Saltar al contenido
OSOKORO

Este documento está disponible únicamente en inglés. Esa es la versión que rige.

Data processing addendum

How we handle data on your behalf.

Effective August 6, 2026. Between Temp and Major Inc., 604 West 60th Street, Chicago, IL 60621, United States, and the customer.

This addendum forms part of the terms of service and applies automatically whenever Osokoro processes personal data on a customer’s behalf. It is written to sit alongside the privacy policy, which covers the data we hold as a controller in our own right.

1. Definitions

Applicable data protection law means the privacy and data-protection laws applying to the processing covered here, including where applicable the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended, and other applicable US state privacy laws.

Customer personal datameans personal information in customer data that we process on the customer’s behalf — waitlist contacts, team members, users, prospects, subscribers and other individuals.

Controller and processor carry their meanings under applicable law, including the equivalent business, service provider and contractor roles under US state law.

Security incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to customer personal data. It does not include unsuccessful attempts that compromise nothing — scans, pings, blocked logins, denial-of-service attempts, or attacks stopped by security controls.

Subprocessormeans a third party we appoint to process customer personal data on the customer’s behalf. The current list is in Annex III.

2. Roles of the parties

The customer is the controller of customer personal data. Temp and Major Inc. is the processor.

The customer decides the purposes of the processing, what is collected, which questions are asked, which communications are sent, the lawful basis, the retention period they require, and how exported or integrated information is used.

We process customer personal data only to provide, secure, support and improve the service, in line with the customer’s documented instructions and applicable law.

For account, billing, security, support and direct business-relationship information, Temp and Major Inc. acts as an independent controller. That processing is described in the privacy policy.

3. Instructions

The terms of service, the customer’s use of the product and their lawful configurations together constitute documented processing instructions. We process customer personal data only to provide the service, as configured or instructed, to secure and maintain the service, to prevent abuse, to provide support, to comply with law, or as otherwise agreed in writing.

If we reasonably believe an instruction breaks applicable data protection law we may suspend the affected processing and notify the customer, unless notifying is itself prohibited. A customer may not instruct us to perform unlawful processing.

4. Customer obligations

The customer represents and warrants that they:

  • have authority to provide the personal data to us
  • have given every notice their own law requires
  • have established an appropriate lawful basis
  • will not collect information unnecessary for their disclosed purpose
  • will respond to individual privacy requests
  • will protect exports and connected systems
  • have obtained the marketing and email permissions their sending requires
  • will not use the service to collect prohibited or unlawfully obtained information

Deciding whether Osokoro is appropriate for a particular legal or regulatory obligation is the customer’s call, not ours.

5. Confidentiality

People authorised to process customer personal data are bound by confidentiality obligations, get access only where reasonably necessary, are told what they are responsible for protecting, and process customer personal data only as their duties require.

6. Security measures

We maintain reasonable and appropriate administrative, technical and organisational measures designed to protect customer personal data. The specific measures in force are listed in Annex II. They may change as technology, threats and the product change, provided overall protection is not materially reduced during a paid term.

The customer is responsible for their account credentials, who they add to their team, which services they connect, where their webhooks point, how they handle API keys, what they do with exports, and the security of their own devices and systems.

7. Security incidents

We notify the affected customer without undue delay after confirming a security incident affecting their customer personal data. The notice includes, as far as it is known at the time: the nature of the incident, the categories of information affected, the known or estimated scope, likely consequences, what we did to contain it, remediation status, and a contact for follow-up.

A notice is not an admission of fault. Whether notice to individuals or regulators is legally required is the customer’s determination to make; we will give reasonable cooperation, taking into account the nature of the processing and what is available to us.

8. Subprocessors

The customer gives general authorisation for us to use the subprocessors necessary to provide the service. The current list is Annex III below, and it is generated from the same source as the list in the privacy policy, so the two cannot diverge.

Each subprocessor is bound by written terms, gets access only to what is reasonably necessary, and we remain responsible for their performance to the extent applicable law requires. Where the law requires notice of a new subprocessor we will give reasonable advance notice through the product, by email, or by updating this page.

A customer may object to a new subprocessor on reasonable data-protection grounds. We will try in good faith to resolve the concern; if there is no reasonable resolution, the customer may stop using the affected feature or terminate the affected service, subject to the terms of service.

9. Individual rights requests

Taking into account the nature of the processing, we give reasonable assistance so a customer can respond to requests for access, correction, deletion, restriction, portability, objection, withdrawal of consent, opt-out and other applicable rights.

If a request reaches us directly we may refer the individual to the customer, notify the customer, confirm the request relates to that customer, and act only as the customer instructs or the law requires. Responding to the individual remains the customer’s responsibility.

10. Regulatory assistance

Taking into account the nature of the processing and the information available to us, we give reasonable assistance with the customer’s obligations around security, incident notification, data-protection impact assessments, prior consultation with regulators, records of processing, and demonstrating compliance. Assistance requiring substantial work beyond ordinary product functionality may be subject to reasonable fees agreed in advance.

11. Deletion and return

During a subscription the customer can export or delete supported customer personal data using the product’s own features. After termination, or on a valid deletion instruction, we delete or return customer personal data within a commercially reasonable period — unless the law requires retention, the information is needed for fraud, security, billing, tax or dispute records, it remains temporarily in backup rotation, or the customer has not completed the cancellation steps their subscription requires.

Suppression information is the deliberate exception. An address that hard-bounced or complained stays on the suppression list, because forgetting it is how somebody who asked never to be emailed gets emailed again. If a customer deletes an entire organisation, so that no further mail can be sent for it, the organisation’s suppression entries go with it. Anything retained under an exception stays protected and is not used for anything else.

