- providing digital business cards;
- providing digital portfolios and resumes;
- enterprise account administration;
- enabling Users to share professional information;
- enabling QR and NFC functionality;
- contact collection and management;
- business-card scanning and OCR;
- analytics;
- customer support;
- account security;
- providing authorized integrations;
- Lead Capture where applicable;
- Lead Marketing where applicable;
- campaign administration;
- maintaining suppression and opt-out information where applicable;
- troubleshooting;
- maintaining and improving Service reliability;
- protecting against fraud and unauthorized use; and
- performing obligations under the Agreement.
5. Categories of Data Subjects
Depending on Customer’s use of the Services, Data Subjects may include:
- Customer employees;
- Customer contractors;
- Customer agents;
- Customer representatives;
- Customer administrators;
- Customer personnel;
- prospective employees;
- business contacts;
- customers of Customer;
- prospective customers;
- persons who exchange contact information with Customer’s Users;
- persons whose business cards are scanned;
- persons voluntarily submitting contact information;
- Lead Capture prospects, where applicable; and
- other individuals whose Personal Data Customer lawfully submits to or collects through the Services.
6. Categories of Personal Data
Depending on the Services used, Personal Data may include:
- name;
- business email address;
- personal email address where provided;
- telephone number;
- mobile number;
- job title;
- employer;
- organization;
- department;
- business address;
- mailing address;
- profile photograph;
- professional biography;
- education;
- qualifications;
- certifications;
- professional skills;
- social-media links;
- website addresses;
- digital business-card content;
- digital resume content;
- digital portfolio content;
- contact records;
- scanned business-card information;
- notes;
- account identifiers;
- device information;
- IP address;
- login and authentication information;
- application usage information;
- card interaction analytics;
- QR-code interactions;
- engagement information;
- technical logs;
- support information;
- campaign information;
- suppression information;
- Lead Data where applicable; and
- other information submitted by or on behalf of Customer.
7. Sensitive Data
The Services are not generally intended for Processing highly sensitive or specially regulated data unless expressly agreed.
Any such Processing will be subject to Section 23 and applicable written agreements.
8. Processing Frequency
Continuous or intermittent as necessary to provide the Services during the Agreement term.
SCHEDULE 2
TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Orange Tree Apps maintains security measures appropriate to the nature of its Services, the information Processed, and reasonably foreseeable risks.
Depending on the relevant system and Services, measures may include the following categories.
1. Access Control
Measures designed to restrict access to systems and Customer Personal Data to authorized personnel based on legitimate business requirements.
2. Authentication
Authentication mechanisms and account-security controls designed to reduce unauthorized account access.
3. Confidentiality
Confidentiality obligations applicable to personnel and contractors with authorized access to Customer Personal Data.
4. Encryption and Transmission Security
Appropriate technological measures designed to protect Personal Data during transmission and, where appropriate, while stored.
5. Infrastructure Security
Network, cloud, application, and infrastructure protections designed to prevent and detect unauthorized access.
6. Logging and Monitoring
Reasonable logging, monitoring, and diagnostic capabilities designed to identify system issues, security concerns, and unauthorized activity.
7. Vulnerability and Security Management
Processes designed to identify, evaluate, and address relevant vulnerabilities and security risks.
8. Backup and Recovery
Backup, redundancy, recovery, or continuity measures appropriate to applicable systems and Services.
9. Incident Response
Procedures for identifying, investigating, responding to, and documenting suspected security incidents.
10. Personnel Security
Reasonable practices concerning access authorization, confidentiality, security responsibilities, and termination of access.
11. Vendor and Subprocessor Management
Reasonable due diligence and contractual controls applicable to third parties Processing Customer Personal Data on Orange Tree Apps’ behalf.
12. Data Minimization and Retention
Processes designed to limit Processing and retention to information reasonably necessary for legitimate business, contractual, legal, and operational purposes.
13. Secure Development and Maintenance
Reasonable measures designed to incorporate security considerations into software development, deployment, maintenance, and change-management processes.
14. Physical Security
Physical security controls appropriate to facilities and infrastructure under Orange Tree Apps’ direct control.
Cloud and hosting providers may maintain separate physical-security controls for their facilities.
SCHEDULE 3
U.S. STATE PRIVACY LAW SUPPLEMENT
To the extent applicable U.S. state privacy law imposes additional Processor, Service Provider, or Contractor requirements not expressly addressed above, the parties agree that this DPA will be interpreted to include those mandatory requirements.
Orange Tree Apps will:
- Process Customer Personal Data in accordance with Customer’s lawful instructions;
- maintain confidentiality;
- implement reasonable security safeguards;
- assist Customer with applicable consumer rights;
- provide appropriate Subprocessor protections;
- delete or return information as legally required;
- provide information reasonably necessary for Customer to demonstrate compliance;
- not sell Customer Personal Data;
- not use Customer Personal Data for prohibited secondary purposes; and
- provide any additional contractual protections that cannot legally be waived.
If a mandatory statutory requirement conflicts with this DPA, the statutory requirement will control solely to the extent of that conflict.
SCHEDULE 4
INTERNATIONAL DATA TRANSFER SUPPLEMENT
Where an international transfer mechanism is legally required for Customer Personal Data:
- the parties will apply the appropriate legally recognized transfer mechanism;
- this DPA, the Agreement, and Schedules 1 and 2 will supply the processing and security information required by that mechanism to the extent legally permissible;
- mandatory provisions of the transfer mechanism will control over conflicting contractual terms;
- the parties will reasonably cooperate with transfer-impact assessments or similar obligations;
- Orange Tree Apps may use authorized Subprocessors located in other countries subject to legally required safeguards; and
- Customer is responsible for identifying any unusual transfer restrictions associated with Customer’s particular industry, jurisdiction, or categories of Personal Data that are not reasonably apparent from Customer’s ordinary use of the Services.
ORANGE TREE APPS, LLC d/b/a L-CARD
Enterprise Data Processing Addendum
Version Date: September 13, 2026
© 2026 Orange Tree Apps, LLC. All rights reserved.