Last updated: 9 October 2026

Data Processing Addendum

This addendum sets out how Orbinly handles the personal data our customers store in the Service. It forms part of the Terms of Service and applies automatically, with no separate signature.

1. Scope and roles

This Data Processing Addendum (“DPA”) is between you (the “Customer”) and Picxer Technologies, LLC (“Orbinly”), and supplements the Terms of Service (the “Agreement”). It applies to the personal data that Orbinly processes on the Customer’s behalf in providing the Service (“Customer Personal Data”), to the extent the GDPR, the UK GDPR, the Swiss FADP or US state privacy laws (together, “Data Protection Laws”) apply to it.

The Customer is the controller of Customer Personal Data, or its processor where it handles that data for its own clients. Orbinly is the Customer’s processor, or sub-processor in the second case, and for US state privacy laws its “service provider”. For information about the Customer’s own account and billing, and for our website, Orbinly is an independent controller under the Privacy Policy and this DPA does not apply.

Terms such as “controller”, “processor”, “personal data”, “data subject” and “personal data breach” have the meaning given in the GDPR. If this DPA conflicts with the Agreement about personal data, this DPA prevails.

2. Processing on your instructions

Orbinly will process Customer Personal Data only on the Customer’s documented instructions, which are the Agreement, this DPA and the Customer’s use and configuration of the Service, unless the law requires otherwise (in which case we will tell the Customer first where the law allows). The details of the processing are in Annex 1. The Customer is responsible for having a lawful basis for the data it puts in the Service, for giving the notices and obtaining the consents that are required, and for the lawfulness of its instructions. We will tell the Customer if we believe an instruction breaches Data Protection Laws.

Orbinly will not sell Customer Personal Data, share it for cross-context behavioural advertising, retain, use or disclose it outside our direct business relationship with the Customer or for any purpose other than providing the Service, or combine it with personal data from other sources, except as the law allows a service provider to. Orbinly confirms that it understands these restrictions.

3. Confidentiality

Orbinly will make sure that the people it authorises to process Customer Personal Data are bound by confidentiality obligations and access it only as needed for their role.

4. Security

Orbinly will keep appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The measures in place at the date of this DPA are in Annex 2. We may update them, but will not reduce the overall level of protection.

5. Sub-processors

The Customer gives Orbinly general authorisation to use sub-processors to provide the Service. The current list, with what each does and where, is on our sub-processors page. Orbinly will require each sub-processor to protect Customer Personal Data by terms that provide protection no less than this DPA in all material respects, and remains responsible for their performance.

We will give at least 30 days’ notice of a new sub-processor, or a change to what an existing one does, by updating that page and emailing workspace owners who have asked to be notified (ask at privacy@orbinly.com). The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the remaining period.

6. Data subject requests and assistance

The Service gives the Customer tools to access, correct, export and delete Customer Personal Data. If a data subject contacts Orbinly about Customer Personal Data, we will refer them to the Customer and will not answer unless the Customer tells us to or the law requires. Taking into account the nature of the processing, Orbinly will give the Customer reasonable help with data subject requests, data protection impact assessments and consultations with regulators, where the Customer cannot do so using the Service. We may charge for assistance that goes beyond what is reasonable.

7. Personal data breaches

Orbinly will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, by email to the workspace owner. The notice will describe, as far as we know them, the nature of the breach, the likely consequences, and the steps taken or proposed, and we will keep the Customer updated and help it meet its own notification duties. A notice is not an admission of fault.

8. International transfers

The Customer authorises Orbinly and its sub-processors to process Customer Personal Data in the United States and in any other country where they operate. Where a transfer of Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision needs a safeguard, the following apply and are incorporated into this DPA:

  • the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914): Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where it is a processor, with the Customer as “data exporter” and Orbinly as “data importer”. The docking clause (Clause 7) is included; the optional redress wording in Clause 11 is not; Clause 9(a) uses general authorisation with the notice period in section 5; Clauses 17 and 18 choose the law and courts of Ireland; and the competent supervisory authority under Clause 13 is the one that applies to the Customer;
  • the UK Addendum to those clauses (version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018) for transfers from the United Kingdom, with the parties, tables and details taken from this DPA and Annexes 1 and 2, and England and Wales as the governing law; and
  • for transfers from Switzerland, the same clauses, with references to the GDPR read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as the competent authority.

