OrbitAlert
Sign in →

Legal

Data Processing Agreement

Effective date: 28 June 2026 · Governs processing pursuant to GDPR Article 28

How this DPA is accepted. By accepting the Terms of Service, the Customer (acting as Data Controller) enters into this Data Processing Agreement with OrbitAlert (acting as Data Processor) on behalf of itself and its Authorised Users. If you require a countersigned PDF copy, contact legal@orbitalert.net.

1. Background & Incorporation

This Data Processing Agreement ("DPA") forms part of and is incorporated into the OrbitAlert Terms of Service ("Agreement") between OrbitAlert ("Processor"or "OrbitAlert") and the Customer ("Controller"). To the extent of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the subject matter of data processing.

This DPA implements the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR and the Swiss Federal Act on Data Protection ("FADP"). The parties acknowledge that the factual arrangements described herein reflect the roles of Controller and Processor as defined under applicable Data Protection Law.

This DPA replaces and supersedes any prior data processing addenda or arrangements between the parties relating to the same subject matter.

2. Definitions

Capitalised terms not defined herein have the meanings given in the Agreement or GDPR.

TermDefinition
Data Protection LawGDPR, UK GDPR, Swiss FADP, and any successor or implementing legislation applicable to the processing of Customer Personal Data.
Customer Personal DataAny Personal Data that OrbitAlert processes on behalf of the Customer as Processor in connection with the Service.
ControllerThe Customer, who determines the purposes and means of processing Customer Personal Data.
ProcessorOrbitAlert, who processes Customer Personal Data on behalf of the Controller.
Processing / ProcessAny operation performed on Personal Data, as defined in Article 4(2) GDPR.
Sub-ProcessorAny third party (including OrbitAlert Affiliates) engaged by OrbitAlert to process Customer Personal Data.
Security IncidentAny breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
Standard Contractual Clauses (SCCs)Module Two (Controller-to-Processor) of the European Commission Decision 2021/914/EU, as may be amended.
EEAThe European Economic Area.
Supervisory AuthorityThe Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ), or any other competent data protection authority under applicable Data Protection Law.

3. Subject Matter & Duration

Subject matter. OrbitAlert processes Customer Personal Data solely for the purpose of providing the Service as described in the Agreement and this DPA.

Duration. This DPA remains in force for the duration of the Agreement. Termination of the Agreement automatically terminates this DPA, subject to the survival of obligations relating to deletion of data and confidentiality.

Role clarification. The parties acknowledge that, with respect to Service Usage Data (aggregate telemetry, platform performance metrics, anonymised error logs), OrbitAlert acts as an independent Controller. This DPA does not govern such processing. Service Usage Data is described in the Privacy Policy §4.

4. Details of Processing

The processing carried out by OrbitAlert on behalf of the Controller is described in Annex I.

ElementDetail
Nature of processingCollection, storage, transmission, retrieval, deletion — automated processing via API and web interface.
Purpose(s)Authentication and user account management; delivery of satellite pass prediction APIs and webhook notifications; billing and subscription management; customer support; security monitoring.
Categories of personal dataSee Annex I, §A.
Categories of data subjectsCustomer's employees, contractors, and Authorised Users accessing the Service; end-users of Customer's downstream applications (where applicable).
RetentionSee §11 of this DPA and Privacy Policy §8.

5. Controller Obligations

The Controller represents, warrants, and undertakes that:

  • It has a valid legal basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for all processing of Customer Personal Data it instructs OrbitAlert to carry out, and it has complied with all applicable transparency obligations (Articles 13–14 GDPR) with respect to data subjects.
  • Its instructions to OrbitAlert regarding the processing of Customer Personal Data will comply with Data Protection Law. The Controller is solely responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it acquired it.
  • It will not instruct OrbitAlert to process Special Categories of Personal Data (Article 9 GDPR) through the Service unless it has implemented appropriate additional safeguards and has notified OrbitAlert in writing.
  • It has the authority to execute this DPA on behalf of the Controller entity and, where required, its Affiliates whose Customer Personal Data is processed under the Agreement.
  • It will promptly inform OrbitAlert of any changes to its lawful basis for processing that may affect OrbitAlert's obligations under this DPA.

6. Processor Obligations

OrbitAlert shall, in its capacity as Processor, comply with the following obligations, each corresponding to the requirements of Article 28(3) GDPR:

6.1 Processing on instructions only. OrbitAlert shall process Customer Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. In such case, OrbitAlert shall inform the Controller of that legal requirement before processing, unless prohibited by law on grounds of public interest. OrbitAlert shall immediately inform the Controller if, in its opinion, any instruction infringes Data Protection Law.

