Data Processing Agreement (DPA)
Baseline data processing terms for business customers that need Orbit to process personal data on their behalf.
001 / Roles
For customer content processed under an enterprise, team, or business account, the customer is generally controller and Orbit is processor unless otherwise agreed.
002 / Instructions
Orbit processes customer personal data according to documented instructions, the agreement, product configuration, and applicable law.
003 / Processing Details
Processing may include storage, retrieval, transmission, analysis, generation, logging, support, security monitoring, and deletion of customer content and account data.
004 / Confidentiality
Personnel authorized to process personal data are subject to confidentiality obligations.
005 / Security
Orbit applies technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure.
006 / Subprocessors
Orbit may use subprocessors for hosting, AI infrastructure, support, payments, security, analytics, and operations. Subprocessors are required to provide appropriate safeguards.
007 / Assistance
Orbit will provide reasonable assistance for data subject requests, security obligations, DPIAs, and regulator inquiries where required by GDPR.
008 / Incident Notice
Orbit will notify affected business customers of confirmed personal data breaches without undue delay as required by law.
009 / Deletion and Return
At termination, Orbit will delete or return personal data according to product controls, agreement terms, legal requirements, and backup cycles.
010 / Enterprise Terms
A signed DPA or order form controls if it conflicts with this public DPA summary.