12. Audits

On reasonable written request we make available the information reasonably necessary to demonstrate compliance with this addendum: security documentation, relevant policies, control descriptions, test summaries and subprocessor information.

If that is insufficient and applicable law requires an audit, an audit may be requested no more than once in twelve months — unless a regulator requires it or one follows a security incident — on reasonable notice, under confidentiality obligations, by an independent qualified auditor, without access to another customer’s data, without access to secrets or vulnerability details whose disclosure would itself create risk, and without unreasonable interference with operations. The customer pays the cost unless the audit finds a material breach by us.

13. International transfers

We and our subprocessors process customer personal data in the United States and other countries. Where a transfer from the EEA, the United Kingdom or Switzerland needs a transfer mechanism, the parties will cooperate to put an appropriate one in place — Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, a recognised certification, or another legally valid mechanism.

Until a required mechanism is in place, do not submit regulated data if the transfer would be unlawful. If you need executed Standard Contractual Clauses or a transfer addendum, contact hello@osokoro.com before submitting the affected information.

14. California and other US state requirements

Where California privacy law applies, we act as a service provider or contractor. We do not sell customer personal data, do not share it for cross-context behavioural advertising, do not retain, use or disclose it outside the business purposes the customer specified, do not use it for our own marketing, do not combine it with personal information from another source except where the law permits, and do not use it outside the direct business relationship with the customer except where the law permits.

We may use aggregated or de-identified information where the law permits, taking reasonable measures to prevent re-identification and making no attempt to re-identify it. The same restrictions apply to comparable obligations under other US state privacy laws. If we determine we can no longer meet an applicable obligation, we will say so as the law requires.

15. Government requests

If we receive a legally binding government request for customer personal data we will, where the law permits, review it, seek to narrow an overbroad request, notify the customer before disclosing, disclose only what is legally required, and record what we did. We do not give governments direct or unrestricted access to customer personal data.

16. Sensitive information

Unless we have agreed otherwise in writing, do not use Osokoro to collect or process government identification numbers, financial account credentials, payment card numbers, authentication passwords, precise geolocation, medical records or health diagnoses, biometric or genetic information, information revealing sexual activity, information about children, criminal history, highly sensitive employment information, or special-category information under European data protection law.

Osokoro is a waitlist and validation product; it collects an email address and the answers to questions a founder wrote. If you intend to process regulated sensitive information, get written approval first and complete whatever additional safeguards that requires.

17. Liability, precedence and changes

Liability under this addendum is subject to the exclusions and limits in the terms of service, except where applicable law does not allow that. Nothing here limits the rights of individuals or regulators where those rights cannot legally be limited.

Where there is a conflict about the processing of customer personal data, the order is: executed Standard Contractual Clauses or mandatory transfer terms; this addendum; a separately signed agreement; the terms of service; then other documentation. Mandatory provisions of applicable law control where a contract cannot change them.

We may update this addendum to reflect changes in law, in the product, or in our subprocessors. A change will not materially reduce the protection of customer personal data during an active paid term without reasonable notice, unless the law requires it. This addendum stays in effect while we process customer personal data, and the obligations on confidentiality, retained information, security incidents, audits, transfers and deletion survive for as long as any of that data remains in our possession.

Annex I — the processing

Subject matter, duration and nature

A hosted waitlist, pre-launch validation, referral, analytics, email, API, webhook and custom-domain platform, for as long as the customer uses Osokoro plus any limited retention period afterwards.

Processing may include collection, organisation, storage, retrieval, display, analysis, export, transmission, email delivery, referral tracking, verification, suppression, deletion and security monitoring — continuously, or whenever the customer and their contacts initiate it.

Data subjects

  • customer account users and team members
  • waitlist contacts, prospects and subscribers
  • referral participants
  • individuals communicating with the customer through the product

Categories of personal data

  • names and email addresses
  • organisation information
  • answers to the customer's own questions
  • referral codes and referral relationships
  • signup dates and verification status
  • UTM, source and referrer information
  • user-agent, network and security information
  • email delivery, unsubscribe and suppression information
  • customer content, integration and webhook information

Sensitive data is not intended to be processed, and section 16 says so. Anything beyond this list is there because the customer chose to collect it.

Annex II — security measures

What is actually in place

Each of these is a control this codebase implements rather than an aspiration, and a test asserts as much, so a control cannot be removed without this page changing with it.

  • HTTPS everywhere, with HSTS and a content security policy
  • authentication and session controls
  • role-based access within an organisation
  • row-level security in the database, so a query cannot cross a tenant boundary
  • least-privilege database grants, verified in CI
  • API keys stored hashed, never in plaintext
  • webhook signature verification on every inbound provider callback
  • outbound URL validation against server-side request forgery
  • rate limiting and abuse detection on public endpoints
  • structured logging that redacts secrets, tokens and personal data before it is written
  • error monitoring that carries technical context, not message content
  • automated backups through the database provider
  • dependency auditing and secret scanning on every change
  • automated tests and migration validation before anything reaches production
  • documented incident investigation and access removal

Annex III — subprocessors

SubprocessorFunctionTypical data
SupabaseDatabase and authentication infrastructureAccount data, Customer Data, authentication records
VercelApplication hosting, deployment, routing and custom domainsRequest data, hosted content, domain information
StripePayments and subscriptionsAccount and billing identifiers, transaction status
Amazon Web Services SESEmail delivery and email-event processingRecipient addresses, message content and delivery events
ResendEmail delivery where configuredRecipient addresses, message content and delivery events
SentryError and incident monitoringError context and limited technical metadata

Contact

Temp and Major Inc., operator of Osokoro, 604 West 60th Street, Chicago, IL 60621, United States. Privacy and data-protection questions, including requests for Standard Contractual Clauses: hello@osokoro.com.