New: US import bans on some Canadian products start September 29. See what it means for your orders. Check a product

Data Processing Addendum

Effective October 2, 2026. Last updated October 2, 2026.

This addendum is part of the Terms of Service between Nagi Consulting Group Inc. ("Othermile", "we") and the Customer. It applies when we process personal information on the Customer's behalf ("Customer Personal Information"), mainly order details about the Customer's own customers. Where it conflicts with the Terms on this subject, this addendum applies.

  1. Roles. The Customer controls Customer Personal Information and decides why it is processed. We process it only to provide Othermile and only on the Customer's documented instructions: the Terms, the settings the Customer chooses, and the requests the Customer and its connected services make. We tell the Customer if we believe an instruction breaks privacy law.
  2. The Customer's responsibilities. The Customer gives the notices and obtains the consents the law requires for us to process the information, sends only what the service needs (never customer names, street addresses or payment details), and keeps its users, settings and retention period current.
  3. Information and purpose. Order details the Customer or its connected services send (order numbers, products, destination region and postal code, prices and costs), approver identities and decisions, and agent action details where the Customer uses agent approvals. We use them only to check orders against border rules and the Customer's limits, compare routes, route approvals, keep signed records, send notifications and give support. Names, street addresses, emails and phone numbers in orders sent by connected stores and printers are discarded as they arrive.
  4. Confidentiality. Only people who need access to provide or support the service have it, and they are bound by confidentiality.
  5. Security. We keep safeguards suited to the sensitivity of the information, including encryption in transit, encryption of connection secrets, separation of each customer's data in the database, hashed keys, passkeys for approvals, signed records, backups, access logging and security reviews every month. We may improve these measures over time but will not reduce the overall level of protection.
  6. Subprocessors. The Customer authorizes the providers on our subprocessors page. Each works under a written contract that protects the information at least as well as this addendum. We give 30 days' notice of a new subprocessor by updating that page and emailing account owners. The Customer may object on reasonable privacy grounds; if we cannot resolve the objection, the Customer may end the affected service and receive a refund of fees it prepaid for the remaining period.
  7. Location and transfers. Customer Personal Information is stored in Canada. It is transferred outside Canada only to subprocessors that protect it to a comparable standard, and outside Quebec only after the assessment Quebec law requires.
  8. Breaches. We notify the Customer without undue delay, and within 72 hours after confirming a breach affecting Customer Personal Information, with the information reasonably available, and we cooperate in responding. The Customer decides whether to notify its customers and regulators, unless the law requires us to do so.
  9. Requests and assistance. We pass on requests from individuals about Customer Personal Information and help the Customer answer them. We give reasonable help with privacy impact assessments and regulator questions; unusual effort may be charged at reasonable rates.
  10. Deletion and return. Readable details are deleted at the end of the Customer's retention period. When the agreement ends, the Customer may export its records for 30 days; after that we delete Customer Personal Information within 90 days, except copies in backups, which are overwritten on their normal schedule, and anything the law requires us to keep. Signed records hold only fingerprints (hashes) and are deleted with the workspace.
  11. Information and audits. Once a year, on written request, we provide the information reasonably needed to show we meet this addendum, such as our security documentation and review log. Independent audit reports will be shared when they exist.
  12. Liability. Each party's liability under this addendum is subject to the limits in the Terms of Service.