6.2 Confidentiality. OrbitAlert shall ensure that persons authorised to process Customer Personal Data are subject to binding confidentiality obligations and have received appropriate data protection training. OrbitAlert shall restrict access to Customer Personal Data to personnel who need access to perform the Service.

6.3 Security. OrbitAlert shall implement and maintain the technical and organisational measures described in Annex II to ensure a level of security appropriate to the risk posed by the processing, taking into account the nature, scope, context, and purposes of processing (Article 32 GDPR).

6.4 Sub-processing. OrbitAlert shall comply with the obligations set out in §7 of this DPA with respect to Sub-Processors.

6.5 Data subject rights. OrbitAlert shall assist the Controller in fulfilling its obligations to respond to data subject requests as set out in §9.

6.6 Security assistance. OrbitAlert shall assist the Controller in ensuring compliance with obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation) taking into account the nature of processing and the information available to OrbitAlert.

6.7 Deletion or return. Upon termination or expiry of the Agreement, OrbitAlert shall delete or return Customer Personal Data in accordance with §11.

6.8 Audit cooperation. OrbitAlert shall make available all information necessary to demonstrate compliance with Article 28 GDPR and shall contribute to audits conducted in accordance with §12.

7. Sub-Processors

7.1 General authorisation. The Controller provides general written authorisation for OrbitAlert to engage Sub-Processors to assist in the provision of the Service. OrbitAlert shall enter into a written agreement with each Sub-Processor that imposes data protection obligations equivalent to those set out in this DPA (Article 28(4) GDPR).

7.2 Current Sub-Processors. The Sub-Processors approved as at the Effective Date are listed in Annex III and in the Privacy Policy §6.

7.3 Changes. OrbitAlert shall notify the Controller of any intended addition or replacement of a Sub-Processor by updating Annex III and providing at least 14 calendar days' prior written notice by email or in-app notification. During the notice period, the Controller may object to the new Sub-Processor by providing written notice to OrbitAlert setting out its specific and documented data protection concerns. If the parties cannot resolve the objection within 30 days, either party may terminate the Agreement on 30 days' notice without penalty.

7.4 Liability. OrbitAlert remains fully liable to the Controller for the performance of any Sub-Processor's obligations under this DPA (Article 28(4) GDPR).

8. Technical & Organisational Measures (TOMs)

OrbitAlert implements and maintains the technical and organisational security measures described in Annex II. OrbitAlert may update these measures over time to reflect improvements in security practices, provided that any such update does not materially reduce the overall level of protection afforded to Customer Personal Data.

Customer acknowledges that the TOMs are appropriate to the risks presented by the processing and represent a reasonable and proportionate level of security for the nature of the Customer Personal Data processed through the Service.

9. Data Subject Rights Assistance

OrbitAlert shall assist the Controller in fulfilling its obligations under Chapter III GDPR (rights of data subjects: access, rectification, erasure, restriction, portability, objection) taking into account the nature of the processing and to the extent technically feasible. Specifically:

  • Self-service: Many rights (access to data, export, deletion of account) can be exercised directly by the data subject through the Service dashboard.
  • Controller-assisted requests: For rights that require OrbitAlert's action, the Controller shall submit a request to legal@orbitalert.net. OrbitAlert shall acknowledge within 5 Business Days and complete the action within 30 calendar days.
  • Direct requests: Where data subjects submit requests directly to OrbitAlert, OrbitAlert shall promptly notify the Controller and shall not respond to the data subject without prior authorisation from the Controller, unless required by law.

OrbitAlert may charge a reasonable fee for assistance with requests that are manifestly unfounded or excessive (Article 12(5) GDPR) by reference to its then-current support rates, notified in advance to the Controller.

10. Personal Data Breach Notification

10.1 Processor notification. OrbitAlert shall notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a Security Incident affecting Customer Personal Data. Notification shall be made to the email address registered for the Customer account or to legal@orbitalert.net.

10.2 Content of notification. The notification shall, to the extent information is available, include:

  • Nature of the Security Incident, including categories and approximate number of data subjects and records affected;
  • Name and contact details of the data protection contact at OrbitAlert;
  • Likely consequences of the Security Incident;
  • Measures taken or proposed to address the Security Incident and mitigate its possible adverse effects.

10.3 Staged disclosure. Where all required information is not available at the time of initial notification, OrbitAlert may provide information in phases without undue further delay.

10.4 Controller notification to Supervisory Authority. The Controller is solely responsible for notifying the relevant Supervisory Authority within 72 hours under Article 33 GDPR and for communicating with affected data subjects under Article 34 GDPR. OrbitAlert shall provide reasonable cooperation and assistance with such notifications at the Controller's written request.