If a sub-processor or Orbinly relies on a different valid transfer mechanism, such as an adequacy decision or the EU–US Data Privacy Framework, that mechanism may be used instead for the transfers it covers.

9. Return and deletion

The Customer can export or delete Customer Personal Data using the Service at any time. After the Agreement ends we keep Customer Personal Data for 30 days so the Customer can export it, then delete it from our systems, and from backups as they are replaced, unless the law requires us to keep it. On request we will confirm deletion in writing.

10. Information and audits

On reasonable written request, Orbinly will give the Customer the information needed to show that it complies with this DPA, such as completed security questionnaires and descriptions of its measures. If that is not enough, the Customer (or an independent auditor bound by confidentiality) may audit Orbinly’s compliance once in any 12 months, or sooner after a personal data breach or where a regulator requires it, on at least 30 days’ notice, during business hours, without disrupting our business or other customers’ data, and at the Customer’s cost.

11. US state privacy laws

For the purposes of US state privacy laws, the Customer discloses Customer Personal Data to Orbinly only for the limited and specified business purposes of providing the Service. Orbinly will comply with the obligations that apply to it as a service provider, will give the Customer the same level of privacy protection those laws require, will tell the Customer if it can no longer meet them, and allows the Customer to take reasonable steps to stop and remediate unauthorised use of the data.

12. Liability and term

Each party’s liability under this DPA is subject to the limits and exclusions in the Agreement, to the extent the law allows. This DPA starts when the Customer first uses the Service and continues for as long as Orbinly processes Customer Personal Data. Nothing in this DPA changes the Standard Contractual Clauses, which prevail over it in a conflict, and nothing limits any data subject’s rights under them.

Annex 1: Details of the processing

ItemDetails
Subject matter and purposeProviding the Orbinly platform: hosting the Customer’s workspace and client portals, project, file, message, invoice, proposal and contract features, automations, sign-in, notifications and, if the Customer turns them on, AI features
Nature of processingStorage, retrieval, transmission, display, backup, deletion and the other operations needed to provide the Service
DurationFor as long as the Customer’s account is active, plus the 30-day period in section 9
Data subjectsThe Customer’s clients and client contacts, the Customer’s team members and invitees, and other people whose data the Customer puts in the Service
Types of personal dataNames, email addresses, phone numbers, company and job details, account credentials (as hashes), messages and files the Customer or its clients upload, invoice, payment and contract information, and activity records. The Customer must not upload special categories of data or data the Agreement does not allow
Sensitive dataNone intended. See the Terms of Service on health information
FrequencyContinuous, while the Service is in use
Competent supervisory authorityThe one that applies to the Customer under the GDPR or UK GDPR

Annex 2: Technical and organisational measures

  • Encryption: data is encrypted in transit (TLS) and at rest.
  • Tenant separation: row-level security is enforced on every database table, so a workspace can reach only its own data.
  • Access control: access to production systems is limited to the people who need it.
  • Customer-side controls: role-based access in each workspace, optional required two-factor sign-in and idle timeout for the Customer’s team, and single sign-on on eligible plans.
  • Files: uploaded files are validated and served through signed, expiring links.
  • Logging: an audit log records important actions and sign-ins, and cannot be edited by customers.
  • Application security: a content-security policy and security headers, dependency scanning and automated tests on every change.
  • Incident response: a written incident-response process and breach notification as in section 7.
  • Vendors: sub-processors are listed publicly, and customers are told of changes as in section 5.
  • Deletion: data is deleted as in section 9.

See also our Security page.

Contact and signed copies

To get a countersigned copy of this DPA, to be notified of sub-processor changes, or with any question:

Picxer Technologies, LLC, a Florida limited liability company, operates Orbinly. Email privacy@orbinly.com.