Last Updated: August 1, 2026
This Addendum governs Customer's use of the artificial intelligence features of the Orgo platform ("AI Features"). It supplements the Organization Terms of Service and the Data Processing Agreement ("DPA").
Order of precedence. Where this Addendum conflicts with the DPA in respect of Personal Data, the DPA prevails. Where it conflicts with the Organization Terms of Service on any other matter, this Addendum prevails for the AI Features only.
| Feature | What it does | Availability |
|---|---|---|
| Ask Orgo | Translates a question written in plain language into a query against the Customer's own data | Available to administrators |
| List suggestions | Proposes member list criteria from a plain-language description | Available to administrators |
| Support assistant | Answers questions about configuring and using Orgo, drawing on Orgo's published product documentation | Available to administrators through in-product chat |
| MCP server | Lets Customer connect an AI assistant of its own choosing to Orgo's API, so that the assistant can read and — where the token permits — write Customer's records | Available to administrators who create an access token; no access exists until one is created |
These four are not alike, and this Addendum does not treat them as if they were. Ask Orgo and list suggestions send a question and the shape of the database to Orgo's model provider, and nothing more (Section 2). The support assistant sits outside the Customer's workspace entirely (Section 2a). The MCP server is the opposite of both: real member records leave Orgo, to an assistant Orgo has no relationship with (Section 2b). Read Section 2b before enabling it.
Orgo does not offer AI-assisted moderation of discussions, and no AI Feature of Orgo's own processes member-written content. If such a capability is introduced, Section 8 applies.
This section is the substance of this Addendum. It describes the architecture, not an intention.
Transmitted to the model provider:
Not transmitted, under any circumstance, by these features:
The query generated from the administrator's question is compiled and executed inside Orgo's own infrastructure in AWS Frankfurt (eu-central-1). The results are returned to the administrator from that infrastructure and are never sent to the model provider.
Two routes therefore exist by which Customer Personal Data can reach the model provider, both at the administrator's own choice. A free-text question is written by a human and could contain a personal identifier if the administrator types one. An attached image is more direct still: a screenshot of an existing report may show member data on its face. That is why the model provider is listed as a Subprocessor in Annex 3, and why this Addendum exists rather than a statement that no personal data is involved.
An administrator who does not wish member data to reach the model provider should not attach images containing it. Orgo cannot inspect the content of an attached image before it is transmitted.
The support assistant is addressed separately because what reaches it differs from the other AI Features.
Transmitted to the assistant:
Not transmitted, under any circumstance:
The assistant answers from Orgo's published product documentation. It has no connection to any Customer workspace, cannot query Customer data, and performs no analysis on it. Its scope is how to configure and use Orgo, not what a Customer's data contains.
The administrator's name, email address and organisation name are Personal Data for which Orgo acts as Controller, as business contact details of the person requesting support — not as Processor on the Customer's behalf. Where an administrator chooses to include Customer Personal Data in the text of a support request, Orgo processes it as Processor under the DPA.
An administrator may ask for a human at any time, and is never required to interact with the assistant to reach support. Response targets, severity levels and escalation are set out in the Organization Terms of Service, Section 6.4.
The provider of the support assistant is listed in Annex 3 — Subprocessors.
The MCP server is an interface, not a model. Orgo supplies no artificial intelligence here at all: it exposes its API over the Model Context Protocol so that an AI assistant chosen by Customer — Claude, ChatGPT, or any other MCP-compatible client — can call that API on Customer's behalf.
Sections 2 and 2a describe features in which member records never leave Orgo. This one is different, and Customer must understand the difference before enabling it. An assistant connected through the MCP server reads Customer's actual records — members, events, payments, and the other areas the token covers — and, where the token grants write access, creates and modifies them. Those records leave Orgo's infrastructure and reach the assistant Customer selected.
That is the purpose of the feature, not a defect in it. But it is a disclosure of Personal Data to a third party, and the remainder of this Section allocates responsibility for it.
The provider of an assistant Customer connects is not Orgo's Subprocessor. Orgo has no contract with it, does not select it, cannot inspect it, and receives nothing from it. Orgo's role is to answer an authenticated API call from a token Customer's own administrator created.
Accordingly:
Customer shall:
Where Customer's workspace contains special categories of data under Article 9 GDPR — political opinions or religious beliefs, which are processed by design in some organisations — a read-scoped token exposes them to the assistant. This is not prohibited, but it is a decision for Customer to take deliberately and to record in its own documentation. Where the workspace contains children's data, Annex 5 to the DPA applies, and Customer should consider Section 7 (administrator access and safeguarding) and Section 8 (data minimisation) of that Annex before granting any token access to it.
So that Customer can assess this feature rather than assume a capability that is not in place:
These limitations are stated expressly so that Customer can assess them rather than assume a capability that is not in place.
Ask Orgo and list suggestions are delivered using models provided by Anthropic PBC, San Francisco, United States. The support assistant is delivered by the provider identified in Annex 3.
This Section does not apply to the MCP server, for which Customer selects the assistant and no model provider is engaged by Orgo. See Section 2b(b).
Orgo does not use Customer Input or Output to train or fine-tune any model, whether its own or a third party's, and does not permit its model provider to do so.
This is not a matter of configuration alone: for Ask Orgo and list suggestions, no member record is transmitted in the first place (Section 2), and what is transmitted is excluded from training under the model provider's commercial terms.
Orgo cannot make this commitment on behalf of an assistant Customer connects through the MCP server. Whether that provider trains on data it receives is a matter between Customer and that provider — see Section 2b(d).
AI Features are probabilistic. A generated query may misinterpret a question.
Customer shall not use the AI Features to:
In relation to the MCP server, Customer shall additionally not:
Orgo may suspend access to the AI Features, without suspending the rest of the Services, where use breaches this Section and is not remedied after notice — or immediately, where continued use presents a material security or legal risk. In the case of the MCP server, suspension may take the form of revoking a specific token rather than disabling the feature for the whole organisation.
Orgo's liability arising from the AI Features is subject to the limitations in the Organization Terms of Service. Nothing in this Addendum limits liability that cannot be limited under applicable law, including liability under Article 82 GDPR.
This Addendum applies for as long as Customer has access to the AI Features. Sections 4, 5 and 10 survive termination.
S.C. ORGO INFORMATICS SRL Str. Gheorghe Grigore Cantacuzino nr 14, etaj PARTER, ap 1, Ploiești, județul Prahova, Romania J29/2796/2019 · CIF RO41650396
Related documents: Organization Terms of Service · Data Processing Agreement · Annex 3 — Subprocessors · Trust & Security