10.5 Limitation. Notification by OrbitAlert of a Security Incident does not constitute an admission of fault or liability on the part of OrbitAlert.

11. Return & Deletion of Personal Data

Upon termination or expiry of the Agreement for any reason, OrbitAlert shall, at the Controller's written election made within 30 days of termination:

  • Return: Provide the Controller with an export of Customer Personal Data in machine-readable format (JSON or CSV); or
  • Delete: Securely delete or destroy all Customer Personal Data and all copies thereof, including data held by Sub-Processors, and provide written confirmation within 30 days.

If the Controller makes no election within the 30-day window, OrbitAlert shall delete all Customer Personal Data within a further 30 days and provide written confirmation.

OrbitAlert may retain Customer Personal Data to the extent and for the duration required by applicable law (e.g., tax record retention obligations) or pursuant to aggregate, de-identified Service Usage Data, and shall notify the Controller of any such retention obligation.

For Customers on paid subscription plans, the Customer may export their data via the dashboard during the 30-day grace period following account termination.

12. Audit & Inspection Rights

12.1 Documentation. OrbitAlert shall make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA and any relevant third-party audit reports or certifications ("Audit Documentation").

12.2 Third-party audits. Where the Controller determines that the Audit Documentation is insufficient to demonstrate compliance and cannot address its compliance concerns through documentation review alone, the Controller may commission a third-party auditor (subject to OrbitAlert's reasonable approval of the auditor, which shall not be unreasonably withheld) to conduct an inspection, subject to:

  • At least 60 days' prior written notice to OrbitAlert;
  • Audit conducted during normal business hours with minimum disruption to operations;
  • No more than one audit per 12-month period, unless a Security Incident has occurred;
  • All audit costs borne by the Controller;
  • The auditor executing a confidentiality undertaking acceptable to OrbitAlert before commencing.

12.3 Regulatory audits. Nothing in this §12 limits the rights of a Supervisory Authority to conduct audits or inspections under Data Protection Law.

13. International Transfers

13.1 EEA processing. OrbitAlert shall process Customer Personal Data within the EEA wherever practicable. Where processing necessarily occurs outside the EEA (e.g., through Sub-Processors in the United States or other third countries), OrbitAlert shall ensure an appropriate transfer mechanism is in place as described in §13.2.

13.2 Transfer mechanisms. For transfers of Customer Personal Data to third countries without an adequacy decision under Article 45 GDPR, OrbitAlert relies on:

  • Standard Contractual Clauses (Module Two, Controller-to-Processor) as adopted by European Commission Decision 2021/914/EU, incorporated herein by reference;
  • Adequacy decisions issued by the European Commission under Article 45 GDPR (e.g., EU-US Data Privacy Framework, where applicable); or
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs for transfers from the United Kingdom.

13.3 Transfer impact assessment. OrbitAlert has conducted and maintains a transfer impact assessment (TIA) covering the third-country transfers described in Annex III. The TIA is available to the Controller upon written request.

13.4 Controller transfers. The Controller shall not transfer or instruct OrbitAlert to transfer Customer Personal Data to a third country except as permitted by this DPA and in compliance with Data Protection Law.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Agreement (including §18 — Limitation of Liability). This DPA does not expand either party's liability beyond the caps agreed in the Agreement.

Where a data subject or a Supervisory Authority brings a claim, action or investigation against OrbitAlert for processing carried out on the Controller's behalf, the Controller shall indemnify and hold OrbitAlert harmless from and against all losses, penalties, fines, and costs arising from such claim to the extent attributable to the Controller's failure to comply with its obligations as Controller under Data Protection Law or this DPA.

Each party shall promptly notify the other party of any order, claim, complaint or investigation by a Supervisory Authority or data subject relating to the processing of Customer Personal Data.

15. Governing Law

This DPA shall be governed by the laws of the Hellenic Republic, without reference to its choice-of-law rules. The courts of Athens, Greece shall have exclusive jurisdiction to settle any dispute arising out of or in connection with this DPA.

To the extent the Standard Contractual Clauses apply, the governing law and forum clauses therein shall take precedence over this §15 solely with respect to matters regulated by the SCCs.

Annexes

Annex I — Description of Processing Activities

Pursuant to Article 28(3) GDPR and Clause 1(b) of EU SCCs 2021/914.

