Accord de traitement des données
Le contrat conformément à l'article 28 pour les données personnelles traitées par OrbitPage pour le compte du client.
En vigueur et mis à jour à : 31 août 2026Cette traduction est fournie à titre pratique. La version anglaise reste la version de référence.
1. Parties, status and formation
This Data Processing Agreement forms part of the OrbitPage Terms & Conditions. It is concluded electronically between the account holder or organisation identified by the OrbitPage account (the Customer) and Paolo Ronco, operating OrbitPage from Italy (the Processor). It becomes binding when the Customer accepts the Terms or first submits Customer Personal Data to a processor feature.
It applies only where the Customer determines the purposes and essential means of processing and OrbitPage processes personal data on the Customer's behalf. OrbitPage remains an independent controller for account administration, billing, service security, fraud and abuse prevention, legal compliance and its own website analytics, as explained in the Privacy Policy.
Customer Personal Data, controller, processor, processing and personal data breach have the meanings given by Regulation (EU) 2016/679 (GDPR).
2. Scope, duration and documented instructions
OrbitPage processes Customer Personal Data to provide the hosted workspace, publication, consent controls, newsletter, Shop, booking, delivery, support and connected features selected by the Customer. Processing continues for the term of the service and the deletion periods described below.
The Customer's documented instructions are this DPA, the Terms, the Customer's configuration and content, authenticated Dashboard and API actions, and written support instructions consistent with the service. OrbitPage will process Customer Personal Data only on those instructions, including for international transfers, unless Union or Member State law requires otherwise. Where legally permitted, OrbitPage will inform the Customer before that required processing.
OrbitPage will promptly inform the Customer if an instruction appears to infringe applicable data-protection law and may suspend the affected instruction while the parties clarify it.
3. Processor obligations
OrbitPage will ensure that authorised personnel process Customer Personal Data only as needed for their duties and are bound by confidentiality; maintain measures appropriate to the risk under Article 32 GDPR; impose equivalent data-protection duties on subprocessors; assist the Customer with data-subject rights, security, breach assessment, DPIAs and prior consultation where the nature of the service and available information permit; delete or return data as set out in section 11; and make the information necessary to demonstrate compliance with Article 28 available under section 10.
4. Customer obligations
The Customer is responsible for lawful, fair and transparent instructions; notices and legal bases; data accuracy and minimisation; responding to data subjects; configuring retention, consent and recipients; and ensuring that its users and selected third-party services are authorised. The Customer must not use OrbitPage to process special-category data, criminal-offence data, large-scale systematic monitoring or data about children without a separate written agreement confirming that the service and safeguards are suitable.
The Customer must protect account, SMTP, API and connected-service credentials, grant minimum necessary access and notify OrbitPage promptly of suspected compromise. The Customer remains responsible for independent providers it selects, including its SMTP, analytics, consent-management, booking, form and embedded-content providers.
5. Security and confidentiality
OrbitPage applies the measures in Annex II and may update them as technology and risk change, provided the overall protection of Customer Personal Data is not materially reduced. No measure creates an uptime, recovery-time or recovery-point guarantee unless a separate signed service-level agreement expressly states one.
6. Data-subject and compliance assistance
Taking account of the nature of processing, OrbitPage will provide available self-service tools and reasonable assistance for access, correction, export, restriction, objection and deletion requests. If OrbitPage receives a request relating primarily to Customer Personal Data, it will direct the requester to the Customer or forward the request where lawful and reasonably identifiable, and will not respond on the Customer's behalf unless instructed or legally required.
OrbitPage will provide information reasonably available to assist with Articles 32 to 36 GDPR. Work requiring custom development, extensive retrieval or third-party professional services may be charged at an agreed reasonable rate unless caused by OrbitPage's breach of this DPA.
7. Personal data breaches
OrbitPage will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and people where known, likely consequences, mitigation and a contact point. OrbitPage may provide information in phases and will take reasonable steps to contain, investigate and remediate the incident. Notification is not an admission of fault.
8. Subprocessors
The Customer gives general written authorisation for the subprocessors on the Subprocessors page, which is incorporated as Annex III. OrbitPage remains responsible for their performance of applicable processor duties and will bind them to data-protection obligations appropriate to the service.
OrbitPage will give reasonable advance notice through the service or account contact before a new or replacement subprocessor begins a materially different processing activity where required. The Customer may object on documented data-protection grounds before the announced change. The parties will seek a reasonable solution; if none is available, the Customer may stop using the affected feature or terminate the affected paid service.
9. International transfers
Where Customer Personal Data is transferred outside the EEA to a country without an applicable adequacy decision, OrbitPage will use a lawful transfer mechanism, including the 2021 European Commission Standard Contractual Clauses where appropriate, and supplementary measures required by the transfer assessment. Current provider locations and safeguards are described on the Subprocessors page.
10. Information and audits
On reasonable written request, OrbitPage will provide information needed to demonstrate compliance with this DPA, such as relevant policies, provider terms, security summaries and responses to a proportionate questionnaire. No more than once in a twelve-month period, unless a breach, authority request or credible material non-compliance justifies more, the Customer may request an audit by an independent qualified auditor bound by confidentiality.
Audits require reasonable advance notice, must avoid disruption and may not expose another customer's data, security secrets or privileged material. The Customer bears its audit costs unless the audit identifies a material breach by OrbitPage. Contact contact@orbitpage.com to begin this process.
11. Return and deletion
During the service term, the Customer can retrieve supported workspace data through the available export and backup functions. On request made before account closure, OrbitPage will provide reasonable assistance with an available export. When the Customer deletes the account or the service ends, OrbitPage deletes Customer Personal Data from active systems according to the Privacy Policy, unless the Customer requests return before deletion or applicable law requires retention.
Provider backups and immutable security records remain protected and expire on their controlled schedules. Data retained for law, fraud prevention, disputes or legal claims is isolated from ordinary product use and deleted when that purpose ends. At the Customer's request, OrbitPage will confirm completion of the applicable active-system deletion process.
12. Priority, liability, term and contact
If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. The Terms govern all other matters, including liability, payment, suspension, governing law and disputes, without limiting rights or liability that cannot lawfully be limited under data-protection law.
This DPA remains effective while OrbitPage processes Customer Personal Data. Updates follow the change process in the Terms and will not materially reduce mandatory Article 28 protections. Data-protection notices and requests may be sent through the contact page or to contact@orbitpage.com.
Annex I — Processing details
Annex II — Technical and organisational measures
- HTTPS/TLS for supported data in transit and provider-managed protection for stored service data.
- Firebase authentication, verified identities where required, tenant membership checks, role-based permissions and server-side authorisation.
- Server-side secrets, one-way hashing of API credentials and encryption of Customer-supplied SMTP passwords.
- Tenant-scoped records, validated publication paths, private object storage for protected files and time-limited delivery credentials.
- Rate limits, App Check or equivalent request attestation where configured, abuse controls, moderation safeguards and operational logging.
- Revision history, managed backups where configured, deployment checks, incident procedures and controlled credential rotation.
- Data minimisation, bounded AI context, restricted provider credentials and deletion/export controls described in the Privacy Policy.
- Personnel confidentiality, least-privilege provider access and review of subprocessors appropriate to their role.
Annex III — Authorised subprocessors
The current list, purpose, data scope and provider documentation are maintained on the Subprocessors page. Customer-selected SMTP, analytics, consent, booking, form and embed providers are controlled by the Customer and are not appointed by OrbitPage as platform subprocessors for those Customer-selected uses.