Legal · DPA

Data Processing Addendum

Last updated · 25 May 2026 · Version 1.0

This page sets out the terms of Orbie’s Data Processing Addendum (“DPA”). It forms part of the Terms of Service when Orbie processes personal data on a customer’s behalf. A countersignable copy is available on request — see “How to execute”.


1. Roles and scope

This DPA applies where Orbie (Orbie Labs, the “Processor”) processes personal data on behalf of a customer (the “Controller”) in providing the Service. Each party will comply with applicable data-protection law, including the EU GDPR, the UK GDPR, the Swiss FADP, and the CCPA/CPRA (under which Orbie acts as a “service provider”). The Controller is responsible for the lawfulness of the personal data it provides and instructs us to process.

2. Processing instructions

We process personal data only on the Controller’s documented instructions — the Terms, this DPA, and the Controller’s configuration and use of the Service — and as required by law (in which case we will inform the Controller unless prohibited). The subject matter, duration, nature, purpose, data categories, and data subjects are described in Annex I. We will inform the Controller if, in our opinion, an instruction infringes data-protection law.

3. Confidentiality

We ensure that personnel authorised to process personal data are bound by confidentiality and are trained on their obligations. Access is limited on a need-to-know, least-privilege basis.

4. Security

We implement and maintain the technical and organisational measures set out in Annex II, appropriate to the risk under Art. 32 GDPR. The Controller is responsible for the secure configuration and use of the Service within its control.

5. Sub-processors

The Controller authorises Orbie to engage the sub-processors listed in Annex III to provide the Service. We impose data-protection obligations on each sub-processor no less protective than this DPA and remain responsible for their performance. We will give at least 30 days’ notice before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds, in which case the parties will work in good faith toward a resolution, and failing that the Controller may terminate the affected part of the Service.

6. Data-subject requests

Taking into account the nature of the processing, we will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests. Where we receive a request directly, we will, unless legally required to act, refer the data subject to the Controller.

7. Personal data breach

We will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller’s personal data, and will provide information reasonably available to assist the Controller’s own notification obligations.

8. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. Where available, we may satisfy audit requests by providing third-party certifications or reports where we hold them.

9. International transfers

Where processing involves a transfer of personal data outside the EEA/UK/Switzerland to a country without an adequacy decision, the parties agree that the European Commission’s Standard Contractual Clauses (Module Two: controller-to-processor, and Module Three: processor-to-processor for onward transfers) are incorporated by reference, together with the UK International Data Transfer Addendum and Swiss amendments where applicable. Annex I and Annex II serve as the SCC appendices; the optional docking clause applies; the governing law and forum are as stated in the SCCs’ options selected in the executable copy.

10. Return and deletion

On termination of the Service, and at the Controller’s choice, we will delete or return Controller personal data and delete existing copies within 30 days, unless retention is required by law, in which case we will protect it and limit further processing.

11. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where applicable data-protection law prohibits such limitation.


Annex I — Details of processing

  • Subject matter: provision of the Orbie generative game-development Service.
  • Duration: the term of the Service plus the retention periods in the Privacy Policy.
  • Nature and purpose: hosting, processing, transmission, and generation of assets from Controller Inputs; account administration; security; support.
  • Categories of data subjects: the Controller’s authorised users and team members, and any individuals whose personal data is contained in the Controller’s Inputs.
  • Categories of personal data: identifiers (name, email, account/billing identifiers), usage/technical data, and any personal data the Controller chooses to include in Inputs. Special-category or children’s data should not be submitted unless agreed in writing and lawfully permitted.
  • Frequency: continuous, for the duration of the Service.

Annex II — Technical and organisational measures

  • Encryption of personal data in transit (and at rest where supported).
  • Role-based access control, least-privilege, and authentication controls.
  • Network segmentation and isolation of production environments.
  • Logging, monitoring, and alerting for security events.
  • Vulnerability management and change control.
  • Personnel confidentiality, screening as permitted by law, and security training.
  • Backup, resilience, and tested restoration procedures.
  • Vendor/sub-processor due diligence and contractual data-protection terms.

Annex III — Approved sub-processors

The current sub-processors engaged to provide the Service:

  • Cloud / compute hosting — Google Cloud Platform (Google), purpose: render fleet and storage; primary region: EU.
  • Payments — Stripe, purpose: billing and payment processing.
  • Email delivery — Resend, purpose: transactional email.
  • Error monitoring — Sentry, purpose: diagnostics and reliability.

We keep this list current and give notice of changes as described in section 5.

How to execute

For a countersigned copy, email [email protected] with your legal entity name and contact. We aim to counter-sign within two business days.