A. Categories of Personal Data

CategorySpecific data elementsNecessity
Identity & contactFull name, email address, company name, job titleAccount creation, authentication
Authentication credentialsHashed passwords (managed by Clerk), session tokens, API keys (hashed), OAuth tokensService access control
Billing dataPayment method (tokenised, stored by payment processor), billing address, invoice historySubscription management, tax compliance
Usage & log dataIP addresses, user agent, API request metadata, webhook delivery logs, timestampsService operation, security, abuse prevention
Configuration dataGround station coordinates, satellite watchlist, webhook endpoint URLs, notification preferencesCore service functionality
Support dataCorrespondence content submitted via support channelsCustomer support

B. Categories of Data Subjects

  • The Controller's employees, contractors, and Authorised Users who access the Service;
  • End-users of applications built by the Controller using the OrbitAlert API (their personal data limited to IP address and usage metadata visible in API logs, if at all);
  • The Controller's contacts whose data is submitted via support tickets.

C. Sensitive Data

The Service is not designed to process Special Categories of Personal Data (Article 9 GDPR). The Controller shall not submit such data through the Service without prior written agreement.

D. Frequency & Duration of Processing

Processing is continuous during the term of the Agreement. Data is processed in real-time (API requests, webhook delivery) and in batch (scheduled pass prediction jobs, billing cycles). Retention periods are set out in the Privacy Policy §8.

Annex II — Technical & Organisational Measures

Pursuant to Article 32 GDPR and Clause 1(d) of EU SCCs 2021/914.

Encryption

  • All data in transit encrypted using TLS 1.2 or higher (TLS 1.3 preferred).
  • Data at rest encrypted using AES-256 or equivalent.
  • API keys and webhook secrets stored as salted hashes; plaintext is never stored.
  • Database backups encrypted before transfer to backup storage.

Access Control

  • Role-based access control (RBAC) restricts employee access to Customer Personal Data to the minimum necessary.
  • Multi-factor authentication (MFA) enforced for all personnel with access to production systems.
  • Privileged access management (PAM) controls and logs all administrative access.
  • Access rights reviewed quarterly and revoked upon employee termination.

Infrastructure & Network Security

  • Production systems hosted on infrastructure with SOC 2 Type II certification.
  • Network segmentation between production, staging, and development environments.
  • Automated vulnerability scanning of infrastructure and dependencies.
  • Web application firewall (WAF) and DDoS protection in place.
  • Intrusion detection and anomaly alerting on production API traffic.

Application Security

  • HMAC-SHA256 webhook signature verification enables endpoints to authenticate OrbitAlert payloads.
  • API keys are rate-limited and can be revoked instantly by the Customer.
  • Dependency vulnerability scanning integrated into CI/CD pipeline.
  • Security review incorporated into code review process for changes affecting data processing.
  • Regular penetration testing by internal or contracted third-party security professionals.

Availability & Business Continuity

  • Database backups performed daily with point-in-time recovery capability.
  • Backups stored in geographically separate location from primary data.
  • Recovery Time Objective (RTO): 4 hours; Recovery Point Objective (RPO): 24 hours.
  • Incident response plan documented and tested at least annually.

Organisational Measures

  • Data protection training provided to all personnel handling Customer Personal Data on appointment and annually thereafter.
  • Data Protection Officer (DPO) or equivalent privacy function designated.
  • Data protection impact assessments (DPIAs) conducted for high-risk processing activities.
  • Vendor risk assessments conducted before engaging new Sub-Processors.
  • Internal privacy policies and acceptable use policies maintained and enforced.
  • Pseudonymisation applied to analytics and telemetry data where technically feasible.

Incident Response

  • Security incident response procedure documented and tested at least annually.
  • Dedicated security contact and escalation path for Security Incidents.
  • Post-incident reviews conducted after significant Security Incidents with findings documented.

Annex III — Approved Sub-Processors

Current as of 28 June 2026. Updates notified per §7.3 of this DPA.

Sub-ProcessorFunctionLocationTransfer Mechanism
Clerk, Inc.Identity & authentication management; session tokens, MFA, user recordsUnited StatesEU SCCs (Module 2) / EU-US DPF
Vercel, Inc.Frontend hosting & edge network; CDN delivery of web applicationUnited States (global PoPs)EU SCCs (Module 2) / EU-US DPF
Cloud infrastructure providerAPI server hosting, database, object storage, background worker executionEEA (primary) / United States (DR)Adequacy decision / EU SCCs
Payment processorPayment card processing, subscription billing, invoice generationUnited States / EEAEU SCCs (Module 2) / EU-US DPF
Transactional email providerDelivery of system notification emails, billing receipts, alert summariesUnited StatesEU SCCs (Module 2)
Error tracking providerApplication error logging and performance monitoring (pseudonymised)United StatesEU SCCs (Module 2)

The Controller will be notified of additions or replacements per §7.3 with at least 14 calendar days' notice. The most current Sub-Processor list is maintained in the Privacy Policy §6.

Questions about this DPA?

Email legal@orbitalert.net or visit the Legal Notice page for full company details. To request a countersigned PDF copy of this DPA, contact us at the same address.