Data Processing Agreement

Last updated: 14 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditionsbetween Orbit / LVerbeeck (“we”, “us”, the “processor”) and the client using the portal (“you”, the “controller”). It applies whenever we process personal data on your behalf under the GDPR.

1. Roles & scope

You are the data controller for the personal data handled through the portal on your behalf: leads captured from your websites (names, email addresses, phone numbers, messages), review data fetched for your business listing, and personal data contained in your site content. We process that data only to provide the service to you.

2. Instructions

We process personal data only on your documented instructions — which are, in the first place, these terms and your configuration of the service — unless EU or member-state law requires otherwise, in which case we inform you before processing.

3. Confidentiality

Anyone we authorise to process personal data is bound by a contractual or statutory duty of confidentiality.

4. Security

  • Data is hosted on servers in the European Union.
  • All traffic is encrypted in transit (TLS); credentials are stored hashed.
  • Access to production systems is limited to authorised personnel and protected accounts.
  • Automated backups are kept on separate storage.

5. Subprocessors

You authorise the following subprocessors:

  • Hetzner Online GmbH (Germany) — hosting.
  • Cloudflare, Inc. (USA) — CDN, DNS, security, and static site hosting.
  • Stripe, Inc. (USA) — payment processing.
  • Amazon Web Services (SES) (EU region) — transactional email delivery.
  • Anthropic, PBC (USA) — AI features (reply drafts, content assistance).
  • SerpApi, LLC (USA) — retrieval of your public Google review data.

Subprocessors outside the EU are engaged under appropriate safeguards (Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework). We give notice before adding or replacing a subprocessor; you may object on reasonable data-protection grounds.

6. Assistance

Taking into account the nature of the processing, we assist you in responding to data-subject requests (access, rectification, erasure, objection) and in meeting your security, breach, and impact-assessment obligations.

7. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably needed for your own notification obligations.

8. Deletion & return

On termination of your account we delete the personal data we process on your behalf within 30 days, unless EU or member-state law requires longer storage. Before termination you can export your lead data from the portal.

9. Audit

We make available the information reasonably necessary to demonstrate compliance with this DPA and allow audits you reasonably request, at your cost and with reasonable notice.

10. Duration & contact

This DPA applies for as long as we process personal data on your behalf. Questions: [